Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google redirect virus


  • This topic is locked This topic is locked
42 replies to this topic

#1 cambrus

cambrus

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 21 July 2012 - 07:53 AM

Hi,
I've got the redirect virus, I scanned my computer with McAfee, stinger and malware bytes and they all came up blank.

Can someone help me?

Thanks,

C

BC AdBot (Login to Remove)

 


#2 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,911 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:08:42 PM

Posted 21 July 2012 - 09:03 AM

Hello,

Please follow the instructions in ==>This Guide<== starting at step 6. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then post them in a reply to this topic by using the Add Reply button.

If you can produce at least some of the logs, then please create the post and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the reply and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

Please note that I am not a member of the Malware Removal Team and will not be assisting you in removing the infection. I'm simply helping you to post the information they need in order to assist you.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#3 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 21 July 2012 - 05:39 PM

I wasn't able to download DDS but I had an old version from Jan 2012 that I was able to run. I didn't run GMER as I am running a 64 bit version.


.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_31
Run by Christine at 8:28:44 on 2012-07-22
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.6133.4180 [GMT 10:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120318225133.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO: Toolbar - Big Fish Games: {c7c9fc25-88b0-4682-9c9f-2608e9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Toolbar - Big Fish Games: {c7c9fc25-88b0-4682-9c9f-2608e9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [Google Update] "C:\Users\Christine\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [FAStartup]
mRun: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
StartupFolder: C:\Users\CHRIST~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aolsvc.aol.com/onlinegames/popzuma/popcaploader_v10.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://inforapac.webex.com/client/T27L10NSP11EP5/webex/ieatgpc1.cab
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73} : DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73}\16879657D67627F657070313 : DhcpNameServer = 192.168.203.13 192.168.203.10 192.168.203.12
TCP: Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73}\2454C4C4431383 : DhcpNameServer = 192.168.20.1
TCP: Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73}\3416D626275737 : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73}\D6F647F627F6C61602246463 : DhcpNameServer = 192.168.10.1
TCP: Interfaces\{6098B8C2-999C-4D69-8EAC-88677C5B47D5} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7DF920AE-430B-4452-BE8A-8BC1F448D665} : DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{83EB4D42-2F62-45D7-B7E0-4A6FFF72017D} : DhcpNameServer = 10.4.81.103 10.4.182.20
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120318225133.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FAIESSOHelper Class: {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO-X64: FAIESSO Helper Object - No File
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO-X64: Toolbar - Big Fish Games: {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll
BHO-X64: Toolbar - Big Fish Games - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Toolbar - Big Fish Games: {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [FAStartup]
mRun-x64: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Download Manager\npfpdlm.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Christine\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 acedrv11;acedrv11;\??\C:\Windows\system32\drivers\acedrv11.sys --> C:\Windows\system32\drivers\acedrv11.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2010-8-4 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-10 155648]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-2-23 2409800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 249936]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2010-9-3 199272]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2010-9-3 208536]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe [2010-9-3 161168]
R2 rimspci;rimspci;C:\Windows\system32\DRIVERS\rimspe64.sys --> C:\Windows\system32\DRIVERS\rimspe64.sys [?]
R2 risdpcie;risdpcie;C:\Windows\system32\DRIVERS\risdpe64.sys --> C:\Windows\system32\DRIVERS\risdpe64.sys [?]
R2 rixdpcie;rixdpcie;C:\Windows\system32\DRIVERS\rixdpe64.sys --> C:\Windows\system32\DRIVERS\rixdpe64.sys [?]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-9-3 705856]
R2 SwiCardDetectSvc;Sierra Wireless Card Detection Service;C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [2010-7-6 282992]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys --> C:\Windows\system32\DRIVERS\itecir.sys [?]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-2-11 13336]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\system32\drivers\btusbflt.sys --> C:\Windows\system32\drivers\btusbflt.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys --> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;C:\Windows\system32\DRIVERS\ewusbdev.sys --> C:\Windows\system32\DRIVERS\ewusbdev.sys [?]
S3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;C:\Windows\System32\drivers\libusb0.sys [2010-6-25 21504]
S3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\system32\drivers\massfilter.sys --> C:\Windows\system32\drivers\massfilter.sys [?]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2012-3-2 24176]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe [2009-6-27 1124848]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-3 126352]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 ZTEusbnet;ZTE USB-NDIS miniport;C:\Windows\system32\DRIVERS\ZTEusbnet.sys --> C:\Windows\system32\DRIVERS\ZTEusbnet.sys [?]
S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-12-2 249936]
.
=============== Created Last 30 ================
.
2012-07-21 07:30:24 -------- d-----w- C:\Windows\tmp
2012-07-20 23:50:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-20 23:29:11 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-20 23:29:11 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-20 23:29:10 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-20 23:29:08 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-20 23:29:06 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-20 23:29:06 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2012-07-20 23:28:04 525312 ----a-w- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
2012-07-20 23:28:03 505344 ----a-w- C:\Program Files\Internet Explorer\jsdbgui.dll
2012-07-20 23:25:53 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-07-20 23:22:45 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-07-20 23:22:35 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-07-20 23:22:31 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-07-20 23:22:30 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-07-20 23:22:20 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-07-20 23:22:20 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-07-20 23:22:20 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-07-20 23:22:19 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-07-20 23:22:18 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-07-20 23:22:17 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-07-20 23:22:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-07-20 23:22:14 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-07-20 23:22:10 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-07-20 23:21:51 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-07-20 23:21:48 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-07-20 23:21:48 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-07-20 23:21:48 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-07-20 23:21:44 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-07-20 23:21:41 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-07-20 23:20:18 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-07-20 23:20:15 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2012-07-20 23:19:45 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-07-20 23:19:45 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-07-20 23:19:44 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-07-20 23:19:21 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-07-20 23:06:59 16200 ----a-w- C:\Windows\stinger.sys
2012-07-20 23:05:59 -------- d-----w- C:\Program Files (x86)\stinger
2012-07-09 08:44:00 -------- d-----w- C:\Program Files (x86)\Telltale Games
.
==================== Find3M ====================
.
2012-07-09 08:43:49 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2012-07-03 03:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 05:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 05:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-05-15 04:01:31 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-05-15 03:03:54 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
.
============= FINISH: 8:29:35.93 ===============

Attached Files



#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 23 July 2012 - 12:41 AM

Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your computer problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of hartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

Security Check

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 23 July 2012 - 05:02 AM

I turned off my McAfee Firewall and Real Time Scanning but ComboFix still said it was on. I ran it anyway.

Security Check

Results of screen317's Security Check version 0.99.43
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 8 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
McAfee Anti-Virus and Anti-Spyware
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.62.0.1300
Java™ 6 Update 31
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader X 10.0.1 Adobe Reader out of Date!
Mozilla Firefox 11.0 Firefox out of Date!
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````


ComboFix

ComboFix 12-07-21.01 - Christine 23/07/2012 19:10:39.3.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.6133.4632 [GMT 10:00]
Running from: c:\users\Christine\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-23 09:42 . 2012-07-23 09:42 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-07-23 09:42 . 2012-07-23 09:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-21 07:30 . 2012-07-21 07:35 -------- d-----w- c:\windows\tmp
2012-07-20 23:50 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-20 23:29 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-07-20 23:29 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-07-20 23:29 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-07-20 23:29 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-07-20 23:29 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-07-20 23:29 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2012-07-20 23:29 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-07-20 23:28 . 2012-04-20 05:42 12297216 ----a-w- c:\windows\system32\ieframe.dll
2012-07-20 23:28 . 2012-04-20 05:42 9059840 ----a-w- c:\windows\system32\mshtml.dll
2012-07-20 23:28 . 2012-04-20 05:42 735744 ----a-w- c:\windows\system32\msfeeds.dll
2012-07-20 23:28 . 2012-04-20 04:57 525312 ----a-w- c:\program files (x86)\Internet Explorer\jsdbgui.dll
2012-07-20 23:28 . 2012-04-20 05:42 505344 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
2012-07-20 23:25 . 2012-04-20 03:45 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-20 23:22 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-20 23:22 . 2012-05-04 11:06 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-07-20 23:22 . 2012-05-04 10:03 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-07-20 23:22 . 2012-05-04 10:03 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-07-20 23:22 . 2012-06-02 05:50 458704 ----a-w- c:\windows\system32\drivers\cng.sys
2012-07-20 23:22 . 2012-06-02 05:45 340992 ----a-w- c:\windows\system32\schannel.dll
2012-07-20 23:22 . 2012-06-02 05:44 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-20 23:22 . 2012-06-02 05:48 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-07-20 23:22 . 2012-06-02 04:39 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-07-20 23:22 . 2012-06-02 04:40 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2012-07-20 23:22 . 2012-06-02 05:48 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-20 23:22 . 2012-06-02 04:40 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-07-20 23:22 . 2012-06-02 04:34 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-07-20 23:21 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-07-20 23:21 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-20 23:21 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-20 23:21 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-07-20 23:21 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-07-20 23:21 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-07-20 23:20 . 2012-04-07 12:31 3216384 ----a-w- c:\windows\system32\msi.dll
2012-07-20 23:20 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2012-07-20 23:20 . 2012-04-17 05:31 918016 ----a-w- c:\windows\system32\jscript.dll
2012-07-20 23:19 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-07-20 23:19 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-07-20 23:19 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-07-20 23:19 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-07-20 23:06 . 2012-07-21 06:19 16200 ----a-w- c:\windows\stinger.sys
2012-07-20 23:05 . 2012-07-21 06:35 -------- d-----w- c:\program files (x86)\stinger
2012-07-09 08:44 . 2012-07-10 01:27 -------- d-----w- c:\program files (x86)\Telltale Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-09 08:43 . 2012-02-10 09:55 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-07-03 03:46 . 2010-09-18 19:40 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-02 17:19 . 2010-09-21 15:12 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-06-02 22:19 . 2012-06-19 14:49 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:49 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 14:49 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:49 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:49 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 14:49 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 14:49 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 05:19 . 2012-06-19 14:49 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 05:15 . 2012-06-19 14:49 36864 ----a-w- c:\windows\system32\wuapp.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-10_22.01.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-30 20:47 . 2011-11-19 14:01 67072 c:\windows\SysWOW64\packager.dll
+ 2011-12-05 12:03 . 2011-12-05 12:03 54784 c:\windows\SysWOW64\OVDecode.dll
+ 2011-12-05 12:04 . 2011-12-05 12:04 59904 c:\windows\SysWOW64\OpenVideo.dll
+ 2011-12-05 12:02 . 2011-12-05 12:02 44032 c:\windows\SysWOW64\OpenCL.dll
+ 2012-07-20 23:27 . 2012-04-20 04:57 67584 c:\windows\SysWOW64\mshtmled.dll
+ 2012-07-20 23:27 . 2012-05-15 03:03 68608 c:\windows\SysWOW64\migration\WininetPlugin.dll
- 2011-12-04 00:10 . 2011-08-20 04:31 68608 c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2012-01-11 18:29 . 2012-01-14 01:40 84661 c:\windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe
- 2011-12-04 00:10 . 2011-08-20 04:27 48128 c:\windows\SysWOW64\jsproxy.dll
+ 2012-07-20 23:27 . 2012-05-15 03:00 48128 c:\windows\SysWOW64\jsproxy.dll
+ 2012-02-11 00:16 . 2009-07-08 06:34 53248 c:\windows\SysWOW64\CSVer.dll
- 2009-07-14 04:54 . 2012-01-10 21:48 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-07-22 08:39 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-01-10 21:48 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-22 08:39 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-22 08:39 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-10 21:48 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-06 02:11 . 2011-12-06 02:11 33280 c:\windows\SysWOW64\atiuxpag.dll
+ 2010-08-04 12:46 . 2011-12-06 02:11 29696 c:\windows\SysWOW64\atiu9pag.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 53760 c:\windows\SysWOW64\atimpc32.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 14336 c:\windows\SysWOW64\atiglpxx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 33280 c:\windows\SysWOW64\atigktxx.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 46080 c:\windows\SysWOW64\aticalrt.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 44032 c:\windows\SysWOW64\aticalcl.dll
+ 2011-12-06 03:09 . 2011-12-06 03:09 43520 c:\windows\SysWOW64\ati2edxx.dll
- 2010-08-04 12:46 . 2010-01-22 00:58 43520 c:\windows\SysWOW64\ati2edxx.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 53760 c:\windows\SysWOW64\amdpcom32.dll
+ 2010-09-03 04:25 . 2012-07-15 05:35 54116 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-22 08:38 34076 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-22 11:59 . 2012-07-22 08:38 13238 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2013641587-3539477181-1548398233-1001_UserData.bin
+ 2011-01-07 05:02 . 2011-01-07 05:02 57168 c:\windows\system32\vcomp100.dll
+ 2012-02-11 23:12 . 2011-11-17 06:35 29184 c:\windows\system32\sspisrv.dll
- 2011-06-13 04:08 . 2010-11-20 13:27 29184 c:\windows\system32\sspisrv.dll
+ 2012-02-11 23:12 . 2011-11-17 06:35 28160 c:\windows\system32\secur32.dll
- 2011-06-13 04:08 . 2010-11-20 13:27 28160 c:\windows\system32\secur32.dll
+ 2012-01-30 20:47 . 2011-11-19 14:58 77312 c:\windows\system32\packager.dll
+ 2011-12-05 12:03 . 2011-12-05 12:03 61952 c:\windows\system32\OVDecode64.dll
+ 2011-12-05 12:04 . 2011-12-05 12:04 69632 c:\windows\system32\OpenVideo64.dll
+ 2011-12-05 12:02 . 2011-12-05 12:02 51200 c:\windows\system32\OpenCL.dll
+ 2012-07-20 23:27 . 2012-04-20 05:42 97792 c:\windows\system32\mshtmled.dll
+ 2012-07-20 23:27 . 2012-05-15 04:01 95232 c:\windows\system32\migration\WininetPlugin.dll
- 2011-12-04 00:10 . 2011-08-20 05:37 95232 c:\windows\system32\migration\WininetPlugin.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 91472 c:\windows\system32\mfcm100u.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 91472 c:\windows\system32\mfcm100.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 62288 c:\windows\system32\mfc100ita.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 36176 c:\windows\system32\mfc100chs.dll
- 2009-07-13 23:20 . 2009-07-14 01:39 31232 c:\windows\system32\lsass.exe
+ 2012-02-11 23:12 . 2011-11-17 06:33 31232 c:\windows\system32\lsass.exe
+ 2011-09-02 06:30 . 2011-09-02 06:30 55064 c:\windows\system32\LMouFiltCoInst.dll
- 2011-12-04 00:09 . 2011-08-20 05:33 64512 c:\windows\system32\jsproxy.dll
+ 2012-07-20 23:27 . 2012-05-15 03:59 64512 c:\windows\system32\jsproxy.dll
+ 2012-04-21 14:22 . 2012-03-01 06:33 81408 c:\windows\system32\imagehlp.dll
+ 2009-07-14 05:30 . 2012-03-25 08:53 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2011-12-17 01:49 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-02-15 01:01 . 2012-02-15 01:01 52736 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_c111aaecb61e9a2b\usbaapl64.sys
+ 2012-02-11 00:15 . 2009-06-25 06:38 57856 c:\windows\system32\DriverStore\FileRepository\rixdptsk.inf_amd64_neutral_a070830f98d2817a\rixdpx64.sys
+ 2012-02-11 00:15 . 2004-09-03 17:00 90112 c:\windows\system32\DriverStore\FileRepository\rimsptsk.inf_amd64_neutral_498cd0d9067e967a\snymsico.dll
+ 2012-02-11 00:15 . 2009-06-25 06:13 55296 c:\windows\system32\DriverStore\FileRepository\rimsptsk.inf_amd64_neutral_498cd0d9067e967a\rimspx64.sys
+ 2012-02-11 00:15 . 2009-06-25 07:04 67584 c:\windows\system32\DriverStore\FileRepository\rimmptsk.inf_amd64_neutral_4c2b9c9fc1312297\rimmpx64.sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 55064 c:\windows\system32\DriverStore\FileRepository\lfmouhid.inf_amd64_neutral_12000fce12220350\LMouFiltCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 60696 c:\windows\system32\DriverStore\FileRepository\lfmouhid.inf_amd64_neutral_12000fce12220350\LMouFilt.Sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 66840 c:\windows\system32\DriverStore\FileRepository\lfmouhid.inf_amd64_neutral_12000fce12220350\LHidFilt.Sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 66840 c:\windows\system32\DriverStore\FileRepository\lfkbdhid.inf_amd64_neutral_99503c6390c9346a\LHidFilt.Sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 42776 c:\windows\system32\DriverStore\FileRepository\lfhidusb.inf_amd64_neutral_6d6ec350722ee849\LUsbFilt.sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 66840 c:\windows\system32\DriverStore\FileRepository\lfhidhid.inf_amd64_neutral_67db93f52e33f460\LHidFilt.Sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 15128 c:\windows\system32\DriverStore\FileRepository\lfhideqd.inf_amd64_neutral_f82f5301e4a99eb5\LHidEqd.sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 76056 c:\windows\system32\DriverStore\FileRepository\lfeqdusb.inf_amd64_neutral_c33b2f7768fc3d46\LEqdUsb.sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 52504 c:\windows\system32\DriverStore\FileRepository\lbtcoins.inf_amd64_neutral_cbd347b8acf5ddfe\LBTCoIns.DLL
+ 2009-09-08 21:50 . 2009-09-08 21:50 37552 c:\windows\system32\DriverStore\FileRepository\frmupgr.inf_amd64_neutral_b5d2e43c95cabb3d\frmupgr.sys
+ 2011-12-06 02:18 . 2011-12-06 02:18 58880 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\coinst.dll
+ 2011-12-06 02:11 . 2011-12-06 02:11 33280 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiuxpag.dll
+ 2011-12-06 02:11 . 2011-12-06 02:11 42496 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiuxp64.dll
+ 2011-12-06 02:11 . 2011-12-06 02:11 29696 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiu9pag.dll
+ 2011-12-06 02:11 . 2011-12-06 02:11 39936 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiu9p64.dll
+ 2009-06-22 16:34 . 2009-06-22 16:34 51200 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ATIODCLI.exe
+ 2011-12-06 03:09 . 2011-12-06 03:09 21504 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atimuixx.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 54784 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atimpc64.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 53760 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atimpc32.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 14336 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiglpxx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 33280 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atigktxx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 39936 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atig6txx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 17408 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atig6pxx.dll
+ 2011-12-06 03:09 . 2011-12-06 03:09 59392 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiedu64.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 51200 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticalrt64.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 46080 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticalrt.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 44544 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticalcl64.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 44032 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticalcl.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 53248 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ati2erec.dll
+ 2011-12-06 03:09 . 2011-12-06 03:09 43520 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ati2edxx.dll
+ 2011-12-05 19:47 . 2011-12-05 19:47 95248 c:\windows\system32\DriverStore\FileRepository\atihdw76.inf_amd64_neutral_929c0592bbc732d6\AtihdW76.sys
+ 2012-02-15 01:01 . 2012-02-15 01:01 52736 c:\windows\system32\drivers\usbaapl64.sys
- 2009-07-14 00:16 . 2009-07-14 00:16 23552 c:\windows\system32\drivers\tdtcp.sys
+ 2012-04-21 14:15 . 2012-02-17 04:57 23552 c:\windows\system32\drivers\tdtcp.sys
+ 2012-06-09 03:32 . 2012-03-17 07:58 75120 c:\windows\system32\drivers\partmgr.sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 60696 c:\windows\system32\drivers\LMouFilt.Sys
+ 2011-09-02 06:30 . 2011-09-02 06:30 66840 c:\windows\system32\drivers\LHidFilt.Sys
+ 2012-04-21 14:22 . 2012-03-01 06:46 23408 c:\windows\system32\drivers\fs_rec.sys
+ 2011-12-05 19:47 . 2011-12-05 19:47 95248 c:\windows\system32\drivers\AtihdW76.sys
- 2010-08-04 12:46 . 2010-01-22 00:09 53248 c:\windows\system32\drivers\ati2erec.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 53248 c:\windows\system32\drivers\ati2erec.dll
- 2009-07-13 23:19 . 2009-07-14 01:40 43520 c:\windows\system32\csrsrv.dll
+ 2012-01-30 20:48 . 2011-10-26 05:21 43520 c:\windows\system32\csrsrv.dll
- 2010-09-18 19:20 . 2012-01-10 19:52 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-18 19:20 . 2012-07-23 08:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-18 19:20 . 2012-07-23 08:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-09-18 19:20 . 2012-01-10 19:52 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-23 08:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-10 19:52 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-04 12:46 . 2011-12-06 02:18 58880 c:\windows\system32\coinst.dll
+ 2010-08-04 12:46 . 2011-12-06 02:11 42496 c:\windows\system32\atiuxp64.dll
+ 2010-08-04 12:46 . 2011-12-06 02:11 39936 c:\windows\system32\atiu9p64.dll
+ 2009-06-22 16:34 . 2009-06-22 16:34 51200 c:\windows\system32\ATIODCLI.exe
- 2010-08-04 12:46 . 2009-02-03 08:52 51200 c:\windows\system32\ATIODCLI.exe
+ 2011-12-06 03:09 . 2011-12-06 03:09 21504 c:\windows\system32\atimuixx.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 54784 c:\windows\system32\atimpc64.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 14336 c:\windows\system32\atiglpxx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 39936 c:\windows\system32\atig6txx.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 17408 c:\windows\system32\atig6pxx.dll
- 2010-08-04 12:46 . 2010-01-22 00:58 59392 c:\windows\system32\atiedu64.dll
+ 2011-12-06 03:09 . 2011-12-06 03:09 59392 c:\windows\system32\atiedu64.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 51200 c:\windows\system32\aticalrt64.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 44544 c:\windows\system32\aticalcl64.dll
+ 2011-12-06 02:10 . 2011-12-06 02:10 54784 c:\windows\system32\amdpcom64.dll
+ 2010-09-19 14:14 . 2012-07-22 08:39 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-19 14:14 . 2012-01-10 21:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:46 . 2012-07-22 08:40 91888 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-09-19 14:14 . 2012-07-22 08:39 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-09-19 14:14 . 2012-01-10 21:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-09-19 14:14 . 2012-07-22 08:39 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-19 14:14 . 2012-01-10 21:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-19 02:40 . 2012-01-10 21:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-19 02:40 . 2012-07-23 09:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-19 02:40 . 2012-01-10 21:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-19 02:40 . 2012-07-23 09:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-15 04:01 . 2011-12-15 04:01 68880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
+ 2012-01-30 20:50 . 2011-12-25 20:40 43280 c:\windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_wp.exe
+ 2011-12-15 03:08 . 2011-12-15 03:08 57616 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
+ 2012-01-30 20:50 . 2011-12-25 20:42 31504 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
- 2011-12-17 00:31 . 2011-12-17 00:31 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{F71A71E1-285C-95CE-A8F7-231E3827138E}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{F1F1CCD6-34FE-81C6-CE0C-F22695E6409F}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{EAF0F475-CFE2-9F4D-F26A-875FF09AD40E}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 10134 c:\windows\Installer\{E19490CD-5380-4F37-B0A7-624D635605DC}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{DBA5EE42-A143-A658-9F86-C611BFDBEFCA}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{D3689EED-3943-9E90-1D65-D2246EB58AD1}\ARPPRODUCTICON.exe
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{D07BB56A-7DB4-4564-A1F9-EBCE75FBE3C6}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{CF053286-7F4C-CAFB-616B-58EC562BB28E}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{CEEA6219-8792-3E40-D361-4FB5F0FBBB0F}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{BDCBA80C-A3BD-9DA5-E43F-EBBBE779C032}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{BC71B06F-BFAE-6A73-091C-F18ACF00A04C}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{BB095F3E-0A7D-7DD4-B2A8-47CB12E416B0}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{AF859F36-5F97-F6EC-A617-62771A8B4FDC}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{9FA5B08F-9162-BCCB-AFAC-28DF1751BEC3}\ARPPRODUCTICON.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-11-17 08:07 . 2012-07-20 23:31 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-11-17 08:07 . 2011-12-03 23:33 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe
+ 2012-02-10 11:35 . 2012-02-10 11:35 88102 c:\windows\Installer\{8924F1FE-8AC5-C2AE-59EF-C5D65B226933}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{7F7C616E-6971-77D9-7D59-82DC35DF81AC}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{7ADFB885-8E98-6AAE-8687-D6EFB5127F6B}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{7765BB73-D985-42C9-C7EE-AB434D59429F}\ARPPRODUCTICON.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 55176 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\UNINST_Uninstall_D_4299976C1167441FA07CEF9926E410B1.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\ProductName.chm.de_D066A77819B7480BA99CC79FB02C9357.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\NewShortcut7_093EA01C878D4FB8BBB75CF2AF29E7A1.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 71560 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriversHQ.DriverDe_84B8F33B3EBF407BAC7CF7FF8090594C.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 71560 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriversHQ.DriverDe_73EA94828B1A467994E24B03923D8FFE.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriverDetective.pt_6CF114D33913468CBA2AA6967939B819.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriverDetective.it_251B66F1CA924E82A1EE29E85D5EC5A1.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriverDetective.fr_E1678746353A46E3A9150D3E8B3832B1.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriverDetective.es_654C8EA5162D4D4084239A5EDD67F462.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 75656 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\DriverDetective.ch_571875AB094D409B841CA52363CEAF75.exe
+ 2012-02-10 23:47 . 2012-02-10 23:47 71560 c:\windows\Installer\{686695ED-BB3F-415D-B0DB-18CF535F7B50}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{5D5B8455-50E0-F94A-4C82-0F9303BB4C0E}\ARPPRODUCTICON.exe
+ 2012-02-10 11:37 . 2012-02-10 11:37 10134 c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{4EAF46A2-DB90-6B67-F640-5CC876A2B5C4}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{4C8E1E1B-175F-AF47-8B21-E12C7C8B5D40}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{4BA6B7C9-65AE-BE8B-687A-6F1A2D7F9705}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{45CB0703-D49C-31B2-0DBD-FDD98D7DEF7A}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{428536FB-25A0-8531-75EF-D7A7C340B0A4}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{418A8D89-B9AA-B872-5927-3D1A052CEAA8}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{30DAAF05-3679-C10C-953C-BB422FCDF557}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{1F36B20F-7408-EC75-2825-E9FE81B0339D}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{1DBC5882-96E2-3A01-A32C-9B6F6EF6CF25}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{14CE04AF-0EBC-B865-382F-1FB466CAC301}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{0D98B285-0777-B3B7-7A3D-9C85422203B9}\ARPPRODUCTICON.exe
+ 2012-02-10 11:36 . 2012-02-10 11:36 88102 c:\windows\Installer\{06870F63-4D1C-171F-9552-368D3890D92F}\ARPPRODUCTICON.exe
+ 2012-02-20 11:28 . 2012-02-20 11:28 53608 c:\windows\Installer\$PatchCache$\Managed\057978BEDBCC3104FB5D20494DADB50D\2.1.7\pthreadVC2.dll
+ 2012-02-20 11:28 . 2012-02-20 11:28 23248 c:\windows\Installer\$PatchCache$\Managed\057978BEDBCC3104FB5D20494DADB50D\2.1.7\AppleVersions.dll
+ 2006-07-24 14:50 . 2006-07-24 14:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBAME.DLL
+ 2006-07-24 14:50 . 2006-07-24 14:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
+ 2009-04-02 17:01 . 2009-04-02 17:01 56680 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_XPS.DLL
+ 2009-04-03 23:46 . 2009-04-03 23:46 97640 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_PDF.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
+ 2012-06-10 08:55 . 2012-06-10 08:55 10240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\7fa267d10b2df6dbd00d00d130715f0a\System.Xml.Serialization.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\054fce9466c6cef615b2f7cc9ff4e7f8\System.Windows.Presentation.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\ff78ec1b5bf38a8fb74c2d4f41bb308a\System.Web.ApplicationServices.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\e144d0028365c62178eb0662911ac910\System.AddIn.Contract.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\93295f3771dc9e5be2d49d5f5d76a7a6\Microsoft.VisualC.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5ea625ce2d6c08687f70cb81a003a28b\dfsvc.ni.exe
+ 2012-06-10 01:31 . 2012-06-10 01:31 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\061cbee19075e086d675a9e1f65725d7\Accessibility.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\4add87007e0864467659e6a248a7fe06\UIAutomationProvider.ni.dll
+ 2012-06-10 01:29 . 2012-06-10 01:29 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\28caa2ab8a4999900321b653e8b6ddc1\System.Windows.Presentation.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\4967f3e8b106851802f212e963bb8735\System.Web.ApplicationServices.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\7f49661d0e79763b30e9e99e714409a3\System.ServiceModel.Channels.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\a5c37bc9caf315df294f8b680a1ccd6f\System.AddIn.Contract.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\5ccc57bb582bf753166610089f204601\Microsoft.VisualC.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\414da765b5d5bb7fde97c0ea22de7d74\Accessibility.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\fb4bc14964a1d415bdbe55b62ce73a52\System.Windows.Presentation.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\eef76dd965ea0a8ae5fb0c734d84389c\System.Web.DynamicData.Design.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\ee709a01b51c82626f4b2c1173f2db28\stdole.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\78f495970511b726a0ca7b8119360e25\PresentationFontCache.ni.exe
+ 2012-06-10 01:40 . 2012-06-10 01:40 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\1a359e9b908a2565c546a8ca04b241c2\PresentationCFFRasterizer.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\9d57c4bbbc0b3243046fc7839da71b00\Microsoft.WSMan.Runtime.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\d6578432220dbabf2b15027681327bf8\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\66deb65a87750efddf62d1e0c0655352\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4b6402dc918e41b8de8c501f29833d91\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\28545d2b6a0aaef4aa168f9808603bc5\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\1d8a17a2c1416a8ad4d6ad2a28b4c5fd\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\0abc7256549c204f39af7dcc52c9e5d5\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\3c3a6cce983114e7406e0a6e6116ecd8\Microsoft.VisualC.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6ab0575bf49b60fd4b697d47e1754072\Microsoft.MediaCenter.iTv.Hosting.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\1569a004b1f41193818e3b3777f2c73d\LoadMxf.ni.exe
+ 2012-06-10 08:48 . 2012-06-10 08:48 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\3ee98e8b2084e27d65953bbd7e362bf8\ehiUPnP.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\1cd9f92749d29b9fd61fcb1c4ae84294\ehiTVMSMusic.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0811f67973c32efb2bfad62a4a2592b5\dfsvc.ni.exe
+ 2012-06-10 01:39 . 2012-06-10 01:39 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\ae9311dcb0e713330a2a86b04cf361dc\Accessibility.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\fbca78795c4dd2a0df1fbc45cef56513\WindowsLiveWriter.ni.exe
+ 2012-06-10 08:44 . 2012-06-10 08:44 81408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\20225dde0701a809f23364e1c3492449\WindowsLive.Writer.Passport.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ca2eff60beb3ba00a529a2d42dceca22\UIAutomationProvider.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\66d750f3f8dde0cc865f921497ab3545\System.Windows.Presentation.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\2b97ccae44726f13c418f1406180c3e8\System.Web.DynamicData.Design.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\543b0e12423bcec010bdd2ac27c5dc04\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-06-10 01:42 . 2012-06-10 01:42 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f34410ab8e82063735d876533db26c49\System.AddIn.Contract.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\d246780b91fd9f6393e85fb13bde94a6\stdole.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\d24744f15243e28ea541a459ff7ff5d5\PresentationFontCache.ni.exe
+ 2012-06-10 01:37 . 2012-06-10 01:37 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5a9d0ff936810991cedd098fe006a9be\PresentationCFFRasterizer.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\87a30ba337ed55d0905f19742e2985bc\napcrypt.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\9f2e8e0df9ff39ad21088f1d66cfadb1\Microsoft.WSMan.Runtime.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\d797123d55bb7b823120d0a7ffbbc2a7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb8ad29814d9e5589bd400d38e7a0b10\Microsoft.Windows.Diagnosis.SDHost.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb42a0f25b7608b2675080081b03f6e5\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\c6e9143be5afb36345875d56b61c444f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\91767cf3facefe10e00734c815e925ad\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\66cd99d2f576cde047074e98bd5e1848\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\4308e1bdc640e1c3f1ea966e84e48900\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\06fcf2fbbe38d9425fc49d935498ec93\Microsoft.Vsa.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\55c57057dc81a5e8c5bde3a230f0bcb9\Microsoft.VisualC.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e3ef400b1f37e4d3b79a42a8a602ea02\Microsoft.Build.Framework.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2095344bf8c40f8baa94ba53a993fb4c\Microsoft.Build.Framework.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\ff043f94e3aeb8764419d9bf2904dc68\IAStorDataMgrSvc.ni.exe
+ 2012-06-10 08:43 . 2012-06-10 08:43 59392 c:\windows\assembly\NativeImages_v2.0.50727_32\ExceptionLogging\d8ccff006f1726fe5ed870c0d554f415\ExceptionLogging.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\dc93539af5a961641a26ada75f730136\ehiUserXp.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\53d03b0e238c77cf7e5ac88e02aecd2c\dfsvc.ni.exe
+ 2012-06-10 01:37 . 2012-06-10 01:37 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
+ 2012-02-11 23:39 . 2012-02-11 23:39 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2012-02-11 23:39 . 2012-02-11 23:39 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2010-11-17 08:04 . 2010-11-17 08:04 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-07-14 00:19 . 2009-07-14 01:11 5120 c:\windows\SysWOW64\wmi.dll
+ 2012-04-21 14:22 . 2012-03-01 05:29 5120 c:\windows\SysWOW64\wmi.dll
+ 2012-01-30 20:52 . 2011-11-05 04:26 2048 c:\windows\SysWOW64\tzres.dll
- 2011-12-03 23:28 . 2011-07-09 04:29 2048 c:\windows\SysWOW64\tzres.dll
+ 2011-09-12 23:06 . 2011-09-12 23:06 3917 c:\windows\SysWOW64\atipblag.dat
+ 2012-04-21 14:22 . 2012-03-01 06:28 5120 c:\windows\system32\wmi.dll
- 2009-07-14 00:41 . 2009-07-14 01:33 5120 c:\windows\system32\wmi.dll
+ 2011-07-08 13:38 . 2012-06-19 15:24 3090 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-01-30 20:52 . 2011-11-05 05:32 2048 c:\windows\system32\tzres.dll
- 2011-12-03 23:28 . 2011-07-09 05:26 2048 c:\windows\system32\tzres.dll
+ 2011-09-12 23:06 . 2011-09-12 23:06 3917 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atipblag.dat
+ 2011-09-12 23:06 . 2011-09-12 23:06 3917 c:\windows\system32\atipblag.dat
+ 2012-07-22 08:37 . 2012-07-22 08:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-10 21:50 . 2012-01-10 21:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-22 08:37 . 2012-07-22 08:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-10 21:50 . 2012-01-10 21:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-10 01:29 . 2012-06-10 01:29 9216

c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\5d0529cca67ada47749f5373ae050a4a\System.Xml.Serialization.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\1361a05238cfe45d7da6cb4b367a986c\dfsvc.ni.exe
+ 2012-04-21 14:22 . 2012-03-01 05:37 172544 c:\windows\SysWOW64\wintrust.dll
+ 2012-07-20 23:27 . 2012-05-15 03:03 981504 c:\windows\SysWOW64\wininet.dll
- 2011-12-04 00:12 . 2011-08-20 04:31 981504 c:\windows\SysWOW64\wininet.dll
- 2011-06-13 04:09 . 2010-11-20 12:21 314880 c:\windows\SysWOW64\webio.dll
+ 2012-02-11 23:12 . 2011-11-17 05:35 314880 c:\windows\SysWOW64\webio.dll
+ 2012-07-20 23:27 . 2012-04-20 05:00 132096 c:\windows\SysWOW64\url.dll
- 2011-12-04 00:10 . 2011-08-20 04:30 132096 c:\windows\SysWOW64\url.dll
+ 2011-11-15 07:57 . 2011-11-15 07:57 122880 c:\windows\SysWOW64\SlotMaximizerAg.dll
+ 2012-04-21 14:15 . 2012-02-17 05:34 826880 c:\windows\SysWOW64\rdpcore.dll
- 2011-06-13 04:08 . 2010-11-20 12:20 514560 c:\windows\SysWOW64\qdvd.dll
+ 2012-01-30 20:49 . 2011-10-26 04:32 514560 c:\windows\SysWOW64\qdvd.dll
+ 2011-12-06 03:10 . 2011-12-06 03:10 278528 c:\windows\SysWOW64\Oemdspif.dll
+ 2012-02-23 10:49 . 2012-01-04 08:58 442880 c:\windows\SysWOW64\ntshrui.dll
- 2011-06-13 04:09 . 2010-11-20 12:20 442880 c:\windows\SysWOW64\ntshrui.dll
+ 2012-02-23 10:50 . 2011-12-16 07:52 690688 c:\windows\SysWOW64\msvcrt.dll
- 2009-07-13 23:12 . 2009-07-14 01:15 690688 c:\windows\SysWOW64\msvcrt.dll
+ 2012-07-20 23:28 . 2012-04-20 04:57 627712 c:\windows\SysWOW64\msfeeds.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2011-04-14 08:46 . 2011-02-18 05:41 716800 c:\windows\SysWOW64\jscript.dll
+ 2012-07-20 23:20 . 2012-04-17 04:34 716800 c:\windows\SysWOW64\jscript.dll
+ 2012-03-18 06:54 . 2012-03-18 06:54 157472 c:\windows\SysWOW64\javaws.exe
- 2011-12-04 07:48 . 2011-10-02 19:06 157472 c:\windows\SysWOW64\javaws.exe
+ 2012-03-18 06:54 . 2012-03-18 06:54 149280 c:\windows\SysWOW64\javaw.exe
+ 2012-03-18 06:54 . 2012-03-18 06:54 149280 c:\windows\SysWOW64\java.exe
+ 2012-04-21 14:22 . 2012-03-01 05:33 159232 c:\windows\SysWOW64\imagehlp.dll
+ 2012-07-20 23:27 . 2012-04-20 04:56 176640 c:\windows\SysWOW64\ieui.dll
- 2011-12-04 00:11 . 2011-08-20 04:26 176640 c:\windows\SysWOW64\ieui.dll
- 2011-03-14 13:02 . 2010-12-23 05:54 534528 c:\windows\SysWOW64\EncDec.dll
+ 2012-01-30 20:48 . 2011-10-15 05:38 534528 c:\windows\SysWOW64\EncDec.dll
- 2010-09-03 03:59 . 2011-10-02 19:06 472808 c:\windows\SysWOW64\deployJava1.dll
+ 2010-09-03 03:59 . 2012-03-18 06:54 472808 c:\windows\SysWOW64\deployJava1.dll
- 2011-06-13 04:08 . 2010-11-20 12:18 805376 c:\windows\SysWOW64\cdosys.dll
+ 2012-07-20 23:25 . 2012-06-06 05:03 805376 c:\windows\SysWOW64\cdosys.dll
+ 2011-12-06 02:35 . 2011-12-06 02:35 204960 c:\windows\SysWOW64\ativvsvl.dat
+ 2011-12-06 02:35 . 2011-12-06 02:35 157152 c:\windows\SysWOW64\ativvsva.dat
+ 2011-12-06 03:10 . 2011-12-06 03:10 360448 c:\windows\SysWOW64\atipdlxx.dll
+ 2011-12-06 03:17 . 2011-12-06 03:17 778752 c:\windows\SysWOW64\aticfx32.dll
+ 2011-12-06 02:12 . 2011-12-06 02:12 356352 c:\windows\SysWOW64\atiadlxy.dll
- 2011-06-13 04:09 . 2010-11-20 13:27 220672 c:\windows\system32\wintrust.dll
+ 2012-04-21 14:22 . 2012-03-01 06:38 220672 c:\windows\system32\wintrust.dll
+ 2012-02-11 23:12 . 2011-11-17 06:35 395776 c:\windows\system32\webio.dll
- 2011-06-13 04:09 . 2010-11-20 13:27 395776 c:\windows\system32\webio.dll
+ 2010-09-30 19:35 . 2012-07-19 23:26 353582 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-09-19 02:40 . 2012-07-23 07:02 322388 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2011-12-04 00:11 . 2011-08-20 05:37 134144 c:\windows\system32\url.dll
+ 2012-07-20 23:27 . 2012-04-20 05:42 134144 c:\windows\system32\url.dll
- 2011-06-13 04:09 . 2010-11-20 13:27 136192 c:\windows\system32\sspicli.dll
+ 2012-02-11 23:12 . 2011-11-17 06:35 136192 c:\windows\system32\sspicli.dll
+ 2011-11-15 07:58 . 2011-11-15 07:58 146432 c:\windows\system32\SlotMaximizerAg.dll
- 2011-06-13 04:08 . 2010-11-20 13:27 366592 c:\windows\system32\qdvd.dll
+ 2012-01-30 20:49 . 2011-10-26 05:25 366592 c:\windows\system32\qdvd.dll
+ 2009-07-14 02:36 . 2012-07-23 08:42 633336 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-23 08:42 115296 c:\windows\system32\perfc009.dat
+ 2012-02-23 10:49 . 2012-01-04 10:44 509952 c:\windows\system32\ntshrui.dll
- 2011-06-13 04:09 . 2010-11-20 13:27 509952 c:\windows\system32\ntshrui.dll
+ 2012-02-23 10:50 . 2011-12-16 08:46 634880 c:\windows\system32\msvcrt.dll
- 2009-07-13 23:19 . 2009-07-14 01:41 634880 c:\windows\system32\msvcrt.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 827728 c:\windows\system32\msvcr100.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 608080 c:\windows\system32\msvcp100.dll
+ 2012-07-20 23:27 . 2012-04-20 05:42 247808 c:\windows\system32\ieui.dll
- 2011-12-04 00:10 . 2011-08-20 05:33 247808 c:\windows\system32\ieui.dll
- 2009-07-14 04:45 . 2011-12-03 23:42 347536 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 04:45 . 2012-07-21 00:20 347536 c:\windows\system32\FNTCACHE.DAT
+ 2012-01-30 20:49 . 2011-10-15 06:31 723456 c:\windows\system32\EncDec.dll
+ 2009-07-14 05:30 . 2012-03-25 08:53 239616 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-12-17 01:49 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2012-03-22 08:54 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2012-02-11 00:15 . 2007-07-25 02:48 172032 c:\windows\system32\DriverStore\FileRepository\rixdptsk.inf_amd64_neutral_a070830f98d2817a\rixdicon.dll
+ 2012-02-10 23:55 . 2010-03-03 09:51 540696 c:\windows\system32\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
+ 2011-12-06 03:10 . 2011-12-06 03:10 278528 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\Oemdspif.dll
+ 2011-12-06 02:35 . 2011-12-06 02:35 204960 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ativvsvl.dat
+ 2011-12-06 02:35 . 2011-12-06 02:35 157152 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ativvsva.dat
+ 2011-12-06 03:10 . 2011-12-06 03:10 120320 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atitmm64.dll
+ 2011-12-06 03:10 . 2011-12-06 03:10 360448 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atipdlxx.dll
+ 2011-12-06 03:10 . 2011-12-06 03:10 423424 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atipdl64.dll
+ 2010-08-27 19:33 . 2010-08-27 19:33 332800 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ATIODE.exe
+ 2011-12-06 02:12 . 2011-12-06 02:12 327168 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atikmpag.sys
+ 2011-11-14 19:47 . 2011-11-14 19:47 608507 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiicdxx.dat
+ 2011-12-06 03:11 . 2011-12-06 03:11 235520 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiesrxx.exe
+ 2011-12-06 03:12 . 2011-12-06 03:12 494080 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atieclxx.exe
+ 2011-12-06 03:12 . 2011-12-06 03:12 466944 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\ATIDEMGX.dll
+ 2011-12-06 03:16 . 2011-12-06 03:16 933888 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticfx64.dll
+ 2011-12-06 03:17 . 2011-12-06 03:17 778752 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticfx32.dll
+ 2009-05-11 22:35 . 2009-05-11 22:35 118784 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atibtmon.exe
+ 2011-12-06 03:17 . 2011-12-06 03:17 159744 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiapfxx.exe
+ 2011-12-06 02:12 . 2011-12-06 02:12 356352 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiadlxy.dll
+ 2011-12-06 02:13 . 2011-12-06 02:13 509952 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiadlxx.dll
+ 2012-02-10 23:55 . 2010-03-03 09:51 540696 c:\windows\system32\drivers\iaStor.sys
+ 2011-12-06 02:12 . 2011-12-06 02:12 327168 c:\windows\system32\drivers\atikmpag.sys
+ 2012-02-23 10:49 . 2011-12-28 03:59 498688 c:\windows\system32\drivers\afd.sys
+ 2010-02-24 10:20 . 2010-02-24 10:20 191616 c:\windows\system32\drivers\acedrv11.sys
+ 2009-07-14 05:12 . 2012-07-21 02:43 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 05:12 . 2011-12-03 23:52 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2011-01-07 05:02 . 2011-01-07 05:02 158536 c:\windows\system32\atl100.dll
+ 2011-12-06 02:35 . 2011-12-06 02:35 204960 c:\windows\system32\ativvsvl.dat
+ 2011-12-06 02:35 . 2011-12-06 02:35 157152 c:\windows\system32\ativvsva.dat
+ 2011-12-06 03:10 . 2011-12-06 03:10 120320 c:\windows\system32\atitmm64.dll
- 2010-08-04 12:46 . 2010-01-22 00:59 120320 c:\windows\system32\atitmm64.dll
+ 2011-12-06 03:10 . 2011-12-06 03:10 423424 c:\windows\system32\atipdl64.dll
+ 2010-08-27 19:33 . 2010-08-27 19:33 332800 c:\windows\system32\ATIODE.exe
+ 2011-11-14 19:47 . 2011-11-14 19:47 608507 c:\windows\system32\atiicdxx.dat
+ 2011-12-06 03:11 . 2011-12-06 03:11 235520 c:\windows\system32\atiesrxx.exe
+ 2011-12-06 03:12 . 2011-12-06 03:12 494080 c:\windows\system32\atieclxx.exe
+ 2011-12-06 03:12 . 2011-12-06 03:12 466944 c:\windows\system32\ATIDEMGX.dll
+ 2010-08-04 12:46 . 2011-12-06 03:16 933888 c:\windows\system32\aticfx64.dll
+ 2011-12-06 03:17 . 2011-12-06 03:17 159744 c:\windows\system32\atiapfxx.exe
+ 2011-12-06 02:13 . 2011-12-06 02:13 509952 c:\windows\system32\atiadlxx.dll
- 2010-10-29 21:40 . 2011-04-17 01:15 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2010-10-29 21:40 . 2012-02-23 22:16 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-09-20 07:16 . 2012-01-10 21:40 926536 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2010-09-20 07:16 . 2012-07-21 00:19 926536 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-07-14 05:01 . 2012-01-10 21:49 300532 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-07-22 08:29 300532 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-12-15 04:01 . 2011-12-15 04:01 226600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2012-04-21 01:03 . 2012-04-21 01:03 616024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 156440 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 598784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
+ 2011-12-25 19:47 . 2011-12-25 19:47 261912 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
+ 2012-06-09 03:33 . 2012-02-10 23:29 172320 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll
+ 2012-01-30 20:50 . 2011-12-25 20:40 746256 c:\windows\Microsoft.NET\Framework64\v2.0.50727\webengine.dll
+ 2012-07-20 23:19 . 2012-04-23 22:33 630784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 486144 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 182056 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll
+ 2012-04-21 01:03 . 2012-04-21 01:03 616024 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 156440 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 518400 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
+ 2011-12-25 18:39 . 2011-12-25 18:39 192792 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
+ 2011-12-15 03:08 . 2011-12-15 03:08 957200 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 386824 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 131360 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2012-01-30 20:50 . 2011-12-25 20:42 437520 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2012-07-20 23:19 . 2012-04-23 22:35 630784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2012-06-09 03:32 . 2012-01-04 02:51 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2012-06-09 03:32 . 2012-01-04 02:50 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2012-06-09 03:32 . 2012-01-04 02:50 996624 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 616024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 156440 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2012-01-19 16:59 . 2012-01-19 16:59 386560 c:\windows\Installer\17a3aa6b.msi
+ 2012-01-19 16:59 . 2012-01-19 16:59 977920 c:\windows\Installer\17a3aa66.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 972800 c:\windows\Installer\17a3aa5b.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 752640 c:\windows\Installer\17a3a9ff.msi
+ 2011-11-09 22:21 . 2011-11-09 22:21 416768 c:\windows\Installer\17a3a9d9.msi
+ 2012-01-19 16:59 . 2012-01-19 16:59 622592 c:\windows\Installer\17a3a9cc.msi
+ 2010-04-20 21:48 . 2010-04-20 21:48 168960 c:\windows\Installer\17a3a9c6.msi
+ 2012-02-10 09:54 . 2012-02-10 09:54 889344 c:\windows\Installer\17488e48.msi
+ 2012-03-18 06:58 . 2012-03-18 06:58 207360 c:\windows\Installer\12eb14.msi
+ 2012-06-09 03:36 . 2012-06-09 03:36 380928 c:\windows\Installer\{CF8FFD12-602B-422D-AF1D-511B411E7632}\iTunesIco.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2010-09-18 19:51 . 2012-07-20 23:43 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2012-02-11 23:38 . 2012-02-11 23:38 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2010-11-17 08:07 . 2010-11-17 08:07 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2010-03-18 18:16 . 2010-03-18 18:16 181096 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_X86.dll
+ 2010-03-18 19:27 . 2010-03-18 19:27 225640 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_AMD64.dll
+ 2012-02-15 01:02 . 2012-02-15 01:02 236904 c:\windows\Installer\$PatchCache$\Managed\A977DA8BAD2856347A0DDAD3FC5CC5FF\5.1.1\OutlookChangeNotifierAddIn_x64.dll
+ 2012-02-15 01:02 . 2012-02-15 01:02 227176 c:\windows\Installer\$PatchCache$\Managed\A977DA8BAD2856347A0DDAD3FC5CC5FF\5.1.1\OutlookChangeNotifierAddIn.dll
+ 2011-09-15 10:41 . 2011-09-15 10:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WINWORD.EXE
+ 2007-06-08 00:51 . 2007-06-08 00:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
+ 2008-03-19 11:27 . 2008-03-19 11:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
+ 2006-07-24 14:50 . 2006-07-24 14:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
+ 2008-10-25 11:18 . 2008-10-25 11:18 172880 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNF.DLL
- 2011-06-13 04:09 . 2010-11-20 13:27 465920 c:\windows\ehome\mstvcapn.dll
+ 2012-01-30 20:49 . 2011-10-29 05:23 465920 c:\windows\ehome\mstvcapn.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 336896 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\342472450a587d22afebf6e7ecbbca5c\WindowsFormsIntegration.ni.dll
+ 2012-07-21 01:02 . 2012-07-21 01:02 337408 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\08becdcc9bd647c4e4d07ceea7fe4895\WindowsFormsIntegration.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\fb43d84bc59b21e8a7f3e36d616eea90\UIAutomationTypes.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\26f12a0a3baed2a227cf30aaeae03913\UIAutomationProvider.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\1c3c298326e9ac14796516ac1da09a16\UIAutomationClient.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 528896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\307eea660f877dc40ae90882ce554757\System.Xml.Linq.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 256000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\b4afa252d0f0e27b0b5e8fcb2cc5b3a7\System.Windows.Input.Manipulations.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\8c0ee7b970cc4e8c2986c7898af71661\System.Transactions.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\f67f5d2f51eecc45b68bf86d65a1624d\System.ServiceProcess.ni.dll
+ 2012-07-21 01:01 . 2012-07-21 01:01 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\ca5505a49a075ee7ad2535f89d9ea992\System.ServiceProcess.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 108032 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\eb4fb369926faaffede7aaf317fd6532\System.ServiceModel.Channels.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 517120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e5ab3c37897bb578bdbfe6b7e0558ad8\System.ServiceModel.Routing.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 946688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\e48b6a8c491a96d1bc601795532af605\System.Security.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 376832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\7590828d50338d512b11a4d3f87d69a2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\21d5b44ef01ccfa69e79674a51707de0\System.Runtime.Remoting.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\5f2bfb0585061dc256ee9587d430959f\System.Numerics.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 933376 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\6996a415485a84fef2d2556b0462336f\System.Net.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\6e886c2e732ff69ae9eb1dc121b767d8\System.Messaging.ni.dll
+ 2012-07-21 01:01 . 2012-07-21 01:01 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\0d8257087be3e57b071d1d5ccd705c2f\System.Messaging.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\92d266f677605e5475b7f39c063c4a9d\System.Management.Instrumentation.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\07a0e1efc063042be3e8faf62b413a12\System.IO.Log.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\7fd39b9a208214e6e5eba4e9396409f1\System.IdentityModel.Selectors.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.Wrapper.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 512000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\521f5bccf74318a4777597b0c01fda1e\System.Dynamic.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 632832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6a8bd7d373c988a585e90bb61c5ec8cc\System.DirectoryServices.Protocols.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\78dd02d104bb15bc3820c06bd2876239\System.Device.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\97d1aaf3733b107ecdbecb9d21050ff4\System.Data.DataSetExtensions.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c3d7a7ff58ff502887d8f1b77e61adbc\System.Configuration.Install.ni.dll
+ 2012-07-21 01:01 . 2012-07-21 01:01 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\52792a7ce63196551c29f5201562c1ae\System.Configuration.Install.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\a4f91f2dfd1656ef2e42917963f6bf50\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 871936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\b1c67ee2e0e6e78c31985069fbc82596\System.AddIn.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\c69fb0f955adc7ca80cd5f2fd730edea\System.Activities.DurableInstancing.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\11fc863fa4f5092fca4f2ce25a9ac361\SMSvcHost.ni.exe
+ 2012-06-10 08:52 . 2012-06-10 08:52 185344 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\50e8e826488639e549589ba34666933e\SMDiagnostics.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\722c0236432dd5ccc047481d3ebbd49e\PresentationFramework.Royale.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\6739c3715c9e38dbdfbfd57b424a3094\PresentationFramework.Aero.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3e7359f5f0fb68565314f88f6ec2d67a\PresentationFramework.Luna.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\263748f3d18955b9e467710da1e8546f\PresentationFramework.Classic.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 422400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\634a00569f0fe8693873f42039aca35f\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-07-21 00:58 . 2012-07-21 00:58 422912 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\097137b03ff37196b4b8ba62db34d64a\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\6480551111832c83ee88bcf756a72533\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\0e81a3996f7cbff23fc01bea4185a918\CustomMarshalers.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\db6668b547e7504d74c3f345e2519b65\WindowsFormsIntegration.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\6823effdbb0434f96511748697349862\UIAutomationTypes.ni.dll
+ 2012-06-10 01:29 . 2012-06-10 01:29 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\021651282dda157fbe5a1f3575c67534\UIAutomationClient.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 393216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8f0cf05d2b1e46a772312143227cb6ed\System.Xml.Linq.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 189440 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\5fc7ab2af170ab1217c5e1a7328b999b\System.Windows.Input.Manipulations.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 649728 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\6cb2089f1eaf08c3d94a54031cf1313a\System.Transactions.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\9ae3a257c347602d42ab80bb7a5ca3bb\System.ServiceProcess.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 369664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\8e3ba21dc083837fdc1c8b9f98c5f4bf\System.ServiceModel.Routing.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 736768 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\4278bedb3086448c94c1e7f563325052\System.Security.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\490f9ea2b1a2e738d203af00c5c9b735\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 762880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\e5f1db35163684e821bca4a2fb0311b1\System.Runtime.Remoting.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 145408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\360e9c00572679f437fff0ae719a5886\System.Numerics.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 657408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\62a6ed6942237e009110ffa55adbb77a\System.Net.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\7a5371c272b4008457a3af780bf65ae5\System.Messaging.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\0eb2dedcc5b7f32e7886b83635d22dbc\System.Management.Instrumentation.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\54f78c72dbc55f90983ee1a887b27547\System.IO.Log.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 229888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\7cfdedf408ac80e153d7988e308c7caa\System.IdentityModel.Selectors.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\058fc53adeb7f06708bb4fa9f92fab5c\System.EnterpriseServices.Wrapper.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 787456 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\058fc53adeb7f06708bb4fa9f92fab5c\System.EnterpriseServices.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 377856 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\559594e862b578f3040446d7d4498cb7\System.Dynamic.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\41173dd435cb9e35b406e5ee17894cd1\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 470528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\40466b947e5932c0c96529915fef0c45\System.DirectoryServices.Protocols.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\e38e62fe185dbc8344fc242b2093aee2\System.Device.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\bc5bf4e71af4c7689ffed22f5187d922\System.Data.DataSetExtensions.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 982528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\6711765f90c0082ec393943b924ed277\System.Configuration.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\0a0d6610975706aee94ec9f44191bab8\System.Configuration.Install.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 693760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\dcf415181fba99d99ec87eefdf082864\System.ComponentModel.Composition.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\41a21613a657cc7d9ea10386f271d388\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 624128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\cdd87ceeb66eb0db86b02c27372cc31c\System.AddIn.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 411136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\139ec162dfa0903f5b00d623d2e944be\System.Activities.DurableInstancing.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\01c8de400571afc3469fb99c6b7edecc\SMSvcHost.ni.exe
+ 2012-06-10 01:27 . 2012-06-10 01:27 143360 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4dd48e938a8834fe950cf0cd11603c71\SMDiagnostics.ni.dll
+ 2012-06-09 03:41 . 2012-06-09 03:41 309760 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a6b504e505c1c4bc6204136a957a4e30\PresentationFramework.Classic.ni.dll
+ 2012-06-09 03:41 . 2012-06-09 03:41 755712 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\71bcb2ec4fe3e7edb47397dfc1687576\PresentationFramework.Luna.ni.dll
+ 2012-06-09 03:41 . 2012-06-09 03:41 387072 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\453c2355cf76a74cc01226680cca4a01\PresentationFramework.Royale.ni.dll
+ 2012-06-09 03:41 . 2012-06-09 03:41 595968 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3263fe38362543170c1682381eeac25a\PresentationFramework.Aero.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\26599cf02308adfabdc81eff4b322a01\Microsoft.VisualBasic.Compatibility.Data.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\dd47533d2837e1d78400f759f5f05e41\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\8f0e78c2aa12e929ecf3b0c912ac8406\CustomMarshalers.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\ad7f43afb4f124acae4d503b40f591c1\WsatConfig.ni.exe
+ 2012-07-21 00:46 . 2012-07-21 00:46 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\f4d304fcbfda323997083a1f88b83719\WindowsFormsIntegration.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 472576 c:\windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\7518ad68644aee4bb2b17ed2b9f0ed39\VistaBridgeLibrary.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 736768 c:\windows\assembly\NativeImages_v2.0.50727_64\VDialog\2a3ff303b13f40e711ecca128dfe7791\VDialog.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\bf634b0e2e28466c6ed6ae1eb602b09f\UIAutomationTypes.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\1ff8fb81d6f045f1dc6f50be95444292\UIAutomationProvider.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\1f36e020c3563e0ff414f13138e238e1\UIAutomationClient.ni.dll
+ 2012-07-21 00:46 . 2012-07-21 00:46 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\681410f842337dccc72eb059738c3ced\TaskScheduler.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\de45d043775d8c805f6feca40d7a9ed2\System.Xml.Linq.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\72b4992e45d232251a273a59eb3333d5\System.Web.Routing.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\76662ce36d2141e45513e64386073cc2\System.Web.RegularExpressions.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\b905eb57b631a30c60caa4d68c186963\System.Web.Entity.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\e412dfbf1aa49bbe345a02a4d23104f5\System.Web.Entity.Design.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\815769f953ebe3f84439d522c97317b8\System.Web.DynamicData.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\c8144ee08dccdac183527e53c86aa901\System.Web.Abstractions.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\ec95ad2463c5588fc8ef552b3f375ee6\System.Transactions.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\f71d2f65d0f149c75ac7a569dbcc8500\System.ServiceProcess.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\1962f8344f19c367f4e0be9f8f5a7972\System.ServiceProcess.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\1875b50d0228f29aef00bed38ab594d6\System.Security.ni.dll
+ 2012-06-10 01:40 . 2012-06-10 01:40 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\807759890a40e4047c35a24e64dc76d5\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\3b3581851a728bef36f319e9d4c72499\System.Net.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\d5d612f7d372f500e3062e3814e79d75\System.Messaging.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\599954438a668c94dd38e8e7e506ac2a\System.Management.Instrumentation.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 569856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\fd51741bfd973ad507bbd141e98932f8\System.IO.Log.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\ef6abe121bb11bff2514bfdfb7e76b7a\System.IdentityModel.Selectors.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.Wrapper.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\fbc02e9f5a14bb93082ebc88bc577413\System.Drawing.Design.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\a76b760d8b987ce161519e1b8bf18fdd\System.Drawing.Design.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\4bb1134d9b166434327385ddf3c5dd54\System.DirectoryServices.Protocols.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 629760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\7c4ce1b8a2f83ef29aa6d5f126ab5b71\System.Data.Services.Design.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\19d1414f1ca718ce4d0c07e7305b3450\System.Data.DataSetExtensions.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\a88ca70ab9641b8236149bc5dd8d1564\System.Configuration.Install.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\4aebed13b5309398cd809454cafe472f\System.Configuration.Install.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\9536bb262c4f1ea389d287ab669767d4\System.ComponentModel.DataAnnotations.ni.dll
+ 2012-06-10 01:42 . 2012-06-10 01:42 890880 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\84262138e2e9f34c88fd282caa82baa5\System.AddIn.ni.dll
+ 2012-06-10 01:42 . 2012-06-10 01:42 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\176899be7b920fb20408ff49e636a776\System.AddIn.Contract.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\ee0608cd62dfb37016016884fc39e425\sysglobl.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\9fa1abf006689e262527ae50d452e97e\SMSvcHost.ni.exe
+ 2012-06-10 08:47 . 2012-06-10 08:47 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\2eac9c598de3341eba5c16787c74f220\SMDiagnostics.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 282624 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\89de197bdde5984658045ade41c2c9b9\PresentationFramework.Classic.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\7ffb91db770d0b09921f623bc5d68b4f\PresentationFramework.Luna.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\4f3567165e2a444fc9a62980c4d0ea82\PresentationFramework.Aero.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\205bb33cef9ae6b906ceadd6f2861c86\PresentationFramework.Royale.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\2f1bad2fb963482a02443d5e7fece2b6\napsnap.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\bb4947f0ecc925a7bcfd129b6eec8f9b\napinit.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\5f0ae15f9d1cade37fbfaacff7e64bff\naphlpr.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\5346ceca518baf5e5fa3fed9f900f792\napcrypt.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 408064 c:\windows\assembly\NativeImages_v2.0.50727_64\MyDock.Util\7e13e518e889a09f3936dbd5b02cb804\MyDock.Util.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\8f792883d0adad8c7beccf24aed65817\MSBuild.ni.exe
+ 2012-07-21 00:44 . 2012-07-21 00:44 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\67240ddde494b9cc05cd732ccd099668\MMCFxCommon.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 681984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\b78beede8a3c9720095dde4a4a162acc\Microsoft.WSMan.Management.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\83222514e209f186ad3a1c3794168bfd\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\a843956bb452503139683304de4cc8f6\Microsoft.Vsa.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\c56d6513e4b239b1b1dbe29b0588321a\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\fb0d102ca78bd05fe7064b9e6be30fc7\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b21fa6ff448b99a97319e18c166c03e2\Microsoft.PowerShell.Security.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6c3fe42a14ac5b48ebd43be290973d24\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\2572e94f9d0b412cdc529c8d74fdb689\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f04ccbbf5199d2b264f1b1175be44686\Microsoft.MediaCenter.Mheg.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f015188310f7613f819fcf032f98705a\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e29cbd30a31d3c8dae19eb17f70c4ec4\Microsoft.MediaCenter.iTv.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6dbd502a13b5e3caae0b1f2b4847612f\Microsoft.MediaCenter.Playback.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\514667153fd74307d21e7f50b79858c9\Microsoft.MediaCenter.Interop.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\409dae089f2e041343cff71f822cd505\Microsoft.MediaCenter.ITVVM.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\18367b9a0b9e9261d1d9e371230af87c\Microsoft.MediaCenter.Sports.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 798720 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\803188573fb19785a94284e097c48a67\Microsoft.ManagementConsole.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 244736 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\d68a27daca73749e4438a47e61643c3c\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\3151235c1c38db94fd44e3c6f290ff38\Microsoft.Build.Utilities.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 121344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\cf5e9b5d10682467a9e03358a6d6258f\Microsoft.Build.Framework.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\0f233d0eb396065719e83ab573a72cc5\Microsoft.Build.Framework.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\2416af06edb993f98a751acb69f67016\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\69286d5692277a166404cb897a8b2e7a\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\74e4adc90675c3b1365825c7e78b5ce9\Mcx2Dvcs.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\4a1f9a648a3928d42b77a91666d9aa8a\mcupdate.ni.exe
+ 2012-06-10 08:48 . 2012-06-10 08:48 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\40d70417c04f9ccb5fdecb5b9be5a6a3\mcstoredb.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\4ae6ccc32dafb4e3765b9db05585bd48\mcplayerinterop.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\b0db345fd62a84c98fd8b0bf3c72e8bb\mcGlidHostObj.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\3fc113fe40d0145cd87afca2d107bf6d\MCESidebarCtrl.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\bc5df15ee827e248dd6f819874a85718\EventViewer.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\584d419d4c837ea19f7f450a807b0273\ehRecObj.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\20c3505378a50f4859c9b2e7dcbb5fa2\ehiWUapi.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\2f9f48ad6496c9103043db1c21a651fd\ehiwmp.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0955237aa3c1cb3a643248b8c58ec34c\ehiUserXp.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\7998173654fa518876cc97e37b86d465\ehiiTv.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\6c97aa6908f96ac9816ce74e4f6251ac\ehiExtens.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\a501747a95523297a8a1f119df8b1642\ehiBmlDataCarousel.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\414bbac4e1d7761a336bb9d74b9b243a\ehiActivScp.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\08c9aa18b306aa47ddc0ae4a63b05d04\ehExtHost.ni.exe
+ 2012-06-10 08:47 . 2012-06-10 08:47 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\ff7ef4caed03d6934669d1a39877a8ac\ehCIR.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\b7916689137fd0bc9ba1ba5a27e2a38a\CustomMarshalers.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\cc6e6febcd804604bf4d92d0eb8ec6ae\ComSvcConfig.ni.exe
+ 2012-06-10 08:46 . 2012-06-10 08:46 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\d18719c2df1334364cac199bb9c86adf\BDATunePIA.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\85350e8b63e09cacc6959dbb021c81e6\XPBurnComponent.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\9d60139fdead64a892985181d663989f\WsatConfig.ni.exe
+ 2012-07-21 00:29 . 2012-07-21 00:29 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\5b4b71fd140484201d0e285a14cce17a\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e92c100773e1aa6e0094ac430b496ace\WindowsLive.Writer.Mshtml.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e35141184454c11a98f333c5b7b5c4c3\WindowsLive.Writer.BlogClient.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dbbb5914ff727ce0f6793177c4da31ba\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c3902b80bdc944a554776f5d6c07cff9\WindowsLive.Writer.Instrumentation.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ac47170bea9a3515287134ce8c3dae4a\WindowsLive.Writer.Interop.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\aab0bad2dc60d6748745835dc38c52c6\WindowsLive.Writer.HtmlParser.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8adf64dec1f056a5c36720ac34045370\WindowsLive.Writer.BrowserControl.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\882aeb909ff121fae01034b7e9627936\WindowsLive.Writer.Extensibility.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8437eb811a83c1d04c10c6d91abc606b\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6f110f192197df8fd4d84e270edf7825\WindowsLive.Writer.SpellChecker.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\43f78ae7292b5d31b471b9ecf89430af\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3e388ec2100141e62e0f3cb81aa42ce0\WindowsLive.Writer.FileDestinations.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2bfd2895928710d7cf422c48b6e915d0\WindowsLive.Writer.Controls.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1af8e0bd9d63b6263bda26b9ffc1f053\WindowsLive.Writer.Api.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 223232 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\c5d63c774d84fccad17b4215692d4f02\WindowsLive.Client.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f2f8201dd3453250dfd9ed1afce630a0\WindowsFormsIntegration.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d8af9a65cf0ed85d47360796e2645a06\UIAutomationTypes.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\779b08c46960a1824503aa6f089673fa\UIAutomationClient.ni.dll
+ 2012-07-21 00:30 . 2012-07-21 00:30 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA505.tmp\EventViewer.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\f3e052584df9c614407da662dd3c3df3\TaskScheduler.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\64de6810023adccdc56ddae13bdd6b03\System.Xml.Linq.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\06e4119a0a3484bb0ca667a16145ce74\System.Web.Routing.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\2b129372a27469195acbe3b6b81786ef\System.Web.RegularExpressions.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\4f13c2c06fb97f6659473f02802b377b\System.Web.Extensions.Design.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\bc239944bca7cc6b6ddb473259183c7d\System.Web.Entity.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\3701488fb9e601ebe963db25b784d684\System.Web.Entity.Design.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a09cc9877f51f16a4610b702155e8b70\System.Web.DynamicData.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\c6aad1edcc51862ceb26b6b65dad1490\System.Web.Abstractions.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\441f16bb7547cc6f2435d43e68002a47\System.ServiceProcess.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 680448 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\054fcff18035c210487b0888e6461192\System.Security.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\0b5f082230e3486412e0fa333290e85a\System.Net.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\2b4d6976393bf5643a4ef2d8dffdf75b\System.Messaging.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\8280490a2939075b726fd051d9010cc0\System.Management.Instrumentation.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a03191ed937f6c1dc827b53d94ea0176\System.IO.Log.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\100d39c2f8985cb93e26feef86ba5212\System.IdentityModel.Selectors.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.Wrapper.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\912a0776c2bfd35ff76bd0b8ba977ed4\System.Drawing.Design.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\33582b127d761babf8c8cdfe4e43749a\System.Drawing.Design.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\55545e89f96539ef93375524d1145a6f\System.DirectoryServices.Protocols.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4d73a7649876bb6e54a01ccbf235919b\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 462336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e36e03067b12bc35fcc3787dc81022c8\System.Data.Services.Design.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 763392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\5a29fff52e2c3d13ec15e8701027ab17\System.Data.Entity.Design.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\940f62a5d077405e0b324422afb6ff2c\System.Data.DataSetExtensions.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\d3325c6bced333a67122db7414c1fd1e\System.Configuration.Install.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\498d2033c60fe5b777cf923b71b25972\System.Configuration.Install.ni.dll
+ 2012-06-10 01:42 . 2012-06-10 01:42 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\a90ec436f1d2c5cb0133a53c2e47d61a\System.AddIn.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\1ed79278fe139272e868e3a53d736f22\sysglobl.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1b0b19607668635281fa260707f4352f\SMSvcHost.ni.exe
+ 2012-06-10 08:44 . 2012-06-10 08:44 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9e7bf69d97febe4ed1a288c787e5d9ca\SMDiagnostics.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 226816 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae55e761d480fe15781156d1311a1837\PresentationFramework.Classic.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7df1f379457aa5f39183903d115b5479\PresentationFramework.Royale.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\496bc57a53989bb83ec58865fa34be1d\PresentationFramework.Luna.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\acfafa161ea232928cb02b01c50acf1c\napsnap.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\0abec246c5ca6ec4858bfd3ab84da0ec\napinit.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\e0c40329b9cdd7f141a3702d79eb4bda\naphlpr.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\74a8b6419deb005337a1e43ec2502134\MSBuild.ni.exe
+ 2012-07-21 00:38 . 2012-07-21 00:38 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\1e03b7c2539c5376f0665a4aba04efbd\MMCFxCommon.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 531968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\070505350ec9daa3343b3cd2bc8cf59e\Microsoft.WSMan.Management.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1e639225ba30d7f182b893ddacea506b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\ebe72c04f37f354b9d19e5a185de2db9\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 304128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\b5637f4485418e115759154b0df5fbd4\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\52f09afbae8af86b981942a793c078da\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d4c36b363fcd1ca494218e74ba606e99\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 786432 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ba2ca86f5d270f493501848843d2f227\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\607324a312b1c6d7fbede8300e8cee91\Microsoft.PowerShell.GraphicalHost.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1f1185444c8a12ace85ba4c2d49f41f8\Microsoft.PowerShell.Security.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\12715b7e3e89758161053520b57764b2\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\622b582866fca37f113bd97ae4c6d1f6\Microsoft.ManagementConsole.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7e59b3b84ca3c61adfc0dc74a65ea177\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\07e346ee0e3f7433f2de7a72fadd6713\Microsoft.Build.Utilities.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\432160eff3b1f9301c6a74c2e647e03d\Microsoft.Build.Engine.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\8297305de86377d0070a983d99a7f943\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 231424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\f27bc203006e347bb2e7d61bdb470a7d\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 230912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\5238b74beacf1adad1614600d63566d0\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\541a5bb4d0f8490e506f885a4b435566\mcstoredb.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 170496 c:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\dc45bfd22b86df0074e8e521ada8d55f\IsdiInterop.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.WUApiLib\e8ff69deee25671a7555ba911c7ecf47\Interop.WUApiLib.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 547840 c:\windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\0bf2b46825daefcff93f7574ee508d8f\ICSharpCode.SharpZipLib.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 452608 c:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 176640 c:\windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\107e08dcb25471bce0240406a1d9f31b\IAStorDataMgr.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\02577b78c6ed2f9bda301de888dccad8\EventViewer.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\5ae5c6732ef8e7115baaeb66fd69cdd2\ehRecObj.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\c4a5ce4f89c53b9601d13d22d01cf0bf\ehiVidCtl.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\cbf3a07d3ab873b19f47d6a24f06c796\ehiProxy.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\5cc4a5672758f4732ef430b3431f47fc\ehiExtens.ni.dll
+ 2012-07-21 00:30 . 2012-07-21 00:30 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\a6b8eb80cfbdd927b2fa4ecb69fc0209\ehExtHost32.ni.exe
+ 2012-06-10 08:44 . 2012-06-10 08:44 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\626d0ac2f4ada682d7ca6c4ebf821469\CustomMarshalers.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\3912b69593af13d0922279a063e5af66\ComSvcConfig.ni.exe
+ 2012-06-10 08:43 . 2012-06-10 08:43 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\e1c3540ffb669448747187f76c6ebe82\BDATunePIA.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\Agent.Communication\1653c897b5f46425b1d35774bf9e6476\Agent.Communication.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 352768 c:\windows\assembly\NativeImages_v2.0.50727_32\Agent.Common\b96e320eeca03dab689f7943887e1a24\Agent.Common.ni.dll
+ 2012-07-20 23:19 . 2012-04-23 22:35 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-06-09 03:32 . 2012-01-04 02:50 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
- 2011-06-13 04:08 . 2010-11-05 01:53 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2011-06-13 04:09 . 2010-11-05 01:53 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2011-06-13 04:09 . 2010-11-05 01:52 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-09 03:33 . 2012-02-10 23:29 358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2011-06-13 04:09 . 2010-11-05 01:53 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2010-11-17 08:04 . 2010-11-17 08:04 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2012-02-11 23:39 . 2012-02-11 23:39 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2012-01-30 21:02 . 2012-01-30 21:02 350080 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2012-02-11 23:39 . 2012-02-11 23:39 149368 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2012-07-20 23:27 . 2012-04-20 05:00 1231360 c:\windows\SysWOW64\urlmon.dll
- 2011-12-04 00:12 . 2011-08-20 04:30 1231360 c:\windows\SysWOW64\urlmon.dll
+ 2011-11-15 07:57 . 2011-11-15 07:57 2463744 c:\windows\SysWOW64\SlotMaximizerBe.dll
- 2011-06-13 04:09 . 2010-11-20 12:20 1328128 c:\windows\SysWOW64\quartz.dll
+ 2012-01-30 20:49 . 2011-10-26 04:32 1328128 c:\windows\SysWOW64\quartz.dll
+ 2012-01-30 20:48 . 2011-11-17 05:38 1292080 c:\windows\SysWOW64\ntdll.dll
+ 2012-07-20 23:28 . 2012-04-20 04:57 6027776 c:\windows\SysWOW64\mshtml.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
+ 2012-07-20 23:27 . 2012-04-20 04:56 2073600 c:\windows\SysWOW64\iertutil.dll
- 2011-12-04 00:12 . 2011-08-20 04:26 2073600 c:\windows\SysWOW64\iertutil.dll
+ 2011-07-06 16:28 . 2011-07-06 16:28 1193320 c:\windows\SysWOW64\FM20.DLL
+ 2012-06-09 03:32 . 2012-03-03 05:31 1077248 c:\windows\SysWOW64\DWrite.dll
+ 2010-08-04 12:46 . 2011-12-06 02:28 4206592 c:\windows\SysWOW64\atiumdva.dll
+ 2011-12-06 02:39 . 2011-12-06 02:39 1828864 c:\windows\SysWOW64\atiumdmv.dll
+ 2010-08-04 12:46 . 2011-12-06 02:33 5919232 c:\windows\SysWOW64\atiumdag.dll
+ 2011-12-06 03:06 . 2011-12-06 03:06 6159872 c:\windows\SysWOW64\atidxx32.dll
+ 2012-07-20 23:27 . 2012-05-15 04:01 1188864 c:\windows\system32\wininet.dll
- 2011-12-04 00:12 . 2011-08-20 05:37 1188864 c:\windows\system32\wininet.dll
+ 2012-02-15 01:01 . 2012-02-15 01:01 4547944 c:\windows\system32\usbaaplrc.dll
- 2011-12-04 00:12 . 2011-08-20 05:37 1494016 c:\windows\system32\urlmon.dll
+ 2012-07-20 23:27 . 2012-04-20 05:42 1494016 c:\windows\system32\urlmon.dll
- 2009-07-14 00:03 . 2009-07-14 01:41 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2012-06-09 03:32 . 2012-03-31 05:40 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
+ 2011-11-15 07:58 . 2011-11-15 07:58 3507712 c:\windows\system32\SlotMaximizerBe.dll
- 2011-06-13 04:09 . 2010-11-20 13:27 1031680 c:\windows\system32\rdpcore.dll
+ 2012-04-21 14:15 . 2012-02-17 06:38 1031680 c:\windows\system32\rdpcore.dll
+ 2012-01-30 20:49 . 2011-10-26 05:25 1572864 c:\windows\system32\quartz.dll
+ 2012-01-30 20:48 . 2011-11-17 06:41 1731920 c:\windows\system32\ntdll.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 5523280 c:\windows\system32\mfc100u.dll
+ 2011-01-07 05:02 . 2011-01-07 05:02 5493576 c:\windows\system32\mfc100.dll
- 2011-06-13 04:09 . 2010-11-20 13:26 1447936 c:\windows\system32\lsasrv.dll
+ 2012-02-11 23:12 . 2011-11-17 06:35 1447936 c:\windows\system32\lsasrv.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\LkmdfCoInst.dll
- 2011-12-04 00:12 . 2011-08-20 05:33 2454528 c:\windows\system32\iertutil.dll
+ 2012-07-20 23:27 . 2012-04-20 05:42 2454528 c:\windows\system32\iertutil.dll
+ 2012-06-09 03:32 . 2012-03-03 06:35 1544704 c:\windows\system32\DWrite.dll
+ 2012-02-15 01:01 . 2012-02-15 01:01 4547944 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_c111aaecb61e9a2b\usbaaplrc.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfmouhid.inf_amd64_neutral_12000fce12220350\LkmdfCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfkbdhid.inf_amd64_neutral_99503c6390c9346a\LkmdfCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfhidusb.inf_amd64_neutral_6d6ec350722ee849\LkmdfCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfhidhid.inf_amd64_neutral_67db93f52e33f460\LkmdfCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfhideqd.inf_amd64_neutral_f82f5301e4a99eb5\LkmdfCoInst.dll
+ 2011-09-02 06:30 . 2011-09-02 06:30 1845528 c:\windows\system32\DriverStore\FileRepository\lfeqdusb.inf_amd64_neutral_c33b2f7768fc3d46\LkmdfCoInst.dll
+ 2011-12-06 02:28 . 2011-12-06 02:28 4206592 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumdva.dll
+ 2011-12-06 02:39 . 2011-12-06 02:39 1828864 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumdmv.dll
+ 2011-12-06 02:33 . 2011-12-06 02:33 5919232 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumdag.dll
+ 2011-12-06 02:39 . 2011-12-06 02:39 1113088 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumd6v.dll
+ 2011-12-06 02:39 . 2011-12-06 02:39 4072960 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumd6a.dll
+ 2011-12-06 02:24 . 2011-12-06 02:24 7511040 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atiumd64.dll
+ 2011-12-06 02:51 . 2011-12-06 02:51 7520768 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atidxx64.dll
+ 2011-12-06 03:06 . 2011-12-06 03:06 6159872 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atidxx32.dll
+ 2012-06-09 03:32 . 2012-03-30 11:35 1918320 c:\windows\system32\drivers\tcpip.sys
+ 2012-07-20 23:25 . 2012-06-06 06:02 1133568 c:\windows\system32\cdosys.dll
- 2011-06-13 04:08 . 2010-11-20 13:25 1133568 c:\windows\system32\cdosys.dll
+ 2011-12-06 02:39 . 2011-12-06 02:39 1113088 c:\windows\system32\atiumd6v.dll
+ 2010-08-04 12:46 . 2011-12-06 02:39 4072960 c:\windows\system32\atiumd6a.dll
+ 2010-08-04 12:46 . 2011-12-06 02:24 7511040 c:\windows\system32\atiumd64.dll
+ 2010-08-04 12:46 . 2011-12-06 02:51 7520768 c:\windows\system32\atidxx64.dll
- 2009-07-14 04:45 . 2011-12-17 01:53 7114300 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-07-21 00:23 7114300 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-09-30 21:27 . 2012-07-19 13:38 2773032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2013641587-3539477181-1548398233-1001-8192.dat
+ 2012-01-19 03:08 . 2012-01-19 03:08 1369872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 03:08 . 2012-01-19 03:08 6429992 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 03:52 . 2012-01-19 03:52 3825952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
+ 2012-03-15 03:17 . 2012-03-15 03:17 5029672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 3512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 4970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 1455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 1515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 1512712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
+ 2011-12-15 04:01 . 2011-12-15 04:01 9793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
+ 2012-06-09 03:33 . 2012-02-10 23:29 2256152 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
+ 2012-07-20 23:19 . 2012-03-21 22:30 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
- 2011-12-04 00:04 . 2011-03-29 22:32 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
+ 2012-01-30 20:50 . 2011-12-25 20:40 5263360 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
- 2011-12-03 23:59 . 2011-05-04 22:31 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 3190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
- 2011-06-13 04:08 . 2010-11-05 01:56 4927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
+ 2012-07-20 23:19 . 2012-03-21 22:30 4927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 9992464 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
- 2011-12-04 00:06 . 2011-07-08 22:31 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 1577232 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 1756432 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
+ 2012-01-19 03:08 . 2012-01-19 03:08 1369872 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2012-01-19 03:08 . 2012-01-19 03:08 6429992 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2012-01-19 03:08 . 2012-01-19 03:08 3790112 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2012-03-15 03:17 . 2012-03-15 03:17 5029672 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 3512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 5201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 1143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2011-12-15 03:08 . 2011-12-15 03:08 6727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 1737496 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
- 2011-12-04 00:04 . 2011-03-29 22:33 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2012-07-20 23:19 . 2012-03-21 22:32 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2012-01-30 20:50 . 2011-12-25 20:42 5255168 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2012-06-09 03:32 . 2012-01-04 02:51 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2011-12-03 23:59 . 2011-05-04 22:32 3190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2012-07-20 23:19 . 2012-03-21 22:32 4927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
- 2011-06-13 04:08 . 2010-11-05 01:58 4927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2012-06-09 03:32 . 2012-01-04 02:51 5925136 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-12-04 00:06 . 2011-07-08 22:33 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-06-09 03:32 . 2012-01-04 02:50 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 1369872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 3512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 5029672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 1711496

c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2012-07-20 23:46 . 2012-07-20 23:47 6429992 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 3825952 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 4970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2011-12-17 00:31 . 2011-12-17 00:31 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 3790112 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2012-07-20 23:45 . 2012-07-20 23:45 5201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-07-20 23:46 . 2012-07-20 23:46 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2011-12-17 00:30 . 2011-12-17 00:30 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-01-07 10:05 . 2011-01-07 10:05 4583936 c:\windows\Installer\c2797.msp
+ 2011-09-15 08:40 . 2011-09-15 08:40 7959552 c:\windows\Installer\c277f.msp
+ 2011-09-15 08:34 . 2011-09-15 08:34 8499712 c:\windows\Installer\c2761.msp
+ 2012-03-23 04:59 . 2012-03-23 04:59 7899648 c:\windows\Installer\b384375.msp
+ 2011-11-01 03:34 . 2011-11-01 03:34 1169920 c:\windows\Installer\b384364.msp
+ 2012-04-04 12:38 . 2012-04-04 12:38 2831360 c:\windows\Installer\84751d4.msp
+ 2012-04-28 11:44 . 2012-04-28 11:44 9101824 c:\windows\Installer\84751c3.msp
+ 2012-04-28 11:44 . 2012-04-28 11:44 9586176 c:\windows\Installer\84751b2.msp
+ 2006-12-01 21:09 . 2006-12-01 21:09 2818048 c:\windows\Installer\6035a58.msi
+ 2012-02-10 23:47 . 2012-02-10 23:47 2851840 c:\windows\Installer\5f1d0.msi
+ 2012-04-22 12:46 . 2012-04-22 12:46 1187328 c:\windows\Installer\34c4502.msp
+ 2012-06-19 02:54 . 2012-06-19 02:54 2239488 c:\windows\Installer\34c44f9.msp
+ 2012-07-17 22:32 . 2012-07-17 22:32 7919616 c:\windows\Installer\34c44e9.msi
+ 2012-03-15 04:26 . 2012-03-15 04:26 4212736 c:\windows\Installer\34c44d5.msp
+ 2012-04-04 12:38 . 2012-04-04 12:38 3620864 c:\windows\Installer\34c44cc.msp
+ 2012-03-14 16:24 . 2012-03-14 16:24 1795584 c:\windows\Installer\34c44bb.msp
+ 2012-04-04 12:37 . 2012-04-04 12:37 2540544 c:\windows\Installer\34c44aa.msp
+ 2012-04-28 11:43 . 2012-04-28 11:43 8459264 c:\windows\Installer\34c4499.msp
+ 2012-02-16 22:45 . 2012-02-16 22:45 2299392 c:\windows\Installer\34c4488.msp
+ 2011-10-26 06:36 . 2011-10-26 06:36 2829312 c:\windows\Installer\1a89b315.msp
+ 2012-01-19 17:06 . 2012-01-19 17:06 1638912 c:\windows\Installer\17a3aab2.msi
+ 2012-01-19 17:12 . 2012-01-19 17:12 1468416 c:\windows\Installer\17a3aaad.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1274880 c:\windows\Installer\17a3aa61.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1283072 c:\windows\Installer\17a3aa55.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1305600 c:\windows\Installer\17a3aa50.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1274880 c:\windows\Installer\17a3aa4b.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1317888 c:\windows\Installer\17a3aa45.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1285632 c:\windows\Installer\17a3aa3f.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1287680 c:\windows\Installer\17a3aa39.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1274368 c:\windows\Installer\17a3aa34.msi
+ 2012-01-19 16:58 . 2012-01-19 16:58 1285632 c:\windows\Installer\17a3aa2e.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1293824 c:\windows\Installer\17a3aa28.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1309184 c:\windows\Installer\17a3aa22.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1282048 c:\windows\Installer\17a3aa1c.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1297920 c:\windows\Installer\17a3aa16.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1290752 c:\windows\Installer\17a3aa11.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1283072 c:\windows\Installer\17a3aa0b.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1281536 c:\windows\Installer\17a3aa05.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1331712 c:\windows\Installer\17a3a9f9.msi
+ 2012-01-19 16:57 . 2012-01-19 16:57 1264128 c:\windows\Installer\17a3a9f4.msi
+ 2012-01-19 16:56 . 2012-01-19 16:56 1278464 c:\windows\Installer\17a3a9ee.msi
+ 2012-01-19 16:56 . 2012-01-19 16:56 1294336 c:\windows\Installer\17a3a9e8.msi
+ 2012-01-19 17:02 . 2012-01-19 17:02 1885184 c:\windows\Installer\17a3a9e3.msi
+ 2012-01-19 17:06 . 2012-01-19 17:06 8300544 c:\windows\Installer\17a3a9d2.msi
+ 2011-11-01 03:34 . 2011-11-01 03:34 4250112 c:\windows\Installer\137615.msp
+ 2011-11-01 03:34 . 2011-11-01 03:34 2247168 c:\windows\Installer\1375f3.msp
+ 2011-12-25 20:24 . 2011-12-25 20:24 8835072 c:\windows\Installer\1375e3.msp
+ 2011-11-11 06:14 . 2011-11-11 06:14 9096192 c:\windows\Installer\1375da.msp
+ 2011-11-01 03:34 . 2011-11-01 03:34 2531840 c:\windows\Installer\1375c9.msp
+ 2011-11-11 06:15 . 2011-11-11 06:15 1795584 c:\windows\Installer\1375b8.msp
+ 2011-11-11 06:16 . 2011-11-11 06:16 8458240 c:\windows\Installer\1375a7.msp
+ 2011-04-27 23:57 . 2011-04-27 23:57 2721280 c:\windows\Installer\137597.msp
+ 2010-09-18 19:51 . 2012-07-20 23:43 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2010-09-18 19:51 . 2011-12-03 23:32 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-08-16 23:49 . 2011-08-16 23:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
+ 2009-10-10 04:10 . 2009-10-10 04:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBE6.DLL
+ 2011-07-06 16:58 . 2011-07-06 16:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGL.DLL
+ 2011-07-26 19:09 . 2011-07-26 19:09 5310848 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
+ 2012-07-21 00:58 . 2012-07-21 00:58 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e286701acf74012d3aa4a21953f03b6b\WindowsBase.ni.dll
+ 2012-06-10 01:32 . 2012-06-10 01:32 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\4e962b1751cd3b039c5186963ad5f130\WindowsBase.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\6ee9d76d9f1e618cd6fb94b13355bcc9\UIAutomationClientsideProviders.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 7037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\28ca4f076264ab07f1d00a6c9623dc49\System.Xml.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 2449408 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\df013cbfec0defc7e9997cdaa90b89bc\System.Xaml.ni.dll
+ 2012-07-21 01:02 . 2012-07-21 01:02 5645824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\950f64ba9fb22ca06c5b2b9cf6f5f4b4\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 5627904 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\6003f51e67a2ae938571bf999135a05a\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 2236416 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bc6df78c506c89659ab7be738179b2ba\System.Web.Services.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 2735616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\cd7c3aed4408c3554c30a8f0236b90e1\System.Speech.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 1918976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\94289b88c5b494f572cd7114fa995487\System.ServiceModel.Activities.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 1579008 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\2dbc7aabd92cc0d470acb455c498d919\System.ServiceModel.Discovery.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 3412992 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\affb28e2d9cc3c19de0758e7e8c68e8f\System.Runtime.Serialization.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 1348096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\b37e6f4b1d742031f328504eb99d0f6c\System.Runtime.DurableInstancing.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\e29ea726977686cc14c3a57e351e8661\System.Printing.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\d2de16284459454472a6875185c64d08\System.Printing.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\b83f2453b4538b2e80fe09cfd94dce00\System.Management.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\60bf6251873ef465abcebeb9a24b7932\System.IdentityModel.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 1098752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 2290176 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\97b0b093e73d3a40aa4fd72f38bd5070\System.Drawing.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 2305024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1225ef41527a975de83f22328d0a3b93\System.Drawing.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 1217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 2402816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\c66de888fa426d24e6ff4c4725aef1b0\System.Deployment.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 2403328 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\ad9ff5d55f7ea22e80c39e0ff0240984\System.Deployment.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 8601600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\0ec8effb7b9d03ae69d37922813bc880\System.Data.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 3390976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\0eb72df497fad5c273ff16f88b0fb950\System.Data.SqlXml.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 1799168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 3386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\86553c1d7f3e66c17fc3e0274de7a2de\System.Data.Linq.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 1257472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\6aea67f24827961ce1d48356715389d8\System.Configuration.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 1007616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\eac19ca5a18a6d08cd247e68b618ba68\System.ComponentModel.Composition.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 5695488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\3869077874ba987242c791b3a18b2f8b\System.Activities.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\cffc381c37033e26f6aecc9de6f4f793\System.Activities.Presentation.ni.dll
+ 2012-07-21 01:01 . 2012-07-21 01:01 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\707f90689caf41ad429bf3ad373503cb\System.Activities.Presentation.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 2064896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\96083298999a677341c98fc2bf01b248\System.Activities.Core.Presentation.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 4233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\36d8641ebc8601162adae65242087d85\ReachFramework.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 4233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\16c9569b75a9f47c38b60ba733936e1a\ReachFramework.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 2056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\9c3d6b3ddef66cac069b6ab1fec514f8\PresentationUI.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 2056192 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\45b96dd6ea9eb2c7f16ea7b5a1ce6a94\PresentationUI.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e8180bc4b9fe2cfc2c4378fc1b24ccd0\Microsoft.VisualBasic.ni.dll
+ 2012-07-21 00:58 . 2012-07-21 00:58 1843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e4d308f69077903e24de92fe4fc06d29\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-07-21 00:57 . 2012-07-21 00:57 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\70e2694fe050bd480b9f61f935ca2da5\Microsoft.VisualBasic.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 1843200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\5f6c79d821e57c78ceeb90006382f5ff\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 1623040 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\16425c121db8083cbaa51f619c9e51e7\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 1526784 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\5284682fcf04815a86233bcaf696da66\Microsoft.Transactions.Bridge.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 3313664 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\4b1d24a96b3882f9e77445e48a7c59ee\Microsoft.JScript.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 2009600 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\1ff62486cdefbfc2dab41b686a9aa4e2\Microsoft.CSharp.ni.dll
+ 2012-07-20 23:48 . 2012-07-20 23:48 3858432 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\1d3c2d83da69c30ba8edf5cfea3c0057\WindowsBase.ni.dll
+ 2012-06-10 01:29 . 2012-06-10 01:29 1063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\551f143f078d91ce131d3007f16d0b19\UIAutomationClientsideProviders.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 9091584 c:\windows\assembly\NativeImages_v4.0.30319_32\System\9cf67ed1b743fbc3dd6b78fbc0595236\System.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 5617664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bd2433e160ce2f19acc8ebe10babae8d\System.Xml.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 1782272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\a181199f8dec15116e1c2eb4a79ec22b\System.Xaml.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 4587008 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\0927d75b05e9d3bfdae478155e8c0742\System.Windows.Forms.DataVisualization.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1885696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\9c2da5bc8e93845d80dc6768efa78de7\System.Web.Services.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 2012160 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\6f608e64178e985270abbf3b5776fcca\System.Speech.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1140736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\a4345e4ff74ec912a5219576049df7fe\System.ServiceModel.Discovery.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1393152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\509dab10fd00e66d750ac92101fa3d7b\System.ServiceModel.Activities.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 2647040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\3fe3910474b3e2a08fca9b09330a74f7\System.Runtime.Serialization.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 1021952 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\ac5d04fd61df57da0f9976440a8c6c58\System.Runtime.DurableInstancing.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\71e3d9751ca6679c5ce2d707ca173373\System.Printing.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\e72d56a0f58bcf95890614700f925609\System.Management.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1072640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\2f4ce144f88caf780421d66027355f77\System.IdentityModel.ni.dll
+ 2012-07-20 23:47 . 2012-07-20 23:47 1666048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\29e48cb144e24a7b4335d1360cc06642\System.Drawing.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\6cd7a0ee3583e91326c73ca8e934a99c\System.DirectoryServices.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1880064 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\e642f8e9415d53aa2bc08fc3af938236\System.Deployment.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 6815232 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\67065dc691dbf9574b3c8e5ac6ec5246\System.Data.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 2550272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\e26c8064282712b32d529e521eabde5d\System.Data.SqlXml.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 1343488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\743d8f183ebfb457d773fc178bdf450d\System.Data.Services.Client.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 2517504 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\dd5b1a261ce2d2206cdd187666ff0246\System.Data.Linq.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 7069184 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\3e4f9b3b78f0f13b7469a14e69d756ef\System.Core.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 4129280 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\5efc7ead86507fe65d83cde64c1f659d\System.Activities.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 3757568 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\4ff694358b3796883fea64e500c27169\System.Activities.Presentation.ni.dll
+ 2012-06-10 01:27 . 2012-06-10 01:27 1546752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\3dc813516761fde757cba8adfbe86bd7\System.Activities.Core.Presentation.ni.dll
+ 2012-07-21 00:41 . 2012-07-21 00:41 2906624 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\47f8023bf6e24604f908ebc472dbe3b6\ReachFramework.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1641984 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\de8350e990fc1123d26665588c7d68c7\PresentationUI.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1139712 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\e3be750f68ac84f84240e86a5e1020af\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\8b670069b8d6cd402bef08a90b42b0be\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1838080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\4cd09961cd45c4c3d3a079f3e81686f5\Microsoft.VisualBasic.ni.dll
+ 2012-06-10 01:26 . 2012-06-10 01:26 1085952 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\15e239f82d2be50ebf7b4ab8364d4320\Microsoft.Transactions.Bridge.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\d58c3dcfe00d95d9b397cd0d3d5db5a7\Microsoft.JScript.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 1616896 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\4bacbc23cd4c0841cf4c18399b30b63c\Microsoft.CSharp.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 4962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\4bcc5a6e9e9d25e068fc304bd7eda6af\WindowsBase.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 1459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\783df1ee260d3df406fa80afa38502d4\UIAutomationClientsideProviders.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\24d1b7ccbedaa3602bae6a6acea9929e\System.Xml.ni.dll
+ 2012-07-21 00:46 . 2012-07-21 00:46 1818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\70cc5e8a5a3372fe0b104c1b20392cd2\System.WorkflowServices.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\aa638ba79250284eb4af4adaa4a4117b\System.Workflow.Runtime.ni.dll
+ 2012-06-10 01:42 . 2012-06-10 01:42 2711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\8ac687b7f43937c81f1c49d14975c740\System.Workflow.Runtime.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\996dc2af3b9e5c111130935f298908c6\System.Workflow.ComponentModel.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 5957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\3bdad8116f2d3b81552cc1f8b028aa6e\System.Workflow.ComponentModel.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\ef43c05e15a8efb4ced6445d1ea35c86\System.Workflow.Activities.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\178797db84abae2eeaed835bd28ca52c\System.Workflow.Activities.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\a32734087cd0db5607d5744ca63235d7\System.Web.Services.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 2292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\6a0b589c4c1467f6b783991842a0f961\System.Web.Services.ni.dll
+ 2012-07-21 00:46 . 2012-07-21 00:46 3336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\af7689e8cbec5d2755497be23c30e293\System.Web.Mobile.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 3044352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\768ea257d75839979b4efb2d49d653f6\System.Web.Extensions.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\2c47bc5d426a7cf9ffef1425eda08184\System.Web.Extensions.Design.ni.dll
+ 2012-06-10 08:51 . 2012-06-10 08:51 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\ca51f026916139f886519fdf6d6c73e9\System.Speech.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\56ee9b5f220583c1c7374a61ad904044\System.ServiceModel.Web.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\2a02b172fa4cf3d93ce7388b67b2a199\System.Runtime.Remoting.ni.dll
+ 2012-07-20 23:33 . 2012-07-20 23:33 1463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\b964519964d302b4977e1380d8d15f1a\System.Printing.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 1472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\fd4a8227569e64d657b80483da8ffe78\System.Management.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 1444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\d1f21a29e79e73b5401fae156f339f67\System.IdentityModel.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll
+ 2012-07-20 23:32 . 2012-07-20 23:32 2318848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\222eb8aa336953a6b0216db2b0c4770d\System.Drawing.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 1230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll
+ 2012-07-21 00:21 . 2012-07-21 00:21 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\6e4e9b07f376d445df1718c0011fa99b\System.Deployment.ni.dll
+ 2012-07-20 23:32 . 2012-07-20 23:32 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\052d9ef010e4ff1dd46772a8671a7dc1\System.Deployment.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 8681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\ea1848ec07c70f3d3c3445f4fbdae87a\System.Data.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 3463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7f6f74f1cc0ea6c40a2d6707b12af818\System.Data.SqlXml.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 2805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 1868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll
+ 2012-06-10 01:41 . 2012-06-10 01:41 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\97429a1c70c94c49850be3f944a32a2e\System.Data.OracleClient.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\2ec3d436b861d35c586b710a570e170d\System.Data.Linq.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7b5364bc524988f7ca5b8c20a24119d\System.Data.Entity.Design.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 3315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\766ce7ee1a2e4f2a85fd90e7572f5d53\System.Core.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\193d03ca60573c92f92d9b07fa5bc243\System.Configuration.ni.dll
+ 2012-07-20 23:33 . 2012-07-20 23:33 3116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\1f88a3693c8ddd527a130aff49dc58b3\ReachFramework.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\b91c32fab08ba62d8c7681cc596895be\PresentationUI.ni.dll
+ 2012-07-20 23:33 . 2012-07-20 23:33 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\210745b8ab0d0efb287eec496271c7db\PresentationUI.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 1884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\4fbff79b8ebf082d08c0080923ff5036\PresentationBuildTasks.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\ac1ba76ed19d668ce53a74593f040453\Narrator.ni.exe
+ 2012-07-21 00:45 . 2012-07-21 00:45 2327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\df2557ab1b8e4389d846e13dc82eba57\MMCEx.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 7970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\61812970c4743b686a67f28687e1dcb6\MIGUIControls.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\1586ee919f86130df9771cf9b8d95d3a\Microsoft.VisualBasic.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 1598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\28ba52bc122353647f1b547506e2df7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f5790625975320b1ffad63b476da9132\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 5350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ca7e936eed0de2436d87b2601ee3a20a\Microsoft.PowerShell.Editor.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\99049fd20c2a5e2779e879c2d95c96a2\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 2176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6caa366471176a065a96d77e8ba01eeb\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-07-21 00:45 . 2012-07-21 00:45 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\3040e2de07177c0a6a66a49de61fdc59\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c057be8bb6614cce013af3721fe34983\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 1516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b2afc0af3d89ae00e973b4e6e9db382c\Microsoft.MediaCenter.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\73bfbdccdc1b0ae87f70a0ec594fee3c\Microsoft.MediaCenter.Bml.ni.dll
+ 2012-07-21 00:43 . 2012-07-21 00:43 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\653e1ee01f10d658d52ca42e17e74283\Microsoft.MediaCenter.UI.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\260d83ee2128a3388051cf416d4450b0\Microsoft.MediaCenter.Shell.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 3213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\094f6a515ca31504f96b4bad5848d692\Microsoft.JScript.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\dac69844e6333484159a4cf544190906\Microsoft.Ink.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\4b362e9e25c33e371f06403edec8849a\Microsoft.Build.Tasks.ni.dll
+ 2012-07-21 00:44 . 2012-07-21 00:44 2682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\33730d136a34d2f4e56a0322f49ee9b6\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f1a0df6a86ceb708c5e50338f12b77ba\Microsoft.Build.Engine.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\6b727c7aa69ae3e04a869908bfbae696\Microsoft.Build.Engine.ni.dll
+ 2012-07-21 00:43 . 2012-07-21 00:43 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\cc4844e7242c1e35d145bf2439f944c5\mcstore.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 4088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\596902addad034f4df2caf291b12d61d\mcepg.ni.dll
+ 2012-06-10 08:48 . 2012-06-10 08:48 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\cdad46cd58389f53308b735e6f29ce1f\ehiVidCtl.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\0423915e377ec85d71ac216fafa77ab0\ehiProxy.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 3434496 c:\windows\assembly\NativeImages_v2.0.50727_64\DellDock\a1366a89083e8d46625256eaf8249db7\DellDock.ni.exe
+ 2012-07-21 00:29 . 2012-07-21 00:29 7026176 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d3ded9525743f5484dd86c7806ec5553\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bb47137b3e002d82dc7c9f97eeec2c93\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7605419cce72fcf91bb7dbc31ebbbca5\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\328780f2db847d458362c28dfcb62bcd\WindowsLive.Writer.Localization.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 3347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\3b452cde57280624e1085699fe8beb03\UIAutomationClientsideProviders.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 7967232 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 5452800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
+ 2012-07-21 00:40 . 2012-07-21 00:40 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\e3e5aa45736b95804bf6bb7eca08a57b\System.WorkflowServices.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\bfa1ffe928b4e3fd6701aabfee7df15e\System.Workflow.Runtime.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\88bfc62ac0195a8ae673c444a3339505\System.Workflow.Runtime.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 4516352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\cfb739be21092d5b8f7b4fde529e6aaa\System.Workflow.ComponentModel.ni.dll
+ 2012-07-20 23:41 . 2012-07-20 23:41 4516352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0efbc299207e35df9199ca98c7209051\System.Workflow.ComponentModel.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\a815fffab98375c1919df68b5b292725\System.Workflow.Activities.ni.dll
+ 2012-07-20 23:41 . 2012-07-20 23:41 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\12f7432045de0943f05f83ba21ae2795\System.Workflow.Activities.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\761fd1afc17f11bf6d49c3a7d16465ca\System.Web.Services.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\59a5af8e3ea07f7980e0476d2da234cd\System.Web.Services.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4a90802e36dee6e10d9bf54832cbf549\System.Web.Mobile.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 2404352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c45efc7ec92c1da8e67eb597559ec39c\System.Web.Extensions.ni.dll
+ 2012-06-10 08:46 . 2012-06-10 08:46 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\83053c3eeb3255672d84c1ddc0ce8ef3\System.Speech.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 1707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 1044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\991dbe40be5b114ed705bb5b48e6b330\System.Printing.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 1051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 8872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 1083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 1591808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\1f7ce0fa41c5f946666d03ff79cd4f7a\System.Deployment.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 6611456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\797dc4c4f342e5edebb87edc6fb7f1a1\System.Data.SqlXml.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 2029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 1378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\0f4e07fb8b1b7e7133a98f478856f70c\System.Data.OracleClient.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2fe1658f05b0a96fe25c956a31d27b06\System.Data.Linq.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 9921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 2297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 2157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87f73de6e080d37be93adfc7d5c31d7a\ReachFramework.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\81aacc474fa8eab0acc6e4be332c1bc7\PresentationUI.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\163517c8a195fb48f7ef6ee17c585bdb\PresentationUI.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 1451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b3f13707cbd5d48aabaa9ef5264c8a30\PresentationBuildTasks.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\17add09c98fa34255142d42697db53df\Narrator.ni.exe
+ 2012-07-21 00:39 . 2012-07-21 00:39 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\21abde8efab609732b2ade3f05234e79\MMCEx.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 6438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\0e7da0df83f0619e3b0e0a7d7ee05fa3\MIGUIControls.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cd9e47effec6549cdec61eb3aef99f7c\Microsoft.Transactions.Bridge.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\99ae5f32cd1dc3618659bc3c77f2b2a9\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2012-06-10 08:45 . 2012-06-10 08:45 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7ee29045f76b1e9577bfc1e0fab723d8\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 1704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\77b5496d214dd5034294b058c0bb0e8d\Microsoft.PowerShell.GPowerShell.ni.dll
+ 2012-07-21 00:39 . 2012-07-21 00:39 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\72765e5fab12761eb6d3f58180fa34d7\Microsoft.PowerShell.Editor.ni.dll
+ 2012-07-21 00:30 . 2012-07-21 00:30 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\8ce1d10f94b40f054017865757552f2d\Microsoft.MediaCenter.UI.ni.dll
+ 2012-07-21 00:30 . 2012-07-21 00:30 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7fab1ec8f5ed6a55a8a73b2c590bd7cd\Microsoft.MediaCenter.ni.dll
+ 2012-06-10 08:43 . 2012-06-10 08:43 2335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\e3d2577e00aef6bc9b3e235eb83634f3\Microsoft.JScript.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\4d381048e3b9c0914c0f72c6aa0a599d\Microsoft.Ink.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3893fa9a19b52dee8b2cc424840d5d08\Microsoft.Build.Tasks.ni.dll
+ 2012-07-21 00:38 . 2012-07-21 00:38 1970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\1d2250044b1ecff755e26ed12f6d27cb\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6b66f52dbd8f87e53c3c9a1de7ca5bba\Microsoft.Build.Engine.ni.dll
+ 2012-07-21 00:30 . 2012-07-21 00:30 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\3a4e56a8d1075cf0af0619c383b3e592\mcstore.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\69b8de21b08c3412422c5918399ed702\mcepg.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 1150464 c:\windows\assembly\NativeImages_v2.0.50727_32\Common\4d126f359ca26bd9b39d1f629afcb6fa\Common.ni.dll
+ 2012-07-21 00:29 . 2012-07-21 00:29 5004800 c:\windows\assembly\NativeImages_v2.0.50727_32\Agent\7c8d3108510557260928f96e449a242b\Agent.ni.exe
+ 2012-06-09 03:33 . 2012-02-10 23:31 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2011-06-13 04:10 . 2010-11-05 01:53 1253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2012-06-09 03:32 . 2012-01-04 02:51 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-12-03 23:59 . 2011-05-04 22:32 3190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-12-04 00:04 . 2011-03-29 22:33 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-07-20 23:19 . 2012-03-21 22:32 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-06-13 04:09 . 2010-11-05 01:53 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2012-01-30 20:50 . 2011-12-25 20:42 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2011-06-13 04:08 . 2010-11-05 01:58 4927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-07-20 23:19 . 2012-03-21 22:32 4927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2012-01-30 20:50 . 2011-12-25 20:40 5263360 c:\windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-06-09 03:33 . 2012-02-10 23:29 2256152 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-06-09 03:33 . 2012-02-10 23:29 3998208 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-12-04 00:06 . 2011-07-08 22:31 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-06-09 03:32 . 2012-01-04 03:34 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-01-30 20:50 . 2011-12-25 20:42 5255168 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 1737496 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2012-06-09 03:33 . 2012-02-10 23:31 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-06-13 04:10 . 2010-11-05 01:53 4218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-12-04 00:06 . 2011-07-08 22:33 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-06-09 03:32 . 2012-01-04 02:50 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-02-11 23:39 . 2012-02-11 23:39 1279864 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-15 06:32 . 2012-07-15 06:32 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-09-25 04:24 . 2011-09-25 04:24 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2012-07-20 23:28 . 2012-06-09 04:41 12873728 c:\windows\SysWOW64\shell32.dll
+ 2012-07-20 23:28 . 2012-04-20 04:56 11020800 c:\windows\SysWOW64\ieframe.dll
+ 2011-12-06 02:56 . 2011-12-06 02:56 19125760 c:\windows\SysWOW64\atioglxx.dll
+ 2011-12-06 02:29 . 2011-12-06 02:29 11484672 c:\windows\SysWOW64\aticaldd.dll
+ 2011-12-05 12:03 . 2011-12-05 12:03 14499328 c:\windows\SysWOW64\amdocl.dll
+ 2009-07-14 02:34 . 2012-07-21 00:19 11010048 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-12-06 02:56 . 2011-12-06 02:56 19125760 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atioglxx.dll
+ 2011-12-06 03:18 . 2011-12-06 03:18 25371136 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atio6axx.dll
+ 2011-12-06 03:45 . 2011-12-06 03:45 10720256 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\atikmdag.sys
+ 2011-12-06 02:34 . 2011-12-06 02:34 13738496 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticaldd64.dll
+ 2011-12-06 02:29 . 2011-12-06 02:29 11484672 c:\windows\system32\DriverStore\FileRepository\c7132079.inf_amd64_neutral_0f27f15b4549b5e3\B129753\aticaldd.dll
+ 2011-12-06 03:45 . 2011-12-06 03:45 10720256 c:\windows\system32\drivers\atikmdag.sys
+ 2011-12-06 03:18 . 2011-12-06 03:18 25371136 c:\windows\system32\atio6axx.dll
+ 2011-12-06 02:34 . 2011-12-06 02:34 13738496 c:\windows\system32\aticaldd64.dll
+ 2011-12-05 12:03 . 2011-12-05 12:03 17580544 c:\windows\system32\amdocl64.dll
+ 2011-09-15 08:39 . 2011-09-15 08:39 11163136 c:\windows\Installer\c2776.msp
+ 2011-09-15 08:38 . 2011-09-15 08:38 10838528 c:\windows\Installer\c276b.msp
+ 2011-09-15 08:37 . 2011-09-15 08:37 34428416 c:\windows\Installer\c2695.msp
+ 2011-09-15 08:37 . 2011-09-15 08:37 16691712 c:\windows\Installer\c2668.msp
+ 2011-11-21 14:42 . 2011-11-21 14:42 33189888 c:\windows\Installer\b384354.msp
+ 2012-01-19 04:20 . 2012-01-19 04:20 11997696 c:\windows\Installer\84751a1.msp
+ 2011-12-15 04:54 . 2011-12-15 04:54 39732736 c:\windows\Installer\8475195.msp
+ 2012-06-09 03:34 . 2012-06-09 03:34 49125888 c:\windows\Installer\8475173.msi
+ 2012-03-22 08:44 . 2012-03-22 08:44 11105280 c:\windows\Installer\3b5cfb.msi
+ 2012-07-20 23:30 . 2012-07-20 23:30 20343808 c:\windows\Installer\34c4479.msp
+ 2012-05-13 00:40 . 2012-05-13 00:40 46973792 c:\windows\Installer\3307e1.msi
+ 2012-02-23 10:51 . 2012-02-23 10:51 20333056 c:\windows\Installer\1a89b30d.msp
+ 2012-01-19 17:07 . 2012-01-19 17:07 17102336 c:\windows\Installer\17a3aab7.msi
+ 2012-01-19 16:55 . 2012-01-19 16:55 11545088 c:\windows\Installer\17a3aaa8.msi
+ 2010-05-20 08:26 . 2010-05-20 08:26 38900224 c:\windows\Installer\13472573.msi
+ 2012-03-18 06:54 . 2012-03-18 06:54 11631616 c:\windows\Installer\12ea73.msi
+ 2012-03-18 06:54 . 2012-03-18 06:54 12938752 c:\windows\Installer\12e9dd.msi
+ 2012-03-18 06:51 . 2012-03-18 06:51 20396032 c:\windows\Installer\12e73f.msi
+ 2011-09-15 10:42 . 2011-09-15 10:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WWLIB.DLL
+ 2012-06-09 03:38 . 2012-06-09 03:38 11880448 c:\windows\assembly\NativeImages_v4.0.30319_64\System\935aea6e7eae16674abdd96a68ec97af\System.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 17355264 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\e883d90a0210bf99ca88f3b4ade53a24\System.Windows.Forms.ni.dll
+ 2012-06-10 08:53 . 2012-06-10 08:53 17291264 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\3e1fa07a8e487acceef1c22275f08779\System.Windows.Forms.ni.dll
+ 2012-06-10 08:55 . 2012-06-10 08:55 24551936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\c4cc7eb7733c4221c32caccfd66ae320\System.ServiceModel.ni.dll
+ 2012-06-10 08:54 . 2012-06-10 08:54 18479616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\9df4e7ae75baa7bbb1af30c8061a6e9b\System.Data.Entity.ni.dll
+ 2012-06-10 01:31 . 2012-06-10 01:31 10440192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b64f213e823a591607c45fac4997801e\System.Core.ni.dll
+ 2012-07-21 01:00 . 2012-07-21 01:00 24407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a3c3789d54894008501ce5891f1eeb40\PresentationFramework.ni.dll
+ 2012-06-10 08:52 . 2012-06-10 08:52 24407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\5eb97ad52c10035367b07021f1febe97\PresentationFramework.ni.dll
+ 2012-06-10 01:32 . 2012-06-10 01:32 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\c750a4d32ab6ff508c2a8825cc7c9e7d\PresentationCore.ni.dll
+ 2012-07-21 00:59 . 2012-07-21 00:59 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\9d69a7a407bbc43a1bcb2da603af5840\PresentationCore.ni.dll
+ 2012-06-09 03:38 . 2012-06-09 03:38 19353600 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll
+ 2012-07-20 23:48 . 2012-07-20 23:48 13198336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c06946b464ae8dd22151e0a6f310c976\System.Windows.Forms.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 18058752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\4f8ecf03aa4a4165e6850d1d67dc445f\System.ServiceModel.ni.dll
+ 2012-06-10 01:28 . 2012-06-10 01:28 13345792 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\31df9a0b86a3259cb02bbe741e501b85\System.Data.Entity.ni.dll
+ 2012-07-20 23:48 . 2012-07-20 23:48 18000896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\bcec0e7db1d027328cc8cd702185fa66\PresentationFramework.ni.dll
+ 2012-07-20 23:48 . 2012-07-20 23:48 11451904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b460188cf6862491550a006c3660e2e6\PresentationCore.ni.dll
+ 2012-06-09 03:39 . 2012-06-09 03:39 14413824 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\1bdf7de454340e0ea9fc455aeaec49d9\mscorlib.ni.dll
+ 2012-06-10 01:39 . 2012-06-10 01:39 10624512 c:\windows\assembly\NativeImages_v2.0.50727_64\System\c40ec0f4cd203c880298f94c0427dd54\System.ni.dll
+ 2012-07-20 23:32 . 2012-07-20 23:32 17379840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\f0d2181352f262008abe7593454194d8\System.Windows.Forms.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 17383424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\dc5bb74eefdbf954cdfb70dd534d5564\System.Windows.Forms.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 15270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\95f38e7485bbe2b73b6055c45196fedd\System.Web.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 15270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\25d1a444d4ec79a2facc05adf9cd43c1\System.Web.ni.dll
+ 2012-06-10 08:47 . 2012-06-10 08:47 23913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\f74b2d1b8cf279ff6bfe479f79e70fe9\System.ServiceModel.ni.dll
+ 2012-06-10 08:49 . 2012-06-10 08:49 11900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\00c4a761d0a5cafc00f34d763fe76ac4\System.Management.Automation.ni.dll
+ 2012-07-21 00:22 . 2012-07-21 00:22 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\582144c0ee317038621aebc626187b56\System.Design.ni.dll
+ 2012-07-20 23:34 . 2012-07-20 23:34 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\15c75736fbf675454ba78309edeb01ee\System.Design.ni.dll
+ 2012-06-10 08:50 . 2012-06-10 08:50 13760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\daaff9fe9c85fc171d426a3cb6766dbb\System.Data.Entity.ni.dll
+ 2012-07-20 23:33 . 2012-07-20 23:33 19198464 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\47054c4d5b7e522c21a9d57797410302\PresentationFramework.ni.dll
+ 2012-07-20 23:32 . 2012-07-20 23:32 16543232 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\3a9d13514a8c4c710fa5ce8e9b5393fe\PresentationCore.ni.dll
+ 2012-06-10 01:38 . 2012-06-10 01:38 15570944 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\f73f0a9c9a83dcd3ff428be509a7992f\mscorlib.ni.dll
+ 2012-07-21 00:42 . 2012-07-21 00:42 22171136 c:\windows\assembly\NativeImages_v2.0.50727_64\MenuSkinning\601d53bc955e420890464c6ac28b129e\MenuSkinning.ni.dll
+ 2012-07-21 00:43 . 2012-07-21 00:43 25470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\0c1f96a4136efe532bbb8eb91d3de300\ehshell.ni.dll
+ 2012-07-21 00:23 . 2012-07-21 00:23 12436480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 12433408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\697251a50a103e3d047178c2ab710593\System.Windows.Forms.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 11833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 11833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\2b07e726c1c19bb8440d82b200fb603b\System.Web.ni.dll
+ 2012-06-10 08:44 . 2012-06-10 08:44 17478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\107779ca2708d2b31b2e1560e47f6d15\System.ServiceModel.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\bd50eea0424b0f1e4c8b3f5cd79494d1\System.Design.ni.dll
+ 2012-07-21 00:24 . 2012-07-21 00:24 10580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c144f89b1f8f292d6940a1b2f8ffbec\System.Design.ni.dll
+ 2012-07-20 23:40 . 2012-07-20 23:40 14340608 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
+ 2012-07-20 23:39 . 2012-07-20 23:39 12237824 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
+ 2012-06-10 01:37 . 2012-06-10 01:37 11492864 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
+ 2011-09-15 08:34 . 2011-09-15 08:34 428804608 c:\windows\Installer\c2755.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 343168]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1675160]
"FAStartup"="" [BU]
"FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2010-02-22 95560]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-26 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-05 559616]
.
c:\users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2010-02-22 20:24 144712 ----a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli FAPassSync
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-14 54824]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-06-22 132608]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-09-25 238848]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-06-22 113792]
R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-11-23 29184]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2010-07-16 9216]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-15 100912]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-06 24176]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-19 1255736]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 284648]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 75808]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2009-03-02 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-06 235520]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-02-22 2409800]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 208536]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-10-18 161168]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [2009-07-02 60416]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [2009-07-01 80896]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [2009-07-04 55808]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]
S2 SwiCardDetectSvc;Sierra Wireless Card Detection Service;c:\program files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [2010-07-06 282992]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-12-06 10720256]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-12-06 327168]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-12-05 95248]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 65264]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-12 151040]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-07-12 69736]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-23 317480]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 481768]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2010-07-16 135168]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001Core.job
- c:\users\Christine\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 23:11]
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001UA.job
- c:\users\Christine\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 23:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2009-12-16 5470208]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-20 487424]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 10.4.81.103 10.4.182.20
FF - ProfilePath - c:\users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\SecuROM\License information*]
"datasecu"=hex:ce,f9,95,4f,5a,58,47,a6,6a,8a,2b,6d,28,48,55,95,76,15,f6,a6,1a,
94,fb,df,87,42,a0,69,8f,b6,1c,dc,63,74,80,0c,f5,0e,ac,32,77,c4,fd,31,23,52,\
"rkeysecu"=hex:08,ef,8c,6c,91,01,87,29,98,78,bb,fc,0b,9a,28,7c
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-23 19:46:15
ComboFix-quarantined-files.txt 2012-07-23 09:46
ComboFix2.txt 2012-01-10 22:03
.
Pre-Run: 88,117,960,704 bytes free
Post-Run: 90,206,662,656 bytes free
.
- - End Of File - - 5E12CEB19B8E7857BAD82716F1CBCDD4

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 23 July 2012 - 05:17 AM

Greetings

I want you to run these next,

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 23 July 2012 - 07:18 AM

TDSSKiller came up clean no results


20:59:20.0820 4232 TDSS rootkit removing tool 2.7.47.0 Jul 20 2012 20:36:30
20:59:22.0832 4232 ============================================================
20:59:22.0832 4232 Current date / time: 2012/07/23 20:59:22.0832
20:59:22.0832 4232 SystemInfo:
20:59:22.0832 4232
20:59:22.0832 4232 OS Version: 6.1.7601 ServicePack: 1.0
20:59:22.0832 4232 Product type: Workstation
20:59:22.0832 4232 ComputerName: CHRISTINE-PC
20:59:22.0832 4232 UserName: Christine
20:59:22.0832 4232 Windows directory: C:\Windows
20:59:22.0832 4232 System windows directory: C:\Windows
20:59:22.0832 4232 Running under WOW64
20:59:22.0832 4232 Processor architecture: Intel x64
20:59:22.0832 4232 Number of processors: 4
20:59:22.0832 4232 Page size: 0x1000
20:59:22.0832 4232 Boot type: Normal boot
20:59:22.0832 4232 ============================================================
20:59:23.0394 4232 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:59:23.0410 4232 ============================================================
20:59:23.0410 4232 \Device\Harddisk0\DR0:
20:59:23.0410 4232 MBR partitions:
20:59:23.0410 4232 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x2328000
20:59:23.0410 4232 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x233B9C5, BlocksNum 0x38049E6B
20:59:23.0425 4232 ============================================================
20:59:23.0441 4232 C: <-> \Device\Harddisk0\DR0\Partition1
20:59:23.0441 4232 ============================================================
20:59:23.0441 4232 Initialize success
20:59:23.0441 4232 ============================================================
20:59:52.0630 2096 ============================================================
20:59:52.0630 2096 Scan started
20:59:52.0630 2096 Mode: Manual;
20:59:52.0630 2096 ============================================================
20:59:53.0285 2096 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
20:59:53.0285 2096 1394ohci - ok
20:59:53.0378 2096 acedrv11 (a3769020f7e8a70fd3e824c050f33306) C:\Windows\system32\drivers\acedrv11.sys
20:59:53.0378 2096 acedrv11 - ok
20:59:53.0425 2096 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
20:59:53.0425 2096 ACPI - ok
20:59:53.0456 2096 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
20:59:53.0503 2096 AcpiPmi - ok
20:59:53.0581 2096 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
20:59:53.0597 2096 adp94xx - ok
20:59:53.0628 2096 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
20:59:53.0628 2096 adpahci - ok
20:59:53.0659 2096 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
20:59:53.0675 2096 adpu320 - ok
20:59:53.0706 2096 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
20:59:53.0706 2096 AeLookupSvc - ok
20:59:53.0815 2096 AESTFilters (a6fb9db8f1a86861d955fd6975977ae0) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe
20:59:53.0815 2096 AESTFilters - ok
20:59:53.0878 2096 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
20:59:53.0893 2096 AFD - ok
20:59:53.0924 2096 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
20:59:53.0924 2096 agp440 - ok
20:59:53.0956 2096 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
20:59:53.0956 2096 ALG - ok
20:59:54.0002 2096 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
20:59:54.0002 2096 aliide - ok
20:59:54.0034 2096 AMD External Events Utility (b5e2434fc851698c1f119cf1c3935a50) C:\Windows\system32\atiesrxx.exe
20:59:54.0034 2096 AMD External Events Utility - ok
20:59:54.0049 2096 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
20:59:54.0065 2096 amdide - ok
20:59:54.0096 2096 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
20:59:54.0112 2096 AmdK8 - ok
20:59:54.0751 2096 amdkmdag (9e3b4946f7e1bca0b763e19d81edbf2c) C:\Windows\system32\DRIVERS\atikmdag.sys
20:59:54.0845 2096 amdkmdag - ok
20:59:54.0970 2096 amdkmdap (b9e1c7b7f1865f99b16ff2e1bb94edb6) C:\Windows\system32\DRIVERS\atikmpag.sys
20:59:55.0016 2096 amdkmdap - ok
20:59:55.0032 2096 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
20:59:55.0032 2096 AmdPPM - ok
20:59:55.0094 2096 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
20:59:55.0094 2096 amdsata - ok
20:59:55.0110 2096 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
20:59:55.0126 2096 amdsbs - ok
20:59:55.0141 2096 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
20:59:55.0141 2096 amdxata - ok
20:59:55.0204 2096 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
20:59:55.0250 2096 AppID - ok
20:59:55.0282 2096 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
20:59:55.0282 2096 AppIDSvc - ok
20:59:55.0313 2096 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
20:59:55.0313 2096 Appinfo - ok
20:59:55.0391 2096 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:59:55.0391 2096 Apple Mobile Device - ok
20:59:55.0438 2096 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
20:59:55.0438 2096 arc - ok
20:59:55.0453 2096 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
20:59:55.0469 2096 arcsas - ok
20:59:55.0484 2096 ASPI32 - ok
20:59:55.0516 2096 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
20:59:55.0531 2096 AsyncMac - ok
20:59:55.0562 2096 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
20:59:55.0562 2096 atapi - ok
20:59:55.0609 2096 AtiHDAudioService (2b3b05c0a7768bf033217eb8f33f9c35) C:\Windows\system32\drivers\AtihdW76.sys
20:59:55.0656 2096 AtiHDAudioService - ok
20:59:55.0687 2096 AtiHdmiService (fb7602c5c508be281368aae0b61b51c6) C:\Windows\system32\drivers\AtiHdmi.sys
20:59:55.0718 2096 AtiHdmiService - ok
20:59:55.0781 2096 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:59:55.0796 2096 AudioEndpointBuilder - ok
20:59:55.0796 2096 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
20:59:55.0812 2096 AudioSrv - ok
20:59:55.0859 2096 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
20:59:55.0890 2096 AxInstSV - ok
20:59:55.0952 2096 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
20:59:55.0968 2096 b06bdrv - ok
20:59:55.0999 2096 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
20:59:55.0999 2096 b57nd60a - ok
20:59:56.0093 2096 BBSvc (825f81a6f7dd073509db101f0ba6dc59) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
20:59:56.0108 2096 BBSvc - ok
20:59:56.0124 2096 BCM42RLY (5c0f919666954885d7760dffe4b29a25) C:\Windows\system32\drivers\BCM42RLY.sys
20:59:56.0124 2096 BCM42RLY - ok
20:59:56.0311 2096 BCM43XX (215dc2fd9cd0fd0bbd7905339779589e) C:\Windows\system32\DRIVERS\bcmwl664.sys
20:59:56.0327 2096 BCM43XX - ok
20:59:56.0467 2096 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
20:59:56.0467 2096 BDESVC - ok
20:59:56.0514 2096 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
20:59:56.0514 2096 Beep - ok
20:59:56.0608 2096 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
20:59:56.0654 2096 BFE - ok
20:59:56.0717 2096 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
20:59:56.0732 2096 BITS - ok
20:59:56.0748 2096 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
20:59:56.0764 2096 blbdrive - ok
20:59:56.0842 2096 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
20:59:56.0842 2096 Bonjour Service - ok
20:59:56.0873 2096 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
20:59:56.0888 2096 bowser - ok
20:59:56.0920 2096 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:59:56.0920 2096 BrFiltLo - ok
20:59:56.0951 2096 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:59:56.0951 2096 BrFiltUp - ok
20:59:56.0966 2096 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
20:59:56.0966 2096 BridgeMP - ok
20:59:56.0998 2096 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
20:59:56.0998 2096 Browser - ok
20:59:57.0013 2096 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
20:59:57.0029 2096 Brserid - ok
20:59:57.0044 2096 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
20:59:57.0060 2096 BrSerWdm - ok
20:59:57.0076 2096 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:59:57.0076 2096 BrUsbMdm - ok
20:59:57.0091 2096 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
20:59:57.0091 2096 BrUsbSer - ok
20:59:57.0154 2096 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
20:59:57.0154 2096 BthEnum - ok
20:59:57.0169 2096 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
20:59:57.0169 2096 BTHMODEM - ok
20:59:57.0200 2096 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
20:59:57.0200 2096 BthPan - ok
20:59:57.0247 2096 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys
20:59:57.0294 2096 BTHPORT - ok
20:59:57.0325 2096 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
20:59:57.0341 2096 bthserv - ok
20:59:57.0356 2096 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys
20:59:57.0403 2096 BTHUSB - ok
20:59:57.0434 2096 btusbflt (2641a3fe3d7b0646308f33b67f3b5300) C:\Windows\system32\drivers\btusbflt.sys
20:59:57.0434 2096 btusbflt - ok
20:59:57.0466 2096 btwaudio (6bcfdc2b5b7f66d484486d4bd4b39a6b) C:\Windows\system32\drivers\btwaudio.sys
20:59:57.0528 2096 btwaudio - ok
20:59:57.0559 2096 btwavdt (82dc8b7c626e526681c1bebed2bc3ff9) C:\Windows\system32\DRIVERS\btwavdt.sys
20:59:57.0590 2096 btwavdt - ok
20:59:57.0715 2096 btwdins (6dde1e97be4d50253dfb9090a6a62524) c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
20:59:57.0715 2096 btwdins - ok
20:59:57.0731 2096 btwl2cap (6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
20:59:57.0731 2096 btwl2cap - ok
20:59:57.0762 2096 btwrchid (28e105ad3b79f440bf94780f507bf66a) C:\Windows\system32\DRIVERS\btwrchid.sys
20:59:57.0824 2096 btwrchid - ok
20:59:57.0840 2096 catchme - ok
20:59:57.0871 2096 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
20:59:57.0871 2096 cdfs - ok
20:59:57.0918 2096 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
20:59:57.0965 2096 cdrom - ok
20:59:58.0012 2096 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
20:59:58.0027 2096 CertPropSvc - ok
20:59:58.0058 2096 cfwids (ed0263b2eb24f0f4e3898036fa1d28a1) C:\Windows\system32\drivers\cfwids.sys
20:59:58.0058 2096 cfwids - ok
20:59:58.0090 2096 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
20:59:58.0090 2096 circlass - ok
20:59:58.0136 2096 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
20:59:58.0152 2096 CLFS - ok
20:59:58.0199 2096 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:59:58.0214 2096 clr_optimization_v2.0.50727_32 - ok
20:59:58.0261 2096 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:59:58.0261 2096 clr_optimization_v2.0.50727_64 - ok
20:59:58.0339 2096 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:59:58.0339 2096 clr_optimization_v4.0.30319_32 - ok
20:59:58.0370 2096 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:59:58.0370 2096 clr_optimization_v4.0.30319_64 - ok
20:59:58.0402 2096 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
20:59:58.0402 2096 CmBatt - ok
20:59:58.0433 2096 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
20:59:58.0433 2096 cmdide - ok
20:59:58.0480 2096 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
20:59:58.0480 2096 CNG - ok
20:59:58.0511 2096 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
20:59:58.0511 2096 Compbatt - ok
20:59:58.0542 2096 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
20:59:58.0542 2096 CompositeBus - ok
20:59:58.0542 2096 COMSysApp - ok
20:59:58.0558 2096 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
20:59:58.0558 2096 crcdisk - ok
20:59:58.0620 2096 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
20:59:58.0620 2096 CryptSvc - ok
20:59:58.0651 2096 CtClsFlt (ed5cf92396a62f4c15110dcdb5e854d9) C:\Windows\system32\DRIVERS\CtClsFlt.sys
20:59:58.0698 2096 CtClsFlt - ok
20:59:58.0760 2096 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
20:59:58.0760 2096 DcomLaunch - ok
20:59:58.0807 2096 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
20:59:58.0807 2096 defragsvc - ok
20:59:58.0838 2096 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
20:59:58.0838 2096 DfsC - ok
20:59:58.0870 2096 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
20:59:58.0885 2096 Dhcp - ok
20:59:58.0916 2096 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
20:59:58.0916 2096 discache - ok
20:59:58.0948 2096 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
20:59:58.0948 2096 Disk - ok
20:59:58.0963 2096 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
20:59:59.0010 2096 Dnscache - ok
20:59:59.0088 2096 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe
20:59:59.0088 2096 DockLoginService - ok
20:59:59.0119 2096 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
20:59:59.0166 2096 dot3svc - ok
20:59:59.0182 2096 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
20:59:59.0182 2096 DPS - ok
20:59:59.0213 2096 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
20:59:59.0213 2096 drmkaud - ok
20:59:59.0275 2096 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
20:59:59.0338 2096 DXGKrnl - ok
20:59:59.0369 2096 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
20:59:59.0369 2096 EapHost - ok
20:59:59.0603 2096 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
20:59:59.0634 2096 ebdrv - ok
20:59:59.0743 2096 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
20:59:59.0743 2096 EFS - ok
20:59:59.0806 2096 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
20:59:59.0821 2096 ehRecvr - ok
20:59:59.0837 2096 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
20:59:59.0837 2096 ehSched - ok
20:59:59.0930 2096 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
20:59:59.0946 2096 elxstor - ok
20:59:59.0962 2096 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
20:59:59.0962 2096 ErrDev - ok
21:00:00.0024 2096 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
21:00:00.0024 2096 EventSystem - ok
21:00:00.0071 2096 ewusbnet (53913561a7089c9a4649ce4e42f6101b) C:\Windows\system32\DRIVERS\ewusbnet.sys
21:00:00.0071 2096 ewusbnet - ok
21:00:00.0102 2096 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
21:00:00.0102 2096 exfat - ok
21:00:00.0149 2096 FACAP (2c1d443e14f376e8331f52f135dca9ef) C:\Windows\system32\DRIVERS\facap.sys
21:00:00.0196 2096 FACAP - ok
21:00:00.0383 2096 FAService (25afc9a2da1939ae295b346d81390c21) c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
21:00:00.0398 2096 FAService - ok
21:00:00.0508 2096 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
21:00:00.0508 2096 fastfat - ok
21:00:00.0586 2096 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
21:00:00.0601 2096 Fax - ok
21:00:00.0617 2096 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
21:00:00.0617 2096 fdc - ok
21:00:00.0648 2096 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
21:00:00.0648 2096 fdPHost - ok
21:00:00.0664 2096 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
21:00:00.0679 2096 FDResPub - ok
21:00:00.0710 2096 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
21:00:00.0710 2096 FileInfo - ok
21:00:00.0710 2096 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
21:00:00.0710 2096 Filetrace - ok
21:00:00.0726 2096 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
21:00:00.0742 2096 flpydisk - ok
21:00:00.0773 2096 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
21:00:00.0773 2096 FltMgr - ok
21:00:00.0866 2096 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
21:00:00.0866 2096 FontCache - ok
21:00:00.0944 2096 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:00:00.0944 2096 FontCache3.0.0.0 - ok
21:00:00.0991 2096 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
21:00:00.0991 2096 FsDepends - ok
21:00:01.0022 2096 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
21:00:01.0022 2096 Fs_Rec - ok
21:00:01.0054 2096 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
21:00:01.0054 2096 fvevol - ok
21:00:01.0085 2096 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
21:00:01.0100 2096 gagp30kx - ok
21:00:01.0116 2096 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:00:01.0163 2096 GEARAspiWDM - ok
21:00:01.0210 2096 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
21:00:01.0210 2096 GoToAssist - ok
21:00:01.0272 2096 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
21:00:01.0288 2096 gpsvc - ok
21:00:01.0303 2096 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
21:00:01.0303 2096 hcw85cir - ok
21:00:01.0350 2096 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
21:00:01.0366 2096 HDAudBus - ok
21:00:01.0381 2096 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
21:00:01.0381 2096 HidBatt - ok
21:00:01.0397 2096 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
21:00:01.0412 2096 HidBth - ok
21:00:01.0412 2096 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
21:00:01.0412 2096 HidIr - ok
21:00:01.0444 2096 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
21:00:01.0444 2096 hidserv - ok
21:00:01.0459 2096 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
21:00:01.0459 2096 HidUsb - ok
21:00:01.0506 2096 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
21:00:01.0553 2096 hkmsvc - ok
21:00:01.0584 2096 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
21:00:01.0584 2096 HomeGroupListener - ok
21:00:01.0615 2096 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
21:00:01.0615 2096 HomeGroupProvider - ok
21:00:01.0646 2096 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
21:00:01.0646 2096 HpSAMD - ok
21:00:01.0709 2096 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
21:00:01.0724 2096 HTTP - ok
21:00:01.0771 2096 hwdatacard (d96a290f699081ae737390c0fe329d7c) C:\Windows\system32\DRIVERS\ewusbmdm.sys
21:00:01.0818 2096 hwdatacard - ok
21:00:01.0849 2096 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
21:00:01.0849 2096 hwpolicy - ok
21:00:01.0880 2096 hwusbdev (e0c7255498640fc64b19aae17fd6f965) C:\Windows\system32\DRIVERS\ewusbdev.sys
21:00:01.0912 2096 hwusbdev - ok
21:00:01.0943 2096 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
21:00:01.0943 2096 i8042prt - ok
21:00:01.0990 2096 iaStor (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
21:00:02.0005 2096 iaStor - ok
21:00:02.0068 2096 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
21:00:02.0068 2096 IAStorDataMgrSvc - ok
21:00:02.0130 2096 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
21:00:02.0177 2096 iaStorV - ok
21:00:02.0317 2096 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:00:02.0317 2096 idsvc - ok
21:00:02.0348 2096 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
21:00:02.0348 2096 iirsp - ok
21:00:02.0426 2096 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
21:00:02.0442 2096 IKEEXT - ok
21:00:02.0473 2096 Impcd (4ff8a2082d78255d2eb169f986bcc981) C:\Windows\system32\DRIVERS\Impcd.sys
21:00:02.0473 2096 Impcd - ok
21:00:02.0504 2096 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
21:00:02.0504 2096 intelide - ok
21:00:02.0536 2096 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
21:00:02.0536 2096 intelppm - ok
21:00:02.0567 2096 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
21:00:02.0582 2096 IPBusEnum - ok
21:00:02.0598 2096 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:00:02.0660 2096 IpFilterDriver - ok
21:00:02.0723 2096 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
21:00:02.0723 2096 iphlpsvc - ok
21:00:02.0754 2096 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
21:00:02.0801 2096 IPMIDRV - ok
21:00:02.0832 2096 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
21:00:02.0832 2096 IPNAT - ok
21:00:02.0957 2096 iPod Service (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
21:00:02.0972 2096 iPod Service - ok
21:00:03.0004 2096 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
21:00:03.0004 2096 IRENUM - ok
21:00:03.0019 2096 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
21:00:03.0035 2096 isapnp - ok
21:00:03.0066 2096 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
21:00:03.0066 2096 iScsiPrt - ok
21:00:03.0097 2096 itecir (8d990a44b4f2b68e2c56a3724ec3eb84) C:\Windows\system32\DRIVERS\itecir.sys
21:00:03.0113 2096 itecir - ok
21:00:03.0160 2096 k57nd60a (08dd34f74d65e1c8f238565570952630) C:\Windows\system32\DRIVERS\k57nd60a.sys
21:00:03.0160 2096 k57nd60a - ok
21:00:03.0175 2096 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
21:00:03.0175 2096 kbdclass - ok
21:00:03.0206 2096 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
21:00:03.0206 2096 kbdhid - ok
21:00:03.0238 2096 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:00:03.0238 2096 KeyIso - ok
21:00:03.0269 2096 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
21:00:03.0269 2096 KSecDD - ok
21:00:03.0284 2096 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
21:00:03.0284 2096 KSecPkg - ok
21:00:03.0316 2096 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
21:00:03.0316 2096 ksthunk - ok
21:00:03.0378 2096 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
21:00:03.0378 2096 KtmRm - ok
21:00:03.0425 2096 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
21:00:03.0456 2096 LanmanServer - ok
21:00:03.0503 2096 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
21:00:03.0503 2096 LanmanWorkstation - ok
21:00:03.0628 2096 LBTServ (7772dfab22611050b79504e671b06e6e) C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
21:00:03.0628 2096 LBTServ - ok
21:00:03.0706 2096 LHidFilt (241f2648adf090e2a10095bd6d6f5dcb) C:\Windows\system32\DRIVERS\LHidFilt.Sys
21:00:03.0768 2096 LHidFilt - ok
21:00:03.0830 2096 libusb0 (acec35f181075b20a5ef4a71958b13df) C:\Windows\system32\drivers\libusb0.sys
21:00:03.0877 2096 libusb0 - ok
21:00:03.0908 2096 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
21:00:03.0908 2096 lltdio - ok
21:00:03.0955 2096 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
21:00:03.0955 2096 lltdsvc - ok
21:00:03.0986 2096 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
21:00:03.0986 2096 lmhosts - ok
21:00:04.0018 2096 LMouFilt (342ed5a4b3326014438f36d22d803737) C:\Windows\system32\DRIVERS\LMouFilt.Sys
21:00:04.0018 2096 LMouFilt - ok
21:00:04.0049 2096 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
21:00:04.0049 2096 LSI_FC - ok
21:00:04.0080 2096 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
21:00:04.0080 2096 LSI_SAS - ok
21:00:04.0111 2096 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:00:04.0111 2096 LSI_SAS2 - ok
21:00:04.0142 2096 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:00:04.0142 2096 LSI_SCSI - ok
21:00:04.0174 2096 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
21:00:04.0174 2096 luafv - ok
21:00:04.0205 2096 massfilter (f093ef8279734393b0a134fb55c5657d) C:\Windows\system32\drivers\massfilter.sys
21:00:04.0205 2096 massfilter - ok
21:00:04.0330 2096 McAfee SiteAdvisor Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
21:00:04.0330 2096 McAfee SiteAdvisor Service - ok
21:00:04.0330 2096 McMPFSvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
21:00:04.0330 2096 McMPFSvc - ok
21:00:04.0330 2096 mcmscsvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:00:04.0330 2096 mcmscsvc - ok
21:00:04.0345 2096 McNaiAnn (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:00:04.0345 2096 McNaiAnn - ok
21:00:04.0345 2096 McNASvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:00:04.0345 2096 McNASvc - ok
21:00:04.0408 2096 McODS (b3914a7c97a81acb1e9befe07e4c387f) C:\Program Files\mcafee\VirusScan\mcods.exe
21:00:04.0408 2096 McODS - ok
21:00:04.0408 2096 McOobeSv (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:00:04.0423 2096 McOobeSv - ok
21:00:04.0423 2096 McProxy (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:00:04.0423 2096 McProxy - ok
21:00:04.0470 2096 McShield (325b166bf78d8a8ad93e44ca7a6fc332) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
21:00:04.0486 2096 McShield - ok
21:00:04.0517 2096 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
21:00:04.0564 2096 Mcx2Svc - ok
21:00:04.0595 2096 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
21:00:04.0595 2096 megasas - ok
21:00:04.0642 2096 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
21:00:04.0642 2096 MegaSR - ok
21:00:04.0673 2096 mfeapfk (ef3acfb7e3f82d5f7cde9ef5f0a4e2e2) C:\Windows\system32\drivers\mfeapfk.sys
21:00:04.0688 2096 mfeapfk - ok
21:00:04.0720 2096 mfeavfk (e7a60bdb4365b561d896019b82fb7dd0) C:\Windows\system32\drivers\mfeavfk.sys
21:00:04.0782 2096 mfeavfk - ok
21:00:04.0798 2096 mfeavfk01 - ok
21:00:04.0829 2096 mfefire (7d8fdc43972d059907e09ee4022f77e8) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
21:00:04.0829 2096 mfefire - ok
21:00:04.0876 2096 mfefirek (670dffe55e2f9ab99d9169c428bcece9) C:\Windows\system32\drivers\mfefirek.sys
21:00:04.0876 2096 mfefirek - ok
21:00:04.0938 2096 mfehidk (1892616b7f9291fd77c3fa0a5811fe9f) C:\Windows\system32\drivers\mfehidk.sys
21:00:04.0954 2096 mfehidk - ok
21:00:04.0969 2096 mfenlfk (1721261c77f6e7a9e0cb51b7d9f31b60) C:\Windows\system32\DRIVERS\mfenlfk.sys
21:00:05.0016 2096 mfenlfk - ok
21:00:05.0016 2096 mferkdet (65776bd8029e409935b90de30bf99526) C:\Windows\system32\drivers\mferkdet.sys
21:00:05.0063 2096 mferkdet - ok
21:00:05.0125 2096 mfevtp (8a78905057308b084eaa29a9fe1b4f58) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
21:00:05.0141 2096 mfevtp - ok
21:00:05.0188 2096 mfewfpk (4f17d8b85b903d96ef7033bb6ef50516) C:\Windows\system32\drivers\mfewfpk.sys
21:00:05.0188 2096 mfewfpk - ok
21:00:05.0234 2096 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
21:00:05.0234 2096 MMCSS - ok
21:00:05.0250 2096 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
21:00:05.0250 2096 Modem - ok
21:00:05.0266 2096 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
21:00:05.0266 2096 monitor - ok
21:00:05.0297 2096 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
21:00:05.0297 2096 mouclass - ok
21:00:05.0328 2096 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
21:00:05.0328 2096 mouhid - ok
21:00:05.0359 2096 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
21:00:05.0359 2096 mountmgr - ok
21:00:05.0390 2096 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
21:00:05.0453 2096 mpio - ok
21:00:05.0453 2096 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
21:00:05.0453 2096 mpsdrv - ok
21:00:05.0531 2096 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
21:00:05.0531 2096 MpsSvc - ok
21:00:05.0578 2096 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
21:00:05.0578 2096 MRxDAV - ok
21:00:05.0609 2096 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:00:05.0624 2096 mrxsmb - ok
21:00:05.0656 2096 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:00:05.0656 2096 mrxsmb10 - ok
21:00:05.0687 2096 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:00:05.0687 2096 mrxsmb20 - ok
21:00:05.0702 2096 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
21:00:05.0702 2096 msahci - ok
21:00:05.0734 2096 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
21:00:05.0734 2096 msdsm - ok
21:00:05.0780 2096 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
21:00:05.0780 2096 MSDTC - ok
21:00:05.0812 2096 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
21:00:05.0812 2096 Msfs - ok
21:00:05.0827 2096 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
21:00:05.0827 2096 mshidkmdf - ok
21:00:05.0858 2096 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
21:00:05.0858 2096 msisadrv - ok
21:00:05.0890 2096 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
21:00:05.0890 2096 MSiSCSI - ok
21:00:05.0905 2096 msiserver - ok
21:00:05.0921 2096 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
21:00:05.0921 2096 MSKSSRV - ok
21:00:05.0952 2096 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
21:00:05.0952 2096 MSPCLOCK - ok
21:00:05.0968 2096 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
21:00:05.0968 2096 MSPQM - ok
21:00:06.0014 2096 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
21:00:06.0014 2096 MsRPC - ok
21:00:06.0030 2096 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
21:00:06.0030 2096 mssmbios - ok
21:00:06.0046 2096 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
21:00:06.0061 2096 MSTEE - ok
21:00:06.0061 2096 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
21:00:06.0077 2096 MTConfig - ok
21:00:06.0092 2096 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
21:00:06.0092 2096 Mup - ok
21:00:06.0155 2096 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
21:00:06.0155 2096 napagent - ok
21:00:06.0202 2096 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
21:00:06.0202 2096 NativeWifiP - ok
21:00:06.0295 2096 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
21:00:06.0295 2096 NDIS - ok
21:00:06.0326 2096 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
21:00:06.0326 2096 NdisCap - ok
21:00:06.0358 2096 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
21:00:06.0358 2096 NdisTapi - ok
21:00:06.0389 2096 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
21:00:06.0389 2096 Ndisuio - ok
21:00:06.0420 2096 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
21:00:06.0467 2096 NdisWan - ok
21:00:06.0498 2096 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
21:00:06.0529 2096 NDProxy - ok
21:00:06.0545 2096 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
21:00:06.0545 2096 NetBIOS - ok
21:00:06.0576 2096 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
21:00:06.0592 2096 NetBT - ok
21:00:06.0623 2096 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:00:06.0623 2096 Netlogon - ok
21:00:06.0654 2096 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
21:00:06.0670 2096 Netman - ok
21:00:06.0716 2096 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
21:00:06.0716 2096 netprofm - ok
21:00:06.0779 2096 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:00:06.0779 2096 NetTcpPortSharing - ok
21:00:06.0826 2096 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
21:00:06.0826 2096 nfrd960 - ok
21:00:06.0872 2096 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
21:00:06.0888 2096 NlaSvc - ok
21:00:06.0904 2096 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
21:00:06.0904 2096 Npfs - ok
21:00:06.0919 2096 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
21:00:06.0919 2096 nsi - ok
21:00:06.0935 2096 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
21:00:06.0935 2096 nsiproxy - ok
21:00:07.0044 2096 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
21:00:07.0060 2096 Ntfs - ok
21:00:07.0169 2096 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
21:00:07.0169 2096 Null - ok
21:00:07.0200 2096 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
21:00:07.0231 2096 nvraid - ok
21:00:07.0262 2096 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
21:00:07.0294 2096 nvstor - ok
21:00:07.0340 2096 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
21:00:07.0340 2096 nv_agp - ok
21:00:07.0434 2096 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:00:07.0434 2096 odserv - ok
21:00:07.0450 2096 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
21:00:07.0465 2096 ohci1394 - ok
21:00:07.0496 2096 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:00:07.0496 2096 ose - ok
21:00:07.0528 2096 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
21:00:07.0543 2096 p2pimsvc - ok
21:00:07.0590 2096 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
21:00:07.0590 2096 p2psvc - ok
21:00:07.0621 2096 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
21:00:07.0637 2096 Parport - ok
21:00:07.0668 2096 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
21:00:07.0668 2096 partmgr - ok
21:00:07.0777 2096 pbfilter (7c0582921913d00180ec2b8518ba135c) C:\Program Files\PeerBlock\pbfilter.sys
21:00:07.0777 2096 pbfilter - ok
21:00:07.0808 2096 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
21:00:07.0808 2096 PcaSvc - ok
21:00:07.0840 2096 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
21:00:07.0840 2096 pci - ok
21:00:07.0871 2096 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
21:00:07.0871 2096 pciide - ok
21:00:07.0902 2096 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
21:00:07.0902 2096 pcmcia - ok
21:00:07.0918 2096 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
21:00:07.0918 2096 pcw - ok
21:00:07.0980 2096 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
21:00:07.0980 2096 PEAUTH - ok
21:00:08.0058 2096 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
21:00:08.0058 2096 PerfHost - ok
21:00:08.0214 2096 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
21:00:08.0230 2096 pla - ok
21:00:08.0292 2096 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
21:00:08.0339 2096 PlugPlay - ok
21:00:08.0370 2096 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
21:00:08.0370 2096 PNRPAutoReg - ok
21:00:08.0401 2096 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
21:00:08.0417 2096 PNRPsvc - ok
21:00:08.0464 2096 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
21:00:08.0464 2096 PolicyAgent - ok
21:00:08.0495 2096 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
21:00:08.0495 2096 Power - ok
21:00:08.0557 2096 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
21:00:08.0588 2096 PptpMiniport - ok
21:00:08.0620 2096 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
21:00:08.0620 2096 Processor - ok
21:00:08.0651 2096 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
21:00:08.0651 2096 ProfSvc - ok
21:00:08.0682 2096 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:00:08.0682 2096 ProtectedStorage - ok
21:00:08.0729 2096 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
21:00:08.0776 2096 Psched - ok
21:00:08.0791 2096 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys
21:00:08.0807 2096 PxHlpa64 - ok
21:00:08.0900 2096 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
21:00:08.0932 2096 ql2300 - ok
21:00:09.0072 2096 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
21:00:09.0072 2096 ql40xx - ok
21:00:09.0103 2096 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
21:00:09.0119 2096 QWAVE - ok
21:00:09.0119 2096 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
21:00:09.0134 2096 QWAVEdrv - ok
21:00:09.0150 2096 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
21:00:09.0166 2096 RasAcd - ok
21:00:09.0197 2096 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
21:00:09.0197 2096 RasAgileVpn - ok
21:00:09.0212 2096 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
21:00:09.0212 2096 RasAuto - ok
21:00:09.0228 2096 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:00:09.0290 2096 Rasl2tp - ok
21:00:09.0322 2096 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
21:00:09.0322 2096 RasMan - ok
21:00:09.0353 2096 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
21:00:09.0353 2096 RasPppoe - ok
21:00:09.0368 2096 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
21:00:09.0368 2096 RasSstp - ok
21:00:09.0415 2096 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
21:00:09.0415 2096 rdbss - ok
21:00:09.0431 2096 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
21:00:09.0431 2096 rdpbus - ok
21:00:09.0446 2096 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:00:09.0446 2096 RDPCDD - ok
21:00:09.0462 2096 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
21:00:09.0462 2096 RDPENCDD - ok
21:00:09.0478 2096 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
21:00:09.0478 2096 RDPREFMP - ok
21:00:09.0556 2096 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
21:00:09.0556 2096 RDPWD - ok
21:00:09.0602 2096 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
21:00:09.0602 2096 rdyboost - ok
21:00:09.0634 2096 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
21:00:09.0634 2096 RemoteAccess - ok
21:00:09.0665 2096 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
21:00:09.0665 2096 RemoteRegistry - ok
21:00:09.0712 2096 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
21:00:09.0727 2096 RFCOMM - ok
21:00:09.0743 2096 rimspci (e20b1907fc72a3664ece21e3c20fc63d) C:\Windows\system32\DRIVERS\rimspe64.sys
21:00:09.0805 2096 rimspci - ok
21:00:09.0821 2096 risdpcie (a6da2b0c8f5bb3f9f5423cff8d6a02d9) C:\Windows\system32\DRIVERS\risdpe64.sys
21:00:09.0821 2096 risdpcie - ok
21:00:09.0836 2096 rixdpcie (6a1cd4674505e6791390a1ab71da1fbe) C:\Windows\system32\DRIVERS\rixdpe64.sys
21:00:09.0883 2096 rixdpcie - ok
21:00:10.0039 2096 RoxMediaDB10 (05fc44d32a144925eae45570029fd6e1) c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
21:00:10.0055 2096 RoxMediaDB10 - ok
21:00:10.0086 2096 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
21:00:10.0086 2096 RpcEptMapper - ok
21:00:10.0102 2096 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
21:00:10.0117 2096 RpcLocator - ok
21:00:10.0164 2096 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
21:00:10.0180 2096 RpcSs - ok
21:00:10.0226 2096 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
21:00:10.0226 2096 rspndr - ok
21:00:10.0242 2096 RxFilter - ok
21:00:10.0273 2096 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:00:10.0273 2096 SamSs - ok
21:00:10.0304 2096 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
21:00:10.0351 2096 sbp2port - ok
21:00:10.0382 2096 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
21:00:10.0382 2096 SCardSvr - ok
21:00:10.0414 2096 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
21:00:10.0492 2096 scfilter - ok
21:00:10.0570 2096 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
21:00:10.0585 2096 Schedule - ok
21:00:10.0601 2096 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
21:00:10.0648 2096 SCPolicySvc - ok
21:00:10.0663 2096 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
21:00:10.0694 2096 SDRSVC - ok
21:00:10.0772 2096 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
21:00:10.0772 2096 SeaPort - ok
21:00:10.0819 2096 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
21:00:10.0819 2096 secdrv - ok
21:00:10.0850 2096 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
21:00:10.0850 2096 seclogon - ok
21:00:10.0882 2096 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
21:00:10.0882 2096 SENS - ok
21:00:10.0913 2096 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
21:00:10.0913 2096 SensrSvc - ok
21:00:10.0928 2096 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
21:00:10.0928 2096 Serenum - ok
21:00:10.0975 2096 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
21:00:10.0975 2096 Serial - ok
21:00:11.0006 2096 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
21:00:11.0022 2096 sermouse - ok
21:00:11.0053 2096 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
21:00:11.0100 2096 SessionEnv - ok
21:00:11.0131 2096 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
21:00:11.0131 2096 sffdisk - ok
21:00:11.0147 2096 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
21:00:11.0162 2096 sffp_mmc - ok
21:00:11.0162 2096 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
21:00:11.0162 2096 sffp_sd - ok
21:00:11.0178 2096 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
21:00:11.0178 2096 sfloppy - ok
21:00:11.0240 2096 SftService (38f88f0df46c4d42125ef721abd7f6b9) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
21:00:11.0256 2096 SftService - ok
21:00:11.0303 2096 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
21:00:11.0303 2096 SharedAccess - ok
21:00:11.0350 2096 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
21:00:11.0350 2096 ShellHWDetection - ok
21:00:11.0396 2096 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:00:11.0396 2096 SiSRaid2 - ok
21:00:11.0443 2096 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
21:00:11.0443 2096 SiSRaid4 - ok
21:00:11.0459 2096 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
21:00:11.0474 2096 Smb - ok
21:00:11.0521 2096 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
21:00:11.0521 2096 SNMPTRAP - ok
21:00:11.0537 2096 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
21:00:11.0537 2096 spldr - ok
21:00:11.0584 2096 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
21:00:11.0599 2096 Spooler - ok
21:00:11.0818 2096 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
21:00:11.0833 2096 sppsvc - ok
21:00:11.0927 2096 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
21:00:11.0942 2096 sppuinotify - ok
21:00:12.0020 2096 sprtsvc_DellSupportCenter (d630b6f2e8379b6f10dc16e82a426552) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
21:00:12.0020 2096 sprtsvc_DellSupportCenter - ok
21:00:12.0083 2096 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
21:00:12.0098 2096 srv - ok
21:00:12.0145 2096 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
21:00:12.0145 2096 srv2 - ok
21:00:12.0176 2096 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
21:00:12.0176 2096 srvnet - ok
21:00:12.0208 2096 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
21:00:12.0208 2096 SSDPSRV - ok
21:00:12.0239 2096 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
21:00:12.0239 2096 SstpSvc - ok
21:00:12.0348 2096 STacSV (da7702025dfd169b909c4da3126762cc) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe
21:00:12.0364 2096 STacSV - ok
21:00:12.0395 2096 Steam Client Service - ok
21:00:12.0410 2096 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
21:00:12.0410 2096 stexstor - ok
21:00:12.0473 2096 STHDA (caf5a9708671b14b9670260735b22c4e) C:\Windows\system32\DRIVERS\stwrt64.sys
21:00:12.0535 2096 STHDA - ok
21:00:12.0598 2096 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
21:00:12.0613 2096 stisvc - ok
21:00:12.0644 2096 stllssvr (ff5eb78af7dfb68c2fb363537aaf753e) c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
21:00:12.0660 2096 stllssvr - ok
21:00:12.0691 2096 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
21:00:12.0691 2096 swenum - ok
21:00:12.0754 2096 SwiCardDetectSvc (ab416c4f86632b8d9e084a817c00b2c3) C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe
21:00:12.0769 2096 SwiCardDetectSvc - ok
21:00:12.0816 2096 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
21:00:12.0816 2096 swprv - ok
21:00:12.0863 2096 SynTP (868dfb220a18312a12cef01ba9ac069b) C:\Windows\system32\DRIVERS\SynTP.sys
21:00:12.0878 2096 SynTP - ok
21:00:12.0972 2096 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
21:00:12.0988 2096 SysMain - ok
21:00:13.0097 2096 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
21:00:13.0097 2096 TabletInputService - ok
21:00:13.0144 2096 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
21:00:13.0190 2096 TapiSrv - ok
21:00:13.0206 2096 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
21:00:13.0206 2096 TBS - ok
21:00:13.0362 2096 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
21:00:13.0378 2096 Tcpip - ok
21:00:13.0565 2096 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
21:00:13.0580 2096 TCPIP6 - ok
21:00:13.0643 2096 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
21:00:13.0690 2096 tcpipreg - ok
21:00:13.0721 2096 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
21:00:13.0736 2096 TDPIPE - ok
21:00:13.0768 2096 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
21:00:13.0814 2096 TDTCP - ok
21:00:13.0861 2096 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
21:00:13.0908 2096 tdx - ok
21:00:13.0939 2096 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
21:00:13.0939 2096 TermDD - ok
21:00:13.0986 2096 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
21:00:14.0033 2096 TermService - ok
21:00:14.0048 2096 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
21:00:14.0064 2096 Themes - ok
21:00:14.0080 2096 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
21:00:14.0080 2096 THREADORDER - ok
21:00:14.0095 2096 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
21:00:14.0095 2096 TrkWks - ok
21:00:14.0142 2096 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
21:00:14.0158 2096 TrustedInstaller - ok
21:00:14.0189 2096 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:00:14.0236 2096 tssecsrv - ok
21:00:14.0282 2096 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
21:00:14.0282 2096 TsUsbFlt - ok
21:00:14.0329 2096 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
21:00:14.0329 2096 tunnel - ok
21:00:14.0360 2096 TurboB (825e7a1f48fb8bcfba27c178aab4e275) C:\Windows\system32\DRIVERS\TurboB.sys
21:00:14.0360 2096 TurboB - ok
21:00:14.0423 2096 TurboBoost (b206be1174d5964d49a56bb6c4e0524a) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
21:00:14.0423 2096 TurboBoost - ok
21:00:14.0454 2096 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
21:00:14.0454 2096 uagp35 - ok
21:00:14.0501 2096 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
21:00:14.0563 2096 udfs - ok
21:00:14.0579 2096 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
21:00:14.0579 2096 UI0Detect - ok
21:00:14.0626 2096 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
21:00:14.0626 2096 uliagpkx - ok
21:00:14.0672 2096 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
21:00:14.0672 2096 umbus - ok
21:00:14.0672 2096 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
21:00:14.0672 2096 UmPass - ok
21:00:14.0719 2096 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
21:00:14.0719 2096 upnphost - ok
21:00:14.0735 2096 USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
21:00:14.0735 2096 USBAAPL64 - ok
21:00:14.0766 2096 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
21:00:14.0813 2096 usbccgp - ok
21:00:14.0844 2096 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
21:00:14.0844 2096 usbcir - ok
21:00:14.0875 2096 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
21:00:14.0922 2096 usbehci - ok
21:00:14.0953 2096 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
21:00:14.0984 2096 usbhub - ok
21:00:15.0000 2096 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
21:00:15.0000 2096 usbohci - ok
21:00:15.0031 2096 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
21:00:15.0047 2096 usbprint - ok
21:00:15.0078 2096 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
21:00:15.0078 2096 usbscan - ok
21:00:15.0109 2096 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:00:15.0109 2096 USBSTOR - ok
21:00:15.0125 2096 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
21:00:15.0125 2096 usbuhci - ok
21:00:15.0172 2096 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
21:00:15.0172 2096 usbvideo - ok
21:00:15.0203 2096 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
21:00:15.0203 2096 UxSms - ok
21:00:15.0250 2096 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:00:15.0250 2096 VaultSvc - ok
21:00:15.0265 2096 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
21:00:15.0265 2096 vdrvroot - ok
21:00:15.0312 2096 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
21:00:15.0312 2096 vds - ok
21:00:15.0343 2096 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
21:00:15.0343 2096 vga - ok
21:00:15.0359 2096 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
21:00:15.0359 2096 VgaSave - ok
21:00:15.0374 2096 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
21:00:15.0421 2096 vhdmp - ok
21:00:15.0437 2096 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
21:00:15.0452 2096 viaide - ok
21:00:15.0468 2096 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
21:00:15.0468 2096 volmgr - ok
21:00:15.0499 2096 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
21:00:15.0499 2096 volmgrx - ok
21:00:15.0546 2096 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
21:00:15.0546 2096 volsnap - ok
21:00:15.0593 2096 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
21:00:15.0593 2096 vsmraid - ok
21:00:15.0702 2096 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
21:00:15.0718 2096 VSS - ok
21:00:15.0796 2096 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
21:00:15.0811 2096 vwifibus - ok
21:00:15.0827 2096 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
21:00:15.0827 2096 vwififlt - ok
21:00:15.0874 2096 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
21:00:15.0874 2096 W32Time - ok
21:00:15.0920 2096 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
21:00:15.0920 2096 WacomPen - ok
21:00:15.0952 2096 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
21:00:16.0014 2096 WANARP - ok
21:00:16.0014 2096 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
21:00:16.0061 2096 Wanarpv6 - ok
21:00:16.0170 2096 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
21:00:16.0217 2096 WatAdminSvc - ok
21:00:16.0326 2096 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
21:00:16.0404 2096 wbengine - ok
21:00:16.0498 2096 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
21:00:16.0498 2096 WbioSrvc - ok
21:00:16.0560 2096 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
21:00:16.0560 2096 wcncsvc - ok
21:00:16.0576 2096 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
21:00:16.0591 2096 WcsPlugInService - ok
21:00:16.0622 2096 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
21:00:16.0638 2096 Wd - ok
21:00:16.0685 2096 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
21:00:16.0700 2096 Wdf01000 - ok
21:00:16.0716 2096 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
21:00:16.0716 2096 WdiServiceHost - ok
21:00:16.0716 2096 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
21:00:16.0716 2096 WdiSystemHost - ok
21:00:16.0747 2096 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
21:00:16.0763 2096 WebClient - ok
21:00:16.0778 2096 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
21:00:16.0794 2096 Wecsvc - ok
21:00:16.0810 2096 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
21:00:16.0810 2096 wercplsupport - ok
21:00:16.0825 2096 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
21:00:16.0825 2096 WerSvc - ok
21:00:16.0856 2096 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
21:00:16.0872 2096 WfpLwf - ok
21:00:16.0919 2096 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
21:00:16.0966 2096 WimFltr - ok
21:00:16.0997 2096 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
21:00:16.0997 2096 WIMMount - ok
21:00:17.0028 2096 WinDefend - ok
21:00:17.0044 2096 WinHttpAutoProxySvc - ok
21:00:17.0090 2096 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
21:00:17.0090 2096 Winmgmt - ok
21:00:17.0231 2096 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
21:00:17.0278 2096 WinRM - ok
21:00:17.0434 2096 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
21:00:17.0434 2096 WinUsb - ok
21:00:17.0512 2096 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
21:00:17.0527 2096 Wlansvc - ok
21:00:17.0839 2096 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:00:17.0886 2096 wlidsvc - ok
21:00:17.0917 2096 wltrysvc (a96d6c0613dcf84f2d07faeb75663072) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
21:00:17.0933 2096 wltrysvc - ok
21:00:18.0042 2096 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
21:00:18.0042 2096 WmiAcpi - ok
21:00:18.0104 2096 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
21:00:18.0120 2096 wmiApSrv - ok
21:00:18.0151 2096 WMPNetworkSvc - ok
21:00:18.0167 2096 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
21:00:18.0182 2096 WPCSvc - ok
21:00:18.0214 2096 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
21:00:18.0214 2096 WPDBusEnum - ok
21:00:18.0229 2096 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
21:00:18.0229 2096 ws2ifsl - ok
21:00:18.0245 2096 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll
21:00:18.0245 2096 wscsvc - ok
21:00:18.0245 2096 WSearch - ok
21:00:18.0401 2096 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
21:00:18.0416 2096 wuauserv - ok
21:00:18.0541 2096 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
21:00:18.0541 2096 WudfPf - ok
21:00:18.0572 2096 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:00:18.0572 2096 WUDFRd - ok
21:00:18.0604 2096 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
21:00:18.0650 2096 wudfsvc - ok
21:00:18.0682 2096 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
21:00:18.0682 2096 WwanSvc - ok
21:00:18.0744 2096 ZTEusbmdm6k (9313fe79ff3240fa0a73fbe6015b6887) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
21:00:18.0791 2096 ZTEusbmdm6k - ok
21:00:18.0806 2096 ZTEusbnet (788e574905a3e3a08fc218cadedca71f) C:\Windows\system32\DRIVERS\ZTEusbnet.sys
21:00:18.0853 2096 ZTEusbnet - ok
21:00:18.0869 2096 ZTEusbnmea (9313fe79ff3240fa0a73fbe6015b6887) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
21:00:18.0869 2096 ZTEusbnmea - ok
21:00:18.0900 2096 ZTEusbser6k (9313fe79ff3240fa0a73fbe6015b6887) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
21:00:18.0947 2096 ZTEusbser6k - ok
21:00:18.0978 2096 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
21:00:19.0212 2096 \Device\Harddisk0\DR0 - ok
21:00:19.0212 2096 Boot (0x1200) (2aaeeb6bc7cd5bf45ae4e2585f35019f) \Device\Harddisk0\DR0\Partition0
21:00:19.0212 2096 \Device\Harddisk0\DR0\Partition0 - ok
21:00:19.0228 2096 Boot (0x1200) (b68b2e7813974c241b23aa7c14f5a568) \Device\Harddisk0\DR0\Partition1
21:00:19.0228 2096 \Device\Harddisk0\DR0\Partition1 - ok
21:00:19.0228 2096 ============================================================
21:00:19.0228 2096 Scan finished
21:00:19.0228 2096 ============================================================
21:00:19.0243 4724 Detected object count: 0
21:00:19.0243 4724 Actual detected object count: 0
21:00:47.0089 3852 Deinitialize success

#8 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 23 July 2012 - 07:19 AM

Here is the log for aswMBR


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-23 21:00:56
-----------------------------
21:00:56.160 OS Version: Windows x64 6.1.7601 Service Pack 1
21:00:56.160 Number of processors: 4 586 0x2505
21:00:56.160 ComputerName: CHRISTINE-PC UserName: Christine
21:00:57.564 Initialize success
21:08:31.964 AVAST engine defs: 12072300
21:17:33.269 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:17:33.269 Disk 0 Vendor: Hitachi_ PC4O Size: 476940MB BusType: 3
21:17:33.285 Disk 0 MBR read successfully
21:17:33.301 Disk 0 MBR scan
21:17:33.301 Disk 0 Windows VISTA default MBR code
21:17:33.316 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
21:17:33.316 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 18000 MB offset 80325
21:17:33.332 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 458899 MB offset 36944325
21:17:33.363 Disk 0 scanning C:\Windows\system32\drivers
21:17:46.701 Service scanning
21:18:11.427 Modules scanning
21:18:11.443 Disk 0 trace - called modules:
21:18:11.474 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
21:18:11.474 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006638060]
21:18:11.490 3 CLASSPNP.SYS[fffff88001a5143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062e6050]
21:18:13.159 AVAST engine scan C:\Windows
21:18:16.934 AVAST engine scan C:\Windows\system32
21:22:56.690 AVAST engine scan C:\Windows\system32\drivers
21:23:24.023 AVAST engine scan C:\Users\Christine
22:10:28.312 AVAST engine scan C:\ProgramData
22:14:29.791 Scan finished successfully
22:15:32.915 Disk 0 MBR has been saved successfully to "C:\Users\Christine\Desktop\MBR.dat"
22:15:32.946 The log file has been saved successfully to "C:\Users\Christine\Desktop\aswMBR.txt"

#9 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 23 July 2012 - 12:46 PM

Greetings

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

Edited by gringo_pr, 23 July 2012 - 12:53 PM.

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#10 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 23 July 2012 - 04:20 PM

I ran the script as requested. I got the following error through every stage of combofix. "Windows cannot find 'NIRKMD'. Make sure you typed the name correctly, and then try again."

After combofix finished, I tried google and was redirected. I restarted my computer, tried google again. First attempt was fine, second attempt was redirected.

Here is my combofix log.


ComboFix 12-07-21.01 - Christine 24/07/2012 6:57.4.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.6133.4261 [GMT 10:00]
Running from: c:\users\Christine\Desktop\ComboFix.exe
Command switches used :: c:\users\Christine\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-23 21:06 . 2012-07-23 21:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-07-23 21:06 . 2012-07-23 21:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-21 07:30 . 2012-07-21 07:35 -------- d-----w- c:\windows\tmp
2012-07-20 23:50 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-20 23:29 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-07-20 23:29 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-07-20 23:29 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-07-20 23:29 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-07-20 23:29 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-07-20 23:29 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2012-07-20 23:29 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-07-20 23:28 . 2012-04-20 05:42 12297216 ----a-w- c:\windows\system32\ieframe.dll
2012-07-20 23:28 . 2012-04-20 05:42 9059840 ----a-w- c:\windows\system32\mshtml.dll
2012-07-20 23:28 . 2012-04-20 05:42 735744 ----a-w- c:\windows\system32\msfeeds.dll
2012-07-20 23:28 . 2012-04-20 04:57 525312 ----a-w- c:\program files (x86)\Internet Explorer\jsdbgui.dll
2012-07-20 23:28 . 2012-04-20 05:42 505344 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
2012-07-20 23:25 . 2012-04-20 03:45 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-20 23:22 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-20 23:22 . 2012-05-04 11:06 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-07-20 23:22 . 2012-05-04 10:03 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-07-20 23:22 . 2012-05-04 10:03 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-07-20 23:22 . 2012-06-02 05:50 458704 ----a-w- c:\windows\system32\drivers\cng.sys
2012-07-20 23:22 . 2012-06-02 05:45 340992 ----a-w- c:\windows\system32\schannel.dll
2012-07-20 23:22 . 2012-06-02 05:44 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-20 23:22 . 2012-06-02 05:48 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-07-20 23:22 . 2012-06-02 04:39 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-07-20 23:22 . 2012-06-02 04:40 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2012-07-20 23:22 . 2012-06-02 05:48 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-20 23:22 . 2012-06-02 04:40 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-07-20 23:22 . 2012-06-02 04:34 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-07-20 23:21 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-07-20 23:21 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-20 23:21 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-20 23:21 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-07-20 23:21 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-07-20 23:21 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-07-20 23:20 . 2012-04-07 12:31 3216384 ----a-w- c:\windows\system32\msi.dll
2012-07-20 23:20 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2012-07-20 23:20 . 2012-04-17 05:31 918016 ----a-w- c:\windows\system32\jscript.dll
2012-07-20 23:19 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-07-20 23:19 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-07-20 23:19 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-07-20 23:19 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-07-20 23:06 . 2012-07-21 06:19 16200 ----a-w- c:\windows\stinger.sys
2012-07-20 23:05 . 2012-07-21 06:35 -------- d-----w- c:\program files (x86)\stinger
2012-07-09 08:44 . 2012-07-10 01:27 -------- d-----w- c:\program files (x86)\Telltale Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-09 08:43 . 2012-02-10 09:55 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-07-03 03:46 . 2010-09-18 19:40 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-02 17:19 . 2010-09-21 15:12 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-06-02 22:19 . 2012-06-19 14:49 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 14:49 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 14:49 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 14:49 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 14:49 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 14:49 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 14:49 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 05:19 . 2012-06-19 14:49 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 05:15 . 2012-06-19 14:49 36864 ----a-w- c:\windows\system32\wuapp.exe
.
.
((((((((((((((((((((((((((((( SnapShot_2012-07-23_09.42.30 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-09-18 19:20 . 2012-07-23 08:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-18 19:20 . 2012-07-23 20:57 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-18 19:20 . 2012-07-23 08:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-09-18 19:20 . 2012-07-23 20:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-23 08:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-23 20:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-19 02:40 . 2012-07-23 20:50 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-19 02:40 . 2012-07-23 09:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-19 02:40 . 2012-07-23 20:50 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-19 02:40 . 2012-07-23 09:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-19 02:40 . 2012-07-23 20:47 323100 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 343168]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1675160]
"FAStartup"="" [BU]
"FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2010-02-22 95560]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-26 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-05 559616]
.
c:\users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2010-02-22 20:24 144712 ----a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli FAPassSync
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-14 54824]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-06-22 132608]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [2008-09-25 238848]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-06-22 113792]
R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-11-23 29184]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2010-07-16 9216]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-15 100912]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-06 24176]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-19 1255736]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 284648]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 75808]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 191616]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2009-03-02 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-06 235520]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-02-22 2409800]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 208536]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-10-18 161168]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [2009-07-02 60416]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [2009-07-01 80896]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [2009-07-04 55808]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]
S2 SwiCardDetectSvc;Sierra Wireless Card Detection Service;c:\program files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [2010-07-06 282992]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-12-06 10720256]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-12-06 327168]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-12-05 95248]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 65264]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-12 151040]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-07-12 69736]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-23 317480]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 481768]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2010-07-16 135168]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 13617843
*NewlyCreated* - ASWMBR
*Deregistered* - 13617843
*Deregistered* - aswMBR
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001Core.job
- c:\users\Christine\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 23:11]
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001UA.job
- c:\users\Christine\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 23:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2009-12-16 5470208]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-20 487424]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1060933&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\SecuROM\License information*]
"datasecu"=hex:ce,f9,95,4f,5a,58,47,a6,6a,8a,2b,6d,28,48,55,95,76,15,f6,a6,1a,
94,fb,df,87,42,a0,69,8f,b6,1c,dc,63,74,80,0c,f5,0e,ac,32,77,c4,fd,31,23,52,\
"rkeysecu"=hex:08,ef,8c,6c,91,01,87,29,98,78,bb,fc,0b,9a,28,7c
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-24 07:09:17
ComboFix-quarantined-files.txt 2012-07-23 21:09
ComboFix2.txt 2012-07-23 09:46
ComboFix3.txt 2012-01-10 22:03
.
Pre-Run: 90,199,150,592 bytes free
Post-Run: 90,185,248,768 bytes free
.
- - End Of File - - 7CEC4DAD873AA556ABC6F6D8D0E4A361

#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 23 July 2012 - 05:01 PM

Hello

Lets get a deeper look into the system and see if something shows up.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTL.txt in your next reply.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 23 July 2012 - 05:42 PM

OTL logfile created on: 24/07/2012 8:30:35 AM - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Christine\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

5.99 Gb Total Physical Memory | 4.59 Gb Available Physical Memory | 76.61% Memory free
11.98 Gb Paging File | 9.68 Gb Available in Paging File | 80.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 448.14 Gb Total Space | 84.10 Gb Free Space | 18.77% Space Free | Partition Type: NTFS

Computer Name: CHRISTINE-PC | User Name: Christine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Christine\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
PRC - c:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\libglesv2.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\libegl.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\avutil-51.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\avformat-54.dll ()
MOD - C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\avcodec-54.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Windows\SysWOW64\FAIEExtension.dll ()
MOD - C:\Windows\SysWOW64\FAib.dll ()
MOD - C:\Windows\SysWOW64\FACrashRpt.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (McODS) -- C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) -- C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (McProxy) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (wltrysvc) -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Dell Inc.)
SRV:64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (btwdins) -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (DockLoginService) -- C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (SftService) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SwiCardDetectSvc) -- C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe (Sierra Wireless, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (FAService) -- c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe (IDT, Inc.)
SRV - (RoxMediaDB10) -- c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (sprtsvc_DellSupportCenter) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (libusb0) -- C:\Windows\SysNative\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) -- C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) -- C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (pbfilter) -- C:\Program Files\PeerBlock\pbfilter.sys ()
DRV:64bit: - (ZTEusbnet) -- C:\Windows\SysNative\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV:64bit: - (ZTEusbser6k) -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (massfilter) -- C:\Windows\SysNative\drivers\massfilter.sys (ZTE Incorporated)
DRV:64bit: - (itecir) -- C:\Windows\SysNative\drivers\itecir.sys (ITE Tech. Inc. )
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (acedrv11) -- C:\Windows\SysNative\drivers\acedrv11.sys (Protect Software GmbH)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (rixdpcie) -- C:\Windows\SysNative\drivers\rixdpe64.sys (REDC)
DRV:64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimspe64.sys (REDC)
DRV:64bit: - (risdpcie) -- C:\Windows\SysNative\drivers\risdpe64.sys (REDC)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (k57nd60a) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ewusbnet) -- C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwusbdev) -- C:\Windows\SysNative\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (FACAP) -- C:\Windows\SysNative\drivers\facap.sys (Sensible Vision )
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (libusb0) -- C:\Windows\SysWOW64\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) -- C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (ASPI32) -- C:\Windows\SysWow64\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {D21E7B50-2E3F-4E38-A646-EF3D7DE23BCC}
IE:64bit: - HKLM\..\SearchScopes\{D21E7B50-2E3F-4E38-A646-EF3D7DE23BCC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {5EE3A866-CBA1-4D90-BD08-0A0F3DE3ADCC}
IE - HKLM\..\SearchScopes\{5EE3A866-CBA1-4D90-BD08-0A0F3DE3ADCC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\SearchScopes,DefaultScope = {5EE3A866-CBA1-4D90-BD08-0A0F3DE3ADCC}
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://search.yahoo.com/search?fr=chr-bfg&q={searchTerms}&ei=UTF-8
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\SearchScopes\{5EE3A866-CBA1-4D90-BD08-0A0F3DE3ADCC}: "URL" = http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\SearchScopes\{6AA97CFF-83D7-4EF0-8F6D-C685A833265B}: "URL" = http://ca.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Freecorder Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1060933&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {6847DFAE-037A-400c-A524-27F0A281B692}:2.1
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.1.3
FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.2.1.3
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..keyword.URL: "http://ca.search.yahoo.com/search?fr=mcafee&p="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: C:\Program Files (x86)\Download Manager\npfpdlm.dll (IGN Entertainment)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Christine\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Christine\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/02/24 08:13:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/03/19 17:38:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/18 17:30:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/03/18 17:30:31 | 000,000,000 | ---D | M]

[2010/10/12 07:09:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christine\AppData\Roaming\Mozilla\Extensions
[2011/10/23 19:18:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions
[2011/03/18 06:30:36 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/10/23 00:09:09 | 000,000,000 | ---D | M] (Toolbar - Big Fish Games) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}
[2011/03/18 07:06:32 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/03/18 06:57:45 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/10/23 19:18:26 | 000,000,000 | ---D | M] (Default Manager) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\DefaultManager@Microsoft
[2011/03/18 06:30:36 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com
[2010/10/21 04:40:12 | 000,000,923 | ---- | M] () -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\searchplugins\conduit.xml
[2012/03/18 18:08:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/19 17:38:40 | 000,000,000 | ---D | M] (McAfee ScriptScan for Firefox) -- C:\PROGRAM FILES (X86)\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/02/24 08:13:27 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/03/13 14:38:06 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2012/03/18 16:54:26 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/03/13 15:38:05 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/03/13 15:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 15:38:05 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/03/13 15:38:05 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/01/14 14:04:23 | 000,002,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/03/13 15:38:05 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Christine\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Logitech Device Detection (Enabled) = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\npLogitechDeviceDetection.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Christine\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: IGN Download Manager Plug-in (Enabled) = C:\Program Files (x86)\Download Manager\npfpdlm.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Christine\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: Logitech Device Detection = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\
CHR - Extension: SiteAdvisor = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: AdBlock = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.38_0\
CHR - Extension: Picnik = C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\

O1 HOSTS File: ([2012/01/11 08:01:36 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20111230144700.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120318225133.dll (McAfee, Inc.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Toolbar - Big Fish Games) - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Toolbar - Big Fish Games) - {C7C9FC25-88B0-4682-9C9F-2608E9117647} - C:\Program Files (x86)\bfgbartb\BfgBarDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/popzuma/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://inforapac.webex.com/client/T27L10NSP11EP5/webex/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{24ECB9CA-F4F7-4D4D-955C-E49D88A88A73}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6098B8C2-999C-4D69-8EAC-88677C5B47D5}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7DF920AE-430B-4452-BE8A-8BC1F448D665}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\FastAccess: DllName - (c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/24 08:29:12 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Christine\Desktop\OTL.exe
[2012/07/24 07:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/07/24 07:15:36 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/24 07:09:19 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/23 20:56:33 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Christine\Desktop\aswMBR.exe
[2012/07/23 20:55:46 | 002,136,152 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Christine\Desktop\tdsskiller.exe
[2012/07/23 18:48:33 | 004,582,474 | R--- | C] (Swearware) -- C:\Users\Christine\Desktop\ComboFix.exe
[2012/07/21 17:30:24 | 000,000,000 | ---D | C] -- C:\Windows\tmp
[2012/07/21 09:29:06 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2012/07/21 09:29:06 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2012/07/21 09:28:11 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/07/21 09:27:58 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/07/21 09:27:50 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/07/21 09:27:42 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/07/21 09:27:41 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/07/21 09:27:28 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/07/21 09:27:19 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/07/21 09:25:16 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll
[2012/07/21 09:25:06 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll
[2012/07/21 09:22:35 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/07/21 09:22:31 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/07/21 09:22:30 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/07/21 09:22:20 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012/07/21 09:21:51 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/07/21 09:21:48 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/07/21 09:20:18 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012/07/21 09:20:11 | 000,918,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/07/21 09:20:06 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/07/21 09:19:45 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012/07/21 09:19:45 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012/07/21 09:19:44 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012/07/21 09:06:59 | 000,016,200 | ---- | C] (McAfee, Inc.) -- C:\Windows\stinger.sys
[2012/07/21 09:05:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\stinger
[2012/07/15 16:33:14 | 000,000,000 | ---D | C] -- C:\Users\Christine\Documents\Remedy
[2012/07/09 18:45:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Telltale Games
[2012/07/09 18:44:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Telltale Games
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/24 08:36:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001UA.job
[2012/07/24 08:29:16 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Christine\Desktop\OTL.exe
[2012/07/24 07:22:54 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/24 07:22:54 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/24 07:15:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/24 07:14:57 | 527,855,615 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/23 22:15:32 | 000,000,512 | ---- | M] () -- C:\Users\Christine\Desktop\MBR.dat
[2012/07/23 20:57:56 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Christine\Desktop\aswMBR.exe
[2012/07/23 20:56:02 | 002,136,152 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Christine\Desktop\tdsskiller.exe
[2012/07/23 18:49:29 | 004,582,474 | R--- | M] (Swearware) -- C:\Users\Christine\Desktop\ComboFix.exe
[2012/07/23 18:43:45 | 000,881,494 | ---- | M] () -- C:\Users\Christine\Desktop\SecurityCheck.exe
[2012/07/23 18:42:22 | 000,735,536 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/23 18:42:22 | 000,633,336 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/23 18:42:22 | 000,115,296 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/23 18:32:44 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2013641587-3539477181-1548398233-1001Core.job
[2012/07/21 17:30:38 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Kobo.lnk
[2012/07/21 16:19:38 | 000,016,200 | ---- | M] (McAfee, Inc.) -- C:\Windows\stinger.sys
[2012/07/21 10:20:29 | 000,347,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/21 09:22:23 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/16 20:21:30 | 510,368,460 | ---- | M] () -- C:\Users\Christine\Desktop\True.Blood.S05E06.HDTV.x264-EVOLVE.mp4
[2012/07/15 16:21:22 | 000,000,222 | ---- | M] () -- C:\Users\Christine\Desktop\Alan Wake.url
[2012/07/10 21:12:54 | 442,039,719 | ---- | M] () -- C:\Users\Christine\Desktop\True.Blood.S05E05.HDTV.x264-ASAP.mp4
[2012/07/10 11:52:11 | 000,001,459 | ---- | M] () -- C:\Users\Public\Desktop\Law and Order - Legacies.lnk
[2012/07/09 18:47:41 | 000,001,403 | ---- | M] () -- C:\Users\Public\Desktop\The Walking Dead.lnk
[2012/07/09 18:43:49 | 000,018,960 | ---- | M] (Logitech, Inc.) -- C:\Windows\SysNative\drivers\LNonPnP.sys
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/02 22:29:58 | 533,378,739 | ---- | M] () -- C:\Users\Christine\Desktop\True.Blood.S05E04.HDTV.x264-ASAP.mp4
[2012/06/25 19:52:10 | 494,399,192 | ---- | M] () -- C:\Users\Christine\Desktop\True.Blood.S05E03.HDTV.x264-ASAP.mp4
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/23 22:15:32 | 000,000,512 | ---- | C] () -- C:\Users\Christine\Desktop\MBR.dat
[2012/07/23 18:43:40 | 000,881,494 | ---- | C] () -- C:\Users\Christine\Desktop\SecurityCheck.exe
[2012/07/19 23:50:36 | 494,399,192 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E03.HDTV.x264-ASAP.mp4
[2012/07/19 23:49:35 | 444,929,495 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E02.HDTV.x264-ASAP.mp4
[2012/07/19 23:48:53 | 469,357,669 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E01.REPACK.HDTV.x264-ASAP.mp4
[2012/07/19 23:47:40 | 478,365,655 | ---- | C] () -- C:\Users\Christine\Desktop\Game.of.Thrones.S02E10.HDTV.x264-ASAP.mp4
[2012/07/19 23:44:17 | 442,039,719 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E05.HDTV.x264-ASAP.mp4
[2012/07/19 23:43:06 | 533,378,739 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E04.HDTV.x264-ASAP.mp4
[2012/07/19 23:36:40 | 510,368,460 | ---- | C] () -- C:\Users\Christine\Desktop\True.Blood.S05E06.HDTV.x264-EVOLVE.mp4
[2012/07/15 16:21:22 | 000,000,222 | ---- | C] () -- C:\Users\Christine\Desktop\Alan Wake.url
[2012/07/10 11:52:11 | 000,001,459 | ---- | C] () -- C:\Users\Public\Desktop\Law and Order - Legacies.lnk
[2012/07/09 18:47:41 | 000,001,403 | ---- | C] () -- C:\Users\Public\Desktop\The Walking Dead.lnk
[2012/02/10 22:35:25 | 000,000,017 | ---- | C] () -- C:\Users\Christine\AppData\Local\resmon.resmoncfg
[2012/01/11 08:29:55 | 000,000,000 | ---- | C] () -- C:\Users\Christine\defogger_reenable
[2012/01/11 07:13:42 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/11 07:13:42 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/11 07:13:42 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/11 07:13:42 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/11 07:13:42 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/06 12:35:10 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/12/06 12:35:10 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/12/05 22:04:00 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/12/05 22:03:52 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/09/13 09:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/20 19:00:17 | 000,000,000 | ---- | C] () -- C:\Windows\Secrets.INI
[2011/08/11 19:37:59 | 000,009,728 | ---- | C] () -- C:\Users\Christine\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/17 12:01:19 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\EAPQECC.dll
[2011/02/10 19:15:57 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2010/10/23 00:05:39 | 000,000,059 | ---- | C] () -- C:\ProgramData\user.ini
[2010/09/21 00:28:15 | 000,000,242 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2010/09/21 00:28:15 | 000,000,094 | ---- | C] () -- C:\Windows\brpcfx.ini
[2010/09/21 00:27:18 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010/09/21 00:27:18 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2010/09/21 00:24:17 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2010/09/19 06:08:55 | 000,125,952 | ---- | C] () -- C:\Users\Christine\metadata.db
[2010/09/19 05:51:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/09/19 05:26:57 | 000,000,918 | ---- | C] () -- C:\Users\Christine\Downloads.lnk
[2010/09/03 15:51:04 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/09/03 14:22:03 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 241 bytes -> C:\ProgramData\TEMP:39EDBD33
@Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:E99D1D3C
@Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:8E9C9E8F
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:BDD83DC4
@Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:371A321E
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:5C0CABC7
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:C0913157
@Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:07437A8C
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:58E38390
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:4E4ABF17
@Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:40DA0795
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:4A1628E5
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:A866F8A3
@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:5E9B629B
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:EA666F77
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA7D76BE

< End of report >

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 23 July 2012 - 06:51 PM

Hello

Run this custom script and when it is complete I need to know how the computer is doing

Run OTL Script

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the Posted Image textbox. Do not include the word Code
    :OTL
    FF - user.js - File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-2013641587-3539477181-1548398233-1001\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O4 - HKLM..\Run: [FAStartup] File not found
    O4 - Startup: C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
    O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
    O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
    O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
    @Alternate Data Stream - 241 bytes -> C:\ProgramData\TEMP:39EDBD33
    @Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:751D6870
    @Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:E99D1D3C
    @Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:8E9C9E8F
    @Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:BDD83DC4
    @Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:371A321E
    @Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:5C0CABC7
    @Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:3B07E6F4
    @Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:C0913157
    @Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:07437A8C
    @Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:58E38390
    @Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:4E4ABF17
    @Alternate Data Stream - 206 bytes -> C:\ProgramData\TEMP:40DA0795
    @Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:4A1628E5
    @Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:A866F8A3
    @Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:5E9B629B
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:EA666F77
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA7D76BE  
    FF - prefs.js..browser.search.defaultenginename: "Secure Search"
    FF - prefs.js..browser.search.defaultthis.engineName: "Freecorder Customized Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}"
    FF - prefs.js..browser.search.selectedEngine: "Secure Search"
    FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1060933&SearchSource=13"
    FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.1.3
    FF - prefs.js..extensions.enabledItems: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.2.1.3
    [2011/03/18 06:30:36 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
    [2010/10/23 00:09:09 | 000,000,000 | ---D | M] (Toolbar - Big Fish Games) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}
    [2011/03/18 06:30:36 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com
    [2010/10/21 04:40:12 | 000,000,923 | ---- | M] () -- C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\searchplugins\conduit.xml
    :Files
    ipconfig /flushdns /c
    :Commands
    [PURITY]
    [emptyjava]
    [EMPTYFLASH]
    
  • Then click the Run Fix button at the top.
  • Click Posted Image.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

Let me know How things are doing

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 cambrus

cambrus
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:11:12 AM

Posted 24 July 2012 - 03:50 AM

Here are the results of the script run in OTL


========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2013641587-3539477181-1548398233-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\FAStartup deleted successfully.
C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk moved successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk moved successfully.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk scheduled to be moved on reboot.
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
C:\Windows\Downloaded Program Files\OnlineScanner.inf moved successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully.
File Protocol\Handler\skype-ie-addon-data - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist\ deleted successfully.
ADS C:\ProgramData\TEMP:39EDBD33 deleted successfully.
ADS C:\ProgramData\TEMP:751D6870 deleted successfully.
ADS C:\ProgramData\TEMP:E99D1D3C deleted successfully.
ADS C:\ProgramData\TEMP:8E9C9E8F deleted successfully.
ADS C:\ProgramData\TEMP:BDD83DC4 deleted successfully.
ADS C:\ProgramData\TEMP:371A321E deleted successfully.
ADS C:\ProgramData\TEMP:5C0CABC7 deleted successfully.
ADS C:\ProgramData\TEMP:3B07E6F4 deleted successfully.
ADS C:\ProgramData\TEMP:C0913157 deleted successfully.
ADS C:\ProgramData\TEMP:07437A8C deleted successfully.
ADS C:\ProgramData\TEMP:58E38390 deleted successfully.
ADS C:\ProgramData\TEMP:4E4ABF17 deleted successfully.
ADS C:\ProgramData\TEMP:40DA0795 deleted successfully.
ADS C:\ProgramData\TEMP:4A1628E5 deleted successfully.
ADS C:\ProgramData\TEMP:A866F8A3 deleted successfully.
ADS C:\ProgramData\TEMP:5E9B629B deleted successfully.
ADS C:\ProgramData\TEMP:EA666F77 deleted successfully.
ADS C:\ProgramData\TEMP:EA7D76BE deleted successfully.
Prefs.js: "Secure Search" removed from browser.search.defaultenginename
Prefs.js: "Freecorder Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Secure Search" removed from browser.search.selectedEngine
Prefs.js: "http://search.conduit.com/?ctid=CT1060933&SearchSource=13" removed from browser.startup.homepage
Prefs.js: engine@conduit.com:3.2.1.3 removed from extensions.enabledItems
Prefs.js: {1392b8d2-5c05-419f-a8f6-b9f15a596612}:3.2.1.3 removed from extensions.enabledItems
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\searchplugin folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\META-INF folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\lib folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\defaults folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\chrome folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\components folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\whatsnew folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames\fg folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames\bg folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\options folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames\fg folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames\bg folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\uwa folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio\images folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio\css folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\images folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\scripts folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\images folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\css folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\css folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\bigfishgames folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\modules folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\lib folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data\search folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data\feeds folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692} folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\searchplugin folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\META-INF folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\lib folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\DualPackage folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\defaults folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\components folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com\chrome folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\extensions\engine@conduit.com folder moved successfully.
C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\2wksn3qn.default\searchplugins\conduit.xml moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christine\Desktop\cmd.bat deleted successfully.
C:\Users\Christine\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYJAVA]

User: All Users

User: Christine
->Java cache emptied: 10713673 bytes

User: Default

User: Default User

User: Public

Total Java Files Cleaned = 10.00 mb


[EMPTYFLASH]

User: All Users

User: Christine
->Flash cache emptied: 65389 bytes

User: Default
->Flash cache emptied: 56504 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.54.1 log created on 07242012_183527

Files\Folders moved on Reboot...
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!

PendingFileRenameOperations files...
File C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk not found!

Registry entries deleted on Reboot...

#15 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:08:42 PM

Posted 24 July 2012 - 09:39 PM

How are things running after that fix?


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users