Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

EasyA-Z.com browser hijack


  • This topic is locked This topic is locked
13 replies to this topic

#1 Mr Lau

Mr Lau

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 10 May 2012 - 05:59 PM

Hi there, I'm running Windows 7 Home Premium and keep getting redirected from google to Easy A-Z.com.

Avira Free is installed and is not picking up any viruses but I still get redirected to Easy A-Z.com
Malwarebytes doesn't show anything either.

Here's the log from DDS:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.0.0
Run by William at 23:55:37 on 2012-05-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8104.5459 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
FW: ZoneAlarm Free Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\windows\system32\svchost.exe -k apphost
C:\windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\viakaraokesrv.exe
C:\windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\windows\system32\conhost.exe
C:\Windows\system32\WUDFHost.exe
C:\windows\system32\taskhost.exe
C:\windows\System32\rundll32.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\William\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
C:\windows\splwow64.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\windows\system32\sppsvc.exe
C:\program files (x86)\avira\antivir desktop\avcenter.exe
C:\program files (x86)\avira\antivir desktop\avscan.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\AUDIODG.EXE
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://nmd.msn.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
StartupFolder: C:\Users\William\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\William\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{65BD9CB7-16A0-438A-93BA-8902DBA1FA61} : DhcpNameServer = 192.168.1.1 192.168.1.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
BHO-X64: ZoneAlarm Security Engine Registrar - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun-x64: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\William\AppData\Roaming\Mozilla\Firefox\Profiles\icbyerx8.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll
FF - plugin: C:\Program Files\VLC\npvlc.dll
FF - plugin: C:\Users\William\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 ioatdma;Intel® QuickData Technology device;C:\windows\system32\Drivers\ioatdma.sys --> C:\windows\system32\Drivers\ioatdma.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]
R0 PxHlpa64;PxHlpa64;C:\windows\system32\Drivers\PxHlpa64.sys --> C:\windows\system32\Drivers\PxHlpa64.sys [?]
R1 avkmgr;avkmgr;C:\windows\system32\DRIVERS\avkmgr.sys --> C:\windows\system32\DRIVERS\avkmgr.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-9-14 169624]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-5-10 86224]
R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-5-10 110032]
R2 avgntflt;avgntflt;C:\windows\system32\DRIVERS\avgntflt.sys --> C:\windows\system32\DRIVERS\avgntflt.sys [?]
R2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2012-3-16 33672]
R2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe [2012-3-16 827520]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-7 654408]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\windows\system32\viakaraokesrv.exe --> C:\windows\system32\viakaraokesrv.exe [?]
R3 athur;Wireless Network Adapter Service;C:\windows\system32\DRIVERS\athurx.sys --> C:\windows\system32\DRIVERS\athurx.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\windows\system32\drivers\viahduaa.sys --> C:\windows\system32\drivers\viahduaa.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys --> C:\windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-12 136176]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-1 183560]
S3 fssfltr;fssfltr;C:\windows\system32\DRIVERS\fssfltr.sys --> C:\windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-12 136176]
S3 ioatdma1;ioatdma1;C:\windows\system32\Drivers\qd162x64.sys --> C:\windows\system32\Drivers\qd162x64.sys [?]
S3 ioatdma2;Intel® QuickData Technology device ver.2;C:\windows\system32\Drivers\qd262x64.sys --> C:\windows\system32\Drivers\qd262x64.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-4 129976]
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;C:\windows\system32\DRIVERS\netr28x.sys --> C:\windows\system32\DRIVERS\netr28x.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\windows\system32\drivers\nusb3hub.sys --> C:\windows\system32\drivers\nusb3hub.sys [?]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\windows\system32\drivers\nusb3xhc.sys --> C:\windows\system32\drivers\nusb3xhc.sys [?]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\windows\system32\drivers\nvstusb.sys --> C:\windows\system32\drivers\nvstusb.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-05-10 22:07:42 -------- d-----w- C:\Users\William\AppData\Roaming\CheckPoint
2012-05-10 22:07:35 -------- d-----w- C:\Program Files\CheckPoint
2012-05-10 22:06:34 -------- d-----w- C:\Program Files (x86)\CheckPoint
2012-05-10 22:06:06 -------- d-----w- C:\ProgramData\CheckPoint
2012-05-10 21:54:24 -------- d-----w- C:\Users\William\AppData\Roaming\Avira
2012-05-10 21:48:54 97312 ----a-w- C:\windows\System32\drivers\avgntflt.sys
2012-05-10 21:48:54 27760 ----a-w- C:\windows\System32\drivers\avkmgr.sys
2012-05-10 21:48:54 -------- d-----w- C:\ProgramData\Avira
2012-05-10 21:48:54 -------- d-----w- C:\Program Files (x86)\Avira
2012-05-09 23:48:08 8917360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CA3DEFE2-2E5D-41DD-B933-08081A1894E3}\mpengine.dll
2012-05-08 21:22:24 8917360 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-07 11:52:16 -------- d-----w- C:\Users\William\AppData\Roaming\Malwarebytes
2012-05-07 11:52:02 24904 ----a-w- C:\windows\System32\drivers\mbam.sys
2012-05-07 11:52:02 -------- d-----w- C:\ProgramData\Malwarebytes
2012-05-07 11:52:02 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-07 11:43:40 -------- d-----w- C:\$RECYCLE.BIN
2012-05-07 11:34:31 98816 ----a-w- C:\windows\sed.exe
2012-05-07 11:34:31 518144 ----a-w- C:\windows\SWREG.exe
2012-05-07 11:34:31 256000 ----a-w- C:\windows\PEV.exe
2012-05-07 11:34:31 208896 ----a-w- C:\windows\MBR.exe
2012-05-07 11:31:43 -------- d-----w- C:\windows\pss
2012-05-06 22:04:46 -------- d-----w- C:\Users\William\AppData\Roaming\fifa
2012-05-06 22:03:58 -------- d-----w- C:\Users\William\AppData\Local\{5F46DF5E-97C7-11E1-826E-B8AC6F996F26}
2012-05-06 22:03:58 -------- d-----w- C:\Users\William\AppData\Local\{5F46AD4A-97C7-11E1-826E-B8AC6F996F26}
2012-05-04 19:51:01 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-05-04 19:50:58 157352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 19:50:58 129976 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-04-26 20:46:49 -------- d-----r- C:\Users\William\Dropbox
2012-04-26 20:44:28 -------- d-----w- C:\Users\William\AppData\Roaming\Dropbox
2012-04-17 21:36:44 -------- d-----w- C:\Program Files (x86)\MSECache
2012-04-16 21:02:28 -------- d-----w- C:\Users\William\AppData\Local\CutePDF Writer
2012-04-16 21:00:49 -------- d-----w- C:\Program Files (x86)\GPLGS
2012-04-16 21:00:20 86608 ----a-w- C:\windows\System32\cpwmon64.dll
2012-04-16 21:00:19 -------- d-----w- C:\Program Files (x86)\Acro Software
2012-04-15 15:06:27 -------- d-----w- C:\Program Files (x86)\AndreaMosaic
2012-04-14 11:04:17 -------- d-----w- C:\Program Files (x86)\Lame For Audacity
2012-04-14 11:01:35 -------- d-----w- C:\Program Files (x86)\Audacity
2012-04-12 17:49:59 81408 ----a-w- C:\windows\System32\imagehlp.dll
2012-04-12 17:49:59 23408 ----a-w- C:\windows\System32\drivers\fs_rec.sys
2012-04-12 17:49:59 159232 ----a-w- C:\windows\SysWow64\imagehlp.dll
2012-04-12 17:49:55 5120 ----a-w- C:\windows\SysWow64\wmi.dll
2012-04-12 17:49:55 5120 ----a-w- C:\windows\System32\wmi.dll
2012-04-12 17:49:55 220672 ----a-w- C:\windows\System32\wintrust.dll
2012-04-12 17:49:55 172544 ----a-w- C:\windows\SysWow64\wintrust.dll
2012-04-11 16:56:18 419488 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
.
==================== Find3M ====================
.
2012-05-06 22:04:10 70304 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-01 20:31:54 544656 ----a-w- C:\windows\SysWow64\deployJava1.dll
2012-04-01 20:09:45 627600 ----a-w- C:\windows\System32\deployJava1.dll
2012-03-31 06:05:57 5559664 ----a-w- C:\windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\windows\System32\drivers\tcpip.sys
2012-03-20 19:44:12 98688 ----a-w- C:\windows\System32\drivers\NisDrvWFP.sys
2012-03-20 19:44:12 203888 ----a-w- C:\windows\System32\drivers\MpFilter.sys
2012-03-17 07:58:57 75120 ----a-w- C:\windows\System32\drivers\partmgr.sys
2012-03-03 06:35:38 1544704 ----a-w- C:\windows\System32\DWrite.dll
2012-03-03 05:31:19 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll
2012-02-28 06:56:48 2311168 ----a-w- C:\windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb
2012-02-17 06:38:26 1031680 ----a-w- C:\windows\System32\rdpcore.dll
2012-02-17 05:34:22 826880 ----a-w- C:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32 23552 ----a-w- C:\windows\System32\drivers\tdtcp.sys
2006-11-16 12:45:54 35 ----a-w- C:\Program Files\run.bat
2006-11-16 11:01:40 4382208 ----a-w- C:\Program Files\IU.MSP
.
============= FINISH: 23:56:08.01 ===============


Thanks

Will

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 11 May 2012 - 12:35 AM

Hello and Welcome to Bleeping Computer!!

My name is Gringo and I'll be glad to help you with your computer problems.

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of hartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

:multiple Anti Virus programs:

It looks like you are operating your computer with multiple Anti Virus programs running in memory at once:

AV: Avira Desktop
AV: Microsoft Security Essentials


Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

Please remove all but one of them.

Security Check

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 12 May 2012 - 05:21 AM

Hi there, thanks for your reply and your assistance. MSE was uninstalled. Here are the logs:




ComboFix 12-05-10.04 - William 12/05/2012 1:01.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8104.6277 [GMT 1:00]
Running from: c:\users\William\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-04-12 to 2012-05-12 )))))))))))))))))))))))))))))))
.
.
2012-05-12 00:06 . 2012-05-12 00:06 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2012-05-12 00:06 . 2012-05-12 00:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-10 23:08 . 2012-05-10 23:08 -------- d-----w- c:\program files\Microsoft Silverlight
2012-05-10 23:08 . 2012-05-10 23:08 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-05-10 22:07 . 2012-05-10 22:07 -------- d-----w- c:\users\William\AppData\Roaming\CheckPoint
2012-05-10 22:06 . 2012-05-10 22:06 -------- d-----w- c:\programdata\CheckPoint
2012-05-10 21:54 . 2012-05-10 21:54 -------- d-----w- c:\users\William\AppData\Roaming\Avira
2012-05-10 21:48 . 2012-05-11 21:54 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-10 21:48 . 2012-05-11 21:54 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-05-10 21:48 . 2012-05-10 21:48 -------- d-----w- c:\programdata\Avira
2012-05-10 21:48 . 2012-05-10 21:48 -------- d-----w- c:\program files (x86)\Avira
2012-05-10 21:48 . 2011-09-16 15:09 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-05-10 20:29 . 2012-05-10 20:29 -------- d-----w- c:\users\William\AppData\Roaming\dvdcss
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\users\William\AppData\Roaming\Malwarebytes
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\programdata\Malwarebytes
2012-05-07 11:52 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-06 22:04 . 2012-05-06 22:05 -------- d-----w- c:\users\William\AppData\Roaming\fifa
2012-05-06 22:03 . 2012-05-06 22:03 -------- d-----w- c:\users\William\AppData\Local\{5F46DF5E-97C7-11E1-826E-B8AC6F996F26}
2012-05-06 22:03 . 2012-05-06 22:03 -------- d-----w- c:\users\William\AppData\Local\{5F46AD4A-97C7-11E1-826E-B8AC6F996F26}
2012-05-05 09:26 . 2012-05-11 22:27 -------- d-----w- c:\users\William\AppData\Roaming\Skype
2012-05-04 19:51 . 2012-05-04 19:51 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-05-04 19:50 . 2012-05-04 19:50 157352 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 19:50 . 2012-05-04 19:50 129976 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-04-26 20:46 . 2012-05-11 21:28 -------- d-----r- c:\users\William\Dropbox
2012-04-26 20:44 . 2012-05-11 21:28 -------- d-----w- c:\users\William\AppData\Roaming\Dropbox
2012-04-17 21:36 . 2012-04-17 21:36 -------- d-----w- c:\program files (x86)\MSECache
2012-04-16 21:02 . 2012-04-16 21:45 -------- d-----w- c:\users\William\AppData\Local\CutePDF Writer
2012-04-16 21:00 . 2012-04-16 21:00 -------- d-----w- c:\program files (x86)\GPLGS
2012-04-16 21:00 . 2012-03-11 13:56 86608 ----a-w- c:\windows\system32\cpwmon64.dll
2012-04-16 21:00 . 2012-04-16 21:00 -------- d-----w- c:\program files (x86)\Acro Software
2012-04-15 15:06 . 2012-04-15 15:08 -------- d-----w- c:\program files (x86)\AndreaMosaic
2012-04-14 11:04 . 2012-04-14 11:04 -------- d-----w- c:\program files (x86)\Lame For Audacity
2012-04-14 11:03 . 2012-04-14 11:19 -------- d-----w- c:\users\William\AppData\Roaming\Audacity
2012-04-14 11:01 . 2012-04-14 11:01 -------- d-----w- c:\program files (x86)\Audacity
2012-04-12 17:49 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 17:49 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 17:49 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-12 17:49 . 2012-03-01 06:38 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 17:49 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 17:49 . 2012-03-01 05:37 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-12 17:49 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-06 22:04 . 2012-04-11 16:56 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-06 22:04 . 2011-11-07 13:52 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-01 20:31 . 2012-04-01 20:31 544656 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-01 20:09 . 2012-04-01 20:09 627600 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-26 18:55 . 2011-03-28 18:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-02-17 06:38 . 2012-03-13 18:36 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-13 18:36 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-13 18:36 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-13 18:36 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2006-11-16 12:45 . 2012-02-24 22:00 35 ----a-w- c:\program files\run.bat
2006-11-16 11:01 . 2012-02-24 21:59 4382208 ----a-w- c:\program files\IU.MSP
.
.
((((((((((((((((((((((((((((( SnapShot@2012-05-07_11.43.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-11 00:58 . 2011-06-11 00:58 51024 c:\windows\SysWOW64\vcomp100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\SysWOW64\mfcm100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 81744 c:\windows\SysWOW64\mfcm100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 60752 c:\windows\SysWOW64\mfc100rus.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43344 c:\windows\SysWOW64\mfc100kor.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 43856 c:\windows\SysWOW64\mfc100jpn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 62288 c:\windows\SysWOW64\mfc100ita.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\SysWOW64\mfc100fra.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 63824 c:\windows\SysWOW64\mfc100esn.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 55120 c:\windows\SysWOW64\mfc100enu.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 64336 c:\windows\SysWOW64\mfc100deu.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\SysWOW64\mfc100cht.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 36176 c:\windows\SysWOW64\mfc100chs.dll
- 2009-07-14 04:54 . 2012-03-17 22:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-05-10 23:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-03-17 22:04 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-10 23:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-10 23:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-17 22:04 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-21 03:09 . 2012-05-11 21:30 41544 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-05-11 21:30 34714 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-02-24 20:17 . 2012-05-11 21:30 10198 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1360622652-2071615853-753804455-1000_UserData.bin
- 2009-07-14 05:30 . 2012-03-10 22:25 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2012-05-10 23:14 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-05-08 21:19 . 2012-03-17 07:58 75120 c:\windows\system32\drivers\partmgr.sys
+ 2009-07-14 04:46 . 2012-05-10 22:57 93528 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-12-15 13:01 . 2011-12-15 13:01 68880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 57616 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2012-04-12 17:53 . 2012-04-12 17:53 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-04-11 03:55 . 2012-04-11 03:55 41472 c:\windows\Installer\25cd1e.msi
+ 2012-02-24 22:04 . 2012-05-08 23:24 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-05-08 23:24 . 2012-05-08 23:24 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2012-04-20 21:56 . 2012-04-20 21:56 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2012-05-10 19:11 . 2012-05-10 19:11 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\e34c413f0e39f444adbb5965d02430ef\System.Windows.Presentation.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\dc413d5d31ec337f7452fcc2bd57deb6\System.Web.ApplicationServices.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\e144d0028365c62178eb0662911ac910\System.AddIn.Contract.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\93295f3771dc9e5be2d49d5f5d76a7a6\Microsoft.VisualC.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5ea625ce2d6c08687f70cb81a003a28b\dfsvc.ni.exe
+ 2012-05-10 19:08 . 2012-05-10 19:08 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\061cbee19075e086d675a9e1f65725d7\Accessibility.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\4add87007e0864467659e6a248a7fe06\UIAutomationProvider.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\5172f64c070a65b834e61f5cd6d0e632\System.Windows.Presentation.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\64032bf6e0ddb07ec8e374dae9afcd17\System.Web.ApplicationServices.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76ba7b2f5232c390b8db9dfcd935af93\System.ServiceModel.Channels.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\a5c37bc9caf315df294f8b680a1ccd6f\System.AddIn.Contract.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\5ccc57bb582bf753166610089f204601\Microsoft.VisualC.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\414da765b5d5bb7fde97c0ea22de7d74\Accessibility.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\fb4bc14964a1d415bdbe55b62ce73a52\System.Windows.Presentation.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\acd8bdefdcae0ce7c27b5ec016ef865c\System.Web.DynamicData.Design.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\ee709a01b51c82626f4b2c1173f2db28\stdole.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\78f495970511b726a0ca7b8119360e25\PresentationFontCache.ni.exe
+ 2012-05-09 20:49 . 2012-05-09 20:49 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\1a359e9b908a2565c546a8ca04b241c2\PresentationCFFRasterizer.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\9d57c4bbbc0b3243046fc7839da71b00\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\d6578432220dbabf2b15027681327bf8\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\66deb65a87750efddf62d1e0c0655352\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4b6402dc918e41b8de8c501f29833d91\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\28545d2b6a0aaef4aa168f9808603bc5\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1d8a17a2c1416a8ad4d6ad2a28b4c5fd\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\0abc7256549c204f39af7dcc52c9e5d5\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\3c3a6cce983114e7406e0a6e6116ecd8\Microsoft.VisualC.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6ab0575bf49b60fd4b697d47e1754072\Microsoft.MediaCenter.iTv.Hosting.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\1569a004b1f41193818e3b3777f2c73d\LoadMxf.ni.exe
+ 2012-05-10 05:25 . 2012-05-10 05:25 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\3ee98e8b2084e27d65953bbd7e362bf8\ehiUPnP.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\1cd9f92749d29b9fd61fcb1c4ae84294\ehiTVMSMusic.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0811f67973c32efb2bfad62a4a2592b5\dfsvc.ni.exe
+ 2012-05-09 20:48 . 2012-05-09 20:48 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\ae9311dcb0e713330a2a86b04cf361dc\Accessibility.ni.dll
+ 2012-05-10 01:31 . 2012-05-10 01:31 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\9c08aba33effec93e02906727f539866\WindowsLiveWriter.ni.exe
+ 2012-05-10 19:04 . 2012-05-10 19:04 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4bd9d7d8d3686f779672029df66df150\WindowsLive.Writer.Passport.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\66d750f3f8dde0cc865f921497ab3545\System.Windows.Presentation.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c1ea7869d01b1b668de2181be6ebca56\System.Web.DynamicData.Design.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\543b0e12423bcec010bdd2ac27c5dc04\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f34410ab8e82063735d876533db26c49\System.AddIn.Contract.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\d24744f15243e28ea541a459ff7ff5d5\PresentationFontCache.ni.exe
+ 2012-05-09 20:47 . 2012-05-09 20:47 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\87a30ba337ed55d0905f19742e2985bc\napcrypt.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\9f2e8e0df9ff39ad21088f1d66cfadb1\Microsoft.WSMan.Runtime.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\d797123d55bb7b823120d0a7ffbbc2a7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb8ad29814d9e5589bd400d38e7a0b10\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb42a0f25b7608b2675080081b03f6e5\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\c6e9143be5afb36345875d56b61c444f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\91767cf3facefe10e00734c815e925ad\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\66cd99d2f576cde047074e98bd5e1848\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\4308e1bdc640e1c3f1ea966e84e48900\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\06fcf2fbbe38d9425fc49d935498ec93\Microsoft.Vsa.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e3ef400b1f37e4d3b79a42a8a602ea02\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2095344bf8c40f8baa94ba53a993fb4c\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\dc93539af5a961641a26ada75f730136\ehiUserXp.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\53d03b0e238c77cf7e5ac88e02aecd2c\dfsvc.ni.exe
+ 2012-05-09 20:46 . 2012-05-09 20:46 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
+ 2012-05-12 00:07 . 2012-05-12 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-05-07 11:43 . 2012-05-07 11:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-05-07 11:43 . 2012-05-07 11:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-05-12 00:07 . 2012-05-12 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-05-10 19:06 . 2012-05-10 19:06 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\1361a05238cfe45d7da6cb4b367a986c\dfsvc.ni.exe
+ 2011-06-11 00:58 . 2011-06-11 00:58 773968 c:\windows\SysWOW64\msvcr100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 421200 c:\windows\SysWOW64\msvcp100.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 138056 c:\windows\SysWOW64\atl100.dll
+ 2012-03-02 21:36 . 2012-05-11 05:54 208260 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-07-14 02:36 . 2012-05-11 23:51 703364 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-05-11 23:51 137512 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:30 . 2012-05-10 23:14 239616 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-03-10 22:25 239616 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-02-24 20:48 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2012-05-10 23:14 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:01 . 2012-05-12 00:06 810468 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-05-07 11:31 810468 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-12-15 13:01 . 2011-12-15 13:01 226600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 156440 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 598784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2012-05-08 21:19 . 2012-02-10 23:29 172320 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 486144 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 182056 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 156440 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 518400 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 957200 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 386824 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 131360 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2012-05-08 21:19 . 2012-01-04 02:50 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2012-05-08 21:19 . 2012-01-04 02:50 996624 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 231760 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 231760 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 616216 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 616216 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 156440 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2011-02-19 22:08 . 2011-02-19 22:08 163840 c:\windows\Installer\b913c6.msi
- 2012-02-24 22:04 . 2012-04-12 17:52 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-03-18 13:16 . 2010-03-18 13:16 181096 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_X86.dll
+ 2010-03-18 14:27 . 2010-03-18 14:27 225640 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_AMD64.dll
+ 2011-01-14 06:10 . 2011-01-14 06:10 155520 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD6.DLL
+ 2011-01-14 06:10 . 2011-01-14 06:10 140160 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL2.DLL
+ 2011-09-15 20:41 . 2011-09-15 20:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WINWORD.EXE
+ 2012-05-10 19:11 . 2012-05-10 19:11 337408 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\e3b05df5a0142d8d945c1c52fd6c0fdf\WindowsFormsIntegration.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\fb43d84bc59b21e8a7f3e36d616eea90\UIAutomationTypes.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\26f12a0a3baed2a227cf30aaeae03913\UIAutomationProvider.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\0c30a04c2a2ce726e9df80e63b9941fe\UIAutomationClient.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 525824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\cca2655b780a81391a36911c9c77da47\System.Xml.Linq.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 254976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\63eef49d5fa6aa154afdab1f24fcb1f2\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\2c0396b17ab45c876b0b8a9a2e2e07f9\System.Transactions.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\3ac099d351880b4dac6dc3db936be70f\System.ServiceProcess.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 107520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\dc3dd654dd6a25415648e45aaebd4c10\System.ServiceModel.Channels.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 507904 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\6f2503d889641a3b1dc64d1dd3614899\System.ServiceModel.Routing.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 939520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\8be3df0dcf6323d96fd70cd9742dd580\System.Security.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 376320 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\e452508116ce025d9d217b946bf4da23\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\364e049574be99cecd8ea194d7d0aef6\System.Runtime.Remoting.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\5f2bfb0585061dc256ee9587d430959f\System.Numerics.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 930304 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\5ad4774a3c57720615e31c4025124511\System.Net.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\f933b5dc77839f4ac1a00a922e5e3d8e\System.Messaging.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\0c07bb03259038de82006be95ff39ef9\System.Management.Instrumentation.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\fb3879c8826f6b033438828121d9f19b\System.IO.Log.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\38b2a14002c7e932f2339b92ca177ab0\System.IdentityModel.Selectors.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\83c68e06cc189bf09bbaad27dea4c2ca\System.EnterpriseServices.Wrapper.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 511488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\de61e364c22b35e0314e894d92f27766\System.Dynamic.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 628736 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\00843dd1d0c08cb07d02ecee0d72aeb1\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\73e93e2850ef84b2ee92de3cee3edfbe\System.Device.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\100e1ef222674959a460bee836b23c07\System.Data.DataSetExtensions.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 181248 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\70f2b200f3014536034ff198da0a792a\System.Configuration.Install.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\083ea7b0572d76f7143decc04861eab4\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 871936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\40633de91a680a2fc0abfdaa010c5a07\System.AddIn.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 552960 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\50b2ac698d62562e0b4eda282d13ca54\System.Activities.DurableInstancing.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 430080 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\01f30c1d8d7c197fa009ca7f80527197\SMSvcHost.ni.exe
+ 2012-05-10 19:09 . 2012-05-10 19:09 184832 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\9663e78670b85973d8c0f91d35bcd855\SMDiagnostics.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\db00b66060d6268ae0a27b206f2246ea\PresentationFramework.Royale.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\7e8c4d8904eba7c0b96c5b256bb83dc9\PresentationFramework.Classic.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\6970999fae28b1a2445c271e55c679eb\PresentationFramework.Luna.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3bb2e7347dca5840f4aaa7aa1e23004c\PresentationFramework.Aero.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 422912 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\2cae1f40fca6bf47ffd47f14a3cb6841\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\903978da69aaad4ccc24f7bf824839e6\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\0e81a3996f7cbff23fc01bea4185a918\CustomMarshalers.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\08865eb19bdd47a2cb9fb382e3ab4ca9\WindowsFormsIntegration.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\6823effdbb0434f96511748697349862\UIAutomationTypes.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\067c005d73ef58a2c3b85c1eb1f82468\UIAutomationClient.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 391680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\738d3077763a0ce3ddf9228b5854e26d\System.Xml.Linq.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 188928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\eaa4a186f9f15fe9e94ce946b603e42e\System.Windows.Input.Manipulations.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 646656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\530e202cb070fa04243f083c48c7723c\System.Transactions.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\a0c81f698208f3a0e93b054d7ebe7ee6\System.ServiceProcess.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 365056 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c59256d906eb8bf251fdcade8d3e8db8\System.ServiceModel.Routing.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 729088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\3a852d2bd1860c7e917dd7ae2676c97c\System.Security.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\1ea68db6df26604de2e14af08dde4adb\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 762368 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\dbb4966fd679de3336ad5a15e44e1cb2\System.Runtime.Remoting.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 145408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\360e9c00572679f437fff0ae719a5886\System.Numerics.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 652800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\24d2d4150f7c122d6c66cf7574db5b2f\System.Net.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\e9075140a13aa2ea0756540bdee37137\System.Messaging.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\5cb0d92749a57afb6f7fb8220fd5a23d\System.Management.Instrumentation.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\ee6b0560b2f6fe2c590144b716767ac9\System.IO.Log.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 229376 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\fc5861a7b6a55a0179ec33611a25725c\System.IdentityModel.Selectors.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\56d1e62510421b3721142688b44a581b\System.EnterpriseServices.Wrapper.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 786944 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\56d1e62510421b3721142688b44a581b\System.EnterpriseServices.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 377344 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\f32323be4d8b7b9b47e3605ee2cfff18\System.Dynamic.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 468992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\c953921036f6785c65d591bf7308cb46\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\37878191c4d2cea35b7d78b3530f862b\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\6aaf2213386341b4c3d3b3ad0c6438dd\System.Device.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\623f6a322d104b4424aae3a9fb34e13f\System.Data.DataSetExtensions.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 980480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\4b1f1878bf47391d09f9e256fde70e4b\System.Configuration.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\93850f026d034279e163228fe629b674\System.Configuration.Install.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\86c524ba4d7c611933fd831482fc37b2\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 690176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\1f22e510d8f22aebc2ad37944ae9e5b4\System.ComponentModel.Composition.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 624128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\847a89aa3ca79dd380995cb43694d6e9\System.AddIn.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 404992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\48a515b17e8631c620aa0b293a0eb594\System.Activities.DurableInstancing.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\492f2a986cfa8ec67862fc9aef1d0a88\SMSvcHost.ni.exe
+ 2012-05-10 19:06 . 2012-05-10 19:06 142848 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\13a7f21e234d2c7587f7a0b58a17d591\SMDiagnostics.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 755712 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\e28fd0201f1e3003f2f6043b491c69b3\PresentationFramework.Luna.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 387072 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\ae8a309e2b2ff2df84ad53a60c69d157\PresentationFramework.Royale.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 309760 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\53259db9c53023068d56fbfdb75e7f70\PresentationFramework.Classic.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 595968 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\124775115f8585454f2f7470b74a7d8d\PresentationFramework.Aero.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\becdc726fc4f3d576f5d466488d784d4\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\7b9889431566039e4eda08930c626d67\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\8f0e78c2aa12e929ecf3b0c912ac8406\CustomMarshalers.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\ad7f43afb4f124acae4d503b40f591c1\WsatConfig.ni.exe
+ 2012-05-10 19:08 . 2012-05-10 19:08 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\cefe28fde401a6a5718d1718c345fb37\WindowsFormsIntegration.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\bf634b0e2e28466c6ed6ae1eb602b09f\UIAutomationTypes.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\1ff8fb81d6f045f1dc6f50be95444292\UIAutomationProvider.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\1f36e020c3563e0ff414f13138e238e1\UIAutomationClient.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\769b7666d915de95db5b63ec22bf3e42\TaskScheduler.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\de45d043775d8c805f6feca40d7a9ed2\System.Xml.Linq.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\181702fb83901c085401957c6f731cf4\System.Web.Routing.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\76662ce36d2141e45513e64386073cc2\System.Web.RegularExpressions.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\9b9d3e3e44dc7d03bb96033a5b829a6b\System.Web.Entity.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\ad2339c5f0fd9aa8a9989800825da487\System.Web.Entity.Design.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\8309dc5dd39b93f3e105a4d455b74a00\System.Web.DynamicData.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\a79640760b61cc1c23ac3cfdfa6f0f3f\System.Web.Abstractions.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\ec95ad2463c5588fc8ef552b3f375ee6\System.Transactions.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\05acafa7eb44049849a5aafd39147ee5\System.ServiceProcess.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\1875b50d0228f29aef00bed38ab594d6\System.Security.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\807759890a40e4047c35a24e64dc76d5\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\3b3581851a728bef36f319e9d4c72499\System.Net.ni.dll
+ 2012-05-10 05:24 . 2012-05-10 05:24 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\b4297ef47e0839fce0145f665349dcc9\System.Messaging.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\599954438a668c94dd38e8e7e506ac2a\System.Management.Instrumentation.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 569856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\fd51741bfd973ad507bbd141e98932f8\System.IO.Log.ni.dll
+ 2012-05-10 05:24 . 2012-05-10 05:24 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\ef6abe121bb11bff2514bfdfb7e76b7a\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\e7abd70c16a5e638a7121fc5f68484cc\System.Drawing.Design.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\4bb1134d9b166434327385ddf3c5dd54\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 629760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\7c4ce1b8a2f83ef29aa6d5f126ab5b71\System.Data.Services.Design.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\19d1414f1ca718ce4d0c07e7305b3450\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\4aebed13b5309398cd809454cafe472f\System.Configuration.Install.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\9536bb262c4f1ea389d287ab669767d4\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 890880 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\84262138e2e9f34c88fd282caa82baa5\System.AddIn.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\176899be7b920fb20408ff49e636a776\System.AddIn.Contract.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\ee0608cd62dfb37016016884fc39e425\sysglobl.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\9fa1abf006689e262527ae50d452e97e\SMSvcHost.ni.exe
+ 2012-05-10 05:24 . 2012-05-10 05:24 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\2eac9c598de3341eba5c16787c74f220\SMDiagnostics.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 282624 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\89de197bdde5984658045ade41c2c9b9\PresentationFramework.Classic.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\7ffb91db770d0b09921f623bc5d68b4f\PresentationFramework.Luna.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4f3567165e2a444fc9a62980c4d0ea82\PresentationFramework.Aero.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\205bb33cef9ae6b906ceadd6f2861c86\PresentationFramework.Royale.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\bc8a2d99d8ebd29f94905072ccf4b3b8\napsnap.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\b79da521cf602154b475ea740cc7fd3b\napinit.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\5f0ae15f9d1cade37fbfaacff7e64bff\naphlpr.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\5346ceca518baf5e5fa3fed9f900f792\napcrypt.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\8f792883d0adad8c7beccf24aed65817\MSBuild.ni.exe
+ 2012-05-10 05:25 . 2012-05-10 05:25 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\926d20041c179cebc6f4398155b1b2c4\MMCFxCommon.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 681984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\b78beede8a3c9720095dde4a4a162acc\Microsoft.WSMan.Management.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\83222514e209f186ad3a1c3794168bfd\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 657408 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Web.Admin#\93e303abb551cc607401e8eca32ba5e9\Microsoft.Web.Administration.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\a843956bb452503139683304de4cc8f6\Microsoft.Vsa.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\c56d6513e4b239b1b1dbe29b0588321a\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\fb0d102ca78bd05fe7064b9e6be30fc7\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b21fa6ff448b99a97319e18c166c03e2\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6c3fe42a14ac5b48ebd43be290973d24\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\2572e94f9d0b412cdc529c8d74fdb689\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f4faec8b6d3e2c327c68070963ec1750\Microsoft.MediaCenter.ITVVM.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f04ccbbf5199d2b264f1b1175be44686\Microsoft.MediaCenter.Mheg.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f015188310f7613f819fcf032f98705a\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c5f4ab28f67d5bf0cc221ef81e7f6966\Microsoft.MediaCenter.iTv.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6dbd502a13b5e3caae0b1f2b4847612f\Microsoft.MediaCenter.Playback.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\514667153fd74307d21e7f50b79858c9\Microsoft.MediaCenter.Interop.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\18367b9a0b9e9261d1d9e371230af87c\Microsoft.MediaCenter.Sports.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 798720 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\718cd5a598ed3e225a73b2aba7bcc1e1\Microsoft.ManagementConsole.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 646656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.IIS.Power#\9d97f44a7b4b77eaeefaa425800c8048\Microsoft.IIS.Powershell.Provider.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 244736 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\d68a27daca73749e4438a47e61643c3c\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\3151235c1c38db94fd44e3c6f290ff38\Microsoft.Build.Utilities.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 121344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\cf5e9b5d10682467a9e03358a6d6258f\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\0f233d0eb396065719e83ab573a72cc5\Microsoft.Build.Framework.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\2416af06edb993f98a751acb69f67016\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\69286d5692277a166404cb897a8b2e7a\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\74e4adc90675c3b1365825c7e78b5ce9\Mcx2Dvcs.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\4a1f9a648a3928d42b77a91666d9aa8a\mcupdate.ni.exe
+ 2012-05-10 05:25 . 2012-05-10 05:25 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\40d70417c04f9ccb5fdecb5b9be5a6a3\mcstoredb.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\927ada02b440d95fdf36a37ee96aaa54\mcplayerinterop.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\35023ad5cb299ca2020bd660f5dba2fc\mcGlidHostObj.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\3fc113fe40d0145cd87afca2d107bf6d\MCESidebarCtrl.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\0bd8d37bc6f648d092e1d8034609a107\EventViewer.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\584d419d4c837ea19f7f450a807b0273\ehRecObj.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\20c3505378a50f4859c9b2e7dcbb5fa2\ehiWUapi.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\2f9f48ad6496c9103043db1c21a651fd\ehiwmp.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0955237aa3c1cb3a643248b8c58ec34c\ehiUserXp.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\7998173654fa518876cc97e37b86d465\ehiiTv.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\6c97aa6908f96ac9816ce74e4f6251ac\ehiExtens.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\a501747a95523297a8a1f119df8b1642\ehiBmlDataCarousel.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\414bbac4e1d7761a336bb9d74b9b243a\ehiActivScp.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\24d3859bba3ed02775f22c50ae5ab5a6\ehExtHost.ni.exe
+ 2012-05-10 05:25 . 2012-05-10 05:25 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\ff7ef4caed03d6934669d1a39877a8ac\ehCIR.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\b7916689137fd0bc9ba1ba5a27e2a38a\CustomMarshalers.ni.dll
+ 2012-05-09 22:36 . 2012-05-09 22:36 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\cc6e6febcd804604bf4d92d0eb8ec6ae\ComSvcConfig.ni.exe
+ 2012-05-09 22:36 . 2012-05-09 22:36 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\d18719c2df1334364cac199bb9c86adf\BDATunePIA.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\9d60139fdead64a892985181d663989f\WsatConfig.ni.exe
+ 2012-05-10 19:04 . 2012-05-10 19:04 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\91e23b6ffbada11e54816b2f329acb0d\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dbbb5914ff727ce0f6793177c4da31ba\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d5f38b26d06719bce75df9b32a557754\WindowsLive.Writer.BlogClient.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cf4374c8bdd547ec387d4e75506b1f09\WindowsLive.Writer.Api.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bf6fd33cd452afed9250a32b89ca636e\WindowsLive.Writer.Controls.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a1ba3ba31e32f7e38e311d06dc4f5fb7\WindowsLive.Writer.Extensibility.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9f3a254c1407ab341858c7e2e525abef\WindowsLive.Writer.FileDestinations.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\853c1f1b75d33bbc710d95042876c71b\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\76e2551cbd4afc49d895d75f0f03e673\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7039bba7ff166706ab0b2cd61ff38302\WindowsLive.Writer.Instrumentation.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\66915176ab5aa52988ff1ee8cef3fe92\WindowsLive.Writer.Interop.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4f6aeeee01549f796d40a3af7b166d86\WindowsLive.Writer.HtmlParser.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\40469c3f4918b300f87937d50390746b\WindowsLive.Writer.BrowserControl.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3303c50c159ca46a4138b587056503b0\WindowsLive.Writer.Mshtml.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1022079e02029f995d2432a837f10bc0\WindowsLive.Writer.SpellChecker.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\63f268e307ec2913c3cdddf13bcc2041\WindowsLive.Client.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9bfbf0613d3780e34d98333c7b381218\WindowsFormsIntegration.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\779b08c46960a1824503aa6f089673fa\UIAutomationClient.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\c4edf782e69aa24453554f8b6cb40773\TaskScheduler.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d75f0b1e2ea688466552da04fd805949\System.Web.Routing.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\2b129372a27469195acbe3b6b81786ef\System.Web.RegularExpressions.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\5d6fdd022660b8ca4be19ff06ddfee7a\System.Web.Extensions.Design.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\d084aa31b82c66eb83e40853ba961b48\System.Web.Entity.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\53ca1042189a64dcd1f8ff487922b749\System.Web.Entity.Design.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\0b8a9e120d8f557a9702229e3c64987c\System.Web.DynamicData.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5d95b9a6cee5a9b1aac34b5d33c721ba\System.Web.Abstractions.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5abddd1112204bd1e3347be519eaa28f\System.ServiceProcess.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 680448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\0b5f082230e3486412e0fa333290e85a\System.Net.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\f1241239a9b8229f91ce55d230fad38c\System.Messaging.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\8280490a2939075b726fd051d9010cc0\System.Management.Instrumentation.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a03191ed937f6c1dc827b53d94ea0176\System.IO.Log.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\100d39c2f8985cb93e26feef86ba5212\System.IdentityModel.Selectors.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.Wrapper.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\6b16664ac4ab46643c4a7fdd960ef9fb\System.Drawing.Design.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\55545e89f96539ef93375524d1145a6f\System.DirectoryServices.Protocols.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4d73a7649876bb6e54a01ccbf235919b\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 462336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e36e03067b12bc35fcc3787dc81022c8\System.Data.Services.Design.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\5a29fff52e2c3d13ec15e8701027ab17\System.Data.Entity.Design.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\940f62a5d077405e0b324422afb6ff2c\System.Data.DataSetExtensions.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\d3325c6bced333a67122db7414c1fd1e\System.Configuration.Install.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\a90ec436f1d2c5cb0133a53c2e47d61a\System.AddIn.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\1ed79278fe139272e868e3a53d736f22\sysglobl.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1b0b19607668635281fa260707f4352f\SMSvcHost.ni.exe
+ 2012-05-10 19:05 . 2012-05-10 19:05 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 226816 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae55e761d480fe15781156d1311a1837\PresentationFramework.Classic.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7df1f379457aa5f39183903d115b5479\PresentationFramework.Royale.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\496bc57a53989bb83ec58865fa34be1d\PresentationFramework.Luna.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\9e0dafde490fbb06e0624ad4e5355b58\napsnap.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\782ffccdf30881e1eb1236c3fd7e959b\napinit.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\e0c40329b9cdd7f141a3702d79eb4bda\naphlpr.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\74a8b6419deb005337a1e43ec2502134\MSBuild.ni.exe
+ 2012-05-10 19:05 . 2012-05-10 19:05 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\9e8d56153e65d3cf74342c741126d396\MMCFxCommon.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 531968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\070505350ec9daa3343b3cd2bc8cf59e\Microsoft.WSMan.Management.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Web.Admin#\78dec864df1ab63654a99b9443c9e9d5\Microsoft.Web.Administration.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1e639225ba30d7f182b893ddacea506b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d4c36b363fcd1ca494218e74ba606e99\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 786432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ba2ca86f5d270f493501848843d2f227\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\607324a312b1c6d7fbede8300e8cee91\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1f1185444c8a12ace85ba4c2d49f41f8\Microsoft.PowerShell.Security.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\12715b7e3e89758161053520b57764b2\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\f077b7199d773c7812c04bb146014257\Microsoft.ManagementConsole.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 664064 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.IIS.Power#\ebb3023033a486f52d1c00e1a59eaf2a\Microsoft.IIS.PowerShell.Framework.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 496640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.IIS.Power#\886cfb258e05e7387c6783aefa444cf3\Microsoft.IIS.Powershell.Provider.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7e59b3b84ca3c61adfc0dc74a65ea177\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\07e346ee0e3f7433f2de7a72fadd6713\Microsoft.Build.Utilities.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\432160eff3b1f9301c6a74c2e647e03d\Microsoft.Build.Engine.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\8297305de86377d0070a983d99a7f943\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\541a5bb4d0f8490e506f885a4b435566\mcstoredb.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\185067f9c70ccbccb4431063f9054b66\EventViewer.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\5ae5c6732ef8e7115baaeb66fd69cdd2\ehRecObj.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\c4a5ce4f89c53b9601d13d22d01cf0bf\ehiVidCtl.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\cbf3a07d3ab873b19f47d6a24f06c796\ehiProxy.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\5cc4a5672758f4732ef430b3431f47fc\ehiExtens.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\15b24807d7e7cae1db4f285f04cb82d7\ehExtHost32.ni.exe
+ 2012-05-10 19:05 . 2012-05-10 19:05 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\3912b69593af13d0922279a063e5af66\ComSvcConfig.ni.exe
+ 2012-05-10 01:30 . 2012-05-10 01:30 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\e1c3540ffb669448747187f76c6ebe82\BDATunePIA.ni.dll
- 2010-11-21 03:25 . 2010-11-21 03:25 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-05-08 21:19 . 2012-01-04 02:50 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2012-05-08 21:19 . 2012-02-10 23:29 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-05-08 21:19 . 2012-03-31 04:39 3913072 c:\windows\SysWOW64\ntoskrnl.exe
+ 2012-05-08 21:19 . 2012-03-31 04:39 3968368 c:\windows\SysWOW64\ntkrnlpa.exe
+ 2011-06-11 00:58 . 2011-06-11 00:58 4422992 c:\windows\SysWOW64\mfc100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58 4397384 c:\windows\SysWOW64\mfc100.dll
- 2012-03-14 00:04 . 2012-02-10 05:38 1077248 c:\windows\SysWOW64\DWrite.dll
+ 2012-05-08 21:19 . 2012-03-03 05:31 1077248 c:\windows\SysWOW64\DWrite.dll
+ 2012-05-08 21:19 . 2012-03-31 03:10 3146240 c:\windows\system32\win32k.sys
- 2009-07-14 00:03 . 2009-07-14 01:41 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2012-05-08 21:19 . 2012-03-31 05:40 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2012-05-08 21:19 . 2012-03-31 06:05 5559664 c:\windows\system32\ntoskrnl.exe
- 2009-07-14 04:45 . 2012-04-17 20:40 3585488 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 04:45 . 2012-05-09 20:45 3585488 c:\windows\system32\FNTCACHE.DAT
+ 2012-05-08 21:19 . 2012-03-03 06:35 1544704 c:\windows\system32\DWrite.dll
+ 2012-05-08 21:19 . 2012-03-30 11:35 1918320 c:\windows\system32\drivers\tcpip.sys
+ 2009-07-14 04:45 . 2012-05-10 22:30 7190096 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2012-04-16 18:14 7190096 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2012-02-24 22:07 . 2012-05-10 23:25 8901220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-12288.dat
- 2012-02-24 22:07 . 2012-05-07 01:11 8901220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-12288.dat
+ 2012-01-19 12:08 . 2012-01-19 12:08 1369872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 12:08 . 2012-01-19 12:08 6429992 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 12:52 . 2012-01-19 12:52 3825952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 5029160 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 3512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 4970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 1455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 1515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 1512712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
+ 2011-12-15 13:01 . 2011-12-15 13:01 9793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2012-05-08 21:19 . 2012-02-10 23:29 2256152 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
- 2012-02-28 20:57 . 2011-03-29 22:32 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
- 2012-02-28 20:57 . 2011-10-31 23:15 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 9992464 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
- 2011-11-07 14:04 . 2011-07-08 22:31 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 1577232 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 1756432 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
+ 2012-01-19 12:08 . 2012-01-19 12:08 1369872 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 12:08 . 2012-01-19 12:08 6429992 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 12:08 . 2012-01-19 12:08 3790112 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 5029160 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 3512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 5201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 1143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2011-12-15 12:08 . 2011-12-15 12:08 6727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 1737496 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
- 2012-02-28 20:57 . 2011-03-29 22:33 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2012-02-28 20:57 . 2011-10-31 23:16 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 5925136 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2012-05-08 21:19 . 2012-01-04 02:50 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2011-11-07 14:04 . 2011-07-08 22:33 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1369872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 5029160 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 6429992 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3111768 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 3111768 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3825952 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 4970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3790112 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 5201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2012-04-12 17:53 . 2012-04-12 17:53 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-03-20 20:06 . 2012-03-20 20:06 2887680 c:\windows\Installer\cdc6d9.msi
+ 2012-04-04 21:38 . 2012-04-04 21:38 2831360 c:\windows\Installer\7314c3.msp
+ 2012-04-28 20:44 . 2012-04-28 20:44 9101824 c:\windows\Installer\7314bb.msp
+ 2012-04-28 20:44 . 2012-04-28 20:44 9586176 c:\windows\Installer\7314a5.msp
+ 2012-04-30 13:38 . 2012-04-30 13:38 5011456 c:\windows\Installer\731482.msp
+ 2012-04-04 21:38 . 2012-04-04 21:38 3620864 c:\windows\Installer\731436.msp
+ 2012-03-15 01:24 . 2012-03-15 01:24 1795584 c:\windows\Installer\73142e.msp
+ 2012-04-28 20:43 . 2012-04-28 20:43 8459264 c:\windows\Installer\731404.msp
+ 2012-02-17 07:45 . 2012-02-17 07:45 2299392 c:\windows\Installer\7313fc.msp
+ 2011-01-15 08:46 . 2011-01-15 08:46 2049536 c:\windows\Installer\5208e.msi
+ 2011-06-28 20:27 . 2011-06-28 20:27 4028928 c:\windows\Installer\42327c1.msp
+ 2011-07-21 11:34 . 2011-07-21 11:34 3456000 c:\windows\Installer\42327aa.msp
+ 2012-02-24 22:04 . 2012-05-08 23:24 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2012-02-24 22:04 . 2012-05-08 23:24 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2012-02-24 22:04 . 2012-04-12 17:52 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-03-18 13:16 . 2010-03-18 13:16 1303896 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\WindowsBase_x86.dll
+ 2010-03-18 13:16 . 2010-03-18 13:16 1303896 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\WindowsBase_amd64.dll
+ 2010-03-18 13:16 . 2010-03-18 13:16 6346600 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationFramework_x86.dll
+ 2010-03-18 13:16 . 2010-03-18 13:16 6346600 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationFramework_amd64.dll
+ 2010-03-18 13:16 . 2010-03-18 13:16 3545952 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationCore_x86.dll
+ 2010-03-18 14:27 . 2010-03-18 14:27 3453792 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationCore_amd64.dll
+ 2011-01-14 06:10 . 2011-01-14 06:10 2395008 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD.DLL
+ 2011-01-14 06:10 . 2011-01-14 06:10 2180992 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKPOWERPOINT.DLL
+ 2011-01-14 06:10 . 2011-01-14 06:10 3443072 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL.DLL
+ 2012-05-10 19:08 . 2012-05-10 19:08 5234688 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\45519c2d486b2fb5547000b1e36afe1c\WindowsBase.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\c0e10c6719dfdf5ee7aa362f2a655070\UIAutomationClientsideProviders.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 7037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\8a4233d4c95786ee1718069b09ebb27a\System.Xml.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 2447360 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\f6ecdb4e1bc0e65d7f0834111edb87ac\System.Xaml.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 5644800 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\8ed12599766c039fae691d65194a5894\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 2221568 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\a82fb80c4e660e8fcc15fd3dcf905b8f\System.Web.Services.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 2733568 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\8947d0056322e41660ca742cc0aedfd0\System.Speech.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1904128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\aa70dcf37578c6a77e8046607b0358a7\System.ServiceModel.Activities.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1561600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\5c28f69ea5e670704ea8d7c5f9a74e29\System.ServiceModel.Discovery.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 3403776 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\c855969aa5863b0459caf7af03dd1d74\System.Runtime.Serialization.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 1346048 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\1deb7429eb578fa45133f974ab2d84a8\System.Runtime.DurableInstancing.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\2f87ca8da7ff9d76bd7adb451f791e99\System.Printing.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\9de3a4202d96fd1a84bb6c1957a4be07\System.Management.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\ee1e57cd488ed11f88d0f1f16b81afd6\System.IdentityModel.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 1096704 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\83c68e06cc189bf09bbaad27dea4c2ca\System.EnterpriseServices.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 2303488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\a7f7289b6c4635058fb85b93a7599830\System.Drawing.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\8f29b33e6f16dc8621ed58a92c162d15\System.DirectoryServices.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\2dca7db5715606a77077feb8bb11ae3d\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 2401280 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\b9d5215d1d8a78fa4f34ef76d562a018\System.Deployment.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 8580096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\a9e553bdda97972c0901f15fe79a6114\System.Data.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 3386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\5442a72958d785203efe9a184d59559f\System.Data.SqlXml.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 1791488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\4306004ecadd1eebb125ad7826e3085b\System.Data.Services.Client.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 3380224 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\f33b4bbf649f2a9e910ff07e53ddda13\System.Data.Linq.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 1255424 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\f80de5841689088340e219106dc7542b\System.Configuration.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 1002496 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\b183fc0c8140853f0e7b9a98d6762694\System.ComponentModel.Composition.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 5681152 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\6e17404677e90d56b9c2ebccfdafd1c8\System.Activities.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 5043200 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\c83984e5b97760db4710a280fb3ac2e7\System.Activities.Presentation.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 2061312 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\a01cde8e4e2e549829ef73e3abee369c\System.Activities.Core.Presentation.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 4229632 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\9e1dfc30a556ee9d3c17659661b1b3f0\ReachFramework.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 2056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\228dbd2740d0eb9b9e03f5059b436e65\PresentationUI.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 2314752 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e3fdd495e839c9853d25658804a5032a\Microsoft.VisualBasic.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 1843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\9e809b61dc30c4b63d6b0aa119e6e608\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\897ae7c3ee29a674ad4c72d63b4c2048\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 1510400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\62321e71691c02649b64c3ffd3c79867\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 3312640 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\d2dfe3f55db792b0999a6a561dda3f11\Microsoft.JScript.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 2009088 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\32cab40d8e9ea969c69e73d693de356f\Microsoft.CSharp.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 3856896 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\1d7cbd715842710ef8a405ad1e1d2aac\WindowsBase.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\699b33373dccad550e1c3816dd75c321\UIAutomationClientsideProviders.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 9090560 c:\windows\assembly\NativeImages_v4.0.30319_32\System\5339ecdda252537e37def11dc77c77aa\System.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 5618176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\6e70ff4b74bed30aa8751253ed8aee56\System.Xml.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1781760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\adf79290d55b53d72aaedf49dc0ab05c\System.Xaml.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 4586496 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\287af325d071e82b0a7732b800085855\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1859584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\393e2a02b90b4e6f17df2f1307190f14\System.Web.Services.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 2010624 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\55ff552cd61d1c825e65660fa705df81\System.Speech.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1128960 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\cac970090ee40f6eb194fcc66391d99f\System.ServiceModel.Discovery.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1387520 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\49d13cef799a2cbb948f3292a87995fe\System.ServiceModel.Activities.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2637312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0b065445b421ccf5e2beb5eecc45a48\System.Runtime.Serialization.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1020928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\3434c23fcc8dfcf056d06f0328d2225d\System.Runtime.DurableInstancing.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\09c9359d9661e4934c20733cc7bcfb2a\System.Printing.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\6a277b0dd5279e1f76d31604b4eeb31f\System.Management.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1072128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9c5381e06b81e9859210d9164288cd8b\System.IdentityModel.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 1665536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ca3e5d50a488146065d1b15e552e99be\System.Drawing.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\2c7bd166899c82a07c0ae33f800166de\System.DirectoryServices.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1879040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\d52dcaccce74fd1bd0b63ed719b8265f\System.Deployment.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 6798336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\6100a4d8635f4e12d3ab23545dbc7dcc\System.Data.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 2545152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\81916491a37ab590ae68cf4e2738d13b\System.Data.SqlXml.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 1338880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\cda5338af4bedb3a42d01451e0cc0784\System.Data.Services.Client.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 2512384 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\a13bba7255b2e85af402b348801761ca\System.Data.Linq.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 7052800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\0ad566912479454ed9ce37fb09de2715\System.Core.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 4121088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\69ed7b4d15e9637e3756f38833a8ae3a\System.Activities.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 3755008 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\53810b1c60d29affab72da39c99130b4\System.Activities.Presentation.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1544192 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\7c94adcec5f00ebe4357fc854e9568d3\System.Activities.Core.Presentation.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2904576 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\13407232969daca5ccd3a77e4f4fcc17\ReachFramework.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1641984 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\5dad9fdce69ecf060156fe9913c4c6b7\PresentationUI.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1139712 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\c75c39a45666489f342f035b1603cbfc\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1836544 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\181690540d71290b2c25802750039206\Microsoft.VisualBasic.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\16becd1736af2b825937882589b46762\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1082368 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\5530d1f5441182d07978e24d3c0125de\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\9f600932530e718cc45e80939bcc1966\Microsoft.JScript.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 1616384 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\c4ed07b3ab497d4b2f60f9935cbf3b08\Microsoft.CSharp.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 4962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\4bcc5a6e9e9d25e068fc304bd7eda6af\WindowsBase.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 1459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\783df1ee260d3df406fa80afa38502d4\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\24d1b7ccbedaa3602bae6a6acea9929e\System.Xml.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\b7d8410b7226a2654823657f0a714441\System.WorkflowServices.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\8ac687b7f43937c81f1c49d14975c740\System.Workflow.Runtime.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\6fdec1a3278d87cbbc5211736d446d32\System.Workflow.ComponentModel.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\052fd2c15eb37e00cecf33f6d13d9b09\System.Workflow.Activities.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\6a0b589c4c1467f6b783991842a0f961\System.Web.Services.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\395c96f5d2a876805d3846d396081c79\System.Web.Mobile.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\e4860ce9959b3593834516b4a6a75593\System.Web.Extensions.Design.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 3044352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\baa7ed93207641c186f79f82ee22aea0\System.Web.Extensions.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\ca51f026916139f886519fdf6d6c73e9\System.Speech.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\56ee9b5f220583c1c7374a61ad904044\System.ServiceModel.Web.ni.dll
+ 2012-05-10 05:24 . 2012-05-10 05:24 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\2a02b172fa4cf3d93ce7388b67b2a199\System.Runtime.Remoting.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 1463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\f0bcd188487600cb07ce08dfd7b471ba\System.Printing.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 1472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\fd4a8227569e64d657b80483da8ffe78\System.Management.ni.dll
+ 2012-05-10 05:24 . 2012-05-10 05:24 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\d1f21a29e79e73b5401fae156f339f67\System.IdentityModel.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 2317312 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\92c038385ee5b9840e941f9c84b988df\System.Drawing.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 1230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\7c7024b309424dfaf8abae617f669fa0\System.Deployment.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 8681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\ea1848ec07c70f3d3c3445f4fbdae87a\System.Data.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 3463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7f6f74f1cc0ea6c40a2d6707b12af818\System.Data.SqlXml.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 1868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll
+ 2012-05-09 20:50 . 2012-05-09 20:50 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\97429a1c70c94c49850be3f944a32a2e\System.Data.OracleClient.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\2ec3d436b861d35c586b710a570e170d\System.Data.Linq.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7b5364bc524988f7ca5b8c20a24119d\System.Data.Entity.Design.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 3315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\766ce7ee1a2e4f2a85fd90e7572f5d53\System.Core.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\193d03ca60573c92f92d9b07fa5bc243\System.Configuration.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 3116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\d6379f3503f00cf1c2bb4f6118efdbd9\ReachFramework.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\5fa575ebe76aab9d9fd07ce601c0d2e1\PresentationUI.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 1884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\4fbff79b8ebf082d08c0080923ff5036\PresentationBuildTasks.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\d0c041e321cf4d752d5113a0cdbccbaa\Narrator.ni.exe
+ 2012-05-10 05:26 . 2012-05-10 05:26 2327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\051b72a48f2c3f7ddd7353c7d5479b10\MMCEx.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\c79bf402b4840e3b0021f75cf467f82b\MIGUIControls.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\70b3f55017e9ddb67ce0f3c983eb6f37\Microsoft.VisualBasic.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\28ba52bc122353647f1b547506e2df7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f5790625975320b1ffad63b476da9132\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 5350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f29b31b09b826a27cced362030561d00\Microsoft.PowerShell.Editor.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d0328b4733d1a99d342a84928e319d4f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\99049fd20c2a5e2779e879c2d95c96a2\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\efdc3b97b3c9d01dd00959970d086937\Microsoft.MediaCenter.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c057be8bb6614cce013af3721fe34983\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5c50dfc78bd40be7ca0d850c781671e4\Microsoft.MediaCenter.UI.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\31fb31c16a37080687f869db6b443adf\Microsoft.MediaCenter.Bml.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\260d83ee2128a3388051cf416d4450b0\Microsoft.MediaCenter.Shell.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 3213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\094f6a515ca31504f96b4bad5848d692\Microsoft.JScript.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\a27890dd120635ba590a6fc9d9014197\Microsoft.Ink.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 1064960 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.IIS.Power#\2526ad675e8b09893a7dd0a549837f26\Microsoft.IIS.PowerShell.Framework.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\588a688a0b71a211247d8e18b05d61e4\Microsoft.Build.Tasks.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 2682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\4eeee4447f5045df9b4157d38d267de9\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f1a0df6a86ceb708c5e50338f12b77ba\Microsoft.Build.Engine.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\6b727c7aa69ae3e04a869908bfbae696\Microsoft.Build.Engine.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\208e6937e39f8f516536ba5f23e79687\mcstore.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 4088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\596902addad034f4df2caf291b12d61d\mcepg.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\cdad46cd58389f53308b735e6f29ce1f\ehiVidCtl.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\0423915e377ec85d71ac216fafa77ab0\ehiProxy.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ffc7ce66bd0fd13b71c8870110124c0f\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ad799293e3b5b4a480ca68bbea49e61a\WindowsLive.Writer.Localization.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\70498b5c0eb482f16e365a4d2d38466a\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-05-10 19:04 . 2012-05-10 19:04 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\36410c38cbb2a080367c5b5f47020f8e\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 3347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\3b452cde57280624e1085699fe8beb03\UIAutomationClientsideProviders.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 7967232 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 5452800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\439862b007b2dd84127ff35af476f5ad\System.WorkflowServices.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\bfa1ffe928b4e3fd6701aabfee7df15e\System.Workflow.Runtime.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 4516352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0a7d29e1614521f3a87cd5a13e57f9f1\System.Workflow.ComponentModel.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\edac556f009c25b62ef1a040152e9cda\System.Workflow.Activities.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\59a5af8e3ea07f7980e0476d2da234cd\System.Web.Services.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\0307caacafd3e157fc003ed4743c5e2e\System.Web.Mobile.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2404352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\04442376410587c6de88f4b84cc69b1a\System.Web.Extensions.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\83053c3eeb3255672d84c1ddc0ce8ef3\System.Speech.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\d900f9ec12af9070d7c8f061a2b2618c\System.Printing.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 8872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 1590784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\bf659f9bb758ac14ed7a37bdfe965849\System.Deployment.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 6610944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\eaeca46457a0c33b93f6f4be08990cab\System.Data.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e9774272e9fc6ca49e6c616a31783040\System.Data.SqlXml.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 1378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\68e9e465d70fdba2cb0aadbc91869ed7\System.Data.OracleClient.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2fe1658f05b0a96fe25c956a31d27b06\System.Data.Linq.ni.dll
+ 2012-05-10 19:06 . 2012-05-10 19:06 9921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 2297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 2157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\305c4315c192a2964a312051caa5259e\ReachFramework.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\b935f8a4e6115d3eeb7bb293bf4b2257\PresentationUI.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b3f13707cbd5d48aabaa9ef5264c8a30\PresentationBuildTasks.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\a96e05eaed77a88a7a495091ed8296dc\Narrator.ni.exe
+ 2012-05-10 19:05 . 2012-05-10 19:05 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\0310b6efd8cd8b1b90bb78303d014081\MMCEx.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\6e602986ed39fd1f9e3801ee96b63f41\MIGUIControls.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dab0ad2d0f5da372a4947d3a1c7c07a9\Microsoft.VisualBasic.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cd9e47effec6549cdec61eb3aef99f7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d62bb06df2169fa249006539173d6b5f\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\870bb30c079ed5bc201057d71661601f\Microsoft.PowerShell.Editor.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7ee29045f76b1e9577bfc1e0fab723d8\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\9ac798ce15e5c0336f43b624af7363ec\Microsoft.MediaCenter.UI.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\0cb862d3708c15fe0f5c66d2a40cb074\Microsoft.MediaCenter.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 2335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\e3d2577e00aef6bc9b3e235eb83634f3\Microsoft.JScript.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\89ebef016091d09d58c8a1066def8bcd\Microsoft.Ink.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\81b8987ca8661d6af40ead6311c45724\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\52e05f8fa4314803ceab2befae2e0a39\Microsoft.Build.Tasks.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6b66f52dbd8f87e53c3c9a1de7ca5bba\Microsoft.Build.Engine.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\14defdf34097afaf302497a7d612aaaf\mcstore.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\69b8de21b08c3412422c5918399ed702\mcepg.ni.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2012-02-28 20:57 . 2011-10-31 23:16 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-05-08 21:19 . 2012-01-04 02:51 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-02-28 20:57 . 2011-03-29 22:33 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-05-08 21:19 . 2012-02-10 23:29 2256152 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-05-08 21:19 . 2012-02-10 23:29 3998208 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-11-07 14:04 . 2011-07-08 22:31 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-08 21:19 . 2012-01-04 03:34 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 1737496 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-05-08 21:19 . 2012-02-10 23:31 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2010-11-21 03:24 . 2010-11-21 03:24 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-11-07 14:04 . 2011-07-08 22:33 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-05-08 21:19 . 2012-01-04 02:50 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2009-07-14 02:34 . 2012-04-12 21:55 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-05-09 20:44 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-03-01 18:09 . 2012-05-08 23:24 57848688 c:\windows\system32\MRT.exe
+ 2012-02-24 22:07 . 2012-05-12 00:06 48032465 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-8192.dat
+ 2012-01-19 13:20 . 2012-01-19 13:20 11997696 c:\windows\Installer\73148f.msp
+ 2011-12-15 13:54 . 2011-12-15 13:54 39732736 c:\windows\Installer\73146d.msp
+ 2012-05-10 23:08 . 2012-05-10 23:08 53217792 c:\windows\Installer\25cd25.msp
+ 2011-09-15 20:42 . 2011-09-15 20:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WWLIB.DLL
+ 2012-05-08 23:21 . 2012-05-08 23:21 11878912 c:\windows\assembly\NativeImages_v4.0.30319_64\System\2e3e108c027b8309682f4dae2a95ece6\System.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 17352192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\d1824eac861b41873c522f182ebe506b\System.Windows.Forms.ni.dll
+ 2012-05-10 19:11 . 2012-05-10 19:11 24484864 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\86aa22efb7a73d3e7ec787bc0a7d18cf\System.ServiceModel.ni.dll
+ 2012-05-10 19:10 . 2012-05-10 19:10 18433024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\85e865cc62be45e033c78a443b1c2658\System.Data.Entity.ni.dll
+ 2012-05-10 19:08 . 2012-05-10 19:08 10421248 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b59dcafce97452b25ae224197cba0123\System.Core.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 24402944 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3df9adc5f3dc3fec5bf0f0288b530d0d\PresentationFramework.ni.dll
+ 2012-05-10 19:09 . 2012-05-10 19:09 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\da837eb9ad33b78060820f1fe312b42c\PresentationCore.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 19353600 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 13196800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\a8d2bf149a0901997a5b6a46c63ac2d6\System.Windows.Forms.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 17996800 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\8be0d48c6312a96e2ff0fd5bafb70469\System.ServiceModel.ni.dll
+ 2012-05-10 19:07 . 2012-05-10 19:07 13324288 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\4c3b8750cd9b5b61f300275a6dd9ed07\System.Data.Entity.ni.dll
+ 2012-05-08 23:24 . 2012-05-08 23:24 17998848 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\bc27eeb2155247bd3eb500428aba7db8\PresentationFramework.ni.dll
+ 2012-05-08 23:23 . 2012-05-08 23:23 11451904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\aec0265c1f17056fb8e2e4db2c3a2c0f\PresentationCore.ni.dll
+ 2012-05-08 23:21 . 2012-05-08 23:21 14413824 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\1bdf7de454340e0ea9fc455aeaec49d9\mscorlib.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 10624512 c:\windows\assembly\NativeImages_v2.0.50727_64\System\c40ec0f4cd203c880298f94c0427dd54\System.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 17379840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\e2ca64137e0da231edc4d158b153e4b7\System.Windows.Forms.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 15270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\1cb5a7cbd9cdf50f1d48cee830331c9f\System.Web.ni.dll
+ 2012-05-10 05:24 . 2012-05-10 05:24 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\f74b2d1b8cf279ff6bfe479f79e70fe9\System.ServiceModel.ni.dll
+ 2012-05-10 05:26 . 2012-05-10 05:26 11900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\00c4a761d0a5cafc00f34d763fe76ac4\System.Management.Automation.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\78c747493d14dd3db5134d26e623851c\System.Design.ni.dll
+ 2012-05-10 05:27 . 2012-05-10 05:27 13760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\daaff9fe9c85fc171d426a3cb6766dbb\System.Data.Entity.ni.dll
+ 2012-05-09 20:49 . 2012-05-09 20:49 19198464 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\9aa6320f06da2553fb04e78722c739c8\PresentationFramework.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 16543232 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\4dc6e89ac37368291890ba27c374208b\PresentationCore.ni.dll
+ 2012-05-09 20:48 . 2012-05-09 20:48 15570944 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\f73f0a9c9a83dcd3ff428be509a7992f\mscorlib.ni.dll
+ 2012-05-10 05:25 . 2012-05-10 05:25 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\d19a72cf466c23b193009386b25049ba\ehshell.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 12433408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 11833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\1a690902e9a6293de228c16fab21e2f7\System.Web.ni.dll
+ 2012-05-10 19:05 . 2012-05-10 19:05 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\649766df70bab5885c1b74a1491d60cb\System.Design.ni.dll
+ 2012-05-09 20:47 . 2012-05-09 20:47 14340608 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07f019692c382d588d3c6cb2da2a9ec5\PresentationFramework.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 12237824 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\2d1fd350e9bc62ce659e5cbcfd555796\PresentationCore.ni.dll
+ 2012-05-09 20:46 . 2012-05-09 20:46 11492864 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
.
-- Snapshot reset to current date --

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-11 348624]
.
c:\users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\William\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-04 129976]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 ioatdma;Intel® QuickData Technology device;c:\windows\System32\Drivers\ioatdma.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-14 169624]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-11 86224]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 23:54]
.
2012-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 23:54]
.
2012-05-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1360622652-2071615853-753804455-1000Core.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-24 20:50]
.
2012-05-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1360622652-2071615853-753804455-1000UA.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-24 20:50]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-09-08 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-09-08 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-09-08 416024]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://nmd.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\William\AppData\Roaming\Mozilla\Firefox\Profiles\icbyerx8.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Completion time: 2012-05-12 01:11:51 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-12 00:11
ComboFix2.txt 2012-05-07 11:46
.
Pre-Run: 544,771,854,336 bytes free
Post-Run: 544,738,402,304 bytes free
.
- - End Of File - - 3E790152A32DE850C3E4BDFD6744056A







The Easy A-Z.com redirects happened every now and again. I will keep monitoring and post updates.

Thanks again,

Will

#4 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 12 May 2012 - 03:19 PM

Yes, I'm still getting re-directs from the first search result I click on from Google, it might not be the top link, but just whichever I click on first.

#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 12 May 2012 - 05:44 PM

Greetings

I want you to run these next,

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#6 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 13 May 2012 - 04:35 PM

22:31:10.0981 4840 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18
22:31:11.0103 4840 ============================================================
22:31:11.0103 4840 Current date / time: 2012/05/13 22:31:11.0103
22:31:11.0103 4840 SystemInfo:
22:31:11.0103 4840
22:31:11.0103 4840 OS Version: 6.1.7601 ServicePack: 1.0
22:31:11.0103 4840 Product type: Workstation
22:31:11.0103 4840 ComputerName: WILLIAM-ZOO
22:31:11.0103 4840 UserName: William
22:31:11.0103 4840 Windows directory: C:\windows
22:31:11.0103 4840 System windows directory: C:\windows
22:31:11.0103 4840 Running under WOW64
22:31:11.0103 4840 Processor architecture: Intel x64
22:31:11.0103 4840 Number of processors: 8
22:31:11.0103 4840 Page size: 0x1000
22:31:11.0103 4840 Boot type: Normal boot
22:31:11.0103 4840 ============================================================
22:31:11.0896 4840 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:31:11.0899 4840 Drive \Device\Harddisk1\DR1 - Size: 0x3BA400000 (14.91 Gb), SectorSize: 0x200, Cylinders: 0x79A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:31:11.0901 4840 ============================================================
22:31:11.0901 4840 \Device\Harddisk0\DR0:
22:31:11.0901 4840 MBR partitions:
22:31:11.0901 4840 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xCB2800, BlocksNum 0x96000
22:31:11.0901 4840 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xD48800, BlocksNum 0x739BE000
22:31:11.0901 4840 \Device\Harddisk1\DR1:
22:31:11.0901 4840 MBR partitions:
22:31:11.0901 4840 \Device\Harddisk1\DR1\Partition0: MBR, Type 0xC, StartLBA 0x1F80, BlocksNum 0x1DD0080
22:31:11.0901 4840 ============================================================
22:31:11.0928 4840 C: <-> \Device\Harddisk0\DR0\Partition1
22:31:11.0928 4840 ============================================================
22:31:11.0928 4840 Initialize success
22:31:11.0928 4840 ============================================================
22:31:18.0997 3156 ============================================================
22:31:18.0997 3156 Scan started
22:31:18.0997 3156 Mode: Manual;
22:31:18.0997 3156 ============================================================
22:31:19.0943 3156 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
22:31:19.0954 3156 1394ohci - ok
22:31:19.0974 3156 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
22:31:19.0977 3156 ACPI - ok
22:31:19.0988 3156 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
22:31:19.0992 3156 AcpiPmi - ok
22:31:20.0112 3156 AdobeActiveFileMonitor10.0 (047bd1eb681453a7fe492a71802ac9f3) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
22:31:20.0114 3156 AdobeActiveFileMonitor10.0 - ok
22:31:20.0164 3156 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:31:20.0165 3156 AdobeARMservice - ok
22:31:20.0276 3156 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:31:20.0279 3156 AdobeFlashPlayerUpdateSvc - ok
22:31:20.0316 3156 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
22:31:20.0345 3156 adp94xx - ok
22:31:20.0389 3156 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
22:31:20.0400 3156 adpahci - ok
22:31:20.0417 3156 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
22:31:20.0425 3156 adpu320 - ok
22:31:20.0444 3156 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
22:31:20.0445 3156 AeLookupSvc - ok
22:31:20.0514 3156 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
22:31:20.0535 3156 AFD - ok
22:31:20.0577 3156 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
22:31:20.0583 3156 agp440 - ok
22:31:20.0597 3156 ALG (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
22:31:20.0603 3156 ALG - ok
22:31:20.0619 3156 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
22:31:20.0623 3156 aliide - ok
22:31:20.0626 3156 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
22:31:20.0630 3156 amdide - ok
22:31:20.0645 3156 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
22:31:20.0651 3156 AmdK8 - ok
22:31:20.0656 3156 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
22:31:20.0661 3156 AmdPPM - ok
22:31:20.0688 3156 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
22:31:20.0695 3156 amdsata - ok
22:31:20.0731 3156 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
22:31:20.0739 3156 amdsbs - ok
22:31:20.0763 3156 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
22:31:20.0768 3156 amdxata - ok
22:31:20.0891 3156 AntiVirSchedulerService (0a1cc583e8147004e4ad4625d7fbf88c) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
22:31:20.0892 3156 AntiVirSchedulerService - ok
22:31:20.0900 3156 AntiVirService (c9a36ef935aced86aedf93e97e606911) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
22:31:20.0901 3156 AntiVirService - ok
22:31:20.0952 3156 AppHostSvc (59d01fa91962c9c1e9b4022b2d3b46db) C:\windows\system32\inetsrv\apphostsvc.dll
22:31:20.0957 3156 AppHostSvc - ok
22:31:20.0983 3156 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
22:31:20.0988 3156 AppID - ok
22:31:21.0009 3156 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
22:31:21.0014 3156 AppIDSvc - ok
22:31:21.0026 3156 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
22:31:21.0027 3156 Appinfo - ok
22:31:21.0066 3156 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
22:31:21.0073 3156 arc - ok
22:31:21.0084 3156 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
22:31:21.0088 3156 arcsas - ok
22:31:21.0117 3156 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
22:31:21.0119 3156 AsyncMac - ok
22:31:21.0128 3156 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
22:31:21.0129 3156 atapi - ok
22:31:21.0222 3156 athur (ea0af9b866df07e8fe6c2342585788b0) C:\windows\system32\DRIVERS\athurx.sys
22:31:21.0244 3156 athur - ok
22:31:21.0340 3156 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
22:31:21.0344 3156 AudioEndpointBuilder - ok
22:31:21.0351 3156 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
22:31:21.0354 3156 AudioSrv - ok
22:31:21.0515 3156 avgntflt (26e38b5a58c6c55fafbc563eeddb0867) C:\windows\system32\DRIVERS\avgntflt.sys
22:31:21.0525 3156 avgntflt - ok
22:31:21.0601 3156 avipbb (9d1f00beff84cbbf46d7f052bc7e0565) C:\windows\system32\DRIVERS\avipbb.sys
22:31:21.0609 3156 avipbb - ok
22:31:21.0634 3156 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
22:31:21.0638 3156 avkmgr - ok
22:31:21.0673 3156 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
22:31:21.0677 3156 AxInstSV - ok
22:31:21.0715 3156 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
22:31:21.0724 3156 b06bdrv - ok
22:31:21.0743 3156 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
22:31:21.0750 3156 b57nd60a - ok
22:31:21.0791 3156 BBSvc (93ee7d9c35ae7e9ffda148d7805f1421) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
22:31:21.0798 3156 BBSvc - ok
22:31:21.0832 3156 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
22:31:21.0836 3156 BDESVC - ok
22:31:21.0862 3156 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
22:31:21.0864 3156 Beep - ok
22:31:21.0905 3156 BFE (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
22:31:21.0914 3156 BFE - ok
22:31:21.0948 3156 BITS (1ea7969e3271cbc59e1730697dc74682) C:\windows\system32\qmgr.dll
22:31:21.0955 3156 BITS - ok
22:31:21.0991 3156 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
22:31:21.0994 3156 blbdrive - ok
22:31:22.0043 3156 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
22:31:22.0047 3156 bowser - ok
22:31:22.0065 3156 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
22:31:22.0068 3156 BrFiltLo - ok
22:31:22.0070 3156 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
22:31:22.0071 3156 BrFiltUp - ok
22:31:22.0085 3156 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\windows\system32\DRIVERS\bridge.sys
22:31:22.0089 3156 BridgeMP - ok
22:31:22.0110 3156 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
22:31:22.0111 3156 Browser - ok
22:31:22.0119 3156 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
22:31:22.0126 3156 Brserid - ok
22:31:22.0128 3156 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
22:31:22.0131 3156 BrSerWdm - ok
22:31:22.0132 3156 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
22:31:22.0134 3156 BrUsbMdm - ok
22:31:22.0136 3156 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
22:31:22.0138 3156 BrUsbSer - ok
22:31:22.0140 3156 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\drivers\bthmodem.sys
22:31:22.0144 3156 BTHMODEM - ok
22:31:22.0157 3156 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
22:31:22.0161 3156 bthserv - ok
22:31:22.0175 3156 catchme - ok
22:31:22.0194 3156 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
22:31:22.0197 3156 cdfs - ok
22:31:22.0223 3156 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
22:31:22.0227 3156 cdrom - ok
22:31:22.0245 3156 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
22:31:22.0245 3156 CertPropSvc - ok
22:31:22.0254 3156 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
22:31:22.0258 3156 circlass - ok
22:31:22.0274 3156 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
22:31:22.0277 3156 CLFS - ok
22:31:22.0330 3156 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:31:22.0337 3156 clr_optimization_v2.0.50727_32 - ok
22:31:22.0356 3156 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:31:22.0364 3156 clr_optimization_v2.0.50727_64 - ok
22:31:22.0455 3156 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:31:22.0457 3156 clr_optimization_v4.0.30319_32 - ok
22:31:22.0482 3156 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:31:22.0483 3156 clr_optimization_v4.0.30319_64 - ok
22:31:22.0505 3156 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\drivers\CmBatt.sys
22:31:22.0507 3156 CmBatt - ok
22:31:22.0520 3156 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
22:31:22.0522 3156 cmdide - ok
22:31:22.0585 3156 CNG (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
22:31:22.0597 3156 CNG - ok
22:31:22.0608 3156 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\drivers\compbatt.sys
22:31:22.0612 3156 Compbatt - ok
22:31:22.0635 3156 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\DRIVERS\CompositeBus.sys
22:31:22.0640 3156 CompositeBus - ok
22:31:22.0643 3156 COMSysApp - ok
22:31:22.0660 3156 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
22:31:22.0664 3156 crcdisk - ok
22:31:22.0688 3156 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\windows\system32\cryptsvc.dll
22:31:22.0693 3156 CryptSvc - ok
22:31:22.0726 3156 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
22:31:22.0731 3156 DcomLaunch - ok
22:31:22.0754 3156 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
22:31:22.0761 3156 defragsvc - ok
22:31:22.0780 3156 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
22:31:22.0784 3156 DfsC - ok
22:31:22.0816 3156 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
22:31:22.0822 3156 Dhcp - ok
22:31:22.0831 3156 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
22:31:22.0834 3156 discache - ok
22:31:22.0855 3156 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
22:31:22.0859 3156 Disk - ok
22:31:22.0869 3156 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
22:31:22.0871 3156 Dnscache - ok
22:31:22.0893 3156 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
22:31:22.0899 3156 dot3svc - ok
22:31:22.0904 3156 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
22:31:22.0905 3156 DPS - ok
22:31:22.0939 3156 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
22:31:22.0941 3156 drmkaud - ok
22:31:22.0979 3156 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
22:31:22.0987 3156 DXGKrnl - ok
22:31:23.0008 3156 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
22:31:23.0008 3156 EapHost - ok
22:31:23.0095 3156 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
22:31:23.0137 3156 ebdrv - ok
22:31:23.0221 3156 EFS (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
22:31:23.0222 3156 EFS - ok
22:31:23.0291 3156 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
22:31:23.0317 3156 ehRecvr - ok
22:31:23.0346 3156 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
22:31:23.0352 3156 ehSched - ok
22:31:23.0400 3156 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
22:31:23.0414 3156 elxstor - ok
22:31:23.0425 3156 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
22:31:23.0429 3156 ErrDev - ok
22:31:23.0459 3156 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
22:31:23.0463 3156 EventSystem - ok
22:31:23.0484 3156 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
22:31:23.0489 3156 exfat - ok
22:31:23.0501 3156 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
22:31:23.0505 3156 fastfat - ok
22:31:23.0537 3156 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
22:31:23.0543 3156 Fax - ok
22:31:23.0554 3156 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
22:31:23.0557 3156 fdc - ok
22:31:23.0567 3156 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
22:31:23.0568 3156 fdPHost - ok
22:31:23.0584 3156 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
22:31:23.0585 3156 FDResPub - ok
22:31:23.0606 3156 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
22:31:23.0609 3156 FileInfo - ok
22:31:23.0617 3156 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
22:31:23.0620 3156 Filetrace - ok
22:31:23.0622 3156 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
22:31:23.0625 3156 flpydisk - ok
22:31:23.0640 3156 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
22:31:23.0647 3156 FltMgr - ok
22:31:23.0684 3156 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
22:31:23.0693 3156 FontCache - ok
22:31:23.0738 3156 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:31:23.0742 3156 FontCache3.0.0.0 - ok
22:31:23.0771 3156 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
22:31:23.0777 3156 FsDepends - ok
22:31:23.0797 3156 fssfltr (dc0dce4ec2c5d2cf6472f9fd6aa9a7dc) C:\windows\system32\DRIVERS\fssfltr.sys
22:31:23.0803 3156 fssfltr - ok
22:31:23.0891 3156 fsssvc (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
22:31:23.0913 3156 fsssvc - ok
22:31:24.0004 3156 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\windows\system32\drivers\Fs_Rec.sys
22:31:24.0008 3156 Fs_Rec - ok
22:31:24.0039 3156 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
22:31:24.0046 3156 fvevol - ok
22:31:24.0071 3156 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
22:31:24.0074 3156 gagp30kx - ok
22:31:24.0108 3156 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
22:31:24.0115 3156 gpsvc - ok
22:31:24.0184 3156 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:31:24.0185 3156 gupdate - ok
22:31:24.0188 3156 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:31:24.0188 3156 gupdatem - ok
22:31:24.0206 3156 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
22:31:24.0212 3156 gusvc - ok
22:31:24.0234 3156 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
22:31:24.0237 3156 hcw85cir - ok
22:31:24.0255 3156 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
22:31:24.0264 3156 HdAudAddService - ok
22:31:24.0285 3156 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\DRIVERS\HDAudBus.sys
22:31:24.0286 3156 HDAudBus - ok
22:31:24.0296 3156 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
22:31:24.0299 3156 HidBatt - ok
22:31:24.0312 3156 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\drivers\hidbth.sys
22:31:24.0315 3156 HidBth - ok
22:31:24.0339 3156 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
22:31:24.0342 3156 HidIr - ok
22:31:24.0367 3156 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\windows\System32\hidserv.dll
22:31:24.0371 3156 hidserv - ok
22:31:24.0394 3156 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
22:31:24.0396 3156 HidUsb - ok
22:31:24.0416 3156 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
22:31:24.0417 3156 hkmsvc - ok
22:31:24.0434 3156 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
22:31:24.0436 3156 HomeGroupListener - ok
22:31:24.0456 3156 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
22:31:24.0458 3156 HomeGroupProvider - ok
22:31:24.0474 3156 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
22:31:24.0477 3156 HpSAMD - ok
22:31:24.0512 3156 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
22:31:24.0552 3156 HTTP - ok
22:31:24.0616 3156 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
22:31:24.0619 3156 hwpolicy - ok
22:31:24.0641 3156 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
22:31:24.0646 3156 i8042prt - ok
22:31:24.0665 3156 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
22:31:24.0673 3156 iaStorV - ok
22:31:24.0731 3156 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:31:24.0756 3156 idsvc - ok
22:31:25.0110 3156 igfx (0d1b8c64bdf0e5cdc523a1409ffb5ef0) C:\windows\system32\DRIVERS\igdkmd64.sys
22:31:25.0219 3156 igfx - ok
22:31:25.0292 3156 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
22:31:25.0295 3156 iirsp - ok
22:31:25.0352 3156 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
22:31:25.0365 3156 IKEEXT - ok
22:31:25.0388 3156 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
22:31:25.0391 3156 intelide - ok
22:31:25.0408 3156 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
22:31:25.0408 3156 intelppm - ok
22:31:25.0430 3156 ioatdma (4dc8ed5a6a5affdc68f9371032b5424b) C:\windows\system32\Drivers\ioatdma.sys
22:31:25.0433 3156 ioatdma - ok
22:31:25.0457 3156 ioatdma1 (e45575812630b049ce0f679d87561a4d) C:\windows\System32\Drivers\qd162x64.sys
22:31:25.0462 3156 ioatdma1 - ok
22:31:25.0469 3156 ioatdma2 (2c23820dd9e81199e60f553eb50bc449) C:\windows\System32\Drivers\qd262x64.sys
22:31:25.0475 3156 ioatdma2 - ok
22:31:25.0482 3156 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
22:31:25.0486 3156 IPBusEnum - ok
22:31:25.0503 3156 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
22:31:25.0507 3156 IpFilterDriver - ok
22:31:25.0542 3156 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
22:31:25.0547 3156 iphlpsvc - ok
22:31:25.0562 3156 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
22:31:25.0565 3156 IPMIDRV - ok
22:31:25.0581 3156 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
22:31:25.0584 3156 IPNAT - ok
22:31:25.0599 3156 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
22:31:25.0601 3156 IRENUM - ok
22:31:25.0618 3156 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
22:31:25.0621 3156 isapnp - ok
22:31:25.0638 3156 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
22:31:25.0649 3156 iScsiPrt - ok
22:31:25.0673 3156 JRAID (1c368c1a2733dcc5b8e15420aa2b0f6d) C:\windows\system32\drivers\jraid.sys
22:31:25.0679 3156 JRAID - ok
22:31:25.0687 3156 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
22:31:25.0692 3156 kbdclass - ok
22:31:25.0713 3156 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
22:31:25.0716 3156 kbdhid - ok
22:31:25.0763 3156 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:31:25.0764 3156 KeyIso - ok
22:31:25.0773 3156 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
22:31:25.0777 3156 KSecDD - ok
22:31:25.0788 3156 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
22:31:25.0794 3156 KSecPkg - ok
22:31:25.0802 3156 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
22:31:25.0805 3156 ksthunk - ok
22:31:25.0829 3156 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
22:31:25.0838 3156 KtmRm - ok
22:31:25.0864 3156 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\System32\srvsvc.dll
22:31:25.0867 3156 LanmanServer - ok
22:31:25.0884 3156 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
22:31:25.0886 3156 LanmanWorkstation - ok
22:31:25.0920 3156 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
22:31:25.0923 3156 lltdio - ok
22:31:25.0948 3156 lltdsvc (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
22:31:25.0960 3156 lltdsvc - ok
22:31:25.0975 3156 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
22:31:25.0976 3156 lmhosts - ok
22:31:26.0002 3156 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
22:31:26.0008 3156 LSI_FC - ok
22:31:26.0019 3156 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
22:31:26.0024 3156 LSI_SAS - ok
22:31:26.0032 3156 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
22:31:26.0036 3156 LSI_SAS2 - ok
22:31:26.0053 3156 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
22:31:26.0057 3156 LSI_SCSI - ok
22:31:26.0070 3156 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
22:31:26.0074 3156 luafv - ok
22:31:26.0102 3156 MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\windows\system32\drivers\mbam.sys
22:31:26.0102 3156 MBAMProtector - ok
22:31:26.0151 3156 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:31:26.0157 3156 MBAMService - ok
22:31:26.0185 3156 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
22:31:26.0192 3156 Mcx2Svc - ok
22:31:26.0214 3156 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
22:31:26.0218 3156 megasas - ok
22:31:26.0246 3156 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
22:31:26.0257 3156 MegaSR - ok
22:31:26.0297 3156 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
22:31:26.0298 3156 MMCSS - ok
22:31:26.0311 3156 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
22:31:26.0315 3156 Modem - ok
22:31:26.0336 3156 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
22:31:26.0337 3156 monitor - ok
22:31:26.0346 3156 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
22:31:26.0351 3156 mouclass - ok
22:31:26.0363 3156 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
22:31:26.0366 3156 mouhid - ok
22:31:26.0387 3156 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
22:31:26.0391 3156 mountmgr - ok
22:31:26.0440 3156 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:31:26.0449 3156 MozillaMaintenance - ok
22:31:26.0470 3156 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
22:31:26.0479 3156 mpio - ok
22:31:26.0491 3156 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
22:31:26.0496 3156 mpsdrv - ok
22:31:26.0549 3156 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
22:31:26.0569 3156 MpsSvc - ok
22:31:26.0588 3156 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
22:31:26.0592 3156 MRxDAV - ok
22:31:26.0644 3156 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
22:31:26.0648 3156 mrxsmb - ok
22:31:26.0662 3156 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
22:31:26.0668 3156 mrxsmb10 - ok
22:31:26.0682 3156 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
22:31:26.0689 3156 mrxsmb20 - ok
22:31:26.0701 3156 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
22:31:26.0706 3156 msahci - ok
22:31:26.0720 3156 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
22:31:26.0727 3156 msdsm - ok
22:31:26.0749 3156 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
22:31:26.0756 3156 MSDTC - ok
22:31:26.0776 3156 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
22:31:26.0779 3156 Msfs - ok
22:31:26.0786 3156 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
22:31:26.0788 3156 mshidkmdf - ok
22:31:26.0797 3156 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
22:31:26.0800 3156 msisadrv - ok
22:31:26.0827 3156 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
22:31:26.0833 3156 MSiSCSI - ok
22:31:26.0837 3156 msiserver - ok
22:31:26.0860 3156 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
22:31:26.0863 3156 MSKSSRV - ok
22:31:26.0867 3156 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
22:31:26.0870 3156 MSPCLOCK - ok
22:31:26.0873 3156 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
22:31:26.0875 3156 MSPQM - ok
22:31:26.0895 3156 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
22:31:26.0904 3156 MsRPC - ok
22:31:26.0918 3156 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
22:31:26.0918 3156 mssmbios - ok
22:31:26.0921 3156 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
22:31:26.0923 3156 MSTEE - ok
22:31:26.0925 3156 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
22:31:26.0927 3156 MTConfig - ok
22:31:26.0947 3156 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\windows\system32\drivers\ASACPI.sys
22:31:26.0950 3156 MTsensor - ok
22:31:26.0962 3156 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
22:31:26.0965 3156 Mup - ok
22:31:26.0999 3156 napagent (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
22:31:27.0004 3156 napagent - ok
22:31:27.0035 3156 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
22:31:27.0042 3156 NativeWifiP - ok
22:31:27.0096 3156 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
22:31:27.0105 3156 NDIS - ok
22:31:27.0118 3156 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
22:31:27.0121 3156 NdisCap - ok
22:31:27.0134 3156 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
22:31:27.0137 3156 NdisTapi - ok
22:31:27.0146 3156 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
22:31:27.0150 3156 Ndisuio - ok
22:31:27.0156 3156 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
22:31:27.0160 3156 NdisWan - ok
22:31:27.0171 3156 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
22:31:27.0174 3156 NDProxy - ok
22:31:27.0189 3156 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
22:31:27.0192 3156 NetBIOS - ok
22:31:27.0222 3156 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
22:31:27.0228 3156 NetBT - ok
22:31:27.0280 3156 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:31:27.0281 3156 Netlogon - ok
22:31:27.0310 3156 Netman (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
22:31:27.0316 3156 Netman - ok
22:31:27.0369 3156 NetMsmqActivator (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:31:27.0370 3156 NetMsmqActivator - ok
22:31:27.0374 3156 NetPipeActivator (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:31:27.0375 3156 NetPipeActivator - ok
22:31:27.0391 3156 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
22:31:27.0397 3156 netprofm - ok
22:31:27.0438 3156 netr28x (b72bb9496a126fcfc7fc5945ded9b411) C:\windows\system32\DRIVERS\netr28x.sys
22:31:27.0453 3156 netr28x - ok
22:31:27.0457 3156 NetTcpActivator (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:31:27.0459 3156 NetTcpActivator - ok
22:31:27.0461 3156 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:31:27.0462 3156 NetTcpPortSharing - ok
22:31:27.0481 3156 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
22:31:27.0484 3156 nfrd960 - ok
22:31:27.0517 3156 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
22:31:27.0522 3156 NlaSvc - ok
22:31:27.0537 3156 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
22:31:27.0541 3156 Npfs - ok
22:31:27.0550 3156 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
22:31:27.0551 3156 nsi - ok
22:31:27.0561 3156 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
22:31:27.0564 3156 nsiproxy - ok
22:31:27.0624 3156 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
22:31:27.0649 3156 Ntfs - ok
22:31:27.0705 3156 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
22:31:27.0707 3156 Null - ok
22:31:27.0724 3156 nusb3hub (285acec1b13a15ba520aae06bacb9cff) C:\windows\system32\drivers\nusb3hub.sys
22:31:27.0729 3156 nusb3hub - ok
22:31:27.0743 3156 nusb3xhc (f6d625ff7b56bb6ea063f0d3a5bbc996) C:\windows\system32\drivers\nusb3xhc.sys
22:31:27.0748 3156 nusb3xhc - ok
22:31:28.0042 3156 nvlddmkm (dd81fbc57ab9134cddc5ce90880bfd80) C:\windows\system32\DRIVERS\nvlddmkm.sys
22:31:28.0153 3156 nvlddmkm - ok
22:31:28.0237 3156 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
22:31:28.0244 3156 nvraid - ok
22:31:28.0261 3156 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
22:31:28.0268 3156 nvstor - ok
22:31:28.0294 3156 NvStUSB (4dc87cda61d7b185e79618581f46b85a) C:\windows\system32\drivers\nvstusb.sys
22:31:28.0301 3156 NvStUSB - ok
22:31:28.0311 3156 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
22:31:28.0316 3156 nv_agp - ok
22:31:28.0432 3156 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:31:28.0458 3156 odserv - ok
22:31:28.0503 3156 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
22:31:28.0509 3156 ohci1394 - ok
22:31:28.0523 3156 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:31:28.0533 3156 ose - ok
22:31:28.0595 3156 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
22:31:28.0600 3156 p2pimsvc - ok
22:31:28.0621 3156 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
22:31:28.0628 3156 p2psvc - ok
22:31:28.0646 3156 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
22:31:28.0652 3156 Parport - ok
22:31:28.0695 3156 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\windows\system32\drivers\partmgr.sys
22:31:28.0701 3156 partmgr - ok
22:31:28.0709 3156 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
22:31:28.0712 3156 PcaSvc - ok
22:31:28.0724 3156 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
22:31:28.0733 3156 pci - ok
22:31:28.0745 3156 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
22:31:28.0749 3156 pciide - ok
22:31:28.0767 3156 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
22:31:28.0777 3156 pcmcia - ok
22:31:28.0786 3156 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
22:31:28.0791 3156 pcw - ok
22:31:28.0819 3156 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
22:31:28.0840 3156 PEAUTH - ok
22:31:28.0885 3156 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
22:31:28.0891 3156 PerfHost - ok
22:31:28.0958 3156 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
22:31:28.0985 3156 pla - ok
22:31:29.0032 3156 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
22:31:29.0039 3156 PlugPlay - ok
22:31:29.0052 3156 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
22:31:29.0058 3156 PNRPAutoReg - ok
22:31:29.0078 3156 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
22:31:29.0082 3156 PNRPsvc - ok
22:31:29.0114 3156 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
22:31:29.0121 3156 PolicyAgent - ok
22:31:29.0130 3156 Power (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
22:31:29.0133 3156 Power - ok
22:31:29.0161 3156 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
22:31:29.0165 3156 PptpMiniport - ok
22:31:29.0173 3156 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
22:31:29.0178 3156 Processor - ok
22:31:29.0200 3156 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\windows\system32\profsvc.dll
22:31:29.0203 3156 ProfSvc - ok
22:31:29.0239 3156 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:31:29.0241 3156 ProtectedStorage - ok
22:31:29.0260 3156 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
22:31:29.0266 3156 Psched - ok
22:31:29.0318 3156 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\windows\system32\Drivers\PxHlpa64.sys
22:31:29.0322 3156 PxHlpa64 - ok
22:31:29.0371 3156 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
22:31:29.0390 3156 ql2300 - ok
22:31:29.0460 3156 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
22:31:29.0465 3156 ql40xx - ok
22:31:29.0492 3156 QWAVE (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
22:31:29.0499 3156 QWAVE - ok
22:31:29.0512 3156 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
22:31:29.0515 3156 QWAVEdrv - ok
22:31:29.0528 3156 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
22:31:29.0530 3156 RasAcd - ok
22:31:29.0541 3156 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
22:31:29.0546 3156 RasAgileVpn - ok
22:31:29.0553 3156 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
22:31:29.0560 3156 RasAuto - ok
22:31:29.0572 3156 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
22:31:29.0577 3156 Rasl2tp - ok
22:31:29.0598 3156 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
22:31:29.0602 3156 RasMan - ok
22:31:29.0624 3156 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
22:31:29.0628 3156 RasPppoe - ok
22:31:29.0643 3156 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
22:31:29.0647 3156 RasSstp - ok
22:31:29.0658 3156 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
22:31:29.0668 3156 rdbss - ok
22:31:29.0681 3156 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\drivers\rdpbus.sys
22:31:29.0683 3156 rdpbus - ok
22:31:29.0702 3156 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
22:31:29.0704 3156 RDPCDD - ok
22:31:29.0712 3156 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
22:31:29.0714 3156 RDPENCDD - ok
22:31:29.0727 3156 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
22:31:29.0729 3156 RDPREFMP - ok
22:31:29.0771 3156 RDPWD (6d76e6433574b058adcb0c50df834492) C:\windows\system32\drivers\RDPWD.sys
22:31:29.0775 3156 RDPWD - ok
22:31:29.0798 3156 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
22:31:29.0806 3156 rdyboost - ok
22:31:29.0825 3156 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
22:31:29.0831 3156 RemoteAccess - ok
22:31:29.0851 3156 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
22:31:29.0857 3156 RemoteRegistry - ok
22:31:29.0868 3156 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
22:31:29.0870 3156 RpcEptMapper - ok
22:31:29.0875 3156 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
22:31:29.0878 3156 RpcLocator - ok
22:31:29.0901 3156 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
22:31:29.0905 3156 RpcSs - ok
22:31:29.0919 3156 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
22:31:29.0923 3156 rspndr - ok
22:31:29.0990 3156 RTL8167 (9140db0911de035fed0a9a77a2d156ea) C:\windows\system32\DRIVERS\Rt64win7.sys
22:31:29.0999 3156 RTL8167 - ok
22:31:30.0039 3156 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:31:30.0041 3156 SamSs - ok
22:31:30.0062 3156 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
22:31:30.0069 3156 sbp2port - ok
22:31:30.0094 3156 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
22:31:30.0102 3156 SCardSvr - ok
22:31:30.0112 3156 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
22:31:30.0117 3156 scfilter - ok
22:31:30.0156 3156 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
22:31:30.0171 3156 Schedule - ok
22:31:30.0200 3156 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
22:31:30.0201 3156 SCPolicySvc - ok
22:31:30.0213 3156 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
22:31:30.0224 3156 SDRSVC - ok
22:31:30.0275 3156 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
22:31:30.0277 3156 SeaPort - ok
22:31:30.0313 3156 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
22:31:30.0317 3156 secdrv - ok
22:31:30.0339 3156 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
22:31:30.0345 3156 seclogon - ok
22:31:30.0354 3156 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\windows\system32\sens.dll
22:31:30.0357 3156 SENS - ok
22:31:30.0366 3156 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
22:31:30.0372 3156 SensrSvc - ok
22:31:30.0386 3156 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\drivers\serenum.sys
22:31:30.0390 3156 Serenum - ok
22:31:30.0404 3156 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
22:31:30.0411 3156 Serial - ok
22:31:30.0418 3156 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
22:31:30.0422 3156 sermouse - ok
22:31:30.0443 3156 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
22:31:30.0448 3156 SessionEnv - ok
22:31:30.0462 3156 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
22:31:30.0464 3156 sffdisk - ok
22:31:30.0472 3156 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
22:31:30.0474 3156 sffp_mmc - ok
22:31:30.0476 3156 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
22:31:30.0478 3156 sffp_sd - ok
22:31:30.0480 3156 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
22:31:30.0482 3156 sfloppy - ok
22:31:30.0512 3156 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
22:31:30.0520 3156 SharedAccess - ok
22:31:30.0544 3156 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
22:31:30.0551 3156 ShellHWDetection - ok
22:31:30.0567 3156 SISAGP (5ff60b0a945343c05f929379b4089525) C:\windows\system32\drivers\SISAGPX.sys
22:31:30.0570 3156 SISAGP - ok
22:31:30.0591 3156 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
22:31:30.0596 3156 SiSRaid2 - ok
22:31:30.0614 3156 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
22:31:30.0620 3156 SiSRaid4 - ok
22:31:30.0643 3156 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
22:31:30.0648 3156 Smb - ok
22:31:30.0677 3156 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
22:31:30.0681 3156 SNMPTRAP - ok
22:31:30.0686 3156 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
22:31:30.0688 3156 spldr - ok
22:31:30.0709 3156 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
22:31:30.0712 3156 Spooler - ok
22:31:30.0826 3156 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
22:31:30.0856 3156 sppsvc - ok
22:31:30.0912 3156 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
22:31:30.0915 3156 sppuinotify - ok
22:31:30.0945 3156 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
22:31:30.0953 3156 srv - ok
22:31:30.0965 3156 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
22:31:30.0974 3156 srv2 - ok
22:31:30.0986 3156 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
22:31:30.0990 3156 srvnet - ok
22:31:31.0006 3156 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
22:31:31.0008 3156 SSDPSRV - ok
22:31:31.0035 3156 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
22:31:31.0039 3156 SstpSvc - ok
22:31:31.0056 3156 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
22:31:31.0059 3156 stexstor - ok
22:31:31.0098 3156 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
22:31:31.0113 3156 stisvc - ok
22:31:31.0118 3156 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
22:31:31.0122 3156 swenum - ok
22:31:31.0148 3156 swprv (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
22:31:31.0152 3156 swprv - ok
22:31:31.0207 3156 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
22:31:31.0223 3156 SysMain - ok
22:31:31.0282 3156 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
22:31:31.0287 3156 TabletInputService - ok
22:31:31.0302 3156 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
22:31:31.0306 3156 TapiSrv - ok
22:31:31.0314 3156 TBS (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
22:31:31.0318 3156 TBS - ok
22:31:31.0411 3156 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\drivers\tcpip.sys
22:31:31.0438 3156 Tcpip - ok
22:31:31.0543 3156 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\DRIVERS\tcpip.sys
22:31:31.0560 3156 TCPIP6 - ok
22:31:31.0600 3156 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
22:31:31.0605 3156 tcpipreg - ok
22:31:31.0621 3156 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
22:31:31.0625 3156 TDPIPE - ok
22:31:31.0689 3156 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
22:31:31.0735 3156 TDTCP - ok
22:31:31.0843 3156 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
22:31:31.0849 3156 tdx - ok
22:31:31.0866 3156 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\DRIVERS\termdd.sys
22:31:31.0871 3156 TermDD - ok
22:31:31.0911 3156 TermService (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
22:31:31.0935 3156 TermService - ok
22:31:31.0947 3156 Themes (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
22:31:31.0950 3156 Themes - ok
22:31:31.0972 3156 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
22:31:31.0974 3156 THREADORDER - ok
22:31:31.0991 3156 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
22:31:31.0993 3156 TrkWks - ok
22:31:32.0031 3156 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
22:31:32.0034 3156 TrustedInstaller - ok
22:31:32.0046 3156 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
22:31:32.0051 3156 tssecsrv - ok
22:31:32.0076 3156 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
22:31:32.0082 3156 TsUsbFlt - ok
22:31:32.0096 3156 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\windows\system32\drivers\TsUsbGD.sys
22:31:32.0101 3156 TsUsbGD - ok
22:31:32.0122 3156 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
22:31:32.0124 3156 tunnel - ok
22:31:32.0134 3156 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\drivers\uagp35.sys
22:31:32.0139 3156 uagp35 - ok
22:31:32.0158 3156 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
22:31:32.0169 3156 udfs - ok
22:31:32.0215 3156 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
22:31:32.0223 3156 UI0Detect - ok
22:31:32.0236 3156 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
22:31:32.0242 3156 uliagpkx - ok
22:31:32.0260 3156 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\DRIVERS\umbus.sys
22:31:32.0266 3156 umbus - ok
22:31:32.0289 3156 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\drivers\umpass.sys
22:31:32.0293 3156 UmPass - ok
22:31:32.0315 3156 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
22:31:32.0321 3156 upnphost - ok
22:31:32.0365 3156 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\windows\system32\drivers\usbaudio.sys
22:31:32.0372 3156 usbaudio - ok
22:31:32.0390 3156 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
22:31:32.0396 3156 usbccgp - ok
22:31:32.0402 3156 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
22:31:32.0410 3156 usbcir - ok
22:31:32.0419 3156 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\DRIVERS\usbehci.sys
22:31:32.0424 3156 usbehci - ok
22:31:32.0445 3156 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
22:31:32.0457 3156 usbhub - ok
22:31:32.0467 3156 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
22:31:32.0472 3156 usbohci - ok
22:31:32.0476 3156 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\drivers\usbprint.sys
22:31:32.0478 3156 usbprint - ok
22:31:32.0491 3156 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
22:31:32.0494 3156 USBSTOR - ok
22:31:32.0497 3156 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
22:31:32.0500 3156 usbuhci - ok
22:31:32.0535 3156 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\windows\system32\Drivers\usbvideo.sys
22:31:32.0540 3156 usbvideo - ok
22:31:32.0564 3156 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
22:31:32.0566 3156 UxSms - ok
22:31:32.0605 3156 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
22:31:32.0606 3156 VaultSvc - ok
22:31:32.0614 3156 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
22:31:32.0618 3156 vdrvroot - ok
22:31:32.0684 3156 vds (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
22:31:32.0698 3156 vds - ok
22:31:32.0719 3156 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
22:31:32.0723 3156 vga - ok
22:31:32.0733 3156 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
22:31:32.0737 3156 VgaSave - ok
22:31:32.0753 3156 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
22:31:32.0763 3156 vhdmp - ok
22:31:32.0853 3156 VIAHdAudAddService (d86967acfe0783cee2909a9af0787045) C:\windows\system32\drivers\viahduaa.sys
22:31:32.0870 3156 VIAHdAudAddService - ok
22:31:32.0937 3156 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
22:31:32.0940 3156 viaide - ok
22:31:32.0955 3156 VIAKaraokeService (9a12b5ac0e983e0309371dba058019a4) C:\windows\system32\viakaraokesrv.exe
22:31:32.0956 3156 VIAKaraokeService - ok
22:31:32.0971 3156 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
22:31:32.0975 3156 volmgr - ok
22:31:32.0989 3156 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
22:31:32.0999 3156 volmgrx - ok
22:31:33.0015 3156 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
22:31:33.0023 3156 volsnap - ok
22:31:33.0039 3156 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\drivers\vsmraid.sys
22:31:33.0045 3156 vsmraid - ok
22:31:33.0101 3156 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
22:31:33.0116 3156 VSS - ok
22:31:33.0180 3156 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
22:31:33.0182 3156 vwifibus - ok
22:31:33.0201 3156 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
22:31:33.0205 3156 vwififlt - ok
22:31:33.0217 3156 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys
22:31:33.0219 3156 vwifimp - ok
22:31:33.0243 3156 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
22:31:33.0247 3156 W32Time - ok
22:31:33.0303 3156 W3SVC (b32009db1972e7f2c227499289c4384a) C:\windows\system32\inetsrv\iisw3adm.dll
22:31:33.0313 3156 W3SVC - ok
22:31:33.0321 3156 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\drivers\wacompen.sys
22:31:33.0325 3156 WacomPen - ok
22:31:33.0350 3156 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
22:31:33.0356 3156 WANARP - ok
22:31:33.0360 3156 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
22:31:33.0361 3156 Wanarpv6 - ok
22:31:33.0368 3156 WAS (b32009db1972e7f2c227499289c4384a) C:\windows\system32\inetsrv\iisw3adm.dll
22:31:33.0372 3156 WAS - ok
22:31:33.0451 3156 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\windows\system32\Wat\WatAdminSvc.exe
22:31:33.0476 3156 WatAdminSvc - ok
22:31:33.0533 3156 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
22:31:33.0553 3156 wbengine - ok
22:31:33.0608 3156 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
22:31:33.0613 3156 WbioSrvc - ok
22:31:33.0630 3156 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
22:31:33.0638 3156 wcncsvc - ok
22:31:33.0649 3156 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
22:31:33.0653 3156 WcsPlugInService - ok
22:31:33.0672 3156 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\drivers\wd.sys
22:31:33.0676 3156 Wd - ok
22:31:33.0703 3156 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
22:31:33.0715 3156 Wdf01000 - ok
22:31:33.0722 3156 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
22:31:33.0727 3156 WdiServiceHost - ok
22:31:33.0729 3156 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
22:31:33.0730 3156 WdiSystemHost - ok
22:31:33.0747 3156 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
22:31:33.0754 3156 WebClient - ok
22:31:33.0770 3156 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
22:31:33.0776 3156 Wecsvc - ok
22:31:33.0801 3156 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
22:31:33.0802 3156 wercplsupport - ok
22:31:33.0812 3156 WerSvc (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
22:31:33.0816 3156 WerSvc - ok
22:31:33.0849 3156 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
22:31:33.0851 3156 WfpLwf - ok
22:31:33.0858 3156 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
22:31:33.0860 3156 WIMMount - ok
22:31:33.0880 3156 WinDefend - ok
22:31:33.0883 3156 WinHttpAutoProxySvc - ok
22:31:33.0924 3156 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
22:31:33.0927 3156 Winmgmt - ok
22:31:34.0002 3156 WinRM (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
22:31:34.0028 3156 WinRM - ok
22:31:34.0126 3156 WinUsb (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
22:31:34.0133 3156 WinUsb - ok
22:31:34.0168 3156 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
22:31:34.0180 3156 Wlansvc - ok
22:31:34.0230 3156 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
22:31:34.0236 3156 wlcrasvc - ok
22:31:34.0358 3156 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:31:34.0369 3156 wlidsvc - ok
22:31:34.0441 3156 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys
22:31:34.0441 3156 WmiAcpi - ok
22:31:34.0477 3156 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
22:31:34.0484 3156 wmiApSrv - ok
22:31:34.0523 3156 WMPNetworkSvc - ok
22:31:34.0543 3156 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
22:31:34.0546 3156 WPCSvc - ok
22:31:34.0559 3156 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
22:31:34.0561 3156 WPDBusEnum - ok
22:31:34.0574 3156 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
22:31:34.0576 3156 ws2ifsl - ok
22:31:34.0601 3156 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\system32\wscsvc.dll
22:31:34.0604 3156 wscsvc - ok
22:31:34.0607 3156 WSearch - ok
22:31:34.0677 3156 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\windows\system32\wuaueng.dll
22:31:34.0699 3156 wuauserv - ok
22:31:34.0762 3156 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
22:31:34.0768 3156 WudfPf - ok
22:31:34.0792 3156 WUDFRd (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
22:31:34.0796 3156 WUDFRd - ok
22:31:34.0820 3156 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
22:31:34.0826 3156 wudfsvc - ok
22:31:34.0839 3156 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
22:31:34.0846 3156 WwanSvc - ok
22:31:34.0869 3156 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:31:34.0939 3156 \Device\Harddisk0\DR0 - ok
22:31:34.0944 3156 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
22:31:34.0948 3156 \Device\Harddisk1\DR1 - ok
22:31:34.0950 3156 Boot (0x1200) (bad03ac73b4b60e852a5b0f89ecf8127) \Device\Harddisk0\DR0\Partition0
22:31:34.0951 3156 \Device\Harddisk0\DR0\Partition0 - ok
22:31:34.0958 3156 Boot (0x1200) (4045f969379b28f562185f2a969818ba) \Device\Harddisk0\DR0\Partition1
22:31:34.0959 3156 \Device\Harddisk0\DR0\Partition1 - ok
22:31:34.0962 3156 Boot (0x1200) (f3aaa7fdd8ddc17c5fbdf4ce3937bfea) \Device\Harddisk1\DR1\Partition0
22:31:34.0963 3156 \Device\Harddisk1\DR1\Partition0 - ok
22:31:34.0964 3156 ============================================================
22:31:34.0964 3156 Scan finished
22:31:34.0964 3156 ============================================================
22:31:34.0975 2752 Detected object count: 0
22:31:34.0975 2752 Actual detected object count: 0

#7 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 13 May 2012 - 06:45 PM

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-13 22:37:05
-----------------------------
22:37:05.860 OS Version: Windows x64 6.1.7601 Service Pack 1
22:37:05.860 Number of processors: 8 586 0x2A07
22:37:05.861 ComputerName: WILLIAM-ZOO UserName: William
22:37:07.004 Initialize success
22:39:29.068 AVAST engine defs: 12051301
22:42:12.959 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:42:12.961 Disk 0 Vendor: Hitachi_HDS721010DLE630 MS2OA5Q0 Size: 953869MB BusType: 3
22:42:12.964 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000067
22:42:12.966 Disk 1 Vendor: Size: 953869MB BusType: 0
22:42:12.988 Disk 0 MBR read successfully
22:42:12.991 Disk 0 MBR scan
22:42:12.996 Disk 0 Windows 7 default MBR code
22:42:13.000 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 6500 MB offset 2048
22:42:13.015 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 300 MB offset 13314048
22:42:13.026 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 947068 MB offset 13928448
22:42:13.041 Disk 0 scanning C:\windows\system32\drivers
22:42:19.339 Service scanning
22:42:36.208 Modules scanning
22:42:36.544 Disk 0 trace - called modules:
22:42:36.562 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
22:42:36.567 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007d50790]
22:42:36.573 3 CLASSPNP.SYS[fffff880019c643f] -> nt!IofCallDriver -> [0xfffffa8007742e40]
22:42:36.578 5 ACPI.sys[fffff88000f087a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8007747060]
22:42:37.638 AVAST engine scan C:\
22:50:17.083 Disk 0 MBR has been saved successfully to "C:\Users\William\Desktop\MBR.dat"
22:50:17.086 The log file has been saved successfully to "C:\Users\William\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-13 22:51:54
-----------------------------
22:51:54.998 OS Version: Windows x64 6.1.7601 Service Pack 1
22:51:54.998 Number of processors: 8 586 0x2A07
22:51:54.998 ComputerName: WILLIAM-ZOO UserName: William
22:51:56.169 Initialze error C000010E - driver not loaded
22:51:58.578 AVAST engine defs: 12051301
22:52:05.071 Service scanning
22:52:21.942 Modules scanning
22:52:21.946 Disk 0 trace - called modules:
22:52:21.949
22:52:22.934 AVAST engine scan C:\
00:05:17.897 Scan finished successfully
00:44:38.634 The log file has been saved successfully to "C:\Users\William\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-13 22:51:54
-----------------------------
22:51:54.998 OS Version: Windows x64 6.1.7601 Service Pack 1
22:51:54.998 Number of processors: 8 586 0x2A07
22:51:54.998 ComputerName: WILLIAM-ZOO UserName: William
22:51:56.169 Initialze error C000010E - driver not loaded
22:51:58.578 AVAST engine defs: 12051301
22:52:05.071 Service scanning
22:52:21.942 Modules scanning
22:52:21.946 Disk 0 trace - called modules:
22:52:21.949
22:52:22.934 AVAST engine scan C:\
00:05:17.897 Scan finished successfully
00:44:38.634 The log file has been saved successfully to "C:\Users\William\Desktop\aswMBR.txt"
00:44:50.725 The log file has been saved successfully to "C:\Users\William\Desktop\aswMBR.txt"

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 13 May 2012 - 08:29 PM

Hello


let me know about the redirects.

which browsers are redirecting - please check all that are installed



:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

Edited by gringo_pr, 13 May 2012 - 08:32 PM.

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 14 May 2012 - 05:32 PM

I think it's sorted. I use Firefox. I've added the log but will keep you posted. Thanks for all your help so far.

ComboFix 12-05-10.04 - William 14/05/2012 23:19:03.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8104.6418 [GMT 1:00]
Running from: c:\users\William\Desktop\ComboFix.exe
Command switches used :: c:\users\William\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-04-14 to 2012-05-14 )))))))))))))))))))))))))))))))
.
.
2012-05-14 22:22 . 2012-05-14 22:22 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2012-05-14 22:22 . 2012-05-14 22:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-13 00:41 . 2012-05-13 00:41 -------- d-----w- c:\users\William\AppData\Local\Windows Live Writer
2012-05-13 00:41 . 2012-05-13 00:41 -------- d-----w- c:\users\William\AppData\Roaming\Windows Live Writer
2012-05-12 10:19 . 2012-04-18 02:03 8917360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{ADF11A33-9F48-4E7D-BDC4-6AD231E5E9B9}\mpengine.dll
2012-05-10 23:08 . 2012-05-10 23:08 -------- d-----w- c:\program files\Microsoft Silverlight
2012-05-10 23:08 . 2012-05-10 23:08 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-05-10 22:07 . 2012-05-10 22:07 -------- d-----w- c:\users\William\AppData\Roaming\CheckPoint
2012-05-10 22:06 . 2012-05-10 22:06 -------- d-----w- c:\programdata\CheckPoint
2012-05-10 21:54 . 2012-05-10 21:54 -------- d-----w- c:\users\William\AppData\Roaming\Avira
2012-05-10 21:48 . 2012-05-11 21:54 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-10 21:48 . 2012-05-11 21:54 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-05-10 21:48 . 2012-05-10 21:48 -------- d-----w- c:\programdata\Avira
2012-05-10 21:48 . 2012-05-10 21:48 -------- d-----w- c:\program files (x86)\Avira
2012-05-10 21:48 . 2011-09-16 15:09 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-05-10 20:29 . 2012-05-10 20:29 -------- d-----w- c:\users\William\AppData\Roaming\dvdcss
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\users\William\AppData\Roaming\Malwarebytes
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-05-07 11:52 . 2012-05-07 11:52 -------- d-----w- c:\programdata\Malwarebytes
2012-05-07 11:52 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-06 22:04 . 2012-05-06 22:05 -------- d-----w- c:\users\William\AppData\Roaming\fifa
2012-05-06 22:03 . 2012-05-06 22:03 -------- d-----w- c:\users\William\AppData\Local\{5F46DF5E-97C7-11E1-826E-B8AC6F996F26}
2012-05-06 22:03 . 2012-05-06 22:03 -------- d-----w- c:\users\William\AppData\Local\{5F46AD4A-97C7-11E1-826E-B8AC6F996F26}
2012-05-05 09:26 . 2012-05-14 18:55 -------- d-----w- c:\users\William\AppData\Roaming\Skype
2012-05-04 19:51 . 2012-05-04 19:51 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-05-04 19:50 . 2012-05-04 19:50 157352 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-04 19:50 . 2012-05-04 19:50 129976 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
2012-04-26 20:46 . 2012-05-14 21:39 -------- d-----r- c:\users\William\Dropbox
2012-04-26 20:44 . 2012-05-14 21:39 -------- d-----w- c:\users\William\AppData\Roaming\Dropbox
2012-04-17 21:36 . 2012-04-17 21:36 -------- d-----w- c:\program files (x86)\MSECache
2012-04-16 21:02 . 2012-04-16 21:45 -------- d-----w- c:\users\William\AppData\Local\CutePDF Writer
2012-04-16 21:00 . 2012-04-16 21:00 -------- d-----w- c:\program files (x86)\GPLGS
2012-04-16 21:00 . 2012-03-11 13:56 86608 ----a-w- c:\windows\system32\cpwmon64.dll
2012-04-16 21:00 . 2012-04-16 21:00 -------- d-----w- c:\program files (x86)\Acro Software
2012-04-15 15:06 . 2012-04-15 15:08 -------- d-----w- c:\program files (x86)\AndreaMosaic
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-13 00:15 . 2012-04-11 16:56 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-13 00:15 . 2011-11-07 13:52 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-01 20:31 . 2012-04-01 20:31 544656 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-01 20:09 . 2012-04-01 20:09 627600 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-01 06:46 . 2012-04-12 17:49 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-03-01 06:38 . 2012-04-12 17:49 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-03-01 06:33 . 2012-04-12 17:49 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-03-01 06:28 . 2012-04-12 17:49 5120 ----a-w- c:\windows\system32\wmi.dll
2012-03-01 05:37 . 2012-04-12 17:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-03-01 05:33 . 2012-04-12 17:49 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-03-01 05:29 . 2012-04-12 17:49 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-02-28 06:56 . 2012-04-12 17:51 2311168 ----a-w- c:\windows\system32\jscript9.dll
2012-02-28 06:49 . 2012-04-12 17:51 1390080 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 06:48 . 2012-04-12 17:51 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 06:42 . 2012-04-12 17:51 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-02-28 01:18 . 2012-04-12 17:51 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-02-28 01:11 . 2012-04-12 17:51 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11 . 2012-04-12 17:51 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2012-02-28 01:03 . 2012-04-12 17:51 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-02-26 18:55 . 2011-03-28 18:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-02-23 09:18 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-02-17 06:38 . 2012-03-13 18:36 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-13 18:36 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-13 18:36 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-13 18:36 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2006-11-16 12:45 . 2012-02-24 22:00 35 ----a-w- c:\program files\run.bat
2006-11-16 11:01 . 2012-02-24 21:59 4382208 ----a-w- c:\program files\IU.MSP
.
.
((((((((((((((((((((((((((((( SnapShot_2012-05-12_00.08.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-21 03:09 . 2012-05-14 21:38 42662 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-05-14 21:38 34858 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-02-24 20:17 . 2012-05-14 21:38 10852 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1360622652-2071615853-753804455-1000_UserData.bin
+ 2009-07-14 05:30 . 2012-05-12 12:07 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2012-05-10 23:14 86016 c:\windows\system32\DriverStore\infpub.dat
- 2012-02-24 20:15 . 2012-04-25 20:49 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-02-24 20:15 . 2012-05-12 16:36 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-02-24 20:15 . 2012-05-12 16:36 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-02-24 20:15 . 2012-04-25 20:49 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-25 20:49 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-05-12 16:36 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2012-05-12 10:18 95640 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2012-05-12 00:07 . 2012-05-12 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-05-14 22:23 . 2012-05-14 22:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-05-14 22:23 . 2012-05-14 22:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-05-12 00:07 . 2012-05-12 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-05-13 00:15 . 2012-05-13 00:15 351904 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_Plugin.exe
+ 2012-04-11 16:56 . 2012-05-13 00:15 257696 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-04-11 16:56 . 2012-05-06 22:04 257696 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2009-07-14 02:36 . 2012-05-14 21:40 715746 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-05-14 21:40 141698 c:\windows\system32\perfc009.dat
+ 2012-05-13 00:15 . 2012-05-13 00:15 630944 c:\windows\system32\Macromed\Flash\FlashUtil64_11_2_202_235_Plugin.exe
- 2009-07-14 05:30 . 2012-05-10 23:14 239616 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2012-05-12 12:07 239616 c:\windows\system32\DriverStore\infstrng.dat
+ 2010-11-21 03:23 . 2010-11-21 03:23 184960 c:\windows\system32\drivers\usbvideo.sys
+ 2010-11-21 03:23 . 2010-11-21 03:23 109696 c:\windows\system32\drivers\USBAUDIO.sys
- 2009-07-14 05:01 . 2012-05-12 00:06 810468 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-05-14 22:22 810468 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-05-13 00:15 . 2012-05-13 00:15 8797856 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
+ 2012-02-24 22:07 . 2012-05-13 02:15 8901220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-12288.dat
- 2012-02-24 22:07 . 2012-05-10 23:25 8901220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-12288.dat
+ 2012-05-13 00:15 . 2012-05-13 00:15 11590304 c:\windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
+ 2012-02-24 22:07 . 2012-05-14 22:22 49470688 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1360622652-2071615853-753804455-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-11 348624]
.
c:\users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\William\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-15 24246216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-13 257696]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-04 129976]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 ioatdma;Intel® QuickData Technology device;c:\windows\System32\Drivers\ioatdma.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-14 169624]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-11 86224]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 00:15]
.
2012-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 23:54]
.
2012-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 23:54]
.
2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1360622652-2071615853-753804455-1000Core.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-24 20:50]
.
2012-05-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1360622652-2071615853-753804455-1000UA.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-24 20:50]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 97792 ----a-w- c:\users\William\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-09-08 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-09-08 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-09-08 416024]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://nmd.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\William\AppData\Roaming\Mozilla\Firefox\Profiles\icbyerx8.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Completion time: 2012-05-14 23:27:28 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-14 22:27
ComboFix2.txt 2012-05-12 00:11
ComboFix3.txt 2012-05-07 11:46
.
Pre-Run: 545,208,963,072 bytes free
Post-Run: 544,889,110,528 bytes free
.
- - End Of File - - 81A67D66FD4DCD37B60A72EDBB552090

#10 Mr Lau

Mr Lau
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:03:51 AM

Posted 14 May 2012 - 05:37 PM

Ah I spoke to soon. The redirect is still happening in Firefox

#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 14 May 2012 - 06:34 PM

I want you to uninstall firefox and if asked about user data or settings I want that removed also

restart the computer and reinstall firefox and then check for redirects



gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 17 May 2012 - 02:43 PM

Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 20 May 2012 - 12:22 AM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:51 PM

Posted 23 May 2012 - 06:06 AM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users