Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I seem to have the Google redirect thing


  • This topic is locked This topic is locked
14 replies to this topic

#1 Hippie Mama

Hippie Mama

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 12 July 2012 - 10:21 PM

Hi,

When I search anything and click on the results, I get redirected to a different site. Also, my computer is at times running very slowly. (Other times, it seems okay except for the search engine problem.)

I don't know much about computers at all, so I'm hoping I can find someone willing to talk me through this.

Thanks so much!

P.S. And now I'm getting "Security Shield Warning" popups.

Edited by Hippie Mama, 13 July 2012 - 08:56 PM.


BC AdBot (Login to Remove)

 


#2 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 14 July 2012 - 10:20 PM

Hello and welcome. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until Iíve given you the ďAll clear.Ē Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
Posted Image Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:
    netsvcs
  • Click the Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and paste them into your next post.
Posted Image Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it
  • You will be asked if you want to use Avast! Free anti virus for scanning - select No
  • Click the "Scan" button to start scan
  • On completion of the scan click save log, save it to your desktop and post in your next reply.
Please include the following in your next post:
  • OTL.txt and Extras.txt logs
  • aswMBR log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#3 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 15 July 2012 - 03:32 PM

Thanks, RP! Here's what I got:

OTL logfile created on: 7/15/2012 3:55:51 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\dx\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 765.13 Mb Available Physical Memory | 75.45% Memory free
2.38 Gb Paging File | 2.17 Gb Available in Paging File | 91.10% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 43.73 Gb Free Space | 58.70% Space Free | Partition Type: NTFS

Computer Name: DX-1F71A2F5EA54 | User Name: dx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/15 15:53:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dx\Desktop\OTL.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | ---- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2008/06/20 12:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/06/20 12:02:47 | 000,245,248 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012/07/12 09:02:40 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/16 19:58:52 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2009/06/30 10:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)
DRV - [2008/12/10 14:56:18 | 000,187,392 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/08/15 11:48:00 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?&.src=ym
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = https://login.yahoo.com/config/login_verify2?&.src=ym
IE - HKCU\..\SearchScopes,DefaultScope = {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=MMG&o=16703&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=3W&apn_dtid=YYYYYYS1US&apn_uid=68070CCE-7FEB-4151-946C-706283403D76&apn_sauid=5F5468B7-1B91-4285-8C04-A74A67C0AE74
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://login.yahoo.com/config/login_verify2?.intl=us&.src=ym"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:3.0.0.311
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\dx\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/16 19:58:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/30 21:35:48 | 000,000,000 | ---D | M]

[2010/12/02 21:59:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\dx\Application Data\Mozilla\Extensions
[2012/05/01 20:56:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\extensions
[2011/07/31 16:16:18 | 000,000,000 | ---D | M] (BlockSite) -- C:\Documents and Settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2011/11/18 13:24:38 | 000,001,945 | ---- | M] () -- C:\Documents and Settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\searchplugins\bing-zugo.xml
[2012/03/08 10:58:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/16 19:58:55 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/25 12:43:29 | 000,289,592 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2011/04/25 12:43:22 | 000,172,344 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2011/03/18 14:32:12 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2012/02/28 22:04:05 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/03/08 10:58:21 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/08 10:58:21 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/06/07 12:50:16 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray File not found
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\Spyware Doctor\BDT\FGuard.exe File not found
O4 - HKLM..\Run: [StartNowToolbarHelper] "C:\Program Files\StartNow Toolbar\ToolbarHelper.exe" File not found
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\dx\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F0A7895E-57AE-431F-9342-023E47DA390E}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/02 20:11:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2012/07/15 15:54:37 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\dx\Desktop\aswMBR.exe
[2012/07/15 15:53:13 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\dx\Desktop\OTL.exe
[2012/07/12 09:02:37 | 009,822,920 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/07/10 23:58:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2012/07/10 23:43:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/07/10 23:43:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/07/10 23:34:39 | 000,000,000 | -HSD | C] -- C:\WINDOWS\assembly
[2012/06/30 10:49:17 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\dx\My Documents\*.tmp files -> C:\Documents and Settings\dx\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/15 16:02:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/15 16:01:01 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/07/15 15:54:48 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\dx\Desktop\aswMBR.exe
[2012/07/15 15:53:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dx\Desktop\OTL.exe
[2012/07/15 12:47:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/15 12:46:17 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/15 00:49:00 | 000,058,912 | ---- | M] () -- C:\Documents and Settings\dx\Desktop\akinator_9_confiant.png
[2012/07/13 21:48:46 | 000,356,352 | ---- | M] () -- C:\Documents and Settings\dx\Local Settings\Application Data\tdcsflbttq.exe
[2012/07/12 11:02:18 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/07/12 11:02:17 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/07/12 11:02:10 | 009,822,920 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/07/11 21:32:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/11 16:43:54 | 000,128,504 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/02 18:09:59 | 001,120,109 | ---- | M] () -- C:\Documents and Settings\dx\Desktop\Volvo3.jpg
[2012/07/02 18:09:39 | 000,843,666 | ---- | M] () -- C:\Documents and Settings\dx\Desktop\Volvo2.jpg
[2012/07/02 18:09:18 | 001,264,222 | ---- | M] () -- C:\Documents and Settings\dx\Desktop\Volvo1.jpg
[2012/07/02 18:08:50 | 001,342,159 | ---- | M] () -- C:\Documents and Settings\dx\Desktop\Volvo.jpg
[2012/06/19 18:20:25 | 000,230,808 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\dx\My Documents\*.tmp files -> C:\Documents and Settings\dx\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/15 00:49:00 | 000,058,912 | ---- | C] () -- C:\Documents and Settings\dx\Desktop\akinator_9_confiant.png
[2012/07/13 21:48:46 | 000,356,352 | ---- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\tdcsflbttq.exe
[2012/07/10 23:35:19 | 000,232,960 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000008.@
[2012/07/10 23:34:50 | 000,095,744 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000032.@
[2012/07/10 23:34:50 | 000,000,804 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\L\00000004.@
[2012/07/10 23:34:45 | 000,012,288 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000000.@
[2012/07/10 23:34:41 | 000,002,048 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000004.@
[2012/07/10 23:34:41 | 000,001,632 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\000000cb.@
[2012/07/02 17:49:34 | 001,120,109 | ---- | C] () -- C:\Documents and Settings\dx\Desktop\Volvo3.jpg
[2012/07/02 17:49:16 | 000,843,666 | ---- | C] () -- C:\Documents and Settings\dx\Desktop\Volvo2.jpg
[2012/07/02 17:48:57 | 001,264,222 | ---- | C] () -- C:\Documents and Settings\dx\Desktop\Volvo1.jpg
[2012/07/02 17:48:42 | 001,342,159 | ---- | C] () -- C:\Documents and Settings\dx\Desktop\Volvo.jpg
[2012/06/30 10:49:18 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/02/16 13:32:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/09/26 14:16:55 | 000,000,274 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2011/06/08 20:37:33 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\dx\Application Data\$_hpcst$.hpc
[2011/06/07 12:20:32 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/06/07 12:20:32 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/06/07 12:20:32 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/06/07 12:20:32 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/06/07 12:20:32 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/06/04 15:45:54 | 000,000,039 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2011/04/30 17:18:44 | 000,015,718 | -HS- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\34352o2be027ho55i2d7a7vvq87lyn
[2011/04/30 17:18:44 | 000,015,718 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\34352o2be027ho55i2d7a7vvq87lyn
[2011/04/16 21:45:50 | 000,000,025 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2011/04/16 21:45:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\popcreg.dat
[2011/03/29 22:33:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\dx\Application Data\4.ini
[2011/02/15 14:15:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2011/01/16 21:22:55 | 000,078,848 | ---- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/19 21:38:30 | 000,000,332 | ---- | C] () -- C:\WINDOWS\System32\CNCMFP21.INI
[2010/12/02 21:59:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/12/02 20:36:54 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/12/02 20:34:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/12/02 20:25:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\arhelper.INI
[2010/12/02 20:23:27 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2010/12/02 20:15:19 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/12/02 20:08:04 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/12/02 15:02:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/02 15:00:59 | 000,128,504 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/14 05:41:26 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\@
[2008/04/14 05:41:26 | 000,002,048 | -HS- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}\@

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

OTL Extras logfile created on: 7/15/2012 3:55:51 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\dx\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.07 Mb Total Physical Memory | 765.13 Mb Available Physical Memory | 75.45% Memory free
2.38 Gb Paging File | 2.17 Gb Available in Paging File | 91.10% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 43.73 Gb Free Space | 58.70% Space Free | Partition Type: NTFS

Computer Name: DX-1F71A2F5EA54 | User Name: dx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{269DBC9C-CAFC-472d-B1F1-0D327C2FFA76}" = Canon MF3200 Series
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"ActiveScan 2.0" = Panda ActiveScan 2.0
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"ie8" = Windows Internet Explorer 8
"Logical Journey of the Zoombinis" = Logical Journey of the Zoombinis
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Plants vs. Zombies" = Plants vs. Zombies
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WMFDist11" = Windows Media Format 11 runtime
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/13/2012 1:42:17 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/13/2012 2:24:30 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/13/2012 2:50:48 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 4:26:31 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 4:27:49 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 6:23:15 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 6:23:19 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 6:23:21 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 6:30:39 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

Error - 7/14/2012 6:30:45 PM | Computer Name = DX-1F71A2F5EA54 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Premium -- Error 1706. No valid source
could be found for product Microsoft Office 2000 Premium. The Windows installer
cannot continue.

[ System Events ]
Error - 7/13/2012 12:16:17 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 1:18:42 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 3:12:17 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 5:33:31 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 6:11:45 PM | Computer Name = DX-1F71A2F5EA54 | Source = DCOM | ID = 10010
Description = The server {D2BD7935-05FC-11D2-9059-00C04FD7A1BD} did not register
with DCOM within the required timeout.

Error - 7/14/2012 7:38:43 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 9:15:43 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/14/2012 10:54:43 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/15/2012 1:35:45 AM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/15/2012 12:47:57 PM | Computer Name = DX-1F71A2F5EA54 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060


< End of report >



aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-06 12:21:51
-----------------------------
12:21:51.953 OS Version: Windows 5.1.2600 Service Pack 3
12:21:51.953 Number of processors: 2 586 0x40A
12:21:51.953 ComputerName: DX-1F71A2F5EA54 UserName: dx
12:21:59.140 Initialize success
12:22:15.515 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
12:22:15.546 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 3
12:22:15.546 Device \Driver\atapi -> DriverStartIo 8636431b
12:22:17.625 Disk 0 MBR read successfully
12:22:17.718 Disk 0 MBR scan
12:22:17.875 Disk 0 TDL4@MBR code has been found
12:22:18.031 Disk 0 Windows XP default MBR code found via API
12:22:18.062 Disk 0 MBR hidden
12:22:18.187 Disk 0 MBR [TDL4] **ROOTKIT**
12:22:18.187 Disk 0 trace - called modules:
12:22:18.281 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys >>UNKNOWN [0x863644d0]<<
12:22:18.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8633bab8]
12:22:18.875 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> [0x86389920]
12:22:18.890 5 PCTCore.sys[f73bd68b] -> nt!IofCallDriver -> [0x863e0d98]
12:22:18.906 \Driver\atapi[0x86339728] -> IRP_MJ_CREATE -> 0x863644d0
12:22:18.968 Scan finished successfully
12:22:59.468 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
12:22:59.593 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-06 12:21:51
-----------------------------
12:21:51.953 OS Version: Windows 5.1.2600 Service Pack 3
12:21:51.953 Number of processors: 2 586 0x40A
12:21:51.953 ComputerName: DX-1F71A2F5EA54 UserName: dx
12:21:59.140 Initialize success
12:22:15.515 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
12:22:15.546 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 3
12:22:15.546 Device \Driver\atapi -> DriverStartIo 8636431b
12:22:17.625 Disk 0 MBR read successfully
12:22:17.718 Disk 0 MBR scan
12:22:17.875 Disk 0 TDL4@MBR code has been found
12:22:18.031 Disk 0 Windows XP default MBR code found via API
12:22:18.062 Disk 0 MBR hidden
12:22:18.187 Disk 0 MBR [TDL4] **ROOTKIT**
12:22:18.187 Disk 0 trace - called modules:
12:22:18.281 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys >>UNKNOWN [0x863644d0]<<
12:22:18.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8633bab8]
12:22:18.875 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> [0x86389920]
12:22:18.890 5 PCTCore.sys[f73bd68b] -> nt!IofCallDriver -> [0x863e0d98]
12:22:18.906 \Driver\atapi[0x86339728] -> IRP_MJ_CREATE -> 0x863644d0
12:22:18.968 Scan finished successfully
12:22:59.468 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
12:22:59.593 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"
12:34:48.875 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
12:34:49.187 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-15 16:10:46
-----------------------------
16:10:46.234 OS Version: Windows 5.1.2600 Service Pack 3
16:10:46.234 Number of processors: 2 586 0x40A
16:10:46.234 ComputerName: DX-1F71A2F5EA54 UserName: dx
16:10:54.578 Initialize success
16:11:08.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
16:11:08.968 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 3
16:11:09.140 Disk 0 MBR read successfully
16:11:09.140 Disk 0 MBR scan
16:11:09.140 Disk 0 Windows XP default MBR code
16:11:09.140 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76285 MB offset 63
16:11:09.234 Disk 0 scanning sectors +156232125
16:11:09.312 Disk 0 scanning C:\WINDOWS\system32\drivers
16:11:13.859 Service scanning
16:11:37.875 Modules scanning
16:11:58.421 Disk 0 trace - called modules:
16:11:58.437 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:11:58.437 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8653fab8]
16:11:58.437 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x8657b030]
16:11:58.453 Scan finished successfully
16:23:14.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:23:15.000 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-15 16:10:46
-----------------------------
16:10:46.234 OS Version: Windows 5.1.2600 Service Pack 3
16:10:46.234 Number of processors: 2 586 0x40A
16:10:46.234 ComputerName: DX-1F71A2F5EA54 UserName: dx
16:10:54.578 Initialize success
16:11:08.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
16:11:08.968 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 3
16:11:09.140 Disk 0 MBR read successfully
16:11:09.140 Disk 0 MBR scan
16:11:09.140 Disk 0 Windows XP default MBR code
16:11:09.140 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76285 MB offset 63
16:11:09.234 Disk 0 scanning sectors +156232125
16:11:09.312 Disk 0 scanning C:\WINDOWS\system32\drivers
16:11:13.859 Service scanning
16:11:37.875 Modules scanning
16:11:58.421 Disk 0 trace - called modules:
16:11:58.437 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:11:58.437 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8653fab8]
16:11:58.437 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x8657b030]
16:11:58.453 Scan finished successfully
16:23:14.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:23:15.000 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"
16:29:08.875 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:29:09.125 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-15 16:10:46
-----------------------------
16:10:46.234 OS Version: Windows 5.1.2600 Service Pack 3
16:10:46.234 Number of processors: 2 586 0x40A
16:10:46.234 ComputerName: DX-1F71A2F5EA54 UserName: dx
16:10:54.578 Initialize success
16:11:08.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
16:11:08.968 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 3
16:11:09.140 Disk 0 MBR read successfully
16:11:09.140 Disk 0 MBR scan
16:11:09.140 Disk 0 Windows XP default MBR code
16:11:09.140 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76285 MB offset 63
16:11:09.234 Disk 0 scanning sectors +156232125
16:11:09.312 Disk 0 scanning C:\WINDOWS\system32\drivers
16:11:13.859 Service scanning
16:11:37.875 Modules scanning
16:11:58.421 Disk 0 trace - called modules:
16:11:58.437 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:11:58.437 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8653fab8]
16:11:58.437 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x8657b030]
16:11:58.453 Scan finished successfully
16:23:14.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:23:15.000 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"
16:29:08.875 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:29:09.125 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"
16:30:02.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dx\Desktop\MBR.dat"
16:30:02.640 The log file has been saved successfully to "C:\Documents and Settings\dx\Desktop\aswMBR.txt"

#4 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 15 July 2012 - 07:34 PM

Please do this next:

Posted Image Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    MOD - [2008/06/20 12:02:47 | 000,245,248 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
    MOD - [2008/06/20 12:02:47 | 000,245,248 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
    [2011/11/18 13:24:38 | 000,001,945 | ---- | M] () -- C:\Documents and Settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\searchplugins\bing-zugo.xml
    O3 - HKLM\..\Toolbar: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    [2012/07/13 21:48:46 | 000,356,352 | ---- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\tdcsflbttq.exe
    [2012/07/10 23:35:19 | 000,232,960 | ---- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}
    [2011/04/30 17:18:44 | 000,015,718 | -HS- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\34352o2be027ho55i2d7a7vvq87lyn
    [2011/04/30 17:18:44 | 000,015,718 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\34352o2be027ho55i2d7a7vvq87lyn
    [2008/04/14 05:41:26 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}
    [2008/04/14 05:41:26 | 000,002,048 | -HS- | C] () -- C:\Documents and Settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}
    @Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
    @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
    :Commands
    [EmptyTemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Posted Image Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

  • Once the Microsoft Windows Recovery Console is installed click on Yes[/b], to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • OTL Fix log
  • ComboFix log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#5 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 16 July 2012 - 03:08 PM

Here they are:

All processes killed
========== OTL ==========
Releasing module \\?\globalroot\systemroot\system32\mswsock.dll
File move failed. \\?\globalroot\systemroot\system32\mswsock.dll scheduled to be moved on reboot.
C:\Documents and Settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\searchplugins\bing-zugo.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5911488E-9D1E-40ec-8CBB-06B231CC153F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825}\ not found.
C:\Documents and Settings\dx\Local Settings\Application Data\tdcsflbttq.exe moved successfully.
File C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead} not found.
C:\Documents and Settings\dx\Local Settings\Application Data\34352o2be027ho55i2d7a7vvq87lyn moved successfully.
C:\Documents and Settings\All Users\Application Data\34352o2be027ho55i2d7a7vvq87lyn moved successfully.
File C:\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead} not found.
File C:\Documents and Settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead} not found.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: dx
->Temp folder emptied: 2197513752 bytes
->Temporary Internet Files folder emptied: 241388790 bytes
->Java cache emptied: 3251109 bytes
->FireFox cache emptied: 176161272 bytes
->Flash cache emptied: 712993 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 258819169 bytes
->Java cache emptied: 20407 bytes
->Flash cache emptied: 4196 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1240707656 bytes
->Java cache emptied: 21525 bytes
->Flash cache emptied: 52361 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 13836712 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33742 bytes
RecycleBin emptied: 50114002 bytes

Total Files Cleaned = 3,991.00 mb


OTL by OldTimer - Version 3.2.54.0 log created on 07162012_151840

Files\Folders moved on Reboot...
File move failed. \\?\globalroot\systemroot\system32\mswsock.dll scheduled to be moved on reboot.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ZLUDORZH\beacon[10].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ZLUDORZH\beacon[9].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\ben-affleck-jennifer-garner-and-kids[1].txt not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\emily[3].html moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\if[2].txt not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\pinit[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\clk[2].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\iframe3[3].htm not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\meta[1].htm not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\xd_arbiter[1].php not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\ad[2].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\if[1].txt not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\pinit[1].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\plusone[1].js not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\REDIRURL=;ord=89507[1].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\TVBSM3PG\afr[1].htm not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\TVBSM3PG\nicole-richie-unveils-pieces-from-her-macys-impulse-line[1].txt moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\T61IP6LY\afr[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\T61IP6LY\emily[1].html moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RHTIMHK1\like[1].php not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\alexandriaflf-italic-webfont[1].eot moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\if[3].txt not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\likebox[1].php not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FGNS4DIV\google_service[1].js moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CZ1R4CWJ\blog[1].txt not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\B6169428[6].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\ddc[4].htm not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\ddc[5].htm not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\xd_arbiter[2].php moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BJHKCDXH\impx[1].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BDCJRQDV\tweet_button.1340179658[1].html not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BDCJRQDV\VideoPreloader[1].swf moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6ZTRUOP8\emily[1].html moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\dvtp_src[1].js not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\jquery.form[1].js not found!
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\jquery[1].js not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\redirect_v107_cim_11_31_0[1].html moved successfully.

PendingFileRenameOperations files...
File \?\globalroot\systemroot\system32\mswsock.dll not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ZLUDORZH\beacon[10].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ZLUDORZH\beacon[9].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\ben-affleck-jennifer-garner-and-kids[1].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\emily[3].html not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\if[2].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YDEPG3AW\pinit[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\clk[2].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\iframe3[3].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\meta[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\VXGB8W48\xd_arbiter[1].php not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\ad[2].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\if[1].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\pinit[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\plusone[1].js not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U177SA6H\REDIRURL=;ord=89507[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\TVBSM3PG\afr[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\TVBSM3PG\nicole-richie-unveils-pieces-from-her-macys-impulse-line[1].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\T61IP6LY\afr[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\T61IP6LY\emily[1].html not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RHTIMHK1\like[1].php not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\alexandriaflf-italic-webfont[1].eot not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\if[3].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAARU37\likebox[1].php not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FGNS4DIV\google_service[1].js not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CZ1R4CWJ\blog[1].txt not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\B6169428[6].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\ddc[4].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\ddc[5].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CXTPO8JT\xd_arbiter[2].php not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BJHKCDXH\impx[1].htm not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BDCJRQDV\tweet_button.1340179658[1].html not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\BDCJRQDV\VideoPreloader[1].swf not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6ZTRUOP8\emily[1].html not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\dvtp_src[1].js not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\jquery.form[1].js not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\jquery[1].js not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5T0F8WQH\redirect_v107_cim_11_31_0[1].html not found!

Registry entries deleted on Reboot...

And this one:

ComboFix 12-07-16.01 - dx 07/16/2012 15:55:31.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.714 [GMT -4:00]
Running from: c:\documents and settings\dx\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\430C6D84.TMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}
c:\documents and settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}\@
c:\documents and settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}\n
c:\documents and settings\dx\My Documents\~WRD1898.tmp
c:\documents and settings\dx\My Documents\~WRL3198.tmp
c:\documents and settings\dx\WINDOWS
c:\windows\assembly\GAC\Desktop.ini
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\L\00000004.@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\L\1afb2d56
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\L\201d3dde
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\n
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000004.@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000008.@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\000000cb.@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000000.@
c:\windows\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000032.@
.
.
((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 )))))))))))))))))))))))))))))))
.
.
2012-07-16 19:18 . 2012-07-16 19:18 -------- d-----w- C:\_OTL
2012-07-12 13:02 . 2012-07-12 15:02 9822920 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-07-11 13:41 . 2012-07-11 13:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2012-07-11 03:45 . 2012-07-11 03:45 -------- d-sh--w- c:\documents and settings\LocalService\UserData
2012-06-30 14:49 . 2012-07-12 15:02 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 15:02 . 2011-07-02 17:10 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-19 22:20 . 2011-10-10 15:04 230808 ----a-r- c:\windows\system32\cpnprt2.cid
2012-06-13 13:19 . 2008-04-14 05:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-14 09:42 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 09:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 09:42 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2010-12-03 00:09 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2010-12-03 00:09 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2010-12-03 00:09 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 00:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2010-12-03 00:09 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2010-12-03 00:09 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2009-08-07 00:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2008-04-14 09:41 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2010-12-03 00:09 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2010-12-03 00:09 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 09:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2008-04-14 09:42 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2008-04-14 09:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 14:42 . 2008-04-14 09:41 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 11:38 . 2008-04-14 04:07 385024 ------w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2008-04-14 04:54 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2008-04-14 00:01 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2010-12-03 00:06 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-04-25 16:43 . 2011-04-25 16:43 289592 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2012-06-16 23:58 . 2012-03-08 14:58 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-05-09 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-06-07_16.51.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-19 03:51 . 2011-04-19 03:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-14 01:17 . 2011-05-14 01:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-14 00:45 . 2011-05-14 00:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-14 06:06 . 2011-05-14 06:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-14 06:23 . 2011-05-14 06:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 23:37 . 2011-05-13 23:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 93184 c:\windows\VIEW32.EXE
+ 2012-07-16 19:45 . 2012-07-16 19:45 16384 c:\windows\Temp\Perflib_Perfdata_668.dat
+ 2006-08-25 01:26 . 2006-08-25 01:26 17408 c:\windows\system32\wpdshextautoplay.exe
+ 2006-08-25 03:30 . 2006-08-25 03:30 63488 c:\windows\system32\wpdmtpus.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 35840 c:\windows\system32\wpdconns.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 37376 c:\windows\system32\wmdmps.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 33792 c:\windows\system32\wmdmlog.dll
+ 2008-04-14 09:42 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2008-04-14 09:42 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
+ 2010-12-03 05:26 . 2009-01-07 22:21 26144 c:\windows\system32\spupdsvc.exe
+ 2012-01-11 17:51 . 2010-07-05 13:15 17272 c:\windows\system32\spmsg.dll
- 2010-12-03 05:26 . 2010-07-05 13:15 17272 c:\windows\system32\spmsg.dll
+ 2012-06-21 16:58 . 2012-06-02 19:19 45080 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.6.7600.256\wups2.dll
+ 2012-06-21 16:58 . 2012-06-02 19:19 35864 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.6.7600.256\wups.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 64512 c:\windows\system32\QTWMCI32.DLL
+ 1996-04-04 06:11 . 1996-04-04 06:11 93696 c:\windows\system32\QTOLE32.DLL
+ 2008-04-14 09:42 . 2009-03-08 08:31 46592 c:\windows\system32\pngfilt.dll
+ 2001-08-23 12:00 . 2012-03-11 19:50 39992 c:\windows\system32\perfc009.dat
- 2001-08-23 12:00 . 2011-03-13 11:59 39992 c:\windows\system32\perfc009.dat
+ 2008-04-14 09:42 . 2011-11-18 12:35 60416 c:\windows\system32\packager.exe
+ 2001-08-23 12:00 . 2011-09-26 15:41 20480 c:\windows\system32\oleaccrc.dll
+ 2009-01-07 22:20 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll
+ 2009-01-07 22:20 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll
+ 2011-12-18 01:37 . 2011-06-23 18:25 24576 c:\windows\system32\msxml3a.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 27648 c:\windows\system32\mspmsnsv.dll
+ 2008-04-14 01:56 . 2009-03-08 08:31 48128 c:\windows\system32\mshtmler.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 67072 c:\windows\system32\mshtmled.dll
+ 2008-04-14 09:42 . 2009-03-08 08:31 45568 c:\windows\system32\mshta.exe
+ 2009-03-08 08:31 . 2009-03-08 08:31 13312 c:\windows\system32\msfeedssync.exe
+ 2009-03-08 08:31 . 2012-05-11 14:42 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-04-14 09:41 . 2011-10-14 14:47 23040 c:\windows\system32\mciseq.dll
- 2008-04-14 09:41 . 2008-04-14 09:41 23040 c:\windows\system32\mciseq.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 11264 c:\windows\system32\LAPRXY.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 25600 c:\windows\system32\jsproxy.dll
+ 2011-08-31 04:05 . 2011-08-31 04:05 50536 c:\windows\system32\jdns_sd.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 94720 c:\windows\system32\inseng.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 34816 c:\windows\system32\imgutil.dll
+ 2009-03-08 08:32 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe
+ 2008-04-14 09:41 . 2009-03-08 08:32 71680 c:\windows\system32\iesetup.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 55808 c:\windows\system32\iernonce.dll
+ 2009-01-07 22:20 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll
+ 2009-03-08 08:31 . 2009-03-08 08:31 59904 c:\windows\system32\icardie.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 18944 c:\windows\system32\HNDLR32.DLL
+ 2012-05-31 01:36 . 2012-02-15 15:01 43520 c:\windows\system32\DRVSTORE\usbaapl_87F84F5DA3368BC69CA5BE7F6A79CAA709E36E13\usbaapl.sys
+ 2012-01-14 03:11 . 2011-08-02 22:38 18432 c:\windows\system32\DRVSTORE\netaapl_63AA05C4700EB9CAF2D048DAC1D06D764A0D4C41\netaapl.sys
+ 2006-08-25 01:26 . 2006-08-25 01:26 38656 c:\windows\system32\drivers\wpdusb.sys
+ 2011-06-16 21:08 . 2008-04-14 04:15 60032 c:\windows\system32\drivers\USBAUDIO.sys
+ 2011-08-07 01:42 . 2009-06-30 14:37 28552 c:\windows\system32\drivers\pavboot.sys
+ 2008-04-14 04:27 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
+ 2011-08-31 04:05 . 2011-08-31 04:05 73064 c:\windows\system32\dnssd.dll
+ 2011-08-31 04:05 . 2011-08-31 04:05 83816 c:\windows\system32\dns-sd.exe
+ 2011-07-03 14:30 . 2012-05-11 14:42 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 35864 c:\windows\system32\dllcache\wups.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 53784 c:\windows\system32\dllcache\wuauclt.exe
+ 2008-04-14 09:42 . 2006-08-25 03:30 37376 c:\windows\system32\dllcache\wmdmps.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 33792 c:\windows\system32\dllcache\wmdmlog.dll
+ 2011-06-16 21:08 . 2008-04-14 04:15 60032 c:\windows\system32\dllcache\usbaudio.sys
+ 2008-04-14 09:42 . 2009-03-08 08:31 46592 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 09:42 . 2011-11-18 12:35 60416 c:\windows\system32\dllcache\packager.exe
+ 2001-08-23 12:00 . 2011-09-26 15:41 20480 c:\windows\system32\dllcache\oleaccrc.dll
+ 2008-04-14 04:27 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
+ 2008-04-14 09:42 . 2006-08-25 03:30 27648 c:\windows\system32\dllcache\mspmsnsv.dll
+ 2008-04-14 01:56 . 2009-03-08 08:31 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 09:42 . 2009-03-08 08:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2011-07-03 14:30 . 2012-05-11 14:42 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-04-14 09:41 . 2011-10-14 14:47 23040 c:\windows\system32\dllcache\mciseq.dll
- 2008-04-14 09:41 . 2008-04-14 09:41 23040 c:\windows\system32\dllcache\mciseq.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 11264 c:\windows\system32\dllcache\LAPRXY.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 34816 c:\windows\system32\dllcache\imgutil.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2010-12-03 00:08 . 2009-03-08 08:24 68608 c:\windows\system32\dllcache\hmmapi.dll
+ 2008-04-14 09:41 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2008-04-14 09:41 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2008-04-14 09:41 . 2012-06-02 19:19 97304 c:\windows\system32\dllcache\cdm.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2008-04-14 09:41 . 2011-10-28 05:31 33280 c:\windows\system32\csrsrv.dll
- 2008-04-14 09:41 . 2010-12-09 14:30 33280 c:\windows\system32\csrsrv.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 18944 c:\windows\system32\corpol.dll
+ 2010-12-03 00:16 . 2012-03-07 23:02 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-06-11 19:03 . 2012-03-07 23:02 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 1996-04-04 06:11 . 1996-04-04 06:11 32768 c:\windows\system32\CMGR32.DLL
+ 2008-04-14 09:41 . 2009-03-08 08:32 72704 c:\windows\system32\admparse.dll
+ 2012-02-22 20:13 . 2012-02-22 20:13 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2012-01-13 21:32 . 2012-01-13 21:32 27136 c:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll
+ 2011-07-03 14:31 . 2009-03-08 08:33 12288 c:\windows\ie8updates\KB982381-IE8\xpshims.dll
+ 2011-07-03 14:31 . 2009-03-08 08:31 55296 c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
+ 2011-07-03 14:31 . 2009-03-08 08:33 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 12800 c:\windows\ie8updates\KB2699988-IE8\xpshims.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 66560 c:\windows\ie8updates\KB2699988-IE8\mshtmled.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 55296 c:\windows\ie8updates\KB2699988-IE8\msfeedsbs.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 43520 c:\windows\ie8updates\KB2699988-IE8\licmgr10.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 25600 c:\windows\ie8updates\KB2699988-IE8\jsproxy.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 12800 c:\windows\ie8updates\KB2675157-IE8\xpshims.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 66560 c:\windows\ie8updates\KB2675157-IE8\mshtmled.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 55296 c:\windows\ie8updates\KB2675157-IE8\msfeedsbs.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 43520 c:\windows\ie8updates\KB2675157-IE8\licmgr10.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 25600 c:\windows\ie8updates\KB2675157-IE8\jsproxy.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 12800 c:\windows\ie8updates\KB2647516-IE8\xpshims.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 66560 c:\windows\ie8updates\KB2647516-IE8\mshtmled.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 55296 c:\windows\ie8updates\KB2647516-IE8\msfeedsbs.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 43520 c:\windows\ie8updates\KB2647516-IE8\licmgr10.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 25600 c:\windows\ie8updates\KB2647516-IE8\jsproxy.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 12800 c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 66560 c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 55296 c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 43520 c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 25600 c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 43520 c:\windows\ie8updates\KB2559049-IE8\licmgr10.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 12800 c:\windows\ie8updates\KB2530548-IE8\xpshims.dll
+ 2011-07-03 14:32 . 2009-03-08 08:31 66560 c:\windows\ie8updates\KB2530548-IE8\mshtmled.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 55296 c:\windows\ie8updates\KB2530548-IE8\msfeedsbs.dll
+ 2011-07-03 14:32 . 2009-03-08 08:34 43008 c:\windows\ie8updates\KB2530548-IE8\licmgr10.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 25600 c:\windows\ie8updates\KB2530548-IE8\jsproxy.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 37888 c:\windows\ie8\url.dll
+ 2011-07-03 14:28 . 2009-03-08 18:23 58464 c:\windows\ie8\spuninst\iecustom.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 39424 c:\windows\ie8\pngfilt.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 96256 c:\windows\ie8\occache.dll
+ 2011-07-03 14:27 . 2008-04-14 01:56 56832 c:\windows\ie8\mshtmler.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 29184 c:\windows\ie8\mshta.exe
+ 2011-07-03 14:27 . 2008-04-14 09:41 22016 c:\windows\ie8\licmgr10.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 15872 c:\windows\ie8\jsproxy.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 96256 c:\windows\ie8\inseng.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 35840 c:\windows\ie8\imgutil.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 93184 c:\windows\ie8\iexplore.exe
+ 2011-07-03 14:27 . 2008-04-14 09:41 62976 c:\windows\ie8\iesetup.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 48640 c:\windows\ie8\iernonce.dll
+ 2011-07-03 14:27 . 2011-04-25 14:47 81920 c:\windows\ie8\ieencode.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 34304 c:\windows\ie8\ie4uinit.exe
+ 2011-07-03 14:27 . 2008-04-14 09:41 38912 c:\windows\ie8\hmmapi.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 35328 c:\windows\ie8\corpol.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 99840 c:\windows\ie8\advpack.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 61440 c:\windows\ie8\admparse.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 23552 c:\windows\$NtUninstallWMFDist11$\wmdmps.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 27136 c:\windows\$NtUninstallWMFDist11$\wmdmlog.dll
+ 2011-12-18 01:47 . 2006-08-25 03:42 13312 c:\windows\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 52224 c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
+ 2011-12-16 03:36 . 2011-07-08 13:49 46080 c:\windows\$NtUninstallKB2633952$\tzchange.exe
+ 2011-12-16 03:36 . 2011-11-08 14:58 16896 c:\windows\$NtUninstallKB2633952$\spuninst\tzchange.dll
+ 2011-12-16 03:36 . 2011-04-26 11:07 33280 c:\windows\$NtUninstallKB2620712$\csrsrv.dll
+ 2012-01-11 17:51 . 2008-04-14 09:41 23040 c:\windows\$NtUninstallKB2598479$\mciseq.dll
+ 2012-01-11 17:51 . 2008-04-14 09:42 58368 c:\windows\$NtUninstallKB2584146$\packager.exe
+ 2011-08-25 04:28 . 2010-11-03 13:12 46080 c:\windows\$NtUninstallKB2570791$\tzchange.exe
+ 2011-08-25 04:28 . 2011-07-09 00:32 16896 c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
+ 2011-08-11 04:30 . 2008-04-14 04:27 10112 c:\windows\$NtUninstallKB2566454$\ndistapi.sys
+ 2011-10-13 20:20 . 2001-08-23 12:00 16896 c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 81920 c:\windows\$NtUninstallKB2530548$\ieencode.dll
+ 2011-07-13 15:15 . 2010-12-09 14:30 33280 c:\windows\$NtUninstallKB2507938$\csrsrv.dll
+ 2011-07-03 14:31 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB982381-IE8\update\spcustom.dll
+ 2011-07-03 14:31 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB982381-IE8\spmsg.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 12800 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\xpshims.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 55296 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\msfeedsbs.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 25600 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\jsproxy.dll
+ 2012-06-04 17:47 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2718704\update\spcustom.dll
+ 2012-06-04 17:47 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2718704\spmsg.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2709162\update\spcustom.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2709162\spmsg.dll
+ 2012-06-14 03:09 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2707511\update\spcustom.dll
+ 2012-06-14 00:34 . 2012-05-05 03:16 16896 c:\windows\$hf_mig$\KB2707511\update\mpsyschk.dll
+ 2012-06-14 03:09 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2707511\spmsg.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2699988-IE8\update\spcustom.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2699988-IE8\spmsg.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 12800 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\xpshims.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 67072 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\mshtmled.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 55296 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\msfeedsbs.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 43520 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\licmgr10.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 25600 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\jsproxy.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2695962\update\spcustom.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2695962\spmsg.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2686509\update\spcustom.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2686509\spmsg.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2685939\update\spcustom.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2685939\spmsg.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2676562\update\spcustom.dll
+ 2012-05-12 16:31 . 2012-04-11 13:53 16896 c:\windows\$hf_mig$\KB2676562\update\mpsyschk.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2676562\spmsg.dll
+ 2012-04-12 03:46 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2675157-IE8\update\spcustom.dll
+ 2012-04-12 03:46 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2675157-IE8\spmsg.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 12800 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\xpshims.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 66560 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\mshtmled.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 55296 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\msfeedsbs.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 43520 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\licmgr10.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 25600 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\jsproxy.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2661637\update\spcustom.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2661637\spmsg.dll
+ 2012-02-17 07:29 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2660465\update\spcustom.dll
+ 2012-02-17 07:29 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2660465\spmsg.dll
+ 2012-04-12 03:44 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2653956\update\spcustom.dll
+ 2012-04-12 03:44 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2653956\spmsg.dll
+ 2012-03-15 01:42 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2647518\update\spcustom.dll
+ 2012-03-15 01:42 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2647518\spmsg.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2647516-IE8\update\spcustom.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2647516-IE8\spmsg.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 12800 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\xpshims.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 66560 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtmled.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 55296 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\msfeedsbs.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 43520 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\licmgr10.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 25600 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\jsproxy.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2646524\update\spcustom.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2646524\spmsg.dll
+ 2011-11-12 02:34 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2641690\update\spcustom.dll
+ 2011-11-12 02:34 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2641690\spmsg.dll
+ 2012-03-15 01:45 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2641653\update\spcustom.dll
+ 2012-03-15 01:45 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2641653\spmsg.dll
+ 2011-12-16 03:39 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2639417\update\spcustom.dll
+ 2011-12-16 03:39 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2639417\spmsg.dll
+ 2011-12-16 03:35 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2633171\update\spcustom.dll
+ 2011-12-15 23:05 . 2011-10-26 10:50 16896 c:\windows\$hf_mig$\KB2633171\update\mpsyschk.dll
+ 2011-12-16 03:35 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2633171\spmsg.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2631813\update\spcustom.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2631813\spmsg.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2624667\update\spcustom.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2624667\spmsg.dll
+ 2012-03-15 01:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2621440\update\spcustom.dll
+ 2012-03-15 01:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2621440\spmsg.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2620712\update\spcustom.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2620712\spmsg.dll
+ 2011-10-28 05:31 . 2011-10-28 05:31 33280 c:\windows\$hf_mig$\KB2620712\SP3QFE\csrsrv.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2619339\update\spcustom.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2619339\spmsg.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618451\update\spcustom.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618451\spmsg.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2618444-IE8\update\spcustom.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2618444-IE8\spmsg.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 12800 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\xpshims.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 66560 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtmled.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 55296 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeedsbs.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 43520 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\licmgr10.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 25600 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\jsproxy.dll
+ 2011-09-17 03:56 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2616676\update\spcustom.dll
+ 2011-09-17 03:56 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2616676\spmsg.dll
+ 2011-09-07 22:36 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2607712\update\spcustom.dll
+ 2011-09-07 22:36 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2607712\spmsg.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2603381\update\spcustom.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2603381\spmsg.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2598479\update\spcustom.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2598479\spmsg.dll
+ 2011-10-14 14:45 . 2011-10-14 14:45 23040 c:\windows\$hf_mig$\KB2598479\SP3QFE\mciseq.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2592799\spmsg.dll
+ 2011-10-13 20:17 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
+ 2011-10-13 20:17 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 12800 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 66560 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 55296 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 43520 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 25600 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
+ 2012-01-18 02:45 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2585542\update\spcustom.dll
+ 2012-01-18 02:45 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2585542\spmsg.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2584146\update\spcustom.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2584146\spmsg.dll
+ 2011-11-18 12:41 . 2011-11-18 12:41 60416 c:\windows\$hf_mig$\KB2584146\SP3QFE\packager.exe
+ 2011-09-17 03:54 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
+ 2011-09-17 03:54 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2570947\spmsg.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2570222\spmsg.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2567680\spmsg.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2567053\spmsg.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2566454\spmsg.dll
+ 2011-08-10 16:42 . 2011-07-08 13:51 10496 c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
+ 2011-08-11 04:29 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
+ 2011-08-11 04:29 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2562937\spmsg.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2559049-IE8\update\spcustom.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2559049-IE8\spmsg.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 12800 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\xpshims.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 66560 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtmled.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 55296 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\msfeedsbs.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 43520 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\licmgr10.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 25600 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\jsproxy.dll
+ 2011-07-13 15:13 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2555917\update\spcustom.dll
+ 2011-07-13 15:13 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2555917\spmsg.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2544893\update\spcustom.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2544893\spmsg.dll
+ 2011-11-10 02:55 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2544893-v2\update\spcustom.dll
+ 2011-11-10 02:55 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2544893-v2\spmsg.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2544521\update\spcustom.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2544521\spmsg.dll
+ 2011-07-05 06:33 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2544521-IE8\update\spcustom.dll
+ 2011-07-05 06:33 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2544521-IE8\spmsg.dll
+ 2011-06-29 19:56 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2541763\update\spcustom.dll
+ 2011-06-29 19:56 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2541763\spmsg.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2536276\update\spcustom.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2536276\spmsg.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2535512\update\spcustom.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2535512\spmsg.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2530548\update\spcustom.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2530548\spmsg.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 81920 c:\windows\$hf_mig$\KB2530548\SP3QFE\ieencode.dll
+ 2011-07-03 14:32 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2530548-IE8\update\spcustom.dll
+ 2011-07-03 14:32 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2530548-IE8\spmsg.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 12800 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\xpshims.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 66560 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\mshtmled.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 55296 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\msfeedsbs.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 43520 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\licmgr10.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 25600 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\jsproxy.dll
+ 2011-07-05 06:34 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2510531-IE8\update\spcustom.dll
+ 2011-07-05 06:34 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2510531-IE8\spmsg.dll
+ 2011-07-13 15:15 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
+ 2011-07-13 15:15 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2507938\spmsg.dll
+ 2011-04-26 11:02 . 2011-04-26 11:02 33280 c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2503665\update\spcustom.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2503665\spmsg.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 26488 c:\windows\$hf_mig$\KB2476490\update\spcustom.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 17272 c:\windows\$hf_mig$\KB2476490\spmsg.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 26488 c:\windows\$hf_mig$\KB2447568-IE8\update\spcustom.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 17272 c:\windows\$hf_mig$\KB2447568-IE8\spmsg.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\wmvdmoe2.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\wmvdmod.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 4096 c:\windows\system32\WMVADVE.DLL
+ 2006-08-25 03:30 . 2006-08-25 03:30 4096 c:\windows\system32\WMVADVD.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\wmsdmoe2.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\wmsdmod.dll
+ 2006-08-25 03:42 . 2006-08-25 03:42 8704 c:\windows\system32\wdfmgr.exe
+ 2006-08-25 03:30 . 2006-08-25 03:30 4096 c:\windows\system32\wdfapi.dll
+ 2006-08-25 03:42 . 2006-08-25 03:42 8704 c:\windows\system32\uwdf.exe
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\MPG4DMOD.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\MP4SDMOD.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\MP43DMOD.dll
+ 2012-02-16 17:32 . 2012-01-11 19:06 3072 c:\windows\system32\iacenc.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\wmvdmod.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\wmsdmoe2.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\wmsdmod.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\MPG4DMOD.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\MP4SDMOD.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 4096 c:\windows\system32\dllcache\MP43DMOD.dll
+ 2011-07-03 14:31 . 2010-10-18 11:10 7680 c:\windows\system32\dllcache\iecompat.dll
+ 2012-02-16 17:32 . 2012-01-11 19:06 3072 c:\windows\system32\dllcache\iacenc.dll
+ 2011-07-03 14:31 . 2009-03-08 08:35 2048 c:\windows\ie8updates\KB2447568-IE8\iecompat.dll
+ 2011-12-18 01:47 . 2008-04-14 09:41 6656 c:\windows\$NtUninstallWMFDist11$\laprxy.dll
+ 2012-05-12 16:31 . 2012-04-19 11:26 8192 c:\windows\$hf_mig$\KB2686509\update\kblChecker.dll
+ 2012-02-16 17:32 . 2012-01-11 19:05 3072 c:\windows\$hf_mig$\KB2661637\SP3QFE\iacenc.dll
+ 2012-01-11 16:37 . 2011-11-03 18:17 4608 c:\windows\$hf_mig$\KB2603381\update\customaddreg.dll
+ 2011-07-03 14:31 . 2010-10-18 10:39 7680 c:\windows\$hf_mig$\KB2447568-IE8\SP3QFE\iecompat.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
- 2006-12-02 02:54 . 2006-12-02 02:54 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2009-02-25 19:13 . 2009-02-25 19:13 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2009-02-25 19:13 . 2009-02-25 19:13 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
- 2006-12-02 02:54 . 2006-12-02 02:54 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2009-02-25 19:13 . 2009-02-25 19:13 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
- 2006-12-02 02:54 . 2006-12-02 02:54 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2011-05-14 06:17 . 2011-05-14 06:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-14 06:12 . 2011-05-14 06:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-14 06:11 . 2011-05-14 06:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2008-04-14 09:42 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 121856 c:\windows\system32\xmllite.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 349184 c:\windows\system32\wpdsp.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 133120 c:\windows\system32\WPDShServiceObj.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 154624 c:\windows\system32\wpdmtp.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 629760 c:\windows\system32\wpd_ci.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 656896 c:\windows\system32\WMVXENCD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 790016 c:\windows\system32\WMVSENCD.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 603648 c:\windows\system32\WMSPDMOD.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 937984 c:\windows\system32\WMNetMgr.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 157184 c:\windows\system32\wmidx.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 532992 c:\windows\system32\wmdrmsdk.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 347648 c:\windows\system32\wmdrmnet.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 428032 c:\windows\system32\wmdrmdev.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 222208 c:\windows\system32\WMASF.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 757248 c:\windows\system32\WMADMOD.dll
- 2008-04-14 09:42 . 2009-12-24 06:59 177664 c:\windows\system32\wintrust.dll
+ 2008-04-14 09:42 . 2012-02-29 14:10 177664 c:\windows\system32\wintrust.dll
+ 2008-04-14 09:42 . 2011-11-25 21:57 293376 c:\windows\system32\winsrv.dll
- 2008-04-14 09:42 . 2010-06-18 17:45 293376 c:\windows\system32\winsrv.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 176128 c:\windows\system32\winmm.dll
+ 2008-04-14 09:42 . 2011-10-14 14:47 176128 c:\windows\system32\winmm.dll
- 2008-04-14 09:42 . 2009-08-25 09:17 354816 c:\windows\system32\winhttp.dll
+ 2008-04-14 09:42 . 2011-11-16 14:21 354816 c:\windows\system32\winhttp.dll
+ 2009-03-08 08:34 . 2009-03-08 08:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2008-04-14 09:42 . 2009-03-08 08:34 236544 c:\windows\system32\webcheck.dll
+ 2008-04-14 09:42 . 2011-03-04 06:37 420864 c:\windows\system32\vbscript.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 105984 c:\windows\system32\url.dll
+ 2011-09-26 15:41 . 2011-09-26 15:41 611328 c:\windows\system32\uiautomationcore.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 345600 c:\windows\system32\QTIM32.DLL
- 2008-04-14 09:42 . 2008-04-14 09:42 386048 c:\windows\system32\qdvd.dll
+ 2008-04-14 09:42 . 2011-11-03 15:28 386048 c:\windows\system32\qdvd.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 210432 c:\windows\system32\qasf.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 198144 c:\windows\system32\PortableDeviceWMDRM.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 132096 c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 166912 c:\windows\system32\PortableDeviceTypes.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 101888 c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 284160 c:\windows\system32\PortableDeviceApi.dll
- 2001-08-23 12:00 . 2011-03-13 11:59 311604 c:\windows\system32\perfh009.dat
+ 2001-08-23 12:00 . 2012-03-11 19:50 311604 c:\windows\system32\perfh009.dat
+ 2008-04-14 09:42 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 551936 c:\windows\system32\oleaut32.dll
+ 2001-08-23 12:00 . 2011-09-26 15:41 220160 c:\windows\system32\oleacc.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 206848 c:\windows\system32\occache.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 320512 c:\windows\system32\mswmdm.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 414208 c:\windows\system32\msscp.dll
+ 2008-04-14 09:42 . 2009-03-08 08:34 193536 c:\windows\system32\msrating.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 175104 c:\windows\system32\mspmsp.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 179712 c:\windows\system32\msnetobj.dll
+ 2001-08-23 12:00 . 2009-03-08 08:22 156160 c:\windows\system32\msls31.dll
+ 2009-03-08 08:32 . 2012-05-11 14:42 629760 c:\windows\system32\msfeeds.dll
+ 2009-01-07 22:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 259072 c:\windows\system32\MPG4DECD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 316928 c:\windows\system32\MP4SDECD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 258560 c:\windows\system32\MP43DECD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 211968 c:\windows\system32\MFPLAT.dll
+ 2012-07-12 15:02 . 2012-07-12 15:02 686280 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_Plugin.exe
+ 2012-07-12 13:02 . 2012-07-12 13:02 686280 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe
+ 2012-07-12 13:02 . 2012-07-12 13:02 465096 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.dll
+ 2012-06-30 14:49 . 2012-07-12 13:02 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2008-04-14 09:42 . 2006-08-25 01:31 100864 c:\windows\system32\logagent.exe
+ 2008-04-14 09:41 . 2011-03-04 06:37 726528 c:\windows\system32\jscript.dll
- 2011-06-04 23:23 . 2011-02-03 01:40 157472 c:\windows\system32\javaws.exe
+ 2012-02-29 02:04 . 2012-02-29 02:04 157472 c:\windows\system32\javaws.exe
+ 2012-02-29 02:04 . 2012-02-29 02:04 149280 c:\windows\system32\javaw.exe
+ 2012-02-29 02:04 . 2012-02-29 02:04 149280 c:\windows\system32\java.exe
- 2010-12-03 00:08 . 2011-03-07 05:33 692736 c:\windows\system32\inetcomm.dll
+ 2010-12-03 00:08 . 2011-10-10 14:22 692736 c:\windows\system32\inetcomm.dll
+ 2008-04-14 09:41 . 2012-02-29 14:10 148480 c:\windows\system32\imagehlp.dll
+ 2009-03-08 08:22 . 2009-03-08 08:22 164352 c:\windows\system32\ieui.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 387584 c:\windows\system32\iedkcs32.dll
+ 2009-03-08 08:11 . 2009-03-08 08:11 445952 c:\windows\system32\ieapfltr.dll
+ 2001-08-23 12:00 . 2009-03-08 08:32 163840 c:\windows\system32\ieakui.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 229376 c:\windows\system32\ieaksie.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 125952 c:\windows\system32\ieakeng.dll
+ 2008-04-14 09:42 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
+ 2010-12-02 19:00 . 2012-07-11 20:43 128504 c:\windows\system32\FNTCACHE.DAT
- 2008-04-14 09:41 . 2011-02-09 13:53 186880 c:\windows\system32\encdec.dll
+ 2008-04-14 09:41 . 2011-10-18 11:13 186880 c:\windows\system32\encdec.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 216064 c:\windows\system32\dxtrans.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 348160 c:\windows\system32\dxtmsft.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 990208 c:\windows\system32\drmv2clt.dll
+ 2006-08-25 01:27 . 2006-08-25 01:27 249344 c:\windows\system32\drmupgds.exe
+ 2006-08-25 03:30 . 2006-08-25 03:30 667648 c:\windows\system32\drivers\umdf\wpdmtpdr.dll
+ 2008-04-14 04:47 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2008-04-14 04:47 . 2011-07-15 13:29 456320 c:\windows\system32\drivers\mrxsmb.sys
- 2008-04-14 04:49 . 2008-10-16 14:43 138496 c:\windows\system32\drivers\afd.sys
+ 2008-04-14 04:49 . 2011-08-17 13:49 138496 c:\windows\system32\drivers\afd.sys
+ 2011-08-31 04:05 . 2011-08-31 04:05 178536 c:\windows\system32\dnssdX.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 210968 c:\windows\system32\dllcache\wuweb.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 329240 c:\windows\system32\dllcache\wucltui.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 577048 c:\windows\system32\dllcache\wuapi.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 603648 c:\windows\system32\dllcache\WMSPDMOD.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 937984 c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 157184 c:\windows\system32\dllcache\wmidx.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 222208 c:\windows\system32\dllcache\WMASF.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 757248 c:\windows\system32\dllcache\WMADMOD.dll
- 2008-04-14 09:42 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2008-04-14 09:42 . 2012-02-29 14:10 177664 c:\windows\system32\dllcache\wintrust.dll
- 2008-04-14 09:42 . 2010-06-18 17:45 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2008-04-14 09:42 . 2011-11-25 21:57 293376 c:\windows\system32\dllcache\winsrv.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 176128 c:\windows\system32\dllcache\winmm.dll
+ 2008-04-14 09:42 . 2011-10-14 14:47 176128 c:\windows\system32\dllcache\winmm.dll
+ 2008-04-14 09:42 . 2012-05-16 15:08 916992 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 09:42 . 2009-08-25 09:17 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2008-04-14 09:42 . 2011-11-16 14:21 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2008-04-14 09:42 . 2009-03-08 08:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2010-12-03 00:09 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-04-14 09:42 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-07 22:20 . 2009-01-07 22:20 134144 c:\windows\system32\dllcache\sqmapi.dll
+ 2008-04-14 09:42 . 2012-06-04 04:32 152576 c:\windows\system32\dllcache\schannel.dll
+ 2010-12-03 00:06 . 2012-05-02 13:46 139656 c:\windows\system32\dllcache\rdpwd.sys
- 2010-12-03 00:06 . 2008-04-14 09:43 139656 c:\windows\system32\dllcache\rdpwd.sys
+ 2008-04-14 09:42 . 2011-11-03 15:28 386048 c:\windows\system32\dllcache\qdvd.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 386048 c:\windows\system32\dllcache\qdvd.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 210432 c:\windows\system32\dllcache\qasf.dll
- 2008-04-14 09:42 . 2008-04-14 09:42 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2008-04-14 09:42 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2001-08-23 12:00 . 2011-09-26 15:41 220160 c:\windows\system32\dllcache\oleacc.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 04:47 . 2011-04-21 13:37 105472 c:\windows\system32\dllcache\mup.sys
+ 2008-04-14 09:42 . 2006-08-25 03:30 320512 c:\windows\system32\dllcache\mswmdm.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 414208 c:\windows\system32\dllcache\msscp.dll
+ 2008-04-14 09:42 . 2009-03-08 08:34 193536 c:\windows\system32\dllcache\msrating.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 175104 c:\windows\system32\dllcache\mspmsp.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 179712 c:\windows\system32\dllcache\msnetobj.dll
+ 2001-08-23 12:00 . 2009-03-08 08:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2011-07-03 14:30 . 2012-05-11 14:42 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2010-12-03 00:08 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
- 2010-12-03 00:08 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2010-12-03 17:48 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-04-14 09:42 . 2006-08-25 01:31 100864 c:\windows\system32\dllcache\logagent.exe
+ 2012-06-14 00:33 . 2012-05-11 14:42 521728 c:\windows\system32\dllcache\jsdbgui.dll
+ 2008-04-14 09:41 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
+ 2010-12-03 00:08 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2010-12-03 00:08 . 2011-03-07 05:33 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-04-14 09:41 . 2012-02-29 14:10 148480 c:\windows\system32\dllcache\imagehlp.dll
+ 2010-12-03 00:08 . 2009-03-08 18:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2011-07-03 14:30 . 2012-05-11 14:42 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2011-07-03 14:30 . 2012-05-11 14:42 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2008-04-14 09:41 . 2012-05-11 14:42 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2001-08-23 12:00 . 2009-03-08 08:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 09:41 . 2009-03-08 08:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-04-14 09:42 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 09:41 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-04-14 09:41 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 09:41 . 2009-03-08 08:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 990208 c:\windows\system32\dllcache\drmv2clt.dll
+ 2008-04-14 09:41 . 2012-05-31 13:22 599040 c:\windows\system32\dllcache\crypt32.dll
- 2008-04-14 09:41 . 2008-04-14 09:41 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 228352 c:\windows\system32\dllcache\cewmdm.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 537600 c:\windows\system32\dllcache\blackbox.dll
- 2008-04-14 04:49 . 2008-10-16 14:43 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-04-14 04:49 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-04-14 09:41 . 2009-03-08 08:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2011-01-24 03:12 . 2012-02-29 02:04 472808 c:\windows\system32\deployJava1.dll
- 2011-01-24 03:12 . 2011-02-03 01:40 472808 c:\windows\system32\deployJava1.dll
+ 2012-02-17 19:11 . 2012-02-17 19:11 262144 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2008-04-14 09:41 . 2006-08-25 03:30 228352 c:\windows\system32\cewmdm.dll
+ 2008-04-14 09:41 . 2006-08-25 03:30 537600 c:\windows\system32\blackbox.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 276480 c:\windows\system32\audiodev.dll
+ 2008-04-14 09:41 . 2009-03-08 08:32 128512 c:\windows\system32\advpack.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 169472 c:\windows\QTW32DEL.EXE
+ 1996-04-04 06:11 . 1996-04-04 06:11 107008 c:\windows\PLAY32.EXE
+ 2012-07-16 19:56 . 2010-12-04 00:21 171286 c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
+ 2012-02-22 20:13 . 2012-02-22 20:13 381440 c:\windows\Installer\e36a75.msi
+ 2011-12-18 01:44 . 2011-12-18 01:44 223744 c:\windows\Installer\b2ac2.msi
+ 2011-12-18 01:43 . 2011-12-18 01:43 467456 c:\windows\Installer\b2abc.msi
+ 2011-11-18 17:15 . 2011-11-18 17:15 836096 c:\windows\Installer\8143f.msi
+ 2012-02-29 02:06 . 2012-02-29 02:06 203776 c:\windows\Installer\1260b71.msi
+ 2012-02-29 02:03 . 2012-02-29 02:03 901120 c:\windows\Installer\1260b63.msi
+ 2012-05-31 01:42 . 2012-05-31 01:42 380928 c:\windows\Installer\{23B8A91D-680B-462B-87AD-3D70F7341731}\iTunesIco.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 103848 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlrShim.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll
+ 2011-07-03 14:31 . 2009-03-08 08:34 914944 c:\windows\ie8updates\KB982381-IE8\wininet.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
+ 2011-07-03 14:31 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
+ 2011-07-03 14:31 . 2009-03-08 08:34 109568 c:\windows\ie8updates\KB982381-IE8\occache.dll
+ 2011-07-03 14:31 . 2009-03-08 08:32 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
+ 2011-07-03 14:31 . 2009-03-08 08:32 594432 c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
+ 2011-07-03 14:31 . 2009-03-08 08:33 246784 c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
+ 2011-07-03 14:31 . 2009-03-08 08:31 183808 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
+ 2011-07-03 14:31 . 2009-03-08 08:35 742912 c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
+ 2011-07-03 14:31 . 2009-03-08 18:09 391536 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
+ 2011-07-03 14:31 . 2009-03-08 08:32 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
+ 2012-06-14 03:07 . 2012-03-01 11:01 916992 c:\windows\ie8updates\KB2699988-IE8\wininet.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 105984 c:\windows\ie8updates\KB2699988-IE8\url.dll
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2699988-IE8\spuninst\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2699988-IE8\spuninst\spuninst.exe
+ 2012-06-14 03:07 . 2012-03-01 11:01 206848 c:\windows\ie8updates\KB2699988-IE8\occache.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 611840 c:\windows\ie8updates\KB2699988-IE8\mstime.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 602112 c:\windows\ie8updates\KB2699988-IE8\msfeeds.dll
+ 2012-06-14 03:07 . 2009-03-08 08:35 521216 c:\windows\ie8updates\KB2699988-IE8\jsdbgui.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 247808 c:\windows\ie8updates\KB2699988-IE8\ieproxy.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 184320 c:\windows\ie8updates\KB2699988-IE8\iepeers.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 743424 c:\windows\ie8updates\KB2699988-IE8\iedvtool.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 387584 c:\windows\ie8updates\KB2699988-IE8\iedkcs32.dll
+ 2012-06-14 03:07 . 2012-02-29 12:17 174080 c:\windows\ie8updates\KB2699988-IE8\ie4uinit.exe
+ 2012-04-12 03:46 . 2011-12-17 19:46 916992 c:\windows\ie8updates\KB2675157-IE8\wininet.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 105984 c:\windows\ie8updates\KB2675157-IE8\url.dll
+ 2012-04-12 03:46 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2675157-IE8\spuninst\updspapi.dll
+ 2012-04-12 03:46 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2675157-IE8\spuninst\spuninst.exe
+ 2012-04-12 03:46 . 2011-12-17 19:46 206848 c:\windows\ie8updates\KB2675157-IE8\occache.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 611840 c:\windows\ie8updates\KB2675157-IE8\mstime.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 602112 c:\windows\ie8updates\KB2675157-IE8\msfeeds.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 247808 c:\windows\ie8updates\KB2675157-IE8\ieproxy.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 184320 c:\windows\ie8updates\KB2675157-IE8\iepeers.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 743424 c:\windows\ie8updates\KB2675157-IE8\iedvtool.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 387584 c:\windows\ie8updates\KB2675157-IE8\iedkcs32.dll
+ 2012-04-12 03:46 . 2011-12-16 12:23 174080 c:\windows\ie8updates\KB2675157-IE8\ie4uinit.exe
+ 2012-02-17 07:28 . 2011-11-04 19:20 916992 c:\windows\ie8updates\KB2647516-IE8\wininet.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 105984 c:\windows\ie8updates\KB2647516-IE8\url.dll
+ 2012-02-17 07:28 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2647516-IE8\spuninst\updspapi.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2647516-IE8\spuninst\spuninst.exe
+ 2012-02-17 07:28 . 2011-11-04 19:20 206848 c:\windows\ie8updates\KB2647516-IE8\occache.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 611840 c:\windows\ie8updates\KB2647516-IE8\mstime.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 602112 c:\windows\ie8updates\KB2647516-IE8\msfeeds.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 247808 c:\windows\ie8updates\KB2647516-IE8\ieproxy.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 184320 c:\windows\ie8updates\KB2647516-IE8\iepeers.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 743424 c:\windows\ie8updates\KB2647516-IE8\iedvtool.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 387584 c:\windows\ie8updates\KB2647516-IE8\iedkcs32.dll
+ 2012-02-17 07:28 . 2011-11-04 11:24 174080 c:\windows\ie8updates\KB2647516-IE8\ie4uinit.exe
+ 2011-12-16 03:38 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-16 03:38 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-16 03:38 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-16 03:38 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2011-10-13 20:17 . 2011-06-23 18:36 916480 c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 105984 c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-13 20:17 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-13 20:17 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-13 20:17 . 2011-06-23 18:36 206848 c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 611840 c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 602112 c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 247808 c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 184320 c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 743424 c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 387584 c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-13 20:17 . 2011-06-23 12:05 173568 c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-08-11 04:30 . 2011-04-25 16:11 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
+ 2011-08-11 04:30 . 2009-03-08 08:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
+ 2011-08-11 04:30 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2559049-IE8\spuninst\updspapi.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2559049-IE8\spuninst\spuninst.exe
+ 2011-08-11 04:30 . 2011-04-25 16:11 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 602112 c:\windows\ie8updates\KB2559049-IE8\msfeeds.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
+ 2011-08-11 04:30 . 2011-04-25 12:01 173568 c:\windows\ie8updates\KB2559049-IE8\ie4uinit.exe
+ 2011-07-05 06:33 . 2009-03-08 08:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-07-05 06:33 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-07-05 06:33 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-07-03 14:32 . 2010-05-06 10:41 916480 c:\windows\ie8updates\KB2530548-IE8\wininet.dll
+ 2011-07-03 14:32 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2530548-IE8\spuninst\updspapi.dll
+ 2011-07-03 14:32 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2530548-IE8\spuninst\spuninst.exe
+ 2011-07-03 14:32 . 2010-05-06 10:41 206848 c:\windows\ie8updates\KB2530548-IE8\occache.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 611840 c:\windows\ie8updates\KB2530548-IE8\mstime.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 599040 c:\windows\ie8updates\KB2530548-IE8\msfeeds.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 247808 c:\windows\ie8updates\KB2530548-IE8\ieproxy.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 184320 c:\windows\ie8updates\KB2530548-IE8\iepeers.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 743424 c:\windows\ie8updates\KB2530548-IE8\iedvtool.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 387584 c:\windows\ie8updates\KB2530548-IE8\iedkcs32.dll
+ 2011-07-03 14:32 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2530548-IE8\ie4uinit.exe
+ 2011-07-05 06:34 . 2009-03-08 08:33 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-07-05 06:34 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-07-05 06:34 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-07-05 06:34 . 2009-03-08 08:33 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB2447568-IE8\spuninst\updspapi.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 231288 c:\windows\ie8updates\KB2447568-IE8\spuninst\spuninst.exe
+ 2011-07-03 14:27 . 2011-04-25 14:47 667136 c:\windows\ie8\wininet.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 276480 c:\windows\ie8\webcheck.dll
+ 2011-07-03 14:27 . 2011-04-29 19:07 852480 c:\windows\ie8\vgx.dll
+ 2011-07-03 14:27 . 2011-03-04 06:45 434176 c:\windows\ie8\vbscript.dll
+ 2011-07-03 14:27 . 2011-04-25 14:47 629760 c:\windows\ie8\urlmon.dll
+ 2011-07-03 14:28 . 2009-01-07 22:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2011-07-03 14:28 . 2009-01-07 22:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2011-07-03 14:27 . 2011-04-25 14:47 532480 c:\windows\ie8\mstime.dll
+ 2011-07-03 14:27 . 2008-04-14 09:42 146432 c:\windows\ie8\msrating.dll
+ 2011-07-03 14:27 . 2001-08-23 12:00 146432 c:\windows\ie8\msls31.dll
+ 2011-07-03 14:27 . 2011-04-25 14:47 449536 c:\windows\ie8\mshtmled.dll
+ 2011-07-03 14:27 . 2011-03-04 06:45 512000 c:\windows\ie8\jscript.dll
+ 2011-07-03 14:27 . 2011-04-25 14:47 251904 c:\windows\ie8\iepeers.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 323584 c:\windows\ie8\iedkcs32.dll
+ 2011-07-03 14:27 . 2001-08-23 12:00 221184 c:\windows\ie8\ieakui.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 216576 c:\windows\ie8\ieaksie.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 143360 c:\windows\ie8\ieakeng.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 205312 c:\windows\ie8\dxtrans.dll
+ 2011-07-03 14:27 . 2008-04-14 09:41 357888 c:\windows\ie8\dxtmsft.dll
+ 2010-12-03 17:48 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-12-18 01:47 . 2008-04-14 09:42 809984 c:\windows\$NtUninstallWMFDist11$\wmvdmod.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 897024 c:\windows\$NtUninstallWMFDist11$\wmspdmoe.dll
+ 2011-12-18 01:47 . 2009-04-03 17:15 485376 c:\windows\$NtUninstallWMFDist11$\wmspdmod.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 759296 c:\windows\$NtUninstallWMFDist11$\wmsdmod.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 151552 c:\windows\$NtUninstallWMFDist11$\wmidx.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 230912 c:\windows\$NtUninstallWMFDist11$\wmasf.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 670720 c:\windows\$NtUninstallWMFDist11$\wmadmoe.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 408064 c:\windows\$NtUninstallWMFDist11$\wmadmod.dll
+ 2011-12-18 01:47 . 2006-08-12 01:14 371424 c:\windows\$NtUninstallWMFDist11$\spuninst\updspapi.dll
+ 2011-12-18 01:47 . 2006-08-12 01:14 213216 c:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe
+ 2011-12-18 01:47 . 2008-04-14 09:42 237568 c:\windows\$NtUninstallWMFDist11$\qasf.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 245760 c:\windows\$NtUninstallWMFDist11$\mswmdm.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 356352 c:\windows\$NtUninstallWMFDist11$\msscp.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 201728 c:\windows\$NtUninstallWMFDist11$\mspmsp.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 259072 c:\windows\$NtUninstallWMFDist11$\msnetobj.dll
+ 2011-12-18 01:47 . 2008-04-14 09:41 240640 c:\windows\$NtUninstallWMFDist11$\mpg4dmod.dll
+ 2011-12-18 01:47 . 2010-04-05 16:54 384512 c:\windows\$NtUninstallWMFDist11$\mp4sdmod.dll
+ 2011-12-18 01:47 . 2008-04-14 09:41 310272 c:\windows\$NtUninstallWMFDist11$\mp43dmod.dll
+ 2011-12-18 01:47 . 2008-06-10 08:11 103936 c:\windows\$NtUninstallWMFDist11$\logagent.exe
+ 2011-12-18 01:47 . 2008-04-14 09:42 695808 c:\windows\$NtUninstallWMFDist11$\drmv2clt.dll
+ 2011-12-18 01:47 . 2008-04-14 09:41 159232 c:\windows\$NtUninstallWMFDist11$\cewmdm.dll
+ 2011-12-18 01:47 . 2008-04-14 09:41 286720 c:\windows\$NtUninstallWMFDist11$\blackbox.dll
+ 2012-06-04 17:47 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2718704$\spuninst\updspapi.dll
+ 2012-06-04 17:47 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2718704$\spuninst\spuninst.exe
+ 2012-06-04 17:47 . 2011-09-28 07:06 599040 c:\windows\$NtUninstallKB2718704$\crypt32.dll
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2709162$\spuninst\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2709162$\spuninst\spuninst.exe
+ 2012-06-14 03:09 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2707511$\spuninst\updspapi.dll
+ 2012-06-14 03:09 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2707511$\spuninst\spuninst.exe
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2695962$\spuninst\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2695962$\spuninst\spuninst.exe
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2686509$\spuninst\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2686509$\spuninst\spuninst.exe
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2685939$\spuninst\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2685939$\spuninst\spuninst.exe
+ 2012-06-14 03:07 . 2012-01-09 16:20 139784 c:\windows\$NtUninstallKB2685939$\rdpwd.sys
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2676562$\spuninst\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2676562$\spuninst\spuninst.exe
+ 2012-02-17 07:28 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2661637$\spuninst\updspapi.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2661637$\spuninst\spuninst.exe
+ 2012-02-17 07:29 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2660465$\spuninst\updspapi.dll
+ 2012-02-17 07:29 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2660465$\spuninst\spuninst.exe
+ 2012-05-12 17:20 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2659262$\spuninst\updspapi.dll
+ 2012-05-12 17:20 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2659262$\spuninst\spuninst.exe
+ 2012-04-12 03:44 . 2009-12-24 06:59 177664 c:\windows\$NtUninstallKB2653956$\wintrust.dll
+ 2012-04-12 03:44 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2653956$\spuninst\updspapi.dll
+ 2012-04-12 03:44 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2653956$\spuninst\spuninst.exe
+ 2012-04-12 03:44 . 2008-04-14 09:41 144384 c:\windows\$NtUninstallKB2653956$\imagehlp.dll
+ 2012-03-15 01:42 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2647518$\spuninst\updspapi.dll
+ 2012-03-15 01:42 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2647518$\spuninst\spuninst.exe
+ 2012-01-11 17:53 . 2011-06-20 17:44 293376 c:\windows\$NtUninstallKB2646524$\winsrv.dll
+ 2012-01-11 17:53 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2646524$\spuninst\updspapi.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2646524$\spuninst\spuninst.exe
+ 2011-11-12 02:34 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2641690$\spuninst\updspapi.dll
+ 2011-11-12 02:34 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2641690$\spuninst\spuninst.exe
+ 2011-11-12 02:34 . 2011-09-09 09:12 599040 c:\windows\$NtUninstallKB2641690$\crypt32.dll
+ 2012-03-15 01:45 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2641653$\spuninst\updspapi.dll
+ 2012-03-15 01:45 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2641653$\spuninst\spuninst.exe
+ 2011-12-16 03:39 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2639417$\spuninst\updspapi.dll
+ 2011-12-16 03:39 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2639417$\spuninst\spuninst.exe
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633952$\spuninst\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633952$\spuninst\spuninst.exe
+ 2011-12-16 03:35 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2633171$\spuninst\updspapi.dll
+ 2011-12-16 03:35 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2633171$\spuninst\spuninst.exe
+ 2012-01-11 17:53 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2631813$\spuninst\updspapi.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2631813$\spuninst\spuninst.exe
+ 2012-01-11 17:53 . 2008-04-14 09:42 386048 c:\windows\$NtUninstallKB2631813$\qdvd.dll
+ 2011-12-16 03:38 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2624667$\spuninst\updspapi.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2624667$\spuninst\spuninst.exe
+ 2012-03-15 01:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2621440$\spuninst\updspapi.dll
+ 2012-03-15 01:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2621440$\spuninst\spuninst.exe
+ 2012-03-15 01:43 . 2011-06-24 14:10 139656 c:\windows\$NtUninstallKB2621440$\rdpwd.sys
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2620712$\spuninst\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2620712$\spuninst\spuninst.exe
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2619339$\spuninst\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2619339$\spuninst\spuninst.exe
+ 2011-12-16 03:36 . 2011-02-09 13:53 186880 c:\windows\$NtUninstallKB2619339$\encdec.dll
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2618451$\spuninst\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2618451$\spuninst\spuninst.exe
+ 2011-09-17 03:56 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2616676$\spuninst\updspapi.dll
+ 2011-09-17 03:56 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2616676$\spuninst\spuninst.exe
+ 2011-09-17 03:56 . 2011-09-03 10:17 599040 c:\windows\$NtUninstallKB2616676$\crypt32.dll
+ 2011-09-07 22:36 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2607712$\spuninst\updspapi.dll
+ 2011-09-07 22:36 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2607712$\spuninst\spuninst.exe
+ 2011-09-07 22:36 . 2008-04-14 09:41 599040 c:\windows\$NtUninstallKB2607712$\crypt32.dll
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2603381$\spuninst\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2603381$\spuninst\spuninst.exe
+ 2012-01-11 17:51 . 2008-04-14 09:42 176128 c:\windows\$NtUninstallKB2598479$\winmm.dll
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2598479$\spuninst\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2598479$\spuninst\spuninst.exe
+ 2011-10-13 20:18 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2592799$\spuninst\updspapi.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2592799$\spuninst\spuninst.exe
+ 2011-10-13 20:18 . 2011-02-16 13:22 138496 c:\windows\$NtUninstallKB2592799$\afd.sys
+ 2012-01-18 02:45 . 2009-08-25 09:17 354816 c:\windows\$NtUninstallKB2585542$\winhttp.dll
+ 2012-01-18 02:45 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2585542$\spuninst\updspapi.dll
+ 2012-01-18 02:45 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2585542$\spuninst\spuninst.exe
+ 2012-01-18 02:45 . 2011-04-29 17:25 151552 c:\windows\$NtUninstallKB2585542$\schannel.dll
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2584146$\spuninst\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2584146$\spuninst\spuninst.exe
+ 2011-09-17 03:54 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570947$\spuninst\updspapi.dll
+ 2011-09-17 03:54 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570947$\spuninst\spuninst.exe
+ 2011-08-25 04:28 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
+ 2011-08-25 04:28 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2570222$\spuninst\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2570222$\spuninst\spuninst.exe
+ 2011-08-11 04:32 . 2008-04-14 09:43 139656 c:\windows\$NtUninstallKB2570222$\rdpwd.sys
+ 2011-08-11 04:32 . 2011-04-26 11:07 293376 c:\windows\$NtUninstallKB2567680$\winsrv.dll
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2567680$\spuninst\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2567680$\spuninst\spuninst.exe
+ 2011-10-13 20:18 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2567053$\spuninst\updspapi.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2567053$\spuninst\spuninst.exe
+ 2011-08-11 04:30 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2566454$\spuninst\updspapi.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2566454$\spuninst\spuninst.exe
+ 2011-10-13 20:20 . 2011-08-12 17:51 382840 c:\windows\$NtUninstallKB2564958$\spuninst\updspapi.dll
+ 2011-10-13 20:20 . 2011-08-12 17:51 231288 c:\windows\$NtUninstallKB2564958$\spuninst\spuninst.exe
+ 2011-10-13 20:20 . 2001-08-23 12:00 163328 c:\windows\$NtUninstallKB2564958$\oleacc.dll
+ 2011-08-11 04:29 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2562937$\spuninst\updspapi.dll
+ 2011-08-11 04:29 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2562937$\spuninst\spuninst.exe
+ 2011-07-13 15:13 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2555917$\spuninst\updspapi.dll
+ 2011-07-13 15:13 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2555917$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2544893$\spuninst\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2544893$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2011-03-07 05:33 692736 c:\windows\$NtUninstallKB2544893$\inetcomm.dll
+ 2011-11-10 02:55 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2544893-v2$\spuninst\updspapi.dll
+ 2011-11-10 02:55 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2544893-v2$\spuninst\spuninst.exe
+ 2011-11-10 02:55 . 2011-05-02 15:31 692736 c:\windows\$NtUninstallKB2544893-v2$\inetcomm.dll
+ 2011-06-17 04:43 . 2008-04-14 09:42 851968 c:\windows\$NtUninstallKB2544521$\vgx.dll
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2544521$\spuninst\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2544521$\spuninst\spuninst.exe
+ 2011-06-29 19:56 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2541763$\spuninst\updspapi.dll
+ 2011-06-29 19:56 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2541763$\spuninst\spuninst.exe
+ 2011-06-29 19:56 . 2010-06-30 12:31 149504 c:\windows\$NtUninstallKB2541763$\schannel.dll
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2536276$\spuninst\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2536276$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2011-02-17 13:18 455936 c:\windows\$NtUninstallKB2536276$\mrxsmb.sys
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2536276-v2$\spuninst\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe
+ 2011-08-11 04:32 . 2011-04-29 16:19 456320 c:\windows\$NtUninstallKB2536276-v2$\mrxsmb.sys
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2535512$\spuninst\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2535512$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2008-04-14 04:47 105344 c:\windows\$NtUninstallKB2535512$\mup.sys
+ 2011-06-17 04:44 . 2011-02-17 13:51 667136 c:\windows\$NtUninstallKB2530548$\wininet.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 629760 c:\windows\$NtUninstallKB2530548$\urlmon.dll
+ 2011-06-17 04:44 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2530548$\spuninst\updspapi.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2530548$\spuninst\spuninst.exe
+ 2011-06-17 04:44 . 2011-02-17 13:51 532480 c:\windows\$NtUninstallKB2530548$\mstime.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 449024 c:\windows\$NtUninstallKB2530548$\mshtmled.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 251904 c:\windows\$NtUninstallKB2530548$\iepeers.dll
+ 2011-07-13 15:15 . 2010-06-18 17:45 293376 c:\windows\$NtUninstallKB2507938$\winsrv.dll
+ 2011-07-13 15:15 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2507938$\spuninst\updspapi.dll
+ 2011-07-13 15:15 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2507938$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2503665$\spuninst\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2503665$\spuninst\spuninst.exe
+ 2011-06-17 04:43 . 2008-10-16 14:43 138496 c:\windows\$NtUninstallKB2503665$\afd.sys
+ 2011-06-17 04:44 . 2010-07-05 13:16 382840 c:\windows\$NtUninstallKB2476490$\spuninst\updspapi.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 231288 c:\windows\$NtUninstallKB2476490$\spuninst\spuninst.exe
+ 2011-06-17 04:44 . 2008-04-14 09:42 551936 c:\windows\$NtUninstallKB2476490$\oleaut32.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB982381-IE8\update\updspapi.dll
+ 2011-07-03 14:31 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB982381-IE8\update\update.exe
+ 2011-07-03 14:31 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB982381-IE8\spuninst.exe
+ 2011-07-03 14:30 . 2010-05-06 10:36 919040 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 206848 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\occache.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 611840 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mstime.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 599040 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\msfeeds.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 247808 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ieproxy.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 184320 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iepeers.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 743424 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iedvtool.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 387584 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iedkcs32.dll
+ 2011-07-03 14:30 . 2010-05-05 13:55 173056 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ie4uinit.exe
+ 2012-06-04 17:47 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2718704\update\updspapi.dll
+ 2012-06-04 17:47 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2718704\update\update.exe
+ 2012-06-04 17:47 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2718704\spuninst.exe
+ 2012-05-31 13:19 . 2012-05-31 13:19 599552 c:\windows\$hf_mig$\KB2718704\SP3QFE\crypt32.dll
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2709162\update\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2709162\update\update.exe
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2709162\spuninst.exe
+ 2012-06-14 03:09 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2707511\update\updspapi.dll
+ 2012-06-14 03:09 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2707511\update\update.exe
+ 2012-06-14 03:09 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2707511\spuninst.exe
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2699988-IE8\update\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2699988-IE8\update\update.exe
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2699988-IE8\spuninst.exe
+ 2012-06-14 00:33 . 2012-05-16 15:06 920064 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\wininet.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 105984 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\url.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 206848 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\occache.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 611840 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\mstime.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 630272 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\msfeeds.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 522240 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\jsdbgui.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 247808 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\ieproxy.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 184320 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\iepeers.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 743424 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\iedvtool.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 387584 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\iedkcs32.dll
+ 2012-06-14 00:33 . 2012-05-11 12:13 174080 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\ie4uinit.exe
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2695962\update\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2695962\update\update.exe
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2695962\spuninst.exe
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2686509\update\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2686509\update\update.exe
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2686509\spuninst.exe
+ 2012-06-14 03:07 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2685939\update\updspapi.dll
+ 2012-06-14 03:07 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2685939\update\update.exe
+ 2012-06-14 03:07 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2685939\spuninst.exe
+ 2012-06-14 00:33 . 2012-05-02 13:45 139656 c:\windows\$hf_mig$\KB2685939\SP3QFE\rdpwd.sys
+ 2012-05-12 17:18 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2676562\update\updspapi.dll
+ 2012-05-12 17:18 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2676562\update\update.exe
+ 2012-05-12 17:18 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2676562\spuninst.exe
+ 2012-04-12 03:46 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2675157-IE8\update\updspapi.dll
+ 2012-04-12 03:46 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2675157-IE8\update\update.exe
+ 2012-04-12 03:46 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2675157-IE8\spuninst.exe
+ 2012-04-11 22:33 . 2012-03-01 10:58 919552 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\wininet.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 105984 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\url.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 206848 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\occache.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 611840 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\mstime.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 602112 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\msfeeds.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 247808 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\ieproxy.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 184320 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\iepeers.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 743424 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\iedvtool.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 387584 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\iedkcs32.dll
+ 2012-04-11 22:33 . 2012-02-29 12:30 174080 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\ie4uinit.exe
+ 2012-02-17 07:28 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2661637\update\updspapi.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2661637\update\update.exe
+ 2012-02-17 07:28 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2661637\spuninst.exe
+ 2012-02-17 07:29 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2660465\update\updspapi.dll
+ 2012-02-17 07:29 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2660465\update\update.exe
+ 2012-02-17 07:29 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2660465\spuninst.exe
+ 2012-04-12 03:44 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2653956\update\updspapi.dll
+ 2012-04-12 03:44 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2653956\update\update.exe
+ 2012-04-12 03:44 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2653956\spuninst.exe
+ 2012-02-29 14:08 . 2012-02-29 14:08 178176 c:\windows\$hf_mig$\KB2653956\SP3QFE\wintrust.dll
+ 2012-02-29 14:08 . 2012-02-29 14:08 148480 c:\windows\$hf_mig$\KB2653956\SP3QFE\imagehlp.dll
+ 2012-03-15 01:42 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2647518\update\updspapi.dll
+ 2012-03-15 01:42 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2647518\update\update.exe
+ 2012-03-15 01:42 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2647518\spuninst.exe
+ 2012-02-17 07:28 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2647516-IE8\update\updspapi.dll
+ 2012-02-17 07:28 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2647516-IE8\update\update.exe
+ 2012-02-17 07:28 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2647516-IE8\spuninst.exe
+ 2012-02-16 17:33 . 2011-12-17 19:45 919552 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\wininet.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 105984 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\url.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 206848 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\occache.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 611840 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mstime.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 602112 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\msfeeds.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 247808 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ieproxy.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 184320 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iepeers.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 743424 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iedvtool.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 387584 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iedkcs32.dll
+ 2012-02-16 17:33 . 2011-12-16 12:33 174080 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ie4uinit.exe
+ 2012-01-11 17:53 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2646524\update\updspapi.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2646524\update\update.exe
+ 2012-01-11 17:53 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2646524\spuninst.exe
+ 2011-11-25 21:56 . 2011-11-25 21:56 293376 c:\windows\$hf_mig$\KB2646524\SP3QFE\winsrv.dll
+ 2011-11-12 02:34 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2641690\update\updspapi.dll
+ 2011-11-12 02:34 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2641690\update\update.exe
+ 2011-11-12 02:34 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2641690\spuninst.exe
+ 2011-09-28 07:05 . 2011-09-28 07:05 599552 c:\windows\$hf_mig$\KB2641690\SP3QFE\crypt32.dll
+ 2012-03-15 01:45 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2641653\update\updspapi.dll
+ 2012-03-15 01:45 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2641653\update\update.exe
+ 2012-03-15 01:45 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2641653\spuninst.exe
+ 2011-12-16 03:39 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2639417\update\updspapi.dll
+ 2011-12-16 03:39 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2639417\update\update.exe
+ 2011-12-16 03:39 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2639417\spuninst.exe
+ 2011-12-16 03:35 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2633171\update\updspapi.dll
+ 2011-12-16 03:35 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2633171\update\update.exe
+ 2011-12-16 03:35 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2633171\spuninst.exe
+ 2012-01-11 17:53 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2631813\update\updspapi.dll
+ 2012-01-11 17:53 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2631813\update\update.exe
+ 2012-01-11 17:53 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2631813\spuninst.exe
+ 2011-11-03 15:27 . 2011-11-03 15:27 386048 c:\windows\$hf_mig$\KB2631813\SP3QFE\qdvd.dll
+ 2011-12-16 03:38 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2624667\update\updspapi.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2624667\update\update.exe
+ 2011-12-16 03:38 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2624667\spuninst.exe
+ 2012-03-15 01:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2621440\update\updspapi.dll
+ 2012-03-15 01:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2621440\update\update.exe
+ 2012-03-15 01:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2621440\spuninst.exe
+ 2012-03-14 22:44 . 2012-01-09 16:19 139784 c:\windows\$hf_mig$\KB2621440\SP3QFE\rdpwd.sys
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2620712\update\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2620712\update\update.exe
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2620712\spuninst.exe
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2619339\update\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2619339\update\update.exe
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2619339\spuninst.exe
+ 2011-10-18 11:12 . 2011-10-18 11:12 186880 c:\windows\$hf_mig$\KB2619339\SP3QFE\encdec.dll
+ 2011-12-16 03:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618451\update\updspapi.dll
+ 2011-12-16 03:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618451\update\update.exe
+ 2011-12-16 03:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618451\spuninst.exe
+ 2011-12-16 03:38 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2618444-IE8\update\updspapi.dll
+ 2011-12-16 03:38 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2618444-IE8\update\update.exe
+ 2011-12-16 03:38 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2618444-IE8\spuninst.exe
+ 2011-12-15 23:05 . 2011-11-04 19:19 919552 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 105984 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\url.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 206848 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\occache.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 611840 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mstime.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 602112 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\msfeeds.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 247808 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieproxy.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 184320 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iepeers.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 743424 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedvtool.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 387584 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iedkcs32.dll
+ 2011-12-15 23:05 . 2011-10-25 12:01 174080 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ie4uinit.exe
+ 2011-09-17 03:56 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2616676\update\updspapi.dll
+ 2011-09-17 03:56 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2616676\update\update.exe
+ 2011-09-17 03:56 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2616676\spuninst.exe
+ 2011-09-09 09:11 . 2011-09-09 09:11 599552 c:\windows\$hf_mig$\KB2616676\SP3QFE\crypt32.dll
+ 2011-09-07 22:36 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2607712\update\updspapi.dll
+ 2011-09-07 22:36 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2607712\update\update.exe
+ 2011-09-07 22:36 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2607712\spuninst.exe
+ 2011-09-03 10:16 . 2011-09-03 10:16 599552 c:\windows\$hf_mig$\KB2607712\SP3QFE\crypt32.dll
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2603381\update\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2603381\update\update.exe
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2603381\spuninst.exe
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2598479\update\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2598479\update\update.exe
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2598479\spuninst.exe
+ 2011-10-14 14:45 . 2011-10-14 14:45 176128 c:\windows\$hf_mig$\KB2598479\SP3QFE\winmm.dll
+ 2011-10-13 20:18 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2592799\update\updspapi.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2592799\update\update.exe
+ 2011-10-13 20:18 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2592799\spuninst.exe
+ 2011-10-13 15:15 . 2011-08-17 13:41 138496 c:\windows\$hf_mig$\KB2592799\SP3QFE\afd.sys
+ 2011-10-13 20:17 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2586448-IE8\update\updspapi.dll
+ 2011-10-13 20:17 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2586448-IE8\update\update.exe
+ 2011-10-13 20:17 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2586448-IE8\spuninst.exe
+ 2011-10-13 15:15 . 2011-08-22 23:47 919552 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 105984 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\url.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 206848 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\occache.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 611840 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mstime.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 602112 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeeds.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 247808 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieproxy.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 184320 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iepeers.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 743424 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedvtool.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 387584 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedkcs32.dll
+ 2011-10-13 15:15 . 2011-08-22 11:52 174080 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ie4uinit.exe
+ 2012-01-18 02:45 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2585542\update\updspapi.dll
+ 2012-01-18 02:45 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2585542\update\update.exe
+ 2012-01-18 02:45 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2585542\spuninst.exe
+ 2011-11-16 14:20 . 2011-11-16 14:20 354816 c:\windows\$hf_mig$\KB2585542\SP3QFE\winhttp.dll
+ 2011-11-16 14:20 . 2011-11-16 14:20 152064 c:\windows\$hf_mig$\KB2585542\SP3QFE\schannel.dll
+ 2012-01-11 17:51 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2584146\update\updspapi.dll
+ 2012-01-11 17:51 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2584146\update\update.exe
+ 2012-01-11 17:51 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2584146\spuninst.exe
+ 2011-09-17 03:54 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2570947\update\updspapi.dll
+ 2011-09-17 03:54 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2570947\update\update.exe
+ 2011-09-17 03:54 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2570947\spuninst.exe
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2570222\update\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2570222\update\update.exe
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2570222\spuninst.exe
+ 2011-08-10 16:43 . 2011-06-24 14:09 139656 c:\windows\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2567680\update\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2567680\update\update.exe
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2567680\spuninst.exe
+ 2011-06-20 17:43 . 2011-06-20 17:43 293376 c:\windows\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
+ 2011-10-13 20:18 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2567053\update\updspapi.dll
+ 2011-10-13 20:18 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2567053\update\update.exe
+ 2011-10-13 20:18 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2567053\spuninst.exe
+ 2011-08-11 04:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2566454\update\updspapi.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2566454\update\update.exe
+ 2011-08-11 04:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2566454\spuninst.exe
+ 2011-08-11 04:29 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2562937\update\updspapi.dll
+ 2011-08-11 04:29 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2562937\update\update.exe
+ 2011-08-11 04:29 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2562937\spuninst.exe
+ 2011-08-11 04:30 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2559049-IE8\update\updspapi.dll
+ 2011-08-11 04:30 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2559049-IE8\update\update.exe
+ 2011-08-11 04:30 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2559049-IE8\spuninst.exe
+ 2011-08-10 16:43 . 2011-06-23 18:33 919552 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\wininet.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 105984 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\url.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 206848 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\occache.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 611840 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mstime.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 602112 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\msfeeds.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 247808 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ieproxy.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 184320 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iepeers.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 743424 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iedvtool.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 387584 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iedkcs32.dll
+ 2011-08-10 16:43 . 2011-06-23 12:19 173568 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ie4uinit.exe
+ 2011-07-13 15:13 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2555917\update\updspapi.dll
+ 2011-07-13 15:13 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2555917\update\update.exe
+ 2011-07-13 15:13 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2555917\spuninst.exe
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2544893\update\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2544893\update\update.exe
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2544893\spuninst.exe
+ 2011-06-16 12:39 . 2011-05-02 15:30 692736 c:\windows\$hf_mig$\KB2544893\SP3QFE\inetcomm.dll
+ 2011-11-10 02:55 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2544893-v2\update\updspapi.dll
+ 2011-11-10 02:55 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2544893-v2\update\update.exe
+ 2011-11-10 02:55 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2544893-v2\spuninst.exe
+ 2011-10-10 14:21 . 2011-10-10 14:21 692736 c:\windows\$hf_mig$\KB2544893-v2\SP3QFE\inetcomm.dll
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2544521\update\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2544521\update\update.exe
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2544521\spuninst.exe
+ 2011-06-16 12:39 . 2011-04-29 19:02 852480 c:\windows\$hf_mig$\KB2544521\SP3QFE\vgx.dll
+ 2011-07-05 06:33 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2544521-IE8\update\updspapi.dll
+ 2011-07-05 06:33 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2544521-IE8\update\update.exe
+ 2011-07-05 06:33 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2544521-IE8\spuninst.exe
+ 2011-07-04 17:58 . 2011-04-30 02:59 758784 c:\windows\$hf_mig$\KB2544521-IE8\SP3QFE\vgx.dll
+ 2011-06-29 19:56 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2541763\update\updspapi.dll
+ 2011-06-29 19:56 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2541763\update\update.exe
+ 2011-06-29 19:56 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2541763\spuninst.exe
+ 2011-04-29 17:23 . 2011-04-29 17:23 151552 c:\windows\$hf_mig$\KB2541763\SP3QFE\schannel.dll
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2536276\update\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2536276\update\update.exe
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2536276\spuninst.exe
+ 2011-06-16 12:39 . 2011-04-29 16:47 457856 c:\windows\$hf_mig$\KB2536276\SP3QFE\mrxsmb.sys
+ 2011-08-11 04:32 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2536276-v2\update\updspapi.dll
+ 2011-08-11 04:32 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2536276-v2\update\update.exe
+ 2011-08-11 04:32 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2536276-v2\spuninst.exe
+ 2011-08-10 16:43 . 2011-07-15 13:29 457856 c:\windows\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2535512\update\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2535512\update\update.exe
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2535512\spuninst.exe
+ 2011-06-16 12:39 . 2011-04-21 13:52 105472 c:\windows\$hf_mig$\KB2535512\SP3QFE\mup.sys
+ 2011-06-17 04:44 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2530548\update\updspapi.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2530548\update\update.exe
+ 2011-06-17 04:44 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2530548\spuninst.exe
+ 2011-04-25 14:46 . 2011-04-25 14:46 668672 c:\windows\$hf_mig$\KB2530548\SP3QFE\wininet.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 630784 c:\windows\$hf_mig$\KB2530548\SP3QFE\urlmon.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 532480 c:\windows\$hf_mig$\KB2530548\SP3QFE\mstime.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 449536 c:\windows\$hf_mig$\KB2530548\SP3QFE\mshtmled.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 251904 c:\windows\$hf_mig$\KB2530548\SP3QFE\iepeers.dll
+ 2011-07-03 14:32 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2530548-IE8\update\updspapi.dll
+ 2011-07-03 14:32 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2530548-IE8\update\update.exe
+ 2011-07-03 14:32 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2530548-IE8\spuninst.exe
+ 2011-07-03 14:32 . 2011-04-25 16:09 919552 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\wininet.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 206848 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\occache.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 611840 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\mstime.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 602112 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\msfeeds.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 247808 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\ieproxy.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 184320 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\iepeers.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 743424 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\iedvtool.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 387584 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\iedkcs32.dll
+ 2011-07-03 14:32 . 2011-04-25 11:37 173568 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\ie4uinit.exe
+ 2011-07-05 06:34 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2510531-IE8\update\updspapi.dll
+ 2011-07-05 06:34 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2510531-IE8\update\update.exe
+ 2011-07-05 06:34 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2510531-IE8\spuninst.exe
+ 2011-07-04 17:58 . 2011-03-04 06:35 420864 c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\vbscript.dll
+ 2011-07-04 17:58 . 2011-03-04 06:35 726528 c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\jscript.dll
+ 2011-07-13 15:15 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2507938\update\updspapi.dll
+ 2011-07-13 15:15 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2507938\update\update.exe
+ 2011-07-13 15:15 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2507938\spuninst.exe
+ 2011-04-26 11:02 . 2011-04-26 11:02 293376 c:\windows\$hf_mig$\KB2507938\SP3QFE\winsrv.dll
+ 2011-06-17 04:43 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2503665\update\updspapi.dll
+ 2011-06-17 04:43 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2503665\update\update.exe
+ 2011-06-17 04:43 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2503665\spuninst.exe
+ 2011-06-16 12:39 . 2011-02-16 13:25 138496 c:\windows\$hf_mig$\KB2503665\SP3QFE\afd.sys
+ 2011-06-17 04:44 . 2010-07-05 13:16 382840 c:\windows\$hf_mig$\KB2476490\update\updspapi.dll
+ 2011-06-17 04:44 . 2010-07-05 13:15 755576 c:\windows\$hf_mig$\KB2476490\update\update.exe
+ 2011-06-17 04:44 . 2010-07-05 13:15 231288 c:\windows\$hf_mig$\KB2476490\spuninst.exe
+ 2010-12-20 17:30 . 2010-12-20 17:30 552448 c:\windows\$hf_mig$\KB2476490\SP3QFE\oleaut32.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 382840 c:\windows\$hf_mig$\KB2447568-IE8\update\updspapi.dll
+ 2011-07-03 14:31 . 2010-02-22 14:23 755576 c:\windows\$hf_mig$\KB2447568-IE8\update\update.exe
+ 2011-07-03 14:31 . 2010-02-22 14:23 231288 c:\windows\$hf_mig$\KB2447568-IE8\spuninst.exe
+ 2012-05-12 16:31 . 2012-02-09 15:43 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-19 03:51 . 2011-04-19 03:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-14 01:04 . 2011-05-14 01:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-14 01:04 . 2011-05-14 01:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 2589184 c:\windows\system32\WpdShext.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 1392128 c:\windows\system32\WMVSDECD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 1532416 c:\windows\system32\WMVENCOD.dll
+ 2006-08-25 03:30 . 2006-08-25 03:30 1539584 c:\windows\system32\WMVDECOD.dll
+ 2008-04-14 09:43 . 2006-08-25 03:30 2450944 c:\windows\system32\wmvcore.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 1327616 c:\windows\system32\WMSPDMOE.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 1118208 c:\windows\system32\WMADMOE.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 09:42 . 2012-06-08 14:26 8462848 c:\windows\system32\shell32.dll
- 2008-04-14 09:42 . 2011-02-17 13:51 1510400 c:\windows\system32\shdocvw.dll
+ 2008-04-14 09:42 . 2011-04-25 14:47 1510400 c:\windows\system32\shdocvw.dll
+ 2008-04-14 09:42 . 2011-11-03 15:28 1292288 c:\windows\system32\quartz.dll
+ 2008-04-14 09:42 . 2011-11-01 16:07 1288704 c:\windows\system32\ole32.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 6007808 c:\windows\system32\mshtml.dll
+ 2012-07-12 15:02 . 2012-07-12 15:02 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll
+ 2009-03-08 08:32 . 2012-05-11 14:42 2000384 c:\windows\system32\iertutil.dll
+ 2009-02-07 01:07 . 2009-02-07 01:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2011-12-18 01:37 . 2011-06-23 18:26 1700352 c:\windows\system32\GdiPlus.dll
+ 2012-05-31 01:36 . 2012-02-15 15:01 4547944 c:\windows\system32\DRVSTORE\usbaapl_87F84F5DA3368BC69CA5BE7F6A79CAA709E36E13\usbaaplrc.dll
+ 2012-01-14 03:11 . 2010-04-20 01:29 1461992 c:\windows\system32\DRVSTORE\netaapl_63AA05C4700EB9CAF2D048DAC1D06D764A0D4C41\wdfcoinstaller01009.dll
+ 2010-12-03 00:09 . 2012-06-02 19:19 1933848 c:\windows\system32\dllcache\wuaueng.dll
+ 2008-04-14 09:43 . 2006-08-25 03:30 2450944 c:\windows\system32\dllcache\wmvcore.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 1327616 c:\windows\system32\dllcache\WMSPDMOE.dll
+ 2008-04-14 09:42 . 2006-08-25 03:30 1118208 c:\windows\system32\dllcache\WMADMOE.dll
+ 2008-04-14 05:00 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 09:42 . 2012-05-11 14:42 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 09:42 . 2012-06-08 14:26 8462848 c:\windows\system32\dllcache\shell32.dll
- 2008-04-14 09:42 . 2011-02-17 13:51 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-14 09:42 . 2011-04-25 14:47 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-14 09:42 . 2011-11-03 15:28 1292288 c:\windows\system32\dllcache\quartz.dll
+ 2008-04-14 09:42 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
+ 2010-12-03 17:47 . 2012-05-04 13:12 2192640 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2010-12-03 17:47 . 2012-05-04 12:32 2026496 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2010-12-03 17:47 . 2012-05-04 12:32 2069120 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2010-12-03 17:47 . 2012-05-04 13:16 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-04-14 09:42 . 2012-06-05 15:50 1372672 c:\windows\system32\dllcache\msxml6.dll
- 2008-04-14 09:42 . 2009-07-31 15:05 1372672 c:\windows\system32\dllcache\msxml6.dll
- 2008-04-14 09:42 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-04-14 09:42 . 2012-06-05 15:50 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-04-14 09:42 . 2012-05-11 14:42 6007808 c:\windows\system32\dllcache\mshtml.dll
+ 2011-07-03 14:30 . 2012-05-11 14:42 2000384 c:\windows\system32\dllcache\iertutil.dll
- 2008-04-14 09:41 . 2011-02-17 13:51 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2008-04-14 09:41 . 2011-04-25 14:47 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2008-04-14 09:41 . 2011-04-25 14:47 1025024 c:\windows\system32\browseui.dll
- 2008-04-14 09:41 . 2011-02-17 13:51 1025024 c:\windows\system32\browseui.dll
+ 1996-04-04 06:11 . 1996-04-04 06:11 2063872 c:\windows\QT32INST.EXE
+ 2012-01-13 21:32 . 2012-01-13 21:32 1769984 c:\windows\Installer\af68c7.msi
+ 2012-05-31 01:42 . 2012-05-31 01:42 4288000 c:\windows\Installer\648392.msi
+ 2012-05-31 01:37 . 2012-05-31 01:37 1718784 c:\windows\Installer\6477f5.msi
+ 2012-05-31 01:35 . 2012-05-31 01:35 9474048 c:\windows\Installer\6477a9.msi
+ 2012-05-31 01:33 . 2012-05-31 01:33 1530368 c:\windows\Installer\6474f8.msi
+ 2011-12-17 17:33 . 2011-12-17 17:33 2295808 c:\windows\Installer\4f52f.msi
+ 2012-01-14 03:10 . 2012-01-14 03:10 2002432 c:\windows\Installer\1dc33ec.msi
+ 2011-06-06 17:55 . 2011-06-06 17:55 2215312 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\rt3d.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 1189004 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\JSByteCodeWin.bin
+ 2011-06-06 17:55 . 2011-06-06 17:55 6543768 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\authplay.dll
+ 2011-06-06 17:55 . 2011-06-06 17:55 1240992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AdobeCollabSync.exe
+ 2011-06-06 17:55 . 2011-06-06 17:55 1480600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.exe
+ 2011-07-03 14:31 . 2009-03-08 08:34 1206784 c:\windows\ie8updates\KB982381-IE8\urlmon.dll
+ 2011-07-03 14:31 . 2009-03-08 08:41 5937152 c:\windows\ie8updates\KB982381-IE8\mshtml.dll
+ 2011-07-03 14:31 . 2009-03-08 08:32 1985024 c:\windows\ie8updates\KB982381-IE8\iertutil.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 1212416 c:\windows\ie8updates\KB2699988-IE8\urlmon.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 5978624 c:\windows\ie8updates\KB2699988-IE8\mshtml.dll
+ 2012-06-14 03:07 . 2012-03-01 11:01 2000384 c:\windows\ie8updates\KB2699988-IE8\iertutil.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 1212416 c:\windows\ie8updates\KB2675157-IE8\urlmon.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 5979136 c:\windows\ie8updates\KB2675157-IE8\mshtml.dll
+ 2012-04-12 03:46 . 2011-12-17 19:46 2000384 c:\windows\ie8updates\KB2675157-IE8\iertutil.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 1212416 c:\windows\ie8updates\KB2647516-IE8\urlmon.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 5978112 c:\windows\ie8updates\KB2647516-IE8\mshtml.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 2000384 c:\windows\ie8updates\KB2647516-IE8\iertutil.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-16 03:38 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-16 03:38 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 1212416 c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
+ 2011-10-13 20:17 . 2011-07-25 15:17 5969920 c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 1991680 c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 1211904 c:\windows\ie8updates\KB2559049-IE8\urlmon.dll
+ 2011-08-11 04:30 . 2011-05-30 22:19 5964800 c:\windows\ie8updates\KB2559049-IE8\mshtml.dll
+ 2011-08-11 04:30 . 2011-04-25 16:11 1991680 c:\windows\ie8updates\KB2559049-IE8\iertutil.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 1209344 c:\windows\ie8updates\KB2530548-IE8\urlmon.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 5950976 c:\windows\ie8updates\KB2530548-IE8\mshtml.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 1985536 c:\windows\ie8updates\KB2530548-IE8\iertutil.dll
+ 2011-07-03 14:27 . 2011-04-25 14:47 3079680 c:\windows\ie8\mshtml.dll
+ 2010-12-03 17:47 . 2012-05-04 13:12 2192640 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2010-12-03 17:47 . 2012-05-04 12:32 2026496 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2010-12-03 17:47 . 2012-05-04 12:32 2069120 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2010-12-03 17:47 . 2012-05-04 13:16 2148352 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-12-18 01:47 . 2008-04-14 09:42 1001472 c:\windows\$NtUninstallWMFDist11$\wmvdmoe2.dll
+ 2011-12-18 01:47 . 2010-04-08 19:03 2113536 c:\windows\$NtUninstallWMFDist11$\wmvcore.dll
+ 2011-12-18 01:47 . 2008-04-14 09:42 1119744 c:\windows\$NtUninstallWMFDist11$\wmsdmoe2.dll
+ 2011-12-18 01:47 . 2008-06-10 11:11 1053696 c:\windows\$NtUninstallWMFDist11$\wmnetmgr.dll
+ 2012-06-14 03:07 . 2012-04-11 13:12 1862272 c:\windows\$NtUninstallKB2709162$\win32k.sys
+ 2012-06-14 03:09 . 2012-04-11 13:14 2148352 c:\windows\$NtUninstallKB2707511$\ntoskrnl.exe
+ 2012-06-14 03:09 . 2012-04-11 12:35 2026496 c:\windows\$NtUninstallKB2707511$\ntkrpamp.exe
+ 2012-06-14 03:09 . 2012-04-11 12:35 2026496 c:\windows\$NtUninstallKB2707511$\ntkrnlpa.exe
+ 2012-06-14 03:09 . 2012-04-11 13:14 2148352 c:\windows\$NtUninstallKB2707511$\ntkrnlmp.exe
+ 2012-05-12 17:18 . 2012-02-03 09:22 1860096 c:\windows\$NtUninstallKB2676562$\win32k.sys
+ 2012-05-12 17:18 . 2011-10-25 13:37 2148864 c:\windows\$NtUninstallKB2676562$\ntoskrnl.exe
+ 2012-05-12 17:18 . 2011-10-25 12:52 2027008 c:\windows\$NtUninstallKB2676562$\ntkrpamp.exe
+ 2012-05-12 17:18 . 2011-10-25 12:52 2027008 c:\windows\$NtUninstallKB2676562$\ntkrnlpa.exe
+ 2012-05-12 17:18 . 2011-10-25 13:37 2148864 c:\windows\$NtUninstallKB2676562$\ntkrnlmp.exe
+ 2012-02-17 07:29 . 2011-11-23 13:25 1859584 c:\windows\$NtUninstallKB2660465$\win32k.sys
+ 2012-03-15 01:45 . 2012-01-12 16:53 1859968 c:\windows\$NtUninstallKB2641653$\win32k.sys
+ 2011-12-16 03:39 . 2011-09-06 13:20 1858944 c:\windows\$NtUninstallKB2639417$\win32k.sys
+ 2011-12-16 03:35 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe
+ 2011-12-16 03:35 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrpamp.exe
+ 2011-12-16 03:35 . 2010-12-09 13:07 2027008 c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe
+ 2011-12-16 03:35 . 2010-12-09 13:42 2148864 c:\windows\$NtUninstallKB2633171$\ntkrnlmp.exe
+ 2012-01-11 17:53 . 2010-02-05 18:27 1291776 c:\windows\$NtUninstallKB2631813$\quartz.dll
+ 2011-12-16 03:38 . 2010-07-16 12:05 1288192 c:\windows\$NtUninstallKB2624667$\ole32.dll
+ 2011-10-13 20:18 . 2011-06-02 14:02 1858944 c:\windows\$NtUninstallKB2567053$\win32k.sys
+ 2011-07-13 15:13 . 2011-03-03 13:21 1857920 c:\windows\$NtUninstallKB2555917$\win32k.sys
+ 2011-06-17 04:44 . 2011-02-17 13:51 1510400 c:\windows\$NtUninstallKB2530548$\shdocvw.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 3078656 c:\windows\$NtUninstallKB2530548$\mshtml.dll
+ 2011-06-17 04:44 . 2011-02-17 13:51 1025024 c:\windows\$NtUninstallKB2530548$\browseui.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 1209856 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\urlmon.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 5953024 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
+ 2011-07-03 14:30 . 2010-05-06 10:36 1986048 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iertutil.dll
+ 2012-05-15 13:27 . 2012-05-15 13:27 1872128 c:\windows\$hf_mig$\KB2709162\SP3QFE\win32k.sys
+ 2012-05-04 13:20 . 2012-05-04 13:20 2192640 c:\windows\$hf_mig$\KB2707511\SP3QFE\ntoskrnl.exe
+ 2012-05-04 12:41 . 2012-05-04 12:41 2026496 c:\windows\$hf_mig$\KB2707511\SP3QFE\ntkrpamp.exe
+ 2012-05-04 12:41 . 2012-05-04 12:41 2069120 c:\windows\$hf_mig$\KB2707511\SP3QFE\ntkrnlpa.exe
+ 2012-05-04 13:24 . 2012-05-04 13:24 2148352 c:\windows\$hf_mig$\KB2707511\SP3QFE\ntkrnlmp.exe
+ 2012-06-14 00:33 . 2012-05-11 14:41 1214464 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\urlmon.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 6009344 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\mshtml.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 2001408 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\iertutil.dll
+ 2012-04-11 13:23 . 2012-04-11 13:23 1871360 c:\windows\$hf_mig$\KB2676562\SP3QFE\win32k.sys
+ 2012-04-11 13:22 . 2012-04-11 13:22 2192640 c:\windows\$hf_mig$\KB2676562\SP3QFE\ntoskrnl.exe
+ 2012-04-11 12:42 . 2012-04-11 12:42 2026496 c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrpamp.exe
+ 2012-04-11 12:42 . 2012-04-11 12:42 2069120 c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe
+ 2012-04-11 13:26 . 2012-04-11 13:26 2148352 c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlmp.exe
+ 2012-04-11 22:33 . 2012-03-01 10:58 1214464 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\urlmon.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 5980672 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\mshtml.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 2001408 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\iertutil.dll
+ 2012-01-12 16:54 . 2012-01-12 16:54 1869056 c:\windows\$hf_mig$\KB2660465\SP3QFE\win32k.sys
+ 2012-02-16 17:33 . 2011-12-17 19:45 1214464 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\urlmon.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 5980160 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 2001408 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\iertutil.dll
+ 2012-03-14 22:44 . 2012-02-03 09:26 1869184 c:\windows\$hf_mig$\KB2641653\SP3QFE\win32k.sys
+ 2011-11-23 13:29 . 2011-11-23 13:29 1868544 c:\windows\$hf_mig$\KB2639417\SP3QFE\win32k.sys
+ 2011-10-25 13:34 . 2011-10-25 13:34 2192768 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe
+ 2011-10-25 12:52 . 2011-10-25 12:52 2027008 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrpamp.exe
+ 2011-10-25 12:52 . 2011-10-25 12:52 2069376 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe
+ 2011-10-25 13:38 . 2011-10-25 13:38 2148864 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlmp.exe
+ 2011-11-03 15:27 . 2011-11-03 15:27 1292288 c:\windows\$hf_mig$\KB2631813\SP3QFE\quartz.dll
+ 2011-11-01 16:05 . 2011-11-01 16:05 1289216 c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 1214464 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\urlmon.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 5978624 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll
+ 2011-12-15 23:05 . 2011-11-04 19:19 2001408 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\iertutil.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 1214464 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\urlmon.dll
+ 2011-10-13 15:15 . 2011-10-03 08:34 5972992 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 2001408 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iertutil.dll
+ 2011-09-06 13:25 . 2011-09-06 13:25 1867904 c:\windows\$hf_mig$\KB2567053\SP3QFE\win32k.sys
+ 2011-08-10 16:43 . 2011-06-23 18:33 1214464 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\urlmon.dll
+ 2011-08-10 16:43 . 2011-07-25 15:15 5971456 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\mshtml.dll
+ 2011-08-10 16:43 . 2011-06-23 18:33 1992192 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\iertutil.dll
+ 2011-06-02 14:07 . 2011-06-02 14:07 1867904 c:\windows\$hf_mig$\KB2555917\SP3QFE\win32k.sys
+ 2011-04-25 14:46 . 2011-04-25 14:46 1510400 c:\windows\$hf_mig$\KB2530548\SP3QFE\shdocvw.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 3080192 c:\windows\$hf_mig$\KB2530548\SP3QFE\mshtml.dll
+ 2011-04-25 14:46 . 2011-04-25 14:46 1025024 c:\windows\$hf_mig$\KB2530548\SP3QFE\browseui.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 1213952 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\urlmon.dll
+ 2011-07-03 14:32 . 2011-05-30 22:17 5967360 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\mshtml.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 1992192 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\iertutil.dll
+ 2011-07-03 14:24 . 2012-07-11 20:10 57442464 c:\windows\system32\MRT.exe
+ 2009-03-08 08:39 . 2012-05-12 00:12 11111424 c:\windows\system32\ieframe.dll
+ 2011-07-03 14:30 . 2012-05-12 00:12 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2011-09-05 22:01 . 2011-09-05 22:01 13135872 c:\windows\Installer\4f5bd.msp
+ 2012-04-04 13:32 . 2012-04-04 13:32 16613376 c:\windows\Installer\3bc6e.msp
+ 2012-01-03 17:58 . 2012-01-03 17:58 15929344 c:\windows\Installer\2d068.msp
+ 2011-06-06 17:55 . 2011-06-06 17:55 24731544 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll
+ 2011-07-03 14:31 . 2009-03-08 08:39 11063808 c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2012-06-14 03:07 . 2012-03-02 10:01 11082752 c:\windows\ie8updates\KB2699988-IE8\ieframe.dll
+ 2012-04-12 03:46 . 2011-12-18 19:46 11082240 c:\windows\ie8updates\KB2675157-IE8\ieframe.dll
+ 2012-02-17 07:28 . 2011-11-04 19:20 11081728 c:\windows\ie8updates\KB2647516-IE8\ieframe.dll
+ 2011-12-16 03:38 . 2011-08-23 21:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
+ 2011-10-13 20:17 . 2011-06-23 18:36 11081728 c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
+ 2011-08-11 04:30 . 2011-04-26 14:11 11081728 c:\windows\ie8updates\KB2559049-IE8\ieframe.dll
+ 2011-07-03 14:32 . 2010-05-06 10:41 11076096 c:\windows\ie8updates\KB2530548-IE8\ieframe.dll
+ 2011-07-03 14:30 . 2010-05-06 20:06 11078144 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ieframe.dll
+ 2012-06-14 00:33 . 2012-05-11 14:41 11112960 c:\windows\$hf_mig$\KB2699988-IE8\SP3QFE\ieframe.dll
+ 2012-04-11 22:33 . 2012-03-01 10:58 11085312 c:\windows\$hf_mig$\KB2675157-IE8\SP3QFE\ieframe.dll
+ 2012-02-16 17:33 . 2011-12-17 19:45 11085312 c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\ieframe.dll
+ 2011-11-05 19:19 . 2011-11-05 19:19 11083776 c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\ieframe.dll
+ 2011-10-13 15:15 . 2011-08-22 23:47 11084288 c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieframe.dll
+ 2011-06-25 05:03 . 2011-06-25 05:03 11083776 c:\windows\$hf_mig$\KB2559049-IE8\SP3QFE\ieframe.dll
+ 2011-07-03 14:32 . 2011-04-25 16:09 11083776 c:\windows\$hf_mig$\KB2530548-IE8\SP3QFE\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-08-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/6/2011 9:42 PM 28552]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/30/2012 10:49 AM 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/26/2012 10:24 AM 113120]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-30 13:02]
.
2012-07-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
.
------- Supplementary Scan -------
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login_verify2?.intl=us&.src=ym
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-StartNowToolbarHelper - c:\program files\StartNow Toolbar\ToolbarHelper.exe
HKLM-Run-Malwarebytes' Anti-Malware - c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
HKLM-Run-PCTools FGuard - c:\program files\Spyware Doctor\BDT\FGuard.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-16 16:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-16 16:02:00
ComboFix-quarantined-files.txt 2012-07-16 20:01
ComboFix2.txt 2011-06-11 18:55
ComboFix3.txt 2011-06-10 18:33
ComboFix4.txt 2011-06-09 01:53
ComboFix5.txt 2012-07-16 19:53
.
Pre-Run: 50,651,914,240 bytes free
Post-Run: 50,760,294,400 bytes free
.
- - End Of File - - A2B2209364326C4CEDB0ABCAFEDD71EB

#6 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 16 July 2012 - 05:22 PM

Please do this next:

Posted Image Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information or C:\Qoobox
  • Be sure that everything else is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post the results.
Please include the following in your next post:
  • MBAM log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#7 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 20 July 2012 - 01:31 AM

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.20.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
dx :: DX-1F71A2F5EA54 [administrator]

7/20/2012 12:51:30 AM
mbam-log-2012-07-20 (00-51-30).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 214108
Time elapsed: 28 minute(s), 19 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 26
C:\Qoobox\Quarantine\C\WINDOWS\assembly\GAC\Desktop.ini.vir (Trojan.0access) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000004.@.vir (Rootkit.0Access) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\00000008.@.vir (Trojan.Dropper.BCMiner) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\000000cb.@.vir (Rootkit.0Access) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000000.@.vir (Trojan.Sirefef) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP422\A0208462.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP422\A0208466.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208503.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208514.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208525.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208535.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208541.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208546.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208552.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208557.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208563.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208568.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208572.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208575.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208580.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208585.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP425\A0208596.ini (Trojan.0access) -> No action taken.
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP425\A0208603.ini (Trojan.0access) -> No action taken.
C:\Documents and Settings\dx\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) -> Quarantined and deleted successfully.
C:\Documents and Settings\dx\My Documents\Downloads\oi_setup.exe (PUP.BundleInstaller.OI) -> Quarantined and deleted successfully.
C:\_OTL\MovedFiles\07162012_151840\C_Documents and Settings\dx\Local Settings\Application Data\tdcsflbttq.exe (Trojan.Lameshield) -> Quarantined and deleted successfully.

(end)

#8 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 20 July 2012 - 10:04 PM

How is your computer running now? Please do this next:

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please go to www.java.com and press the "Free Java Download" button near the center of the page. Follow the prompts to install the latest version.

Posted Image Go to thisLINK to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • If you are using Internet Explorer, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic.
Please include the following in your next post:
  • How is your computer running now?
  • ESET log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#9 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 21 July 2012 - 12:03 AM

Hi. I updated the Java. My computer seems back to normal, except that Adobe Flash seems to be crashing more often than normal. I don't know if that's related to the problem or not, but I thought I'd mention it.

Here's the log:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=b09ac89f076f0a4d8b0c19a87b928984
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-07-21 04:58:54
# local_time=2012-07-21 12:58:54 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=53952
# found=27
# cleaned=0
# scan_time=2822
C:\Documents and Settings\dx\My Documents\Downloads\cnet2_burn4free_setup_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\dx\My Documents\Downloads\winzip155.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Documents and Settings\dx\Local Settings\Application Data\{b966c09e-e406-c269-b021-a0e50409bead}\n.vir Win32/Sirefef.EV trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Program Files\Mighty Magoo\miGHtymagoolib32.dll.vir a variant of Win32/Adware.Gamevance.BF application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Program Files\Mighty Magoo\mmAGootl.dll.vir a variant of Win32/Adware.Gamevance.BF application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\assembly\GAC\Desktop.ini.vir Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\n.vir Win32/Sirefef.EV trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000000.@.vir a variant of Win32/Sirefef.FA trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\Installer\{b966c09e-e406-c269-b021-a0e50409bead}\U\80000032.@.vir a variant of Win32/Sirefef.FD trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP422\A0208462.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP422\A0208466.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208503.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208514.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208525.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208535.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208541.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP423\A0208546.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208552.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208557.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208563.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208568.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208572.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208575.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208580.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP424\A0208585.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP425\A0208596.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP425\A0208603.ini Win32/Sirefef.EZ trojan (unable to clean) 00000000000000000000000000000000 I

#10 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 21 July 2012 - 10:26 PM

Your logs look good! Most of those ESET detections are already in quarantine and will be removed when we uninstall ComboFix. Two of your freeware apps - WinZip and Burn4Free were flagged because they are considered adware, install toolbars or have other unclear objectives. If you no longer want those apps, uninstall them via Control Panel > Programs > Uninstall a program.

Now I have some very important cleanup that you need to take care of:

Posted Image Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
Posted Image

Posted Image Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
Posted Image Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application and MBAM current and updated. Scan with them at least weekly.
  • Please read this post for some helpful information.
Please post once more so I know you are all set and I can mark this thread resolved. Good luck and stay safe!

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#11 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 21 July 2012 - 11:03 PM

Hi. You said to uninstall WinZip and Burn4Free via Control Panel > Programs > Uninstall a program. I'm not seeing anything listed as "Programs" in the Control Panel. Is it the same thing as "Add or Remove programs"? That offers the option to *remove* (not uninstall) programs. Is that the same thing?

Sorry for being dense. :-/

#12 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 22 July 2012 - 11:20 AM

Sorry, I gave you the instructions for Windows Vista or Windows 7. Add or Remove Programs is what you need.

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#13 Hippie Mama

Hippie Mama
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:42 PM

Posted 22 July 2012 - 03:21 PM

Okay, I think I did it. :thumbsup: Is that it--are we done?

And thank you soooooooo much!!!!!!

Edited by Hippie Mama, 22 July 2012 - 03:37 PM.


#14 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 23 July 2012 - 08:47 AM

Yes, we are done! You're very welcome. Take care!

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#15 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 24 July 2012 - 05:07 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users