TechSpot

Browser redirect

By bshaw
Jun 20, 2011
  1. I have this browser redirect virus, and have been trying to remove it for the past week. I have tried every malware removal program. Malwarebytes, hitman pro, spydoctor, spy bot, you name it , I have tried it..

    I even tried to disable the TDSS serv.sys, but I can't find it on my system.

    this redirect problem happens on firefox as well as Internet explorer..

    please help!

    thanks.

    I am running windows XP


    I will post the logs in the following post..
     
  2. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    Malwarebytes' Anti-Malware 1.51.0.1200
    www.malwarebytes.org

    Database version: 6904

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    6/20/2011 1:31:14 PM
    mbam-log-2011-06-20 (13-31-14).txt

    Scan type: Quick scan
    Objects scanned: 160038
    Time elapsed: 11 minute(s), 16 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  3. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    GMER 1.0.15.15640 - http://www.gmer.net
    Rootkit quick scan 2011-06-20 13:47:48
    Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST3160812AS rev.3.ADJ
    Running: gmer.exe; Driver: C:\DOCUME~1\DARELL~1\LOCALS~1\Temp\pwtdapow.sys


    ---- System - GMER 1.0.15 ----

    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEF58A44A]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xEF58A4E1]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEF58A3F8]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEF58A40C]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xEF58A4F5]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xEF58A521]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xEF58A58F]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xEF58A579]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEF58A48A]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEF58A5BB]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xEF58A4CD]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEF58A3D0]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEF58A3E4]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEF58A45E]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xEF58A5F7]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEF58A563]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xEF58A54D]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEF58A50B]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEF58A5E3]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEF58A5CF]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEF58A436]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEF58A422]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xEF58A537]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEF58A4B9]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEF58A5A5]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEF58A4A0]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEF58A474]
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
    Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
    AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
    AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
    AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
    AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

    ---- Threads - GMER 1.0.15 ----

    Thread System [4:120] 85F09E7A
    Thread System [4:124] 85F0C008

    ---- EOF - GMER 1.0.15 ----
     
  4. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    DDS (Ver_2011-06-12.02) - NTFSx86
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
    Run by Darell Blandshaw at 13:49:59 on 2011-06-20
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.990.309 [GMT -4:00]
    .
    AV: McAfee VirusScan *Enabled/Outdated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *Enabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe
    C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
    C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\StompSoft\PC BackUp\NbkCtrl.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    C:\3apps\Catapult\3listen.exe
    C:\3apps\Catapult\appipc.exe
    C:\WINDOWS\system32\P32HELP.EXE
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Java\jre6\bin\jucheck.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\DOCUME~1\DARELL~1\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://smallbusiness.bellsouth.net/
    uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070228
    uSearch Bar =
    mSearch Bar = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070228
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: {0cdc9273-1ec7-4c20-8384-c241b57ef068}: {860fe75b-142c-4838-02c4-7ce13729cdc0}
    BHO: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    {63d85c46-546e-4b4c-b98b-4ba96b9c564d}
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
    BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
    TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [tgcmd] "c:\program files\support.com\bellsouth\hcenter.exe" /starthidden /tgcmdwrapper
    mRun: [<NO NAME>]
    mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [NovaBackup 7 Tray Control] "c:\program files\stompsoft\pc backup\NbkCtrl.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
    mRun: [BellSouthAlertManager.exe] "c:\program files\bellsouth\am\BellSouthAlertManager.exe" /AUTORUN
    mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
    StartupFolder: c:\docume~1\darell~1\startm~1\programs\startup\eaglel~1.lnk - c:\3apps\catapult\3listen.exe
    StartupFolder: c:\docume~1\darell~1\startm~1\programs\startup\eagles~1.lnk - c:\3apps\catapult\Sched.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ativaw~1.lnk - c:\program files\ativa\usb awgua54\wireless utility\Ativawcui.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
    IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    Trusted Zone: wachovia.com
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {F5131C24-E56D-11CF-B78A-444553540000} - hxxps://wc.wachovia.com/common/cab/ikcntrls.cab
    TCP: Interfaces\{86E114BA-0F17-437F-8660-2C26CCF4A375} : NameServer = 4.2.2.2,4.2.2.3
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: nnnkHyvV - nnnkHyvV.dll
    AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll kcjpxh.dll slfmhf.dll zinzpa.dll yayepahu.dll c:\windows\system32\refewodu.dll c:\windows\system32\fitoweju.dll c:\windows\system32\wohobiye.dll, viwamofe.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SSODL: danapugev - {67c5330b-bf8f-416f-9fb4-bd31e6ed1313} - c:\windows\system32\fitoweju.dll
    STS: tokatiluy: {67c5330b-bf8f-416f-9fb4-bd31e6ed1313} - c:\windows\system32\fitoweju.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    LSA: Authentication Packages = msv1_0 c:\windows\system32\ljJBrOhG
    LSA: Notification Packages = scecli jodokono.dll
    Hosts: 192.168.1.1 3USQLODBC # Eagle for Windows U/SQL ODBC Connection (10/21/08 15:45:25)
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\darell blandshaw\application data\mozilla\firefox\profiles\3otsvnu4.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 64970
    FF - prefs.js: network.proxy.type - 0
    FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
    FF - plugin: c:\documents and settings\darell blandshaw\application data\mozilla\firefox\profiles\3otsvnu4.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071302000002.dll
    FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\mcafee\SiteAdvisor
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2007-2-28 3456]
    R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-12-23 213640]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-23 88176]
    R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-12-23 359952]
    R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-12-23 144704]
    R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2011-1-3 632792]
    R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-12-23 606736]
    R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-12-23 79304]
    R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-12-23 35272]
    R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-12-23 40552]
    R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664]
    S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-1-3 366640]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664]
    S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
    S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-12-23 34216]
    S3 ODWGU(Ativa);Ativa Wireless G USB Network Adapter(Ativa);c:\windows\system32\drivers\ODWGU.sys [2010-12-29 408064]
    .
    =============== File Associations ===============
    .
    chm.file=c:\windows\HH.exe %1
    .
    =============== Created Last 30 ================
    .
    2011-06-20 16:09:47 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2011-06-20 16:09:37 -------- d-----w- c:\program files\Hitman Pro 3.5
    2011-06-20 16:08:14 -------- d-----w- c:\documents and settings\all users\application data\Hitman Pro
    2011-06-10 19:20:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2011-06-10 19:20:21 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
    2011-06-10 16:14:39 -------- d-----w- c:\windows\pss
    2011-06-10 15:27:10 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2011-06-10 15:27:10 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-06-10 15:01:42 39192 ----a-w- c:\windows\system32\Partizan.exe
    2011-06-10 15:01:42 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
    2011-06-10 15:01:29 2 --shatr- c:\windows\winstart.bat
    2011-06-10 15:01:24 12808 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
    2011-06-10 15:01:18 -------- d-----w- c:\program files\UnHackMe
    .
    ==================== Find3M ====================
    .
    2011-05-29 13:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    .
    ============= FINISH: 13:50:50.98 ===============
     
  5. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================================================

    Attach.txt part of DDS is missing, so please post that.

    Then...

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    Click the "Scan" button to start scan:
    [​IMG]

    On completion of the scan click "Save log", save it to your desktop and post in your next reply:
    [​IMG]

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

    =======================================================================

    Please download Rootkit Unhooker from one of the following links and save it to your desktop.
    In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can download, install and use the free 7-zip utility.

    • Double-click on RKUnhookerLE.exe to start the program.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • Click the Report tab, then click Scan.
    • Check Drivers, Stealth, and uncheck the rest.
    • Click OK.
    • Wait until it's finished and then go to File > Save Report.
    • Save the report to your Desktop.
    • Copy and paste the contents of the report into your next reply.
    -- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".
     
  6. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    here is the attach .txt part of the DDS

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-12.02)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/8/2007 3:26:43 PM
    System Uptime: 6/20/2011 12:22:05 PM (22 hours ago)
    .
    Motherboard: Dell Inc. | | 0MH651
    Processor: Intel(R) Pentium(R) D CPU 2.80GHz | Microprocessor | 2800/800mhz
    Processor: Intel(R) Pentium(R) D CPU 2.80GHz | Microprocessor | 2800/800mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 149 GiB total, 129.91 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP1381: 3/23/2011 6:23:54 PM - System Checkpoint
    RP1382: 3/25/2011 5:22:12 AM - System Checkpoint
    RP1383: 3/26/2011 6:11:52 AM - System Checkpoint
    RP1384: 3/27/2011 6:23:51 AM - System Checkpoint
    RP1385: 3/28/2011 6:47:51 AM - System Checkpoint
    RP1386: 3/29/2011 8:37:23 AM - System Checkpoint
    RP1387: 3/30/2011 8:38:53 AM - System Checkpoint
    RP1388: 3/31/2011 4:23:19 PM - System Checkpoint
    RP1389: 4/1/2011 5:13:26 PM - System Checkpoint
    RP1390: 4/2/2011 7:11:18 PM - System Checkpoint
    RP1391: 4/3/2011 7:49:26 PM - System Checkpoint
    RP1392: 4/4/2011 11:26:50 PM - System Checkpoint
    RP1393: 4/6/2011 1:13:11 AM - System Checkpoint
    RP1394: 4/7/2011 2:02:53 AM - System Checkpoint
    RP1395: 4/8/2011 3:02:53 AM - System Checkpoint
    RP1396: 4/9/2011 4:02:53 AM - System Checkpoint
    RP1397: 4/10/2011 4:14:52 AM - System Checkpoint
    RP1398: 4/11/2011 4:39:22 AM - System Checkpoint
    RP1399: 4/12/2011 4:51:23 AM - System Checkpoint
    RP1400: 4/13/2011 5:39:54 AM - System Checkpoint
    RP1401: 4/14/2011 10:27:00 AM - System Checkpoint
    RP1402: 4/15/2011 1:59:48 PM - System Checkpoint
    RP1403: 4/16/2011 3:26:52 PM - System Checkpoint
    RP1404: 4/17/2011 4:14:52 PM - System Checkpoint
    RP1405: 4/18/2011 4:39:32 PM - System Checkpoint
    RP1406: 4/19/2011 4:53:20 PM - System Checkpoint
    RP1407: 4/20/2011 5:02:34 PM - System Checkpoint
    RP1408: 4/21/2011 5:03:39 PM - System Checkpoint
    RP1409: 4/22/2011 9:15:04 PM - System Checkpoint
    RP1410: 4/23/2011 9:26:33 PM - System Checkpoint
    RP1411: 4/24/2011 9:50:33 PM - System Checkpoint
    RP1412: 4/25/2011 10:01:08 PM - System Checkpoint
    RP1413: 4/26/2011 10:36:21 PM - System Checkpoint
    RP1414: 4/27/2011 11:48:21 PM - System Checkpoint
    RP1415: 4/29/2011 12:00:23 AM - System Checkpoint
    RP1416: 4/30/2011 1:24:21 AM - System Checkpoint
    RP1417: 5/1/2011 1:36:21 AM - System Checkpoint
    RP1418: 5/2/2011 2:00:21 AM - System Checkpoint
    RP1419: 5/3/2011 2:17:48 AM - System Checkpoint
    RP1420: 5/4/2011 3:29:48 AM - System Checkpoint
    RP1421: 5/5/2011 4:42:18 AM - System Checkpoint
    RP1422: 5/6/2011 1:50:26 PM - System Checkpoint
    RP1423: 5/7/2011 2:41:50 PM - System Checkpoint
    RP1424: 5/8/2011 3:41:52 PM - System Checkpoint
    RP1425: 5/9/2011 4:54:47 PM - System Checkpoint
    RP1426: 5/10/2011 5:20:58 PM - System Checkpoint
    RP1427: 5/11/2011 5:44:58 PM - System Checkpoint
    RP1428: 5/12/2011 6:20:59 PM - System Checkpoint
    RP1429: 5/13/2011 6:33:00 PM - System Checkpoint
    RP1430: 5/14/2011 8:32:58 PM - System Checkpoint
    RP1431: 5/15/2011 9:56:58 PM - System Checkpoint
    RP1432: 5/16/2011 11:20:38 PM - System Checkpoint
    RP1433: 5/18/2011 12:22:39 AM - System Checkpoint
    RP1434: 5/19/2011 12:44:40 AM - System Checkpoint
    RP1435: 5/20/2011 2:56:38 AM - System Checkpoint
    RP1436: 5/21/2011 3:16:27 AM - System Checkpoint
    RP1437: 5/22/2011 4:02:13 AM - System Checkpoint
    RP1438: 5/23/2011 5:02:13 AM - System Checkpoint
    RP1439: 5/24/2011 5:38:04 AM - System Checkpoint
    RP1440: 5/25/2011 7:14:03 AM - System Checkpoint
    RP1441: 5/26/2011 8:02:04 AM - System Checkpoint
    RP1442: 5/27/2011 12:20:08 PM - System Checkpoint
    RP1443: 5/28/2011 1:32:04 PM - System Checkpoint
    RP1444: 5/29/2011 1:56:03 PM - System Checkpoint
    RP1445: 5/30/2011 2:20:03 PM - System Checkpoint
    RP1446: 5/31/2011 4:42:26 PM - System Checkpoint
    RP1447: 6/1/2011 3:01:20 PM - Installed TurboTax 2010 wnyiper
    RP1448: 6/2/2011 3:32:03 PM - System Checkpoint
    RP1449: 6/3/2011 4:14:05 PM - System Checkpoint
    RP1450: 6/4/2011 6:05:50 PM - System Checkpoint
    RP1451: 6/5/2011 6:29:50 PM - System Checkpoint
    RP1452: 6/6/2011 8:17:52 PM - System Checkpoint
    RP1453: 6/7/2011 8:29:52 PM - System Checkpoint
    RP1454: 6/8/2011 2:48:42 PM - Restore Operation
    RP1455: 6/9/2011 3:25:00 PM - System Checkpoint
    RP1456: 6/10/2011 11:04:41 AM - RegRun Virus Scan
    RP1457: 6/10/2011 11:13:17 AM - RegRun Virus Scan
    RP1458: 6/10/2011 11:22:59 AM - Restore Operation
    RP1459: 6/11/2011 12:46:56 PM - System Checkpoint
    RP1460: 6/12/2011 1:10:56 PM - System Checkpoint
    RP1461: 6/13/2011 2:27:31 PM - System Checkpoint
    RP1462: 6/14/2011 4:09:54 PM - System Checkpoint
    RP1463: 6/15/2011 4:22:40 PM - System Checkpoint
    RP1464: 6/17/2011 3:29:45 PM - System Checkpoint
    RP1465: 6/18/2011 3:40:56 PM - System Checkpoint
    RP1466: 6/19/2011 4:40:56 PM - System Checkpoint
    RP1467: 6/20/2011 5:05:55 PM - System Checkpoint
    .
    ==== Installed Programs ======================
    .
    .
    Adobe Acrobat 8 Standard
    Adobe Acrobat 8.1.0 Standard
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Flash Player ActiveX
    AnswerWorks 4.0 Runtime - English
    AnswerWorks 5.0 English Runtime
    Apple Application Support
    Apple Software Update
    ATI Catalyst Control Center
    ATI Display Driver
    Ativa Wireless USB Utility
    AVI Codec Pack
    BellSouth Application Management
    BellSouth FastAccess DSL Help Center
    BellSouth Internet Security - Alert Manager 1.5.11
    BellSouth Toolbar 1.0
    Broadcom Management Programs
    Brother HL-5240
    Conexant D850 56K V.9x DFVc Modem
    Coupon Printer for Windows
    Digital Line Detect
    Eagle for Windows
    Eagle for Windows Training Browser
    FXCM Trading Station
    GFFOREX Forex Trading
    Google Toolbar for Internet Explorer
    Google Update Helper
    GoToMeeting 4.5.0.457
    High Definition Audio Driver Package - KB835221
    Hitman Pro 3.5
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB896256)
    Hotfix for Windows XP (KB908673)
    Hotfix for Windows XP (KB909095)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB928388)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 16
    Malwarebytes' Anti-Malware version 1.51.0.1200
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office Basic Edition 2003
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Modem Helper
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.6.17)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6.0 Parser (KB933579)
    NetWaiting
    Octoshape add-in for Adobe Flash Player
    PC BackUp
    PowerDVD OD
    QuickBooks Premier: Contractor Edition 2004
    QuickTime
    Registry Mechanic 10.0
    Roxio DLA
    Roxio Express Labeler
    Roxio RecordNow Audio
    Roxio RecordNow Copy
    Roxio RecordNow Data
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925454)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933566)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937143)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944533)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB960714)
    Spybot - Search & Destroy
    SUPERAntiSpyware Free Edition
    TurboTax 2008
    TurboTax 2008 wgaiper
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax 2009
    TurboTax 2009 wgaiper
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wrapper
    TurboTax 2010
    TurboTax 2010 wgaiper
    TurboTax 2010 WinPerFedFormset
    TurboTax 2010 WinPerReleaseEngine
    TurboTax 2010 WinPerTaxSupport
    TurboTax 2010 wnyiper
    TurboTax 2010 wrapper
    TurboTax Home & Business 2006
    TurboTax Home & Business 2007
    TurboTax ItsDeductible 2005
    TurboTax ItsDeductible 2006
    TurboTax Premier 2005
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB912945)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB932823-v3)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB942840)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    URL Assistant
    WebFldrs XP
    WexTech AnswerWorks
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB889673
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Xvid 1.2.1 final uninstall
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/15/2011 11:18:07 AM, error: Service Control Manager [7001] - The MBAMService service depends on the MBAMProtector service which failed to start because of the following error: The system cannot find the file specified.
    6/15/2011 11:18:07 AM, error: Service Control Manager [7000] - The MBAMProtector service failed to start due to the following error: The system cannot find the file specified.
    .
    ==== End Of File ===========================
     
  7. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    aswMBR version 0.9.7.675 Copyright(c) 2011 AVAST Software
    Run date: 2011-06-21 13:22:01
    -----------------------------
    13:22:01.046 OS Version: Windows 5.1.2600 Service Pack 2
    13:22:01.046 Number of processors: 2 586 0x407
    13:22:01.046 ComputerName: DARELL UserName:
    13:22:02.421 Initialize success
    13:23:07.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
    13:23:07.578 Disk 0 Vendor: ST3160812AS 3.ADJ Size: 152587MB BusType: 3
    13:23:09.609 Disk 0 MBR read successfully
    13:23:09.609 Disk 0 MBR scan
    13:23:09.609 Disk 0 Windows XP default MBR code
    13:23:11.609 Disk 0 scanning sectors +312480315
    13:23:11.640 Disk 0 scanning C:\WINDOWS\system32\drivers
    13:23:17.578 Service scanning
    13:23:19.187 Disk 0 trace - called modules:
    13:23:19.203 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x85f051ed]<<
    13:23:19.203 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85f28ab8]
    13:23:19.203 3 CLASSPNP.SYS[f753505b] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x85fd3d98]
    13:23:19.218 \Driver\atapi[0x85f7dd20] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x85f051ed
    13:23:19.218 Scan finished successfully
    13:23:53.125 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Darell Blandshaw\Desktop\MBR.dat"
    13:23:53.203 The log file has been saved successfully to "C:\Documents and Settings\Darell Blandshaw\Desktop\aswMBR.txt"
     
  8. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    RkU Version: 3.8.389.593, Type LE (SR2)
    ==============================================
    OS Name: Windows XP
    Version 5.1.2600 (Service Pack 2)
    Number of processors #2
    ==============================================
    >Drivers
    ==============================================
    0xBF0DD000 C:\WINDOWS\System32\ati3duag.dll 2756608 bytes (ATI Technologies Inc. , ati3duag.dll)
    0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2142208 bytes (Microsoft Corporation, NT Kernel & System)
    0x804D7000 PnpManager 2142208 bytes
    0x804D7000 RAW 2142208 bytes
    0x804D7000 WMIxWDM 2142208 bytes
    0xBF800000 Win32k 1847296 bytes
    0xBF800000 C:\WINDOWS\System32\win32k.sys 1847296 bytes (Microsoft Corporation, Multi-User Win32 Driver)
    0xBF37E000 C:\WINDOWS\System32\ativvaxx.dll 1753088 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver)
    0xF6A32000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1642496 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)
    0xF686B000 C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 1044480 bytes (Conexant Systems, Inc., HSF_DP driver)
    0xF67C4000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 684032 bytes (Conexant Systems, Inc., HSF_CNXT driver)
    0xF7291000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
    0xEF5A4000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
    0xF1277000 C:\WINDOWS\system32\drivers\Senfilt.sys 393216 bytes (Sensaura, Sensaura WDM 3D Audio Driver)
    0xF6743000 C:\WINDOWS\system32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver)
    0xF11EC000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
    0xECF4A000 C:\WINDOWS\system32\DRIVERS\srv.sys 335872 bytes (Microsoft Corporation, Server driver)
    0xBF055000 C:\WINDOWS\System32\ati2cqag.dll 286720 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)
    0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
    0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 274432 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)
    0xBF09B000 C:\WINDOWS\System32\atikvmag.dll 270336 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)
    0xF12F9000 C:\WINDOWS\system32\drivers\ADIHdAud.sys 249856 bytes (Analog Devices, Inc., High Definition Audio Function Driver)
    0xF696A000 C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 212992 bytes (Conexant Systems, Inc., HSF_HWB2 WDM driver)
    0xEF571000 C:\WINDOWS\system32\drivers\mfehidk.sys 208896 bytes (McAfee, Inc., Host Intrusion Detection Link Driver)
    0xF73C5000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
    0xF7264000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
    0xECFEC000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
    0xEB67D000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
    0xEF613000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
    0xEF685000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
    0xF11C5000 C:\WINDOWS\System32\Drivers\Mpfp.sys 159744 bytes (McAfee, Inc., McAfee Personal Firewall Plus Driver)
    0xF69B2000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 155648 bytes (Windows (R) Server 2003 DDK provider, High Definition Audio Bus Driver v1.0)
    0xEF63E000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 151552 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS)
    0xEB813000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 143360 bytes (Microsoft Corporation, Fast FAT File System Driver)
    0xF69D8000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
    0xF69FB000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
    0xEF663000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
    0xF12D7000 C:\WINDOWS\system32\drivers\portcls.sys 139264 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
    0xEF6AD000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator)
    0x806E2000 ACPI_HAL 134272 bytes
    0x806E2000 C:\WINDOWS\system32\hal.dll 134272 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
    0xF735D000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
    0xF7395000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
    0xF7249000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver)
    0xEB836000 C:\DOCUME~1\DARELL~1\LOCALS~1\Temp\pwtdapow.sys 102400 bytes
    0xF737D000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
    0xED2C1000 C:\WINDOWS\System32\DLA\DLAUDFAM.SYS 98304 bytes (Sonic Solutions, Drive Letter Access Component)
    0xEF559000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
    0xF731E000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
    0xF67AD000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
    0xED2D9000 C:\WINDOWS\System32\DLA\DLAIFS_M.SYS 90112 bytes (Sonic Solutions, Drive Letter Access Component)
    0xED2AB000 C:\WINDOWS\System32\DLA\DLAUDF_M.SYS 90112 bytes (Sonic Solutions, Drive Letter Access Component)
    0xF7335000 DRVMCDB.SYS 90112 bytes (Sonic Solutions, Device Driver)
    0xED106000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
    0xF699E000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
    0xF6A1E000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
    0xF1244000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
    0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
    0xEC858000 C:\WINDOWS\system32\drivers\mfeavfk.sys 73728 bytes (McAfee, Inc., Anti-Virus File System Filter Driver)
    0xF734B000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
    0xF73B4000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
    0xF679C000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
    0xF75E4000 C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 65536 bytes (Broadcom Corporation, Broadcom Corporation NDIS 5.1 ethernet driver)
    0xF7754000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
    0xF75D4000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
    0xF5C67000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
    0xF75C4000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
    0xF5BE7000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
    0xF6662000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
    0xF75B4000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
    0xF7534000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
    0xF75F4000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
    0xF7514000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
    0xF7614000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
    0xEB9DD000 C:\DOCUME~1\DARELL~1\LOCALS~1\Temp\aswMBR.sys 45056 bytes
    0xF75A4000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
    0xF7504000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
    0xF7604000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
    0xF7724000 C:\WINDOWS\System32\Drivers\DRVNDDM.SYS 40960 bytes (Sonic Solutions, Device Driver Manager)
    0xF7654000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
    0xF7644000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
    0xEB62D000 C:\WINDOWS\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver)
    0xF7524000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
    0xF5C17000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver)
    0xEF9A7000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)
    0xF7594000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
    0xF74F4000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver)
    0xEBDB5000 C:\WINDOWS\system32\drivers\mfesmfk.sys 36864 bytes (McAfee, Inc., System Monitor Filter Driver)
    0xF7624000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
    0xF3DFD000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
    0xEF9B7000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
    0xF784C000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
    0xF78A4000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
    0xF7824000 C:\WINDOWS\System32\DLA\DLABOIOM.SYS 28672 bytes (Sonic Solutions, Drive Letter Access Component)
    0xF7844000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)
    0xF788C000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
    0xEF6FE000 C:\DOCUME~1\DARELL~1\LOCALS~1\Temp\mbr.sys 28672 bytes
    0xF78C4000 C:\WINDOWS\system32\drivers\mfebopk.sys 28672 bytes (McAfee, Inc., Buffer Overflow Protection Driver)
    0xF7774000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
    0xF783C000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
    0xEF6D6000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver)
    0xF7884000 C:\WINDOWS\System32\Drivers\DLARTL_N.SYS 24576 bytes (Sonic Solutions, Shared Driver Component)
    0xF786C000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
    0xF7874000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
    0xEF6E6000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS)
    0xF7894000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
    0xF4CDB000 C:\WINDOWS\System32\drivers\BrPar.sys 20480 bytes (Brother Industries Ltd., Brother Parallel class Driver version 1.01)
    0xF4D0B000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)
    0xF789C000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
    0xF777C000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
    0xF785C000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
    0xF7784000 PxHelp20.sys 20480 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
    0xF7864000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel(R) mini-port/call-manager driver)
    0xF77BC000 C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 20480 bytes ( SUPERAdBlocker.com and SUPERAntiSpyware.com, SASENUM.SYS)
    0xF7854000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
    0xF7834000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)
    0xEF6CE000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
    0xF4D23000 C:\WINDOWS\System32\DLA\DLAOPIOM.SYS 16384 bytes (Sonic Solutions, Drive Letter Access Component)
    0xEF8C9000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver)
    0xF79EC000 C:\WINDOWS\system32\drivers\MODEMCSA.sys 16384 bytes (Microsoft Corporation, Unimodem CSA Filter)
    0xF6BD7000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
    0xED31F000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
    0xF6BE7000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
    0xF7904000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
    0xF71F0000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
    0xF0225000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
    0xECE1A000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 12288 bytes (Conexant, Diagnostic Interface DRIVER)
    0xEF8D1000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver)
    0xF6BE3000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
    0xF4D3F000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
    0xF0219000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer)
    0xF7AA6000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
    0xF7A2C000 C:\WINDOWS\System32\Drivers\DLACDBHM.SYS 8192 bytes (Sonic Solutions, Shared Driver Component)
    0xF7A4A000 C:\WINDOWS\System32\DLA\DLAPoolM.SYS 8192 bytes (Sonic Solutions, Drive Letter Access Component)
    0xF7ABA000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
    0xF7AA4000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
    0xF7A9C000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 8192 bytes (Microsoft Corporation, I2O Utility Filter)
    0xF79F4000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
    0xF7AA8000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
    0xF7AAA000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
    0xF7A2E000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
    0xF7A80000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
    0xF79F6000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
    0xF7ABD000 atiide.sys 4096 bytes (ATI Technologies Inc., ATI SATA(IDE Mode) Controller Driver)
    0xF7C04000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
    0xF7C13000 C:\WINDOWS\System32\DLA\DLADResN.SYS 4096 bytes (Sonic Solutions, Drive Letter Access Component)
    0xF7C36000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
    0xF7B65000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
    0xF7ABC000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
    ==============================================
    >Stealth
    ==============================================
    0x85F06A91 Unknown page with executable code, 1391 bytes
    0x85F05288 Unknown page with executable code, 3448 bytes
    0x85F07191 Unknown page with executable code, 3695 bytes
    0xF7514000 WARNING: Virus alike driver modification [VolSnap.sys], 53248 bytes
    0x85F09E7A Unknown thread object [ ETHREAD 0x85FCD690 ] TID: 120, 600 bytes
    0x85F0C008 Unknown thread object [ ETHREAD 0x85FCD418 ] TID: 124, 600 bytes
    0x85F0BCDC Unknown page with executable code, 804 bytes
     
  9. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  10. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    can you tell me how to disable my antivirus and malware softward..

    and I already have R kill on my computer , I downloaded it a year ago. Should I use that or download it again?
     
  11. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    can you tell me how to disable my antivirus and malware softward..
    There is a link in my previous instructions.

    Combofix may run normally, so no need for rKill.
    If you'll need it, download fresh copy.
     
  12. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    ok, I have a slight problem. i accidentially downloaded combofix twice,and it gave me an error when i tried to run it sayin I can't rename combo fix. I had to restart my computer. I restarted and downloaded again, and it renamed it combo fix 3....

    what should I do.. and how do I save it directly to desktop? when I click on the download it doesn't give me that option, just gives me the option to "run"
     
  13. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    Move the file form your download location to the desktop.
     
  14. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    tried running combofix, the first time it seemed as if one of my antivirus programs came up and it didn't finish, I made sure everything was disabled again, ran combofix and it started then stalled and hung up. I had to stop it because it froze..

    what should I do now.. should I try using the instructions to run in safe mode?

    also, I am going out of town for a few days and won't be near the infected computer. so I will wait for your reply and get back on monday.

    thanks
     
  15. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    Yes.
     
  16. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    Here are the results of my combo fix log..... sorry but I forgot to get the rkill log, what I do remember is that it had the mcafee antivirus on the log.



    ComboFix 11-06-27.04 - Darell Blandshaw 06/28/2011 13:25:44.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.990.279 [GMT -4:00]
    Running from: c:\documents and settings\Darell Blandshaw\Desktop\darell.exe
    AV: McAfee VirusScan *Disabled/Outdated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Darell Blandshaw\Desktop\mbam-setup(6).bat
    c:\documents and settings\Darell Blandshaw\Desktop\Setup.exe
    c:\documents and settings\Darell Blandshaw\g2mdlhlpx.exe
    c:\documents and settings\Darell Blandshaw\GoToAssistDownloadHelper.exe
    c:\documents and settings\Darell Blandshaw\WINDOWS
    c:\program files\INSTALL.LOG
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-05-28 to 2011-06-28 )))))))))))))))))))))))))))))))
    .
    .
    2011-06-23 13:24 . 2011-06-28 17:23 -------- d-----w- C:\ComboFix
    2011-06-20 16:09 . 2011-06-20 16:36 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2011-06-20 16:09 . 2011-06-20 16:09 -------- d-----w- c:\program files\Hitman Pro 3.5
    2011-06-20 16:08 . 2011-06-20 16:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
    2011-06-10 19:20 . 2011-06-13 14:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2011-06-10 19:20 . 2011-06-10 19:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2011-06-10 15:27 . 2011-06-10 15:27 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-06-10 15:01 . 2011-06-10 15:01 39192 ----a-w- c:\windows\system32\Partizan.exe
    2011-06-10 15:01 . 2011-06-10 15:01 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
    2011-06-10 15:01 . 2011-06-10 15:01 2 --shatr- c:\windows\winstart.bat
    2011-06-10 15:01 . 2011-05-18 14:53 12808 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
    2011-06-10 15:01 . 2011-06-10 15:23 -------- d-----w- c:\program files\UnHackMe
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-05-29 13:11 . 2011-01-03 17:23 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 68856]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-06-23 53248]
    "tgcmd"="c:\program files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-22 149280]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
    "NovaBackup 7 Tray Control"="c:\program files\StompSoft\PC BackUp\NbkCtrl.exe" [2007-01-30 402376]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "BellSouthAlertManager.exe"="c:\program files\BellSouth\AM\BellSouthAlertManager.exe" [2007-01-28 2061816]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
    .
    c:\documents and settings\Darell Blandshaw\Start Menu\Programs\Startup\
    Eagle Listener.lnk - c:\3apps\Catapult\3listen.exe [2008-10-21 557056]
    Eagle Scheduler.lnk - c:\3apps\Catapult\Sched.exe [2008-10-21 708608]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Ativa Wireless USB Utility.lnk - c:\program files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe [2006-8-29 1556480]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-3-1 24576]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-5-24 724992]
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:mad:xpsp2res.dll,-22009
    .
    R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2/28/2007 11:41 PM 3456]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 8:56 AM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 74480]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/23/2008 1:56 PM 88176]
    R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [1/3/2011 12:50 PM 632792]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2010 10:27 AM 135664]
    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/3/2011 1:23 PM 366640]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2010 10:27 AM 135664]
    S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
    S3 ODWGU(Ativa);Ativa Wireless G USB Network Adapter(Ativa);c:\windows\system32\drivers\ODWGU.sys [12/29/2010 11:51 AM 408064]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 7408]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
    .
    2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 14:27]
    .
    2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 14:27]
    .
    2011-06-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-23 15:53]
    .
    2011-06-01 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-23 15:53]
    .
    2011-06-28 c:\windows\Tasks\RMSchedule.job
    - c:\program files\Registry Mechanic\RegMech.exe [2011-01-03 22:05]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://smallbusiness.bellsouth.net/
    mSearch Bar = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070228
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    Trusted Zone: intuit.com\ttlc
    Trusted Zone: turbotax.com
    Trusted Zone: wachovia.com
    TCP: Interfaces\{86E114BA-0F17-437F-8660-2C26CCF4A375}: NameServer = 4.2.2.2,4.2.2.3
    FF - ProfilePath - c:\documents and settings\Darell Blandshaw\Application Data\Mozilla\Firefox\Profiles\3otsvnu4.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 64970
    FF - prefs.js: network.proxy.type - 0
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{0cdc9273-1ec7-4c20-8384-c241b57ef068} - (no file)
    BHO-{63D85C46-546E-4B4C-B98B-4BA96B9C564D} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
    HKLM-Run-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    HKLM-Run-<NO NAME> - (no file)
    SharedTaskScheduler-{67c5330b-bf8f-416f-9fb4-bd31e6ed1313} - c:\windows\system32\fitoweju.dll
    SSODL-danapugev-{67c5330b-bf8f-416f-9fb4-bd31e6ed1313} - c:\windows\system32\fitoweju.dll
    Notify-nnnkHyvV - nnnkHyvV.dll
    AddRemove-AVI Codec Pack - c:\program files\AVI Codec Pack\uninstall.exe
    AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9c.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-06-28 13:32
    Windows 5.1.2600 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (LocalSystem)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,cf,56,77,f4,e0,4b,4e,88,26,1d,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,28,cf,56,77,f4,e0,4b,4e,88,26,1d,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(668)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    - - - - - - - > 'explorer.exe'(3824)
    c:\progra~1\mcafee\SITEAD~1\saHook.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\Ati2evxx.exe
    c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\McAfee\MPF\MPFSrv.exe
    c:\program files\StompSoft\PC BackUp\NMSAccess.exe
    c:\program files\StompSoft\PC BackUp\NSENGINE.exe
    c:\windows\system32\rundll32.exe
    c:\progra~1\mcafee.com\agent\mcagent.exe
    c:\windows\system32\wscntfy.exe
    c:\3apps\Catapult\appipc.exe
    c:\windows\system32\P32HELP.EXE
    c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    c:\program files\Support.com\bin\tgcmd.exe
    .
    **************************************************************************
    .
    Completion time: 2011-06-28 13:37:02 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-06-28 17:36
    .
    Pre-Run: 139,707,088,896 bytes free
    Post-Run: 139,616,673,792 bytes free
    .
    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
    .
    - - End Of File - - 339E69B621D076D88D52BC32B5FED9C8
     
  17. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box
    • Click OK
    Windows Vista/7 users: click Start, in "Start search" type notepad and press Enter.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\winstart.bat
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=-
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  18. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    ONE question, with step #5, remember I renamed combofix before I moved it to my desktop. should I delete that and download combo fix again, or do I drag this file to the renamed combofix file I just used?
     
  19. Broni

    Broni Malware Annihilator Posts: 52,905   +344

    That's it.
     
  20. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    the log is so big, I will have to post in in 4 seperate replies. sorry


    ComboFix 11-06-30.01 - Darell Blandshaw 06/30/2011 10:42:17.2.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.990.607 [GMT -4:00]
    Running from: c:\documents and settings\Darell Blandshaw\Desktop\darell.exe
    Command switches used :: c:\documents and settings\Darell Blandshaw\Desktop\CFScript.txt
    AV: McAfee VirusScan *Disabled/Outdated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .
    FILE ::
    "c:\windows\winstart.bat"
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\winstart.bat
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-05-28 to 2011-06-30 )))))))))))))))))))))))))))))))
    .
    .
    2011-06-30 14:40 . 2011-06-30 14:40 -------- d-----w- C:\darell
    2011-06-29 07:07 . 2011-06-29 07:07 -------- d-----w- c:\windows\ServicePackFiles
    2011-06-29 07:04 . 2011-06-29 07:19 -------- d-----w- c:\windows\ie8updates
    2011-06-28 22:43 . 2010-05-06 10:41 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
    2011-06-28 22:43 . 2010-05-06 10:41 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
    2011-06-28 22:43 . 2010-05-06 10:41 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
    2011-06-28 22:42 . 2010-05-06 10:41 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
    2011-06-28 22:42 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
    2011-06-28 22:42 . 2010-05-06 10:41 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
    2011-06-28 22:42 . 2010-05-06 10:41 11076096 ------w- c:\windows\system32\dllcache\ieframe.dll
    2011-06-28 22:41 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
    2011-06-28 22:41 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
    2011-06-23 13:24 . 2011-06-28 17:23 -------- d-----w- C:\ComboFix
    2011-06-20 16:09 . 2011-06-20 16:36 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2011-06-20 16:09 . 2011-06-20 16:09 -------- d-----w- c:\program files\Hitman Pro 3.5
    2011-06-20 16:08 . 2011-06-20 16:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
    2011-06-10 19:20 . 2011-06-13 14:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2011-06-10 19:20 . 2011-06-10 19:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2011-06-10 15:27 . 2011-06-10 15:27 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-06-10 15:01 . 2011-06-10 15:01 39192 ----a-w- c:\windows\system32\Partizan.exe
    2011-06-10 15:01 . 2011-06-10 15:01 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
    2011-06-10 15:01 . 2011-05-18 14:53 12808 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
    2011-06-10 15:01 . 2011-06-10 15:23 -------- d-----w- c:\program files\UnHackMe
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-05-29 13:11 . 2011-01-03 17:23 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-06-28_17.32.40 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-06-30 13:50 . 2011-06-30 13:50 16384 c:\windows\Temp\Perflib_Perfdata_780.dat
    + 2003-03-14 17:24 . 2003-03-14 17:24 24576 c:\windows\system32\ZyDelReg.exe
    + 2004-01-14 16:30 . 2004-01-14 16:30 17151 c:\windows\system32\ZDPNDIS5.SYS
    + 2004-01-14 16:25 . 2004-01-14 16:25 81920 c:\windows\system32\ZDPN50.DLL
    + 2004-08-04 05:56 . 2004-08-04 10:00 51712 c:\windows\system32\wzcsapi.dll
    + 2007-04-17 02:45 . 2009-08-06 23:24 44768 c:\windows\system32\wups2.dll
    + 2004-08-10 18:02 . 2009-08-06 23:24 35552 c:\windows\system32\wups.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 13824 c:\windows\system32\wowfaxui.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 23552 c:\windows\system32\wdmaud.drv
    + 2004-08-10 17:51 . 2009-06-25 08:17 59392 c:\windows\system32\wdigest.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 22016 c:\windows\system32\wbem\evntrprv.dll
    + 2003-03-13 20:10 . 2003-03-13 20:10 40960 c:\windows\system32\vxdmdcdlg.dll
    + 1999-11-24 23:40 . 1999-11-24 23:40 40960 c:\windows\system32\VBAME.DLL
    + 1997-01-15 22:00 . 1997-01-15 22:00 29696 c:\windows\system32\Vb5stkit.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 50176 c:\windows\system32\utilman.exe
    + 2004-08-10 17:51 . 2006-10-04 08:48 50176 c:\windows\system32\utilman.exe
    + 2001-08-18 03:36 . 2004-08-04 10:00 49211 c:\windows\system32\usrvpa.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 45116 c:\windows\system32\usrvoica.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 49209 c:\windows\system32\usrv80a.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 41019 c:\windows\system32\usrsvpia.dll
    + 2001-08-18 03:37 . 2004-08-04 10:00 69700 c:\windows\system32\usrshuta.exe
    + 2001-08-18 03:36 . 2004-08-04 10:00 49211 c:\windows\system32\usrsdpia.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 77883 c:\windows\system32\usrrtosa.dll
    + 2001-08-18 03:37 . 2004-08-04 10:00 61508 c:\windows\system32\usrprbda.exe
    + 2001-08-18 03:37 . 2004-08-04 10:00 77891 c:\windows\system32\usrmlnka.exe
    + 2001-08-18 03:36 . 2004-08-04 10:00 53305 c:\windows\system32\usrlbva.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 86073 c:\windows\system32\usrfaxa.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 77890 c:\windows\system32\usrdpa.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 69699 c:\windows\system32\usrcoina.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 61500 c:\windows\system32\usrcntra.dll
    + 2003-02-21 10:16 . 2003-02-21 10:16 49152 c:\windows\system32\URTTemp\regtlib.exe
    - 2004-08-10 17:51 . 2004-08-04 10:00 35840 c:\windows\system32\umandlg.dll
    + 2004-08-10 17:51 . 2006-10-04 13:33 35840 c:\windows\system32\umandlg.dll
    + 2007-03-01 03:54 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
    + 2000-03-22 16:42 . 2000-03-22 16:42 10240 c:\windows\system32\Tscmg4n.dll
    + 2000-03-22 16:42 . 2000-03-22 16:42 23552 c:\windows\system32\Toril1n.dll
    + 2000-12-03 16:09 . 2000-12-03 16:09 33280 c:\windows\system32\Torero1n.dll
    + 2004-08-10 17:51 . 2009-06-12 11:50 76288 c:\windows\system32\telnet.exe
    - 2004-08-10 17:51 . 2004-08-04 10:00 75776 c:\windows\system32\strmfilt.dll
    + 2004-08-10 17:51 . 2009-10-21 06:00 75776 c:\windows\system32\strmfilt.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 72192 c:\windows\system32\sprio800.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 70656 c:\windows\system32\sprio600.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 69632 c:\windows\system32\spnike.dll
    + 2011-06-28 17:35 . 2009-08-06 23:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
    + 2011-06-28 17:35 . 2009-08-06 23:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 32828 c:\windows\system32\Setup\fp40ext.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 56320 c:\windows\system32\secur32.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 29184 c:\windows\system32\sdhcinst.dll
    + 1998-03-25 02:54 . 1998-03-25 02:54 15872 c:\windows\system32\SCP32.DLL
    + 2004-08-10 17:51 . 2009-02-06 09:54 35328 c:\windows\system32\sc.exe
    - 2004-08-10 17:51 . 2004-08-04 10:00 69632 c:\windows\system32\raschap.dll
    + 2004-08-10 17:51 . 2009-10-12 13:54 69632 c:\windows\system32\raschap.dll
    + 2010-03-31 04:16 . 2010-03-31 04:16 99176 c:\windows\system32\PresentationHostProxy.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 15360 c:\windows\system32\pjlmon.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 35328 c:\windows\system32\pid.dll
    + 2004-08-10 17:51 . 2011-06-29 07:41 72576 c:\windows\system32\perfc009.dat
    - 2004-08-10 17:51 . 2011-03-28 14:23 72576 c:\windows\system32\perfc009.dat
    + 2002-10-04 23:04 . 2002-10-04 23:04 45056 c:\windows\system32\ogg.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 49488 c:\windows\system32\netfxperf.dll
    + 2004-08-10 17:51 . 2006-10-04 08:48 53760 c:\windows\system32\narrator.exe
    - 2004-08-10 17:51 . 2004-08-04 10:00 53760 c:\windows\system32\narrator.exe
    + 2009-11-07 05:07 . 2009-11-07 05:07 11600 c:\windows\system32\mui\0409\mscorees.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 87552 c:\windows\system32\mui\0009\hhctrlui.dll
    + 2004-08-10 18:01 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
    + 2004-08-10 17:51 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
    - 2004-08-10 17:51 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
    + 2004-08-04 05:56 . 2009-11-27 17:33 17920 c:\windows\system32\msyuv.dll
    + 2004-08-10 17:51 . 2009-11-27 16:37 28672 c:\windows\system32\msvidc32.dll
    + 1998-08-09 16:07 . 1999-08-19 21:39 94208 c:\windows\system32\msstkprp.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 11264 c:\windows\system32\msrle32.dll
    + 2004-08-10 17:51 . 2009-11-27 16:37 11264 c:\windows\system32\msrle32.dll
    + 2009-03-08 08:31 . 2010-05-06 10:41 55296 c:\windows\system32\msfeedsbs.dll
    - 2009-03-08 08:31 . 2009-03-08 08:31 55296 c:\windows\system32\msfeedsbs.dll
    - 2004-08-10 18:01 . 2004-08-04 10:00 58880 c:\windows\system32\msdtclog.dll
    + 2004-08-10 18:01 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
    + 2004-08-10 17:51 . 2009-09-04 20:45 58880 c:\windows\system32\msasn1.dll
    + 2002-05-15 23:38 . 2002-05-15 23:38 91136 c:\windows\system32\mp4fil32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 14848 c:\windows\system32\mgmtapi.dll
    + 1997-11-25 12:54 . 1997-11-25 12:54 63488 c:\windows\system32\Mfldll32.dll
    + 1997-11-25 12:53 . 1997-11-25 12:53 19456 c:\windows\system32\Mffdib32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 22528 c:\windows\system32\mfcsubs.dll
    + 2004-02-20 20:15 . 2004-02-20 20:15 49152 c:\windows\system32\MFC71KOR.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 49152 c:\windows\system32\MFC71JPN.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 61440 c:\windows\system32\MFC71ITA.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 61440 c:\windows\system32\MFC71FRA.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 61440 c:\windows\system32\MFC71ESP.DLL
    + 2003-10-17 16:44 . 2003-10-17 16:44 57344 c:\windows\system32\MFC71ENU.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 65536 c:\windows\system32\MFC71DEU.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 45056 c:\windows\system32\MFC71CHT.DLL
    + 2004-02-20 20:15 . 2004-02-20 20:15 40960 c:\windows\system32\MFC71CHS.DLL
    + 1998-06-18 00:08 . 1998-06-18 00:08 53248 c:\windows\system32\MFC42ENU.DLL
    + 2004-08-10 17:51 . 2007-03-08 15:36 40960 c:\windows\system32\mf3216.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 39274 c:\windows\system32\mem.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 50176 c:\windows\system32\mdhcp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 28160 c:\windows\system32\mciwave.drv
    + 2004-08-10 17:51 . 2004-08-04 10:00 23552 c:\windows\system32\mciwave.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 25264 c:\windows\system32\mciseq.drv
    + 2004-08-10 17:51 . 2004-08-04 10:00 23040 c:\windows\system32\mciseq.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 35328 c:\windows\system32\mciqtz32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 17408 c:\windows\system32\mcicda.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 84480 c:\windows\system32\mciavi32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 73376 c:\windows\system32\mciavi.drv
    + 2004-08-10 17:51 . 2004-08-04 10:00 10496 c:\windows\system32\mcdsrv32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 10240 c:\windows\system32\mcd32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 14848 c:\windows\system32\mcastmib.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 85504 c:\windows\system32\makecab.exe
    + 2004-08-10 17:51 . 2006-10-04 08:48 72704 c:\windows\system32\magnify.exe
    + 2004-02-23 18:45 . 2004-02-23 18:45 73728 c:\windows\system32\LTLST14N.DLL
    + 2004-02-24 20:23 . 2004-02-24 20:23 45056 c:\windows\system32\LTDLGCOM14N.DLL
     
  21. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    + 2004-02-24 04:27 . 2004-02-24 04:27 81920 c:\windows\system32\LTBAR14N.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 13312 c:\windows\system32\lsass.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 10240 c:\windows\system32\lprhelp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 22016 c:\windows\system32\lpk.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 59392 c:\windows\system32\logman.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 50176 c:\windows\system32\loghours.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 75264 c:\windows\system32\locator.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 11776 c:\windows\system32\localui.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 97280 c:\windows\system32\loadperf.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 13824 c:\windows\system32\lmhsvc.dll
    + 2004-08-10 17:51 . 2005-09-01 01:41 19968 c:\windows\system32\linkinfo.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 29696 c:\windows\system32\lights.exe
    + 2004-08-10 17:51 . 2009-03-08 08:34 43008 c:\windows\system32\licmgr10.dll
    + 2004-02-22 22:14 . 2004-02-22 22:14 49152 c:\windows\system32\LFWPG14N.DLL
    + 2004-02-22 22:14 . 2004-02-22 22:14 49152 c:\windows\system32\LFWMP14N.DLL
    + 2004-02-19 19:25 . 2004-02-19 19:25 61440 c:\windows\system32\LFWMF14N.DLL
    + 2004-02-22 22:14 . 2004-02-22 22:14 49152 c:\windows\system32\LFWFX14N.DLL
    + 2004-02-22 22:14 . 2004-02-22 22:14 53248 c:\windows\system32\LFTGA14N.DLL
    + 2004-02-22 22:12 . 2004-02-22 22:12 45056 c:\windows\system32\LFRAW14N.DLL
    + 2004-02-23 18:51 . 2004-02-23 18:51 73728 c:\windows\system32\LFPSD14N.DLL
    + 2004-02-24 04:28 . 2004-02-24 04:28 53248 c:\windows\system32\LFPNM14N.DLL
    + 2004-02-22 22:11 . 2004-02-22 22:11 53248 c:\windows\system32\LFPCX14N.DLL
    + 2004-02-22 18:29 . 2004-02-22 18:29 86016 c:\windows\system32\LFPCT14N.DLL
    + 2004-02-23 18:51 . 2004-02-23 18:51 49152 c:\windows\system32\LFPCD14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 45056 c:\windows\system32\LFMSP14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 45056 c:\windows\system32\LFMAC14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 53248 c:\windows\system32\LFLMB14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 57344 c:\windows\system32\LFLMA14N.DLL
    + 2004-02-22 22:09 . 2004-02-22 22:09 49152 c:\windows\system32\LFITG14N.DLL
    + 2004-02-22 22:09 . 2004-02-22 22:09 69632 c:\windows\system32\LFGIF14N.DLL
    + 2004-02-23 18:51 . 2004-02-23 18:51 98304 c:\windows\system32\LFFPX14N.DLL
    + 2004-02-24 04:27 . 2004-02-24 04:27 98304 c:\windows\system32\LFFAX14N.DLL
    + 2004-02-22 22:08 . 2004-02-22 22:08 65536 c:\windows\system32\LFEPS14N.DLL
    + 2004-02-20 01:44 . 2004-02-20 01:44 81920 c:\windows\system32\LFDGN14N.DLL
    + 2004-02-24 04:28 . 2004-02-24 04:28 49152 c:\windows\system32\LFCUT14N.DLL
    + 2004-02-22 22:06 . 2004-02-22 22:06 53248 c:\windows\system32\LFCLP14N.DLL
    + 2004-02-19 21:09 . 2004-02-19 21:09 90112 c:\windows\system32\LFCGM14N.DLL
    + 2004-02-22 22:06 . 2004-02-22 22:06 65536 c:\windows\system32\LFCAL14N.DLL
    + 2004-02-22 22:05 . 2004-02-22 22:05 57344 c:\windows\system32\LFBMP14N.DLL
    + 2004-02-24 04:27 . 2004-02-24 04:27 49152 c:\windows\system32\LFAWD14N.DLL
    + 2004-02-22 22:05 . 2004-02-22 22:05 45056 c:\windows\system32\LFAVI14N.DLL
    + 2004-02-24 04:27 . 2004-02-24 04:27 53248 c:\windows\system32\LFANI14N.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 89600 c:\windows\system32\langwrbk.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 42537 c:\windows\system32\keyboard.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 42809 c:\windows\system32\key01.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 14710 c:\windows\system32\kb16.com
    + 2004-08-10 17:51 . 2010-05-06 10:41 25600 c:\windows\system32\jsproxy.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 47952 c:\windows\system32\jobexec.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 65536 c:\windows\system32\jgsh400.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 45568 c:\windows\system32\jgsd400.dll
    + 2004-08-10 17:51 . 2006-06-01 18:47 27648 c:\windows\system32\jgpl400.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 35840 c:\windows\system32\jgmd400.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 44544 c:\windows\system32\jgaw400.dll
    + 2004-08-04 05:56 . 2009-11-27 16:37 48128 c:\windows\system32\iyuv_32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 54272 c:\windows\system32\ixsso.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 20992 c:\windows\system32\ipxwan.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 66560 c:\windows\system32\ipxsap.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 39936 c:\windows\system32\ipxrtmgr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 23552 c:\windows\system32\ipxroute.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 21504 c:\windows\system32\ipxrip.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 69120 c:\windows\system32\ipxpromn.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 83968 c:\windows\system32\ipxmontr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 59904 c:\windows\system32\ipv6mon.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 53248 c:\windows\system32\ipv6.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 44032 c:\windows\system32\ipsec6.exe
    + 2004-08-10 17:51 . 2006-05-19 12:59 94720 c:\windows\system32\iphlpapi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 55808 c:\windows\system32\ipconfig.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 30720 c:\windows\system32\iologmsg.dll
    + 2004-08-10 17:51 . 2009-03-08 08:32 94720 c:\windows\system32\inseng.dll
    + 2004-03-23 21:38 . 2004-03-23 21:38 28672 c:\windows\system32\InsDrvZD.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 15872 c:\windows\system32\inetppui.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 75264 c:\windows\system32\inetpp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 33280 c:\windows\system32\inetmib1.dll
    + 2004-08-10 17:51 . 2009-03-08 08:31 34816 c:\windows\system32\imgutil.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 36921 c:\windows\system32\imeshare.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 70656 c:\windows\system32\ifsutil.dll
    + 2004-08-10 17:51 . 2009-03-08 08:32 71680 c:\windows\system32\iesetup.dll
    + 2004-08-10 17:51 . 2009-03-08 08:32 55808 c:\windows\system32\iernonce.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 54784 c:\windows\system32\icmui.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 80384 c:\windows\system32\iccvid.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 59392 c:\windows\system32\iassvcs.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 86528 c:\windows\system32\iassam.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 17920 c:\windows\system32\iaspolcy.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 62464 c:\windows\system32\iasnap.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 32256 c:\windows\system32\iashlpr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 41472 c:\windows\system32\iasads.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 23552 c:\windows\system32\iasacct.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 41984 c:\windows\system32\htui.dll
    + 2004-08-10 17:51 . 2009-10-21 06:00 25088 c:\windows\system32\httpapi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 14848 c:\windows\system32\hnetmon.dll
    + 2004-08-10 17:51 . 2006-07-21 08:24 72704 c:\windows\system32\hlink.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 20992 c:\windows\system32\hid.dll
    + 2004-08-10 17:51 . 2005-05-27 02:04 41472 c:\windows\system32\hhsetup.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 14848 c:\windows\system32\help.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 39424 c:\windows\system32\grpconv.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 19694 c:\windows\system32\graphics.com
    + 2004-08-10 17:51 . 2004-08-04 10:00 26112 c:\windows\system32\graftabl.com
    + 2004-08-10 17:51 . 2004-08-04 10:00 24576 c:\windows\system32\gdi.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 76800 c:\windows\system32\gcdef.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 60416 c:\windows\system32\fwcfg.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 42496 c:\windows\system32\ftp.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 56320 c:\windows\system32\fsutil.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 81408 c:\windows\system32\fsusd.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 25600 c:\windows\system32\format.com
    + 2004-08-10 17:51 . 2004-08-04 10:00 20992 c:\windows\system32\fontview.exe
    + 2004-08-10 17:51 . 2009-10-15 17:21 82432 c:\windows\system32\fontsub.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 16384 c:\windows\system32\fmifs.dll
    + 2003-07-15 03:57 . 2003-07-15 03:57 32584 c:\windows\system32\FM20ENU.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 87552 c:\windows\system32\fldrclnr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 27136 c:\windows\system32\findstr.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 21504 c:\windows\system32\feclient.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 14848 c:\windows\system32\fc.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 80384 c:\windows\system32\faultrep.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 45568 c:\windows\system32\extrac32.exe
    + 2004-08-10 17:51 . 2008-10-16 10:37 55808 c:\windows\system32\extmgr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 15872 c:\windows\system32\expand.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 55808 c:\windows\system32\eventlog.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 33280 c:\windows\system32\eventcls.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 39424 c:\windows\system32\esentutl.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 17408 c:\windows\system32\esentprf.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 23040 c:\windows\system32\ersvc.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 20480 c:\windows\system32\encapi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 12642 c:\windows\system32\edlin.exe
    + 1998-10-09 21:02 . 1998-10-09 21:02 75776 c:\windows\system32\Dwspy36.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 17920 c:\windows\system32\dvdupgrd.exe
    + 2001-08-18 03:36 . 2004-08-04 10:00 55296 c:\windows\system32\dvdplay.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 10752 c:\windows\system32\dumprep.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 19456 c:\windows\system32\dswave.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 51200 c:\windows\system32\dssec.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 92672 c:\windows\system32\dskquota.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 71680 c:\windows\system32\dsdmoprp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 62976 c:\windows\system32\dsauth.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 16384 c:\windows\system32\ds32gt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 45568 c:\windows\system32\drwtsn32.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 28112 c:\windows\system32\drwatson.exe
    + 2001-08-17 19:02 . 2004-08-04 10:00 58112 c:\windows\system32\drivers\vdmindvd.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 20480 c:\windows\system32\drivers\usbuhci.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 16000 c:\windows\system32\drivers\usbintel.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 57600 c:\windows\system32\drivers\usbhub.sys
    + 2004-08-04 04:08 . 2005-10-25 23:39 27264 c:\windows\system32\drivers\usbehci.sys
    + 2001-08-17 19:03 . 2004-08-04 10:00 23936 c:\windows\system32\drivers\usbcamd2.sys
     
  22. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    2001-08-17 19:03 . 2004-08-04 10:00 23808 c:\windows\system32\drivers\usbcamd.sys
    + 2004-08-04 04:03 . 2004-08-04 10:00 12416 c:\windows\system32\drivers\tunmp.sys
    + 2001-08-17 19:06 . 2004-08-04 10:00 21376 c:\windows\system32\drivers\tsbvcap.sys
    + 2001-08-17 19:01 . 2004-08-04 10:00 51712 c:\windows\system32\drivers\tosdvd.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 48640 c:\windows\system32\drivers\stream.sys
    + 2004-08-04 04:09 . 2004-08-04 10:00 25472 c:\windows\system32\drivers\sonydcam.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 11392 c:\windows\system32\drivers\sfloppy.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 10240 c:\windows\system32\drivers\sffp_sd.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 11136 c:\windows\system32\drivers\sffdisk.sys
    + 2004-08-04 04:15 . 2004-08-04 10:00 64896 c:\windows\system32\drivers\serial.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 15488 c:\windows\system32\drivers\serenum.sys
    + 2004-08-04 04:07 . 2004-08-04 10:00 67584 c:\windows\system32\drivers\sdbus.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 96256 c:\windows\system32\drivers\scsiport.sys
    + 2001-08-17 18:24 . 2004-08-04 10:00 12032 c:\windows\system32\drivers\riodrv.sys
    + 2001-08-17 18:24 . 2004-08-04 10:00 12032 c:\windows\system32\drivers\rio8drv.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 35328 c:\windows\system32\drivers\processr.sys
    + 2004-08-04 03:59 . 2004-08-04 03:59 25088 c:\windows\system32\drivers\pciidex.sys
    + 2004-08-04 04:07 . 2004-08-04 04:07 68224 c:\windows\system32\drivers\pci.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 80128 c:\windows\system32\drivers\parport.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 42496 c:\windows\system32\drivers\p3.sys
    + 2001-08-17 18:24 . 2004-08-04 10:00 12032 c:\windows\system32\drivers\nikedrv.sys
    + 2004-08-04 03:58 . 2004-08-04 10:00 61824 c:\windows\system32\drivers\nic1394.sys
    + 2004-08-04 04:03 . 2004-08-04 10:00 12928 c:\windows\system32\drivers\ndisuio.sys
    + 2004-08-04 04:07 . 2004-08-04 04:07 15488 c:\windows\system32\drivers\mssmbios.sys
    + 2004-08-04 03:58 . 2004-08-04 03:58 23040 c:\windows\system32\drivers\mouclass.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 30080 c:\windows\system32\drivers\modem.sys
    + 2004-08-04 04:07 . 2004-08-04 10:00 63744 c:\windows\system32\drivers\mf.sys
    + 2004-08-10 17:51 . 2009-06-22 11:35 92544 c:\windows\system32\drivers\ksecdd.sys
    + 2004-08-04 03:58 . 2004-08-04 03:58 24576 c:\windows\system32\drivers\kbdclass.sys
    + 2001-08-17 18:58 . 2001-08-17 18:58 35840 c:\windows\system32\drivers\isapnp.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 74752 c:\windows\system32\drivers\ipsec.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 20992 c:\windows\system32\drivers\ipinip.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 32896 c:\windows\system32\drivers\ipfltdrv.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 29056 c:\windows\system32\drivers\ip6fw.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 36096 c:\windows\system32\drivers\intelppm.sys
    + 2004-08-04 04:00 . 2004-08-04 10:00 41856 c:\windows\system32\drivers\imapi.sys
    + 2004-08-04 04:14 . 2004-08-04 10:00 52736 c:\windows\system32\drivers\i8042prt.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 24960 c:\windows\system32\drivers\hidparse.sys
    + 2004-08-04 04:08 . 2004-08-04 10:00 36224 c:\windows\system32\drivers\hidclass.sys
    + 2001-08-17 18:57 . 2004-08-04 10:00 12160 c:\windows\system32\drivers\fsvga.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 20480 c:\windows\system32\drivers\flpydisk.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 34944 c:\windows\system32\drivers\fips.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 27392 c:\windows\system32\drivers\fdc.sys
    + 2004-08-04 04:00 . 2004-08-04 10:00 71040 c:\windows\system32\drivers\dxg.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 10496 c:\windows\system32\drivers\dxapi.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 14208 c:\windows\system32\drivers\diskdump.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 36352 c:\windows\system32\drivers\disk.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 36480 c:\windows\system32\drivers\crusoe.sys
    + 2001-08-17 18:24 . 2004-08-04 10:00 11776 c:\windows\system32\drivers\cpqdap01.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 49664 c:\windows\system32\drivers\classpnp.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 49536 c:\windows\system32\drivers\cdrom.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 63744 c:\windows\system32\drivers\cdfs.sys
    + 2001-08-17 18:52 . 2004-08-04 10:00 18688 c:\windows\system32\drivers\cdaudio.sys
    + 2001-08-17 18:52 . 2001-08-17 18:52 13952 c:\windows\system32\drivers\cbidf2k.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 71552 c:\windows\system32\drivers\bridge.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 55936 c:\windows\system32\drivers\atmlane.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 31360 c:\windows\system32\drivers\atmepvc.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 59904 c:\windows\system32\drivers\atmarpc.sys
    + 2004-08-04 03:59 . 2004-08-04 03:59 95360 c:\windows\system32\drivers\atapi.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 14336 c:\windows\system32\drivers\asyncmac.sys
    + 2004-08-04 03:58 . 2004-08-04 10:00 60800 c:\windows\system32\drivers\arp1394.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 37376 c:\windows\system32\drivers\amdk7.sys
    + 2004-08-04 03:59 . 2004-08-04 10:00 36992 c:\windows\system32\drivers\amdk6.sys
    + 2001-08-17 18:57 . 2004-08-04 10:00 11648 c:\windows\system32\drivers\acpiec.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 57344 c:\windows\system32\dpwsockx.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 42768 c:\windows\system32\dpwsock.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 83456 c:\windows\system32\dpvsetup.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 21504 c:\windows\system32\dpvacm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 53520 c:\windows\system32\dpserial.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 61952 c:\windows\system32\dpnwsock.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 18432 c:\windows\system32\dpnsvr.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 62464 c:\windows\system32\dpnmodem.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 60928 c:\windows\system32\dpnhupnp.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 35328 c:\windows\system32\dpnhpast.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 23552 c:\windows\system32\dpmodemx.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 30208 c:\windows\system32\dplaysvr.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 33040 c:\windows\system32\dplay.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 97280 c:\windows\system32\dpcdll.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 53840 c:\windows\system32\dosx.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 10752 c:\windows\system32\doskey.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 48128 c:\windows\system32\docprop2.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 46080 c:\windows\system32\docprop.dll
    + 2004-08-10 17:50 . 2008-02-20 05:32 45568 c:\windows\system32\dnsrslvr.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 52224 c:\windows\system32\dmutil.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 23552 c:\windows\system32\dmserver.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 82432 c:\windows\system32\dmscript.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 15872 c:\windows\system32\dmremote.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\system32\dmocx.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 35840 c:\windows\system32\dmloader.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 18432 c:\windows\system32\dmintf.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 61440 c:\windows\system32\dmcompos.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 28672 c:\windows\system32\dmband.dll
    + 2004-08-10 18:02 . 2009-08-06 23:24 35552 c:\windows\system32\dllcache\wups.dll
    + 2009-06-25 08:44 . 2009-06-25 08:17 59392 c:\windows\system32\dllcache\wdigest.dll
    + 2006-10-04 08:48 . 2006-10-04 08:48 50176 c:\windows\system32\dllcache\utilman.exe
    + 2006-10-04 13:33 . 2006-10-04 13:33 35840 c:\windows\system32\dllcache\umandlg.dll
    + 2009-06-12 11:50 . 2009-06-12 11:50 76288 c:\windows\system32\dllcache\telnet.exe
    + 2009-10-21 06:00 . 2009-10-21 06:00 75776 c:\windows\system32\dllcache\strmfilt.dll
    + 2009-06-25 08:44 . 2009-06-25 08:17 56320 c:\windows\system32\dllcache\secur32.dll
    + 2011-06-28 22:44 . 2009-02-06 09:54 35328 c:\windows\system32\dllcache\sc.exe
    + 2009-10-12 13:54 . 2009-10-12 13:54 69632 c:\windows\system32\dllcache\raschap.dll
    + 2006-10-04 08:48 . 2006-10-04 08:48 53760 c:\windows\system32\dllcache\narrator.exe
    + 2008-06-12 14:16 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
    + 2008-06-12 14:16 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
    + 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\system32\dllcache\msyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 28672 c:\windows\system32\dllcache\msvidc32.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 11264 c:\windows\system32\dllcache\msrle32.dll
    + 2008-06-12 14:16 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
    + 2009-09-04 20:45 . 2009-09-04 20:45 58880 c:\windows\system32\dllcache\msasn1.dll
    + 2006-10-04 08:48 . 2006-10-04 08:48 72704 c:\windows\system32\dllcache\magnify.exe
    + 2009-06-22 11:34 . 2009-06-22 11:35 92544 c:\windows\system32\dllcache\ksecdd.sys
    + 2007-03-01 03:53 . 2010-05-06 10:41 25600 c:\windows\system32\dllcache\jsproxy.dll
    - 2007-03-01 03:53 . 2009-03-08 08:33 25600 c:\windows\system32\dllcache\jsproxy.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\system32\dllcache\iyuv_32.dll
    + 2009-10-21 06:00 . 2009-10-21 06:00 25088 c:\windows\system32\dllcache\httpapi.dll
    + 2011-06-28 22:44 . 2009-10-15 17:21 82432 c:\windows\system32\dllcache\fontsub.dll
    + 2009-12-14 07:35 . 2009-12-14 07:35 33280 c:\windows\system32\dllcache\csrsrv.dll
    + 2011-06-28 22:44 . 2005-07-26 04:20 60416 c:\windows\system32\dllcache\colbact.dll
    + 2004-08-10 17:50 . 2009-08-06 23:24 96480 c:\windows\system32\dllcache\cdm.dll
    + 2010-01-13 14:10 . 2010-01-13 14:10 85504 c:\windows\system32\dllcache\cabview.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 84992 c:\windows\system32\dllcache\avifil32.dll
    + 2009-07-17 18:55 . 2009-07-17 18:55 58880 c:\windows\system32\dllcache\atl.dll
    + 2010-03-05 14:57 . 2010-03-05 14:57 65536 c:\windows\system32\dllcache\asycfilt.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 45083 c:\windows\system32\dispex.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 17920 c:\windows\system32\diskperf.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 44032 c:\windows\system32\dimap.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 68608 c:\windows\system32\digest.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 85504 c:\windows\system32\diantz.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 74240 c:\windows\system32\dhcpsapi.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 28672 c:\windows\system32\dfsshlex.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 38912 c:\windows\system32\dfrgsnap.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 51200 c:\windows\system32\dfrgres.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 82432 c:\windows\system32\dfrgfat.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 59904 c:\windows\system32\devenum.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 18432 c:\windows\system32\deskperf.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 16896 c:\windows\system32\deskmon.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 16384 c:\windows\system32\deskadp.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 25088 c:\windows\system32\defrag.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 20634 c:\windows\system32\debug.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 27136 c:\windows\system32\ddrawex.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 30208 c:\windows\system32\ddeshare.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 39424 c:\windows\system32\ddeml.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 28672 c:\windows\system32\dbnmpntw.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 24576 c:\windows\system32\dbmsrpcn.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 24576 c:\windows\system32\davclnt.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 54272 c:\windows\system32\dataclen.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 47616 c:\windows\system32\d3dxof.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 34816 c:\windows\system32\d3dpmesh.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 27200 c:\windows\system32\ctl3dv2.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 73728 c:\windows\system32\csseqchk.dll
    + 2004-08-10 17:50 . 2009-12-14 07:35 33280 c:\windows\system32\csrsrv.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 98304 c:\windows\system32\cscript.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 60416 c:\windows\system32\cryptsvc.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 63488 c:\windows\system32\cryptnet.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 53760 c:\windows\system32\cryptext.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 33280 c:\windows\system32\cryptdll.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 74752 c:\windows\system32\cryptdlg.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 27097 c:\windows\system32\country.sys
    + 2004-08-10 17:50 . 2009-03-08 08:33 18944 c:\windows\system32\corpol.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 13824 c:\windows\system32\convert.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 66560 c:\windows\system32\console.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 27648 c:\windows\system32\conime.exe
    + 2007-05-08 19:11 . 2011-06-30 12:50 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2007-05-08 19:11 . 2011-06-28 15:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2011-06-28 20:28 . 2011-06-30 12:50 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2004-08-10 17:50 . 2004-08-04 10:00 30160 c:\windows\system32\compobj.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 17408 c:\windows\system32\compact.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 15872 c:\windows\system32\comp.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 32816 c:\windows\system32\commdlg.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 50620 c:\windows\system32\command.com
    + 2004-08-10 17:50 . 2004-08-04 10:00 10544 c:\windows\system32\comm.drv
    - 2004-08-10 18:01 . 2005-07-26 04:39 60416 c:\windows\system32\colbact.dll
    + 2004-08-10 18:01 . 2005-07-26 04:20 60416 c:\windows\system32\colbact.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 26624 c:\windows\system32\cnvfat.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 32768 c:\windows\system32\cnetcfg.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 47104 c:\windows\system32\cnbjmon.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 39936 c:\windows\system32\cmutil.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 63488 c:\windows\system32\cmstp.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 13824 c:\windows\system32\cmsetACL.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 14336 c:\windows\system32\cmpbk32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 39936 c:\windows\system32\cmmon32.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 47104 c:\windows\system32\cmdl32.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 15872 c:\windows\system32\cmcfg32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 57856 c:\windows\system32\clusapi.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 33280 c:\windows\system32\clipsrv.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 20480 c:\windows\system32\cliconfg.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 77824 c:\windows\system32\cliconfg.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 64000 c:\windows\system32\cleanmgr.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 10752 c:\windows\system32\clb.dll
    + 2004-08-10 17:50 . 2006-06-22 05:06 69120 c:\windows\system32\ciodm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 11264 c:\windows\system32\chkntfs.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 11776 c:\windows\system32\chkdsk.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 16896 c:\windows\system32\cfgmgr32.dll
    + 2004-08-10 17:50 . 2009-08-06 23:24 96480 c:\windows\system32\cdm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 27648 c:\windows\system32\ccfgnt.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 50688 c:\windows\system32\camocx.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 18432 c:\windows\system32\cacls.exe
    + 2004-08-10 17:50 . 2010-01-13 14:10 85504 c:\windows\system32\cabview.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 59904 c:\windows\system32\cabinet.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 50688 c:\windows\system32\btpanui.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 30208 c:\windows\system32\bthserv.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 20992 c:\windows\system32\bthci.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 78336 c:\windows\system32\browsewm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 77312 c:\windows\system32\browser.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 63488 c:\windows\system32\browselc.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 12288 c:\windows\system32\bootvid.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 17408 c:\windows\system32\bidispl.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 28672 c:\windows\system32\batmeter.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 52736 c:\windows\system32\basesrv.dll
    + 2003-07-15 00:57 . 2003-07-15 00:57 57344 c:\windows\system32\AX7W32N.DLL
    + 2003-07-15 00:57 . 2003-07-15 00:57 90112 c:\windows\system32\AX6W32N.DLL
    + 2003-07-15 00:57 . 2003-07-15 00:57 57344 c:\windows\system32\AX5W32N.DLL
    + 2004-08-10 17:50 . 2009-11-27 16:37 84992 c:\windows\system32\avifil32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 64000 c:\windows\system32\avicap32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 69584 c:\windows\system32\avicap.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 11264 c:\windows\system32\autolfn.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 80384 c:\windows\system32\autodisc.dll
    + 2004-08-10 17:50 . 2005-03-02 18:09 56832 c:\windows\system32\authz.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 14336 c:\windows\system32\auditusr.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 42496 c:\windows\system32\audiosrv.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 11264 c:\windows\system32\attrib.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 34816 c:\windows\system32\atmpvcno.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 30208 c:\windows\system32\atmlib.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 11264 c:\windows\system32\atmadm.exe
    + 2003-10-17 16:44 . 2003-10-17 16:44 89088 c:\windows\system32\atl71.dll
    + 2004-08-10 17:50 . 2009-07-17 18:55 58880 c:\windows\system32\atl.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 13312 c:\windows\system32\atkctrs.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 25088 c:\windows\system32\at.exe
    + 2004-08-10 17:50 . 2010-03-05 14:57 65536 c:\windows\system32\asycfilt.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\system32\arp.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 12498 c:\windows\system32\append.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 70656 c:\windows\system32\amstream.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 17408 c:\windows\system32\alrsvc.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 44544 c:\windows\system32\alg.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 98304 c:\windows\system32\ahui.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 68096 c:\windows\system32\adsmsext.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 26112 c:\windows\system32\adptif.dll
     
  23. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    + 2004-08-10 17:50 . 2009-03-08 08:32 72704 c:\windows\system32\admparse.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 25600 c:\windows\system32\aaaamon.dll
    + 2000-04-06 16:44 . 2000-04-06 16:44 53248 c:\windows\system32\3hpac32.dll
    + 1999-03-11 17:43 . 1999-03-11 17:43 15872 c:\windows\system32\3hist10.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 55632 c:\windows\system32\1033\dwintl.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 20480 c:\windows\msagent\intl\agt0c0a.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 20992 c:\windows\msagent\intl\agt0816.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\msagent\intl\agt041d.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 20480 c:\windows\msagent\intl\agt0416.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\msagent\intl\agt0414.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 20992 c:\windows\msagent\intl\agt0413.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 20992 c:\windows\msagent\intl\agt0410.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 21504 c:\windows\msagent\intl\agt040c.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\msagent\intl\agt040b.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\msagent\intl\agt0409.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 21504 c:\windows\msagent\intl\agt0407.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 19456 c:\windows\msagent\intl\agt0406.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 24064 c:\windows\msagent\agtintl.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 44032 c:\windows\msagent\agentsr.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 24064 c:\windows\msagent\agentpsh.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 49152 c:\windows\msagent\agentmpx.dll
    + 2004-08-10 17:50 . 2007-03-09 13:46 57344 c:\windows\msagent\agentdpv.dll
    + 2004-08-10 17:50 . 2006-10-12 14:02 42496 c:\windows\msagent\agentdp2.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 24064 c:\windows\msagent\agentanm.dll
    - 2008-07-30 00:16 . 2008-07-30 00:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
    + 2010-04-08 03:48 . 2010-04-08 03:48 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
    + 2010-03-23 09:31 . 2010-03-23 09:31 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    + 2004-07-15 07:11 . 2004-07-15 07:11 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
    + 2009-06-24 23:56 . 2009-06-24 23:56 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
    + 2004-07-15 19:28 . 2004-07-15 19:28 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
    + 2010-04-01 15:42 . 2010-04-01 15:42 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
    + 2004-07-15 05:35 . 2004-07-15 05:35 66560 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
    + 2003-02-21 12:26 . 2003-02-21 12:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
    + 2003-02-21 12:26 . 2003-02-21 12:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
    + 2004-07-15 05:34 . 2004-07-15 05:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_PerfCounter.dll
    + 2003-02-21 00:09 . 2003-02-21 00:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_mscorsn.dll
    + 2004-07-15 05:32 . 2004-07-15 05:32 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_CORPerfMonExt.dll
    + 2003-02-21 12:25 . 2003-02-21 12:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
    + 2004-07-15 19:28 . 2004-07-15 19:28 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
    + 2003-02-21 12:25 . 2003-02-21 12:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
    + 2004-07-15 05:34 . 2004-07-15 05:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
    + 2003-02-21 00:09 . 2003-02-21 00:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
    + 2003-02-20 23:43 . 2003-02-20 23:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
    + 2003-02-21 00:18 . 2003-02-21 00:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
    - 2007-04-14 00:58 . 2007-04-14 00:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    + 2010-03-31 18:51 . 2010-03-31 18:51 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
    + 2004-07-15 05:33 . 2004-07-15 05:33 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
    + 2003-02-21 00:06 . 2003-02-21 00:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    + 2010-03-31 18:51 . 2010-03-31 18:51 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
    + 2004-07-15 05:32 . 2004-07-15 05:32 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
    + 2004-07-15 19:28 . 2004-07-15 19:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
    + 2003-02-21 12:25 . 2003-02-21 12:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
    + 2003-02-21 12:24 . 2003-02-21 12:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
    + 2003-02-21 00:22 . 2003-02-21 00:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
    + 2004-07-15 19:31 . 2004-07-15 19:31 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
    + 2003-10-08 19:30 . 2003-10-08 19:30 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
    + 2003-02-21 09:12 . 2003-02-21 09:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
    + 2003-02-21 12:24 . 2003-02-21 12:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
    + 2004-07-15 16:23 . 2004-07-15 16:23 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
    + 2010-03-31 18:51 . 2010-03-31 18:51 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    - 2007-04-14 00:57 . 2007-04-14 00:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
    + 2003-02-21 12:24 . 2003-02-21 12:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
    + 2010-03-31 19:32 . 2010-03-31 19:32 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    - 2007-04-14 01:30 . 2007-04-14 01:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    + 2004-07-15 06:49 . 2004-07-15 06:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
    + 2004-07-15 06:49 . 2004-07-15 06:49 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
    + 2003-02-21 00:19 . 2003-02-21 00:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
    + 2010-03-31 19:32 . 2010-03-31 19:32 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
    + 2003-02-21 10:00 . 2003-02-21 10:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
    + 2003-02-21 08:55 . 2003-02-21 08:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
    + 2003-02-21 07:59 . 2003-02-21 07:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 13664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 86864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
    + 2011-06-29 07:02 . 2011-06-29 07:02 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
    + 2003-07-15 04:00 . 2003-07-15 04:00 99904 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
    + 2003-07-15 03:43 . 2003-07-15 03:43 74288 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\RM.DLL
    + 2003-07-15 03:43 . 2003-07-15 03:43 64056 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
    + 2003-07-15 03:44 . 2003-07-15 03:44 88128 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
    + 2003-07-15 03:41 . 2003-07-15 03:41 24640 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
    + 2003-07-15 03:53 . 2003-07-15 03:53 95792 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OSA.EXE
    + 2003-07-15 08:14 . 2003-07-15 08:14 27192 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
    + 2003-06-18 22:31 . 2003-06-18 22:31 35328 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
    + 2003-06-18 22:31 . 2003-06-18 22:31 18944 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
    + 2003-06-18 22:31 . 2003-06-18 22:31 17920 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
    + 2003-07-15 03:57 . 2003-07-15 03:57 87096 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
    + 2003-07-15 03:53 . 2003-07-15 03:53 34880 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\DWTRIG20.EXE
    + 2003-07-15 03:52 . 2003-07-15 03:52 39992 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\DWDCW20.DLL
    + 2003-07-25 23:57 . 2003-07-25 23:57 75832 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
    + 2003-07-15 08:18 . 2003-07-15 08:18 47160 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
    + 2003-07-15 03:53 . 2003-07-15 03:53 60984 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
    + 2003-07-15 03:43 . 2003-07-15 03:43 87616 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
    + 2011-06-29 07:09 . 2009-03-08 08:33 12288 c:\windows\ie8updates\KB982381-IE8\xpshims.dll
    + 2011-06-29 07:09 . 2009-03-08 08:31 55296 c:\windows\ie8updates\KB982381-IE8\msfeedsbs.dll
    + 2011-06-29 07:09 . 2009-03-08 08:33 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
    + 2004-08-10 17:51 . 2005-05-26 23:22 10752 c:\windows\hh.exe
    + 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\Driver Cache\i386\msyuv.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ecc25a07\System.Drawing.Design.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_3b4a0120\CustomMarshalers.dll
    + 2011-06-29 07:25 . 2011-06-29 07:25 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\3f4b032f69a5c5408ed124f73612b902\UIAutomationProvider.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 26112 c:\windows\assembly\NativeImages_v2.0.50727_32\TVM\63bbe5f95f8b433b9100e46fefc247fc\TVM.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\TVM\2198450d3364c3b17bfb6dfc3f67ad7f\TVM.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6fe7f0c5ee99d48297109820b910bb17\System.Windows.Presentation.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\8dbca20b6ecf6da8ffabe13ef19c514a\System.Web.DynamicData.Design.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\e57e41d9162e72ab646a17ac50c6840f\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\188a8e4b692c01a330f1e5486b22e2c5\System.AddIn.Contract.ni.dll
    + 2011-06-29 07:24 . 2011-06-29 07:24 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\73d407971018d6bca7ec233cd93d6a3b\PresentationFontCache.ni.exe
    + 2011-06-29 07:23 . 2011-06-29 07:23 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\c0769ccd04fe7ea7cb418c3db7a37e8f\PresentationCFFRasterizer.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\b7e05865cd09fecf5c552c3d4ef634d6\Microsoft.Vsa.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\509b3396dd29144152413ee3c589c784\Microsoft.VisualC.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\946c582dd68fd3bd12479841e90391d4\Microsoft.Build.Framework.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\140a057c468f700fa6f11da9fc446184\Microsoft.Build.Framework.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 68608 c:\windows\assembly\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Inte#\a144cc8f772b8d45256a48434f88a63d\Intuit.Ctg.Wte.InterviewControlLibrary.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\e3adb754fc181d07ba9798064436efab\dfsvc.ni.exe
    + 2011-06-29 07:26 . 2011-06-29 07:26 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\4fa74462ee1789cab005c46417ab29d4\Accessibility.ni.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    + 2011-06-29 07:07 . 2011-06-29 07:07 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
    - 2010-01-26 14:46 . 2010-01-26 14:46 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 3200 c:\windows\system32\wowfax.dll
    + 1998-05-12 03:01 . 1998-05-12 03:01 4608 c:\windows\system32\W95Inf32.dll
    + 1998-05-12 03:01 . 1998-05-12 03:01 2272 c:\windows\system32\W95Inf16.dll
    + 2001-08-18 03:36 . 2009-11-27 16:37 8704 c:\windows\system32\tsbyuv.dll
    + 2001-08-18 03:36 . 2001-08-18 03:36 8192 c:\windows\system32\streamci.dll
    + 2003-02-20 23:43 . 2003-02-20 23:43 4096 c:\windows\system32\mui\0409\mscoreer.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\mciole32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 8192 c:\windows\system32\mciole16.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 4608 c:\windows\system32\mchgrcoi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 8192 c:\windows\system32\mag_hook.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 9936 c:\windows\system32\lzexpand.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 2560 c:\windows\system32\lz32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 9216 c:\windows\system32\lprmonui.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 8192 c:\windows\system32\lpr.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\lpq.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 5120 c:\windows\system32\lodctr.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 9728 c:\windows\system32\label.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 2000 c:\windows\system32\keyboard.drv
    + 2004-08-10 17:51 . 2004-08-04 10:00 7040 c:\windows\system32\kdcom.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7424 c:\windows\system32\kd1394.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdusx.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdusr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdusl.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdus.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdur.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\kbdukx.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbduk.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdsw.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdsp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\kbdsmsno.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\kbdsmsfi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdsg.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdsf.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdpo.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdpl1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdpl.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\kbdno1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdno.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\kbdnec.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdne.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdmon.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdmlt48.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdmlt47.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdmaori.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdmac.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdlv1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdlv.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdlt1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdlt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdla.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdkyr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdkaz.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdit142.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdit.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdir.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdic.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdhu1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdhu.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 8192 c:\windows\system32\kbdhept.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdhela3.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdhela2.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdhe319.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdhe220.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdhe.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdgr1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdgr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdgkl.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdgae.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdfr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdfo.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\kbdfi1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdfi.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdfc.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdest.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdes.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5120 c:\windows\system32\kbddv.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdda.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdcz2.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdcz1.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\kbdcz.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\kbdcr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\kbdcan.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdca.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdbu.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdbr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdblr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdbene.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6144 c:\windows\system32\kbdbe.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdazel.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 5632 c:\windows\system32\kbdaze.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 6656 c:\windows\system32\KBDAL.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 4096 c:\windows\system32\iprtprio.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 3584 c:\windows\system32\iprop.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 8192 c:\windows\system32\igmpagnt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 3584 c:\windows\system32\icmp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\hostname.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 4768 c:\windows\system32\himem.sys
    + 2004-08-04 05:56 . 2004-08-04 10:00 7168 c:\windows\system32\hccoin.dll
    + 2004-06-15 19:55 . 2004-06-15 19:55 7882 c:\windows\system32\GTKCMOS.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 9728 c:\windows\system32\gpkrsrc.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 9344 c:\windows\system32\framebuf.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 7168 c:\windows\system32\forcedos.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 3072 c:\windows\system32\fixmapi.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 9216 c:\windows\system32\finger.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 9216 c:\windows\system32\find.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 8424 c:\windows\system32\exe2bin.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 8704 c:\windows\system32\eventvwr.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 4096 c:\windows\system32\dsprpres.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 4656 c:\windows\system32\ds16gt.dLL
    + 2001-08-17 19:03 . 2004-08-04 10:00 4736 c:\windows\system32\drivers\usbd.sys
    + 2004-08-04 03:58 . 2004-08-04 03:58 4352 c:\windows\system32\drivers\swenum.sys
    + 2001-08-17 18:51 . 2001-08-17 18:51 3328 c:\windows\system32\drivers\pciide.sys
    + 2001-08-17 18:57 . 2004-08-04 10:00 3456 c:\windows\system32\drivers\oprghdlr.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 7680 c:\windows\system32\drivers\mcd.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 7936 c:\windows\system32\drivers\fs_rec.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 3328 c:\windows\system32\drivers\dxgthk.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 5888 c:\windows\system32\drivers\dmload.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 4224 c:\windows\system32\drivers\beep.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 3584 c:\windows\system32\dpnlobby.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 3584 c:\windows\system32\dpnaddr.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 4608 c:\windows\system32\dllhst3g.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 5120 c:\windows\system32\dllhost.exe
    + 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\system32\dllcache\tsbyuv.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 7168 c:\windows\system32\diskcopy.com
    + 2004-08-10 17:50 . 2004-08-04 10:00 9216 c:\windows\system32\diskcomp.com
    + 2004-06-09 13:29 . 2004-06-09 13:29 6977 c:\windows\system32\DDMI2.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 8704 c:\windows\system32\dciman32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 1788 c:\windows\system32\Dcache.bin
    + 2004-08-10 17:50 . 2004-08-04 10:00 8192 c:\windows\system32\d3d8thk.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 6144 c:\windows\system32\csrss.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 8192 c:\windows\system32\control.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 3584 c:\windows\system32\comcat.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 7680 c:\windows\system32\ckcnv.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 5632 c:\windows\system32\cisvc.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 8192 c:\windows\system32\cidaemon.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 7680 c:\windows\system32\chcp.com
    + 2004-08-10 17:50 . 2004-08-04 10:00 5120 c:\windows\system32\bootvrfy.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 4608 c:\windows\system32\bootok.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 9029 c:\windows\system32\ansi.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 4096 c:\windows\system32\actmovie.exe
    + 2003-02-21 00:09 . 2003-02-21 00:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
    + 2003-02-21 12:25 . 2003-02-21 12:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
    + 2003-02-21 12:25 . 2003-02-21 12:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
    + 2004-07-15 19:31 . 2004-07-15 19:31 8192 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
    + 2003-02-21 12:24 . 2003-02-21 12:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
    + 2003-02-21 12:24 . 2003-02-21 12:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
    + 2002-06-27 17:45 . 2002-06-27 17:45 5120 c:\windows\Microsoft.NET\Framework\sbs_VsaVb7rt.dll
    + 2002-05-14 14:42 . 2002-05-14 14:42 5632 c:\windows\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll
    + 2002-05-14 14:42 . 2002-05-14 14:42 5120 c:\windows\Microsoft.NET\Framework\sbs_iehost.dll
    + 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    - 2007-03-01 03:53 . 2008-10-15 14:00 351744 c:\windows\system32\xpsp3res.dll
    + 2007-03-01 03:53 . 2009-04-15 09:24 351744 c:\windows\system32\xpsp3res.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 359936 c:\windows\system32\wzcsvc.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 108032 c:\windows\system32\wshbth.dll
    + 2004-08-10 17:51 . 2009-04-02 03:02 604160 c:\windows\system32\wmspdmod.dll
    + 2004-08-10 17:51 . 2009-07-14 03:43 286208 c:\windows\system32\wmpdxm.dll
    + 2004-08-10 17:51 . 2009-06-10 06:32 132096 c:\windows\system32\wkssvc.dll
    - 2004-08-10 17:51 . 2006-08-17 12:28 132096 c:\windows\system32\wkssvc.dll
    + 2002-08-21 10:13 . 2002-08-21 10:13 189952 c:\windows\system32\WISPTIS.EXE
    + 2004-08-10 17:51 . 2009-12-24 07:05 177664 c:\windows\system32\wintrust.dll
    + 2004-08-10 17:51 . 2010-05-06 10:41 916480 c:\windows\system32\wininet.dll
    + 2004-08-10 17:51 . 2009-08-25 09:47 352256 c:\windows\system32\winhttp.dll
    + 2004-08-10 18:01 . 2009-02-06 09:41 227840 c:\windows\system32\wbem\wmiprvse.exe
    + 2004-08-10 18:01 . 2009-02-10 22:31 453120 c:\windows\system32\wbem\wmiprvsd.dll
    + 2004-08-10 18:01 . 2009-02-09 10:01 473088 c:\windows\system32\wbem\fastprox.dll
    + 2002-10-04 23:04 . 2002-10-04 23:04 921600 c:\windows\system32\VorbisEnc.dll
    + 2002-10-04 23:04 . 2002-10-04 23:04 188416 c:\windows\system32\vorbis.dll
    + 1997-10-07 14:57 . 1997-10-07 14:57 416256 c:\windows\system32\Vcfiwz32.dll
    + 2004-08-10 17:51 . 2010-03-10 06:15 420352 c:\windows\system32\vbscript.dll
    - 2004-08-10 17:51 . 2009-03-08 08:33 420352 c:\windows\system32\vbscript.dll
    + 1999-03-26 08:00 . 1999-03-26 08:00 101888 c:\windows\system32\Vb6stkit.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 102457 c:\windows\system32\usrv42a.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 323641 c:\windows\system32\usrdtea.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 347136 c:\windows\system32\tourstart.exe
    + 2004-08-10 17:51 . 2009-10-16 02:51 119808 c:\windows\system32\t2embed.dll
    + 2004-08-10 17:51 . 2009-08-26 08:16 247326 c:\windows\system32\strmdll.dll
    - 2004-08-10 17:51 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll
    + 2003-05-05 21:47 . 2003-05-05 21:47 455168 c:\windows\system32\spool\drivers\w32x86\PSCRIPT5.DLL
    + 2003-05-05 21:47 . 2003-05-05 21:47 129024 c:\windows\system32\spool\drivers\w32x86\PS5UI.DLL
    + 2003-05-05 21:47 . 2003-05-05 21:47 455168 c:\windows\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL
    + 2003-05-05 21:47 . 2003-05-05 21:47 129024 c:\windows\system32\spool\drivers\w32x86\3\Ps5ui.dll
    + 2004-08-10 17:51 . 2009-12-08 09:13 474112 c:\windows\system32\shlwapi.dll
    - 2004-08-10 17:51 . 2008-10-16 10:37 474112 c:\windows\system32\shlwapi.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 435712 c:\windows\system32\shellstyle.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 115712 c:\windows\system32\Setup\imsinsnt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 505344 c:\windows\system32\Setup\iis.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 132608 c:\windows\system32\Setup\fxsocm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 259584 c:\windows\system32\Setup\comsetup.dll
    + 2004-08-10 17:51 . 2009-02-06 10:22 110592 c:\windows\system32\services.exe
    + 2004-08-10 17:51 . 2009-06-25 08:17 168448 c:\windows\system32\schannel.dll
    + 2004-08-10 17:51 . 2009-02-09 10:01 401408 c:\windows\system32\rpcss.dll
    - 2004-08-10 17:51 . 2007-07-09 13:09 584192 c:\windows\system32\rpcrt4.dll
    + 2004-08-10 17:51 . 2009-04-15 15:11 584192 c:\windows\system32\rpcrt4.dll
    + 2000-04-03 22:52 . 2000-04-03 22:52 151552 c:\windows\system32\RDOCURS.DLL
    + 2004-08-10 17:51 . 2009-10-12 13:54 112128 c:\windows\system32\rastls.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 112128 c:\windows\system32\rastls.dll
    + 2010-03-31 04:10 . 2010-03-31 04:10 295264 c:\windows\system32\PresentationHost.exe
    + 2004-08-10 17:51 . 2011-06-29 07:41 445370 c:\windows\system32\perfh009.dat
    - 2004-08-10 17:51 . 2011-03-28 14:23 445370 c:\windows\system32\perfh009.dat
    + 2004-08-10 17:51 . 2009-03-06 14:00 284160 c:\windows\system32\pdh.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 157696 c:\windows\system32\paqsp.dll
    + 1996-04-23 20:44 . 1996-04-23 20:44 227328 c:\windows\system32\P3img32.dll
    + 2004-08-10 17:51 . 2006-10-04 08:48 215552 c:\windows\system32\osk.exe
    - 2004-08-10 17:51 . 2004-08-04 10:00 215552 c:\windows\system32\osk.exe
    + 2002-10-06 18:42 . 2002-10-06 18:42 237568 c:\windows\system32\OggDS.dll
    + 2004-08-10 17:51 . 2010-05-06 10:41 206848 c:\windows\system32\occache.dll
    + 1995-05-22 00:00 . 1995-05-22 00:00 640512 c:\windows\system32\Oc30.dll
    + 2004-08-10 17:51 . 2009-10-13 10:53 266752 c:\windows\system32\oakley.dll
    - 2004-08-10 17:51 . 2004-08-04 10:00 266752 c:\windows\system32\oakley.dll
    + 2004-08-10 17:51 . 2009-02-09 10:01 715264 c:\windows\system32\ntdll.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 329728 c:\windows\system32\netsetup.exe
    + 2004-08-10 17:51 . 2009-02-06 18:46 408064 c:\windows\system32\netlogon.dll
    + 2004-08-10 17:51 . 2009-08-05 09:11 204800 c:\windows\system32\mswebdvd.dll
    + 2003-10-17 16:44 . 2003-10-17 16:44 348160 c:\windows\system32\msvcr71.dll
    + 2003-10-17 16:44 . 2003-10-17 16:44 499712 c:\windows\system32\msvcp71.dll
    + 2004-08-10 17:51 . 2009-09-11 14:03 136192 c:\windows\system32\msv1_0.dll
    + 2004-08-10 18:01 . 2009-06-05 07:42 655872 c:\windows\system32\mstscax.dll
    - 2004-08-10 17:51 . 2009-03-08 08:32 611840 c:\windows\system32\mstime.dll
    + 2004-08-10 17:51 . 2010-05-06 10:41 611840 c:\windows\system32\mstime.dll
    + 2000-04-04 00:05 . 2000-04-04 00:05 118784 c:\windows\system32\msstdfmt.dll
    + 2000-05-11 18:06 . 2000-05-11 18:06 397312 c:\windows\system32\MSRDO20.DLL
    - 2004-08-10 18:01 . 2004-08-04 10:00 343040 c:\windows\system32\mspaint.exe
    + 2004-08-10 18:01 . 2009-12-16 12:58 343040 c:\windows\system32\mspaint.exe
    + 2004-08-10 17:50 . 2008-03-25 04:50 355112 c:\windows\system32\msjetoledb40.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 294912 c:\windows\system32\msh263.drv
    + 2009-03-08 08:32 . 2010-05-06 10:41 599040 c:\windows\system32\msfeeds.dll
    + 2004-08-10 18:01 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
    + 2004-08-10 18:01 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
    + 2004-08-10 18:01 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
    + 2009-11-07 05:07 . 2009-11-07 05:07 297808 c:\windows\system32\mscoree.dll
    + 2001-04-01 23:47 . 2001-04-01 23:47 416304 c:\windows\system32\Mpg4c32.dll
    + 1996-03-19 23:00 . 1996-03-19 23:00 133904 c:\windows\system32\Mfcans32.dll
    + 2004-08-10 17:51 . 2006-12-14 13:45 981760 c:\windows\system32\mfc42u.dll
    + 2004-08-10 17:51 . 2006-11-01 19:17 927504 c:\windows\system32\mfc40u.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 924432 c:\windows\system32\mfc40.dll
    + 2001-08-18 03:36 . 2004-08-04 10:00 147968 c:\windows\system32\mdwmdmsp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 118272 c:\windows\system32\mdminst.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 112128 c:\windows\system32\mapistub.dll
    + 2004-02-21 12:08 . 2004-02-21 12:08 107008 c:\windows\system32\LTRVR14N.DLL
    + 2004-04-22 20:26 . 2004-04-22 20:26 954368 c:\windows\system32\LTRTN14N.DLL
    + 2004-02-23 18:26 . 2004-02-23 18:26 811520 c:\windows\system32\LTR14N.DLL
    + 2004-02-23 18:45 . 2004-02-23 18:45 475136 c:\windows\system32\LTKRN14N.DLL
    + 2004-02-22 21:58 . 2004-02-22 21:58 954368 c:\windows\system32\LTIMG14N.DLL
    + 2004-02-24 04:26 . 2004-02-24 04:26 163840 c:\windows\system32\LTFIL14N.DLL
    + 2004-02-22 21:59 . 2004-02-22 21:59 282624 c:\windows\system32\LTEFX14N.DLL
    + 2004-02-24 20:23 . 2004-02-24 20:23 319488 c:\windows\system32\LTDLGCLR14N.DLL
    + 2004-02-19 22:13 . 2004-02-19 22:13 299008 c:\windows\system32\LTDIS14N.DLL
    + 2004-08-10 17:51 . 2009-06-25 08:17 729600 c:\windows\system32\lsasrv.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 514560 c:\windows\system32\logonui.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 220672 c:\windows\system32\logon.scr
    + 2004-08-10 17:51 . 2009-05-07 15:44 344064 c:\windows\system32\localspl.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 221696 c:\windows\system32\localsec.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 399872 c:\windows\system32\lmrt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 423936 c:\windows\system32\licdll.dll
    + 2002-04-19 14:23 . 2002-04-19 14:23 106137 c:\windows\system32\libpostproc.dll
    + 2002-04-19 13:51 . 2002-04-19 13:51 211760 c:\windows\system32\libavcodec.dll
    + 2004-02-24 03:52 . 2004-02-24 03:52 183296 c:\windows\system32\LFTIF14S.DLL
    + 2004-02-22 22:14 . 2004-02-22 22:14 159744 c:\windows\system32\LFTIF14N.DLL
    + 2004-02-19 21:09 . 2004-02-19 21:09 106496 c:\windows\system32\LFPSP14N.DLL
    + 2004-02-22 22:11 . 2004-02-22 22:11 159744 c:\windows\system32\LFPNG14N.DLL
    + 2004-02-22 22:11 . 2004-02-22 22:11 180224 c:\windows\system32\LFPDF14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 139264 c:\windows\system32\LFPCL14N.DLL
    + 2000-04-12 23:28 . 2000-04-12 23:28 118784 c:\windows\system32\LFKODAK.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 110592 c:\windows\system32\LFJBG14N.DLL
    + 2004-02-22 22:10 . 2004-02-22 22:10 253952 c:\windows\system32\LFJ2K14N.DLL
    + 2000-04-12 23:24 . 2000-04-12 23:24 338944 c:\windows\system32\LFFPX7.DLL
    + 2004-02-24 03:51 . 2004-02-24 03:51 113664 c:\windows\system32\LFFAX14S.DLL
    + 2004-02-24 07:25 . 2004-02-24 07:25 196608 c:\windows\system32\LFDXF14N.DLL
    + 2004-02-22 18:29 . 2004-02-22 18:29 143360 c:\windows\system32\LFDWG14N.DLL
    + 2004-02-19 19:17 . 2004-02-19 19:17 376832 c:\windows\system32\LFDWF14N.DLL
    + 2004-02-22 22:08 . 2004-02-22 22:08 483328 c:\windows\system32\LFCMW14N.DLL
    + 2004-02-22 22:06 . 2004-02-22 22:06 401408 c:\windows\system32\LFCMP14N.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 221600 c:\windows\system32\lanman.drv
    + 2004-08-10 17:51 . 2004-08-04 10:00 150528 c:\windows\system32\keymgr.dll
    + 2004-08-10 17:51 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
    + 2004-08-10 17:51 . 2009-06-25 08:17 301568 c:\windows\system32\kerberos.dll
    + 2004-08-10 17:51 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
     
  24. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    + 2004-08-10 17:51 . 2006-06-01 18:47 163840 c:\windows\system32\jgdw400.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 362496 c:\windows\system32\jet500.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 192000 c:\windows\system32\iuengine.dll
    + 2004-08-10 17:51 . 2005-05-27 02:04 137216 c:\windows\system32\itss.dll
    + 2004-08-10 17:51 . 2005-05-27 02:04 155136 c:\windows\system32\itircl.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 199168 c:\windows\system32\ir32_32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 384000 c:\windows\system32\ipsmsnap.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 182784 c:\windows\system32\ipsecsvc.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 349696 c:\windows\system32\ipsecsnp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 169984 c:\windows\system32\iprtrmgr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 330752 c:\windows\system32\ippromon.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 331264 c:\windows\system32\ipnathlp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 154112 c:\windows\system32\ipmontr.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 123392 c:\windows\system32\input.dll
    + 2002-08-21 10:10 . 2002-08-21 10:10 204800 c:\windows\system32\INKED.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 147456 c:\windows\system32\initpki.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 450560 c:\windows\system32\infosoft.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 110592 c:\windows\system32\inetcplc.dll
    - 2004-08-10 18:02 . 2008-04-11 18:50 683520 c:\windows\system32\inetcomm.dll
    + 2004-08-10 18:02 . 2010-01-29 15:08 683520 c:\windows\system32\inetcomm.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 110080 c:\windows\system32\imm32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 150016 c:\windows\system32\imapi.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 144384 c:\windows\system32\imagehlp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 135680 c:\windows\system32\ifmon.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 114688 c:\windows\system32\iexpress.exe
    + 2004-08-10 17:51 . 2010-05-06 10:41 184320 c:\windows\system32\iepeers.dll
    + 2004-08-10 17:51 . 2010-05-06 10:41 387584 c:\windows\system32\iedkcs32.dll
    + 2004-08-10 17:51 . 2009-03-08 08:32 163840 c:\windows\system32\ieakui.dll
    + 2004-08-10 17:51 . 2009-03-08 08:33 229376 c:\windows\system32\ieaksie.dll
    + 2004-08-10 17:51 . 2009-03-08 08:33 125952 c:\windows\system32\ieakeng.dll
    + 2004-08-10 17:51 . 2010-05-05 13:30 173056 c:\windows\system32\ie4uinit.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 120832 c:\windows\system32\idq.dll
    + 2004-08-10 17:51 . 2005-06-29 01:46 254976 c:\windows\system32\icm32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 247808 c:\windows\system32\iassdo.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 141312 c:\windows\system32\iasrecst.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 119808 c:\windows\system32\iasrad.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 144896 c:\windows\system32\hotplug.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 330752 c:\windows\system32\hnetwiz.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 344064 c:\windows\system32\hnetcfg.dll
    + 2004-08-04 03:59 . 2005-06-23 00:05 134272 c:\windows\system32\HAL.DLL
    + 2004-08-10 17:51 . 2004-08-04 10:00 614912 c:\windows\system32\h323msp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 101888 c:\windows\system32\gpkcsp.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 122880 c:\windows\system32\glu32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 285184 c:\windows\system32\glmf32.dll
    + 2004-08-10 17:51 . 2008-10-23 13:01 283648 c:\windows\system32\gdi32.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 176128 c:\windows\system32\ftsrch.dll
    + 2004-08-04 05:56 . 2004-08-04 10:00 193024 c:\windows\system32\fsquirt.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 382976 c:\windows\system32\fontext.dll
    - 2004-08-10 17:57 . 2011-02-07 17:21 158752 c:\windows\system32\FNTCACHE.DAT
    + 2004-08-10 17:57 . 2011-06-29 07:39 158752 c:\windows\system32\FNTCACHE.DAT
    + 2004-08-10 17:51 . 2004-08-04 10:00 337920 c:\windows\system32\filemgmt.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 121856 c:\windows\system32\exts.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 380957 c:\windows\system32\expsrv.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 193024 c:\windows\system32\eudcedit.exe
    + 2004-08-10 17:51 . 2008-07-07 20:32 253952 c:\windows\system32\es.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 186368 c:\windows\system32\encdec.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 183296 c:\windows\system32\els.dll
    + 2004-08-10 17:51 . 2009-03-08 08:31 216064 c:\windows\system32\dxtrans.dll
    + 2004-08-10 17:51 . 2009-03-08 08:31 348160 c:\windows\system32\dxtmsft.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 619008 c:\windows\system32\dx7vb.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 180224 c:\windows\system32\dwwin.exe
    + 2004-08-10 17:51 . 2004-08-04 10:00 304128 c:\windows\system32\duser.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 113152 c:\windows\system32\dsuiext.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 137216 c:\windows\system32\dssenh.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 218003 c:\windows\system32\dssec.dat
    + 2004-08-10 17:51 . 2004-08-04 10:00 239104 c:\windows\system32\dsquery.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 142336 c:\windows\system32\dsprop.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 367616 c:\windows\system32\dsound.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 144384 c:\windows\system32\dskquoui.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 181760 c:\windows\system32\dsdmo.dll
    + 2004-08-04 04:08 . 2005-10-25 23:39 143104 c:\windows\system32\drivers\usbport.sys
    + 2004-08-10 17:51 . 2010-02-11 12:01 226880 c:\windows\system32\drivers\tcpip6.sys
    + 2004-08-10 17:51 . 2009-12-31 16:14 352640 c:\windows\system32\drivers\srv.sys
    + 2004-03-16 16:58 . 2004-03-16 16:58 136960 c:\windows\system32\drivers\portcls.sys
    + 2004-08-04 04:07 . 2004-08-04 10:00 119936 c:\windows\system32\drivers\pcmcia.sys
    + 2007-03-01 03:39 . 2010-02-24 12:31 454016 c:\windows\system32\drivers\mrxsmb.sys
    + 2004-08-04 04:15 . 2004-08-04 10:00 140928 c:\windows\system32\drivers\ks.sys
    + 2004-08-10 17:51 . 2004-09-29 22:28 134912 c:\windows\system32\drivers\ipnat.sys
    + 2004-08-04 04:00 . 2009-10-20 14:58 263552 c:\windows\system32\drivers\http.sys
    + 2001-08-17 18:52 . 2001-08-17 18:52 125056 c:\windows\system32\drivers\ftdisk.sys
    + 2004-08-10 17:51 . 2004-08-04 10:00 143360 c:\windows\system32\drivers\fastfat.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 153344 c:\windows\system32\drivers\dmio.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 799744 c:\windows\system32\drivers\dmboot.sys
    + 2001-08-17 19:02 . 2004-08-04 10:00 262528 c:\windows\system32\drivers\cinemst2.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 352256 c:\windows\system32\drivers\atmuni.sys
    + 2004-08-10 17:50 . 2008-08-14 09:51 138368 c:\windows\system32\drivers\afd.sys
    + 2004-08-04 04:07 . 2004-08-04 10:00 187776 c:\windows\system32\drivers\acpi.sys
    + 2004-08-10 17:50 . 2004-08-04 10:00 116736 c:\windows\system32\dpvvox.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 212480 c:\windows\system32\dpvoice.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 375296 c:\windows\system32\dpnet.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 229888 c:\windows\system32\dplayx.dll
    + 2004-08-10 17:50 . 2008-06-20 17:41 148992 c:\windows\system32\dnsapi.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 104448 c:\windows\system32\dmusic.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 103424 c:\windows\system32\dmsynth.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 105984 c:\windows\system32\dmstyle.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 181248 c:\windows\system32\dmime.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 118784 c:\windows\system32\dmdskres.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 200704 c:\windows\system32\dmdskmgr.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 273920 c:\windows\system32\dmdlgs.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 330752 c:\windows\system32\dmconfig.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 224768 c:\windows\system32\dmadmin.exe
    + 2009-04-02 03:02 . 2009-04-02 03:02 604160 c:\windows\system32\dllcache\wmspdmod.dll
    + 2009-07-14 03:43 . 2009-07-14 03:43 286208 c:\windows\system32\dllcache\wmpdxm.dll
    + 2011-06-28 22:44 . 2009-02-06 09:41 227840 c:\windows\system32\dllcache\wmiprvse.exe
    + 2009-02-10 22:31 . 2009-02-10 22:31 453120 c:\windows\system32\dllcache\wmiprvsd.dll
    + 2007-03-01 03:53 . 2009-06-10 06:32 132096 c:\windows\system32\dllcache\wkssvc.dll
    - 2007-03-01 03:53 . 2006-08-17 12:28 132096 c:\windows\system32\dllcache\wkssvc.dll
    + 2009-12-24 07:05 . 2009-12-24 07:05 177664 c:\windows\system32\dllcache\wintrust.dll
    + 2007-03-01 03:53 . 2010-05-06 10:41 916480 c:\windows\system32\dllcache\wininet.dll
    + 2008-12-16 12:47 . 2009-08-25 09:47 352256 c:\windows\system32\dllcache\winhttp.dll
    - 2007-12-18 14:40 . 2009-03-08 08:33 420352 c:\windows\system32\dllcache\vbscript.dll
    + 2007-12-18 14:40 . 2010-03-10 06:15 420352 c:\windows\system32\dllcache\vbscript.dll
    + 2011-06-28 22:44 . 2009-06-21 22:04 153088 c:\windows\system32\dllcache\triedit.dll
    + 2007-06-26 13:43 . 2010-02-11 12:01 226880 c:\windows\system32\dllcache\tcpip6.sys
    + 2009-10-16 02:51 . 2009-10-16 02:51 119808 c:\windows\system32\dllcache\t2embed.dll
    + 2006-08-21 14:52 . 2009-08-26 08:16 247326 c:\windows\system32\dllcache\strmdll.dll
    - 2006-08-21 14:52 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll
    + 2007-03-01 03:53 . 2009-12-31 16:14 352640 c:\windows\system32\dllcache\srv.sys
    + 2007-03-01 03:53 . 2009-12-08 09:13 474112 c:\windows\system32\dllcache\shlwapi.dll
    - 2007-03-01 03:53 . 2008-10-16 10:37 474112 c:\windows\system32\dllcache\shlwapi.dll
    + 2011-06-28 22:44 . 2009-02-06 10:22 110592 c:\windows\system32\dllcache\services.exe
    + 2007-06-26 13:46 . 2009-06-25 08:17 168448 c:\windows\system32\dllcache\schannel.dll
    + 2011-06-28 22:44 . 2009-02-09 10:01 401408 c:\windows\system32\dllcache\rpcss.dll
    + 2007-10-09 23:10 . 2009-04-15 15:11 584192 c:\windows\system32\dllcache\rpcrt4.dll
    - 2007-10-09 23:10 . 2007-07-09 13:09 584192 c:\windows\system32\dllcache\rpcrt4.dll
    + 2009-10-12 13:54 . 2009-10-12 13:54 112128 c:\windows\system32\dllcache\rastls.dll
    + 2011-06-28 22:44 . 2009-03-06 14:00 284160 c:\windows\system32\dllcache\pdh.dll
    + 2006-10-04 08:48 . 2006-10-04 08:48 215552 c:\windows\system32\dllcache\osk.exe
    + 2009-03-08 08:34 . 2010-05-06 10:41 206848 c:\windows\system32\dllcache\occache.dll
    + 2009-10-13 10:53 . 2009-10-13 10:53 266752 c:\windows\system32\dllcache\oakley.dll
    + 2011-06-28 22:44 . 2009-02-09 10:01 715264 c:\windows\system32\dllcache\ntdll.dll
    + 2009-02-06 18:46 . 2009-02-06 18:46 408064 c:\windows\system32\dllcache\netlogon.dll
    + 2009-08-05 09:11 . 2009-08-05 09:11 204800 c:\windows\system32\dllcache\mswebdvd.dll
    + 2009-06-25 08:44 . 2009-09-11 14:03 136192 c:\windows\system32\dllcache\msv1_0.dll
    - 2007-03-01 03:53 . 2009-03-08 08:32 611840 c:\windows\system32\dllcache\mstime.dll
    + 2007-03-01 03:53 . 2010-05-06 10:41 611840 c:\windows\system32\dllcache\mstime.dll
    + 2004-03-17 21:05 . 2004-03-17 21:05 134144 c:\windows\system32\dllcache\Mssap.dll
    + 2009-12-16 12:58 . 2009-12-16 12:58 343040 c:\windows\system32\dllcache\mspaint.exe
    + 2008-06-12 14:16 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
    + 2008-06-12 14:16 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
    + 2008-06-12 14:16 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
    + 2006-05-05 09:41 . 2010-02-24 12:31 454016 c:\windows\system32\dllcache\mrxsmb.sys
    + 2007-03-01 03:53 . 2009-06-25 08:17 729600 c:\windows\system32\dllcache\lsasrv.dll
    + 2009-05-07 15:44 . 2009-05-07 15:44 344064 c:\windows\system32\dllcache\localspl.dll
    + 2007-03-01 03:54 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\kernel32.dll
    + 2009-06-25 08:44 . 2009-06-25 08:17 301568 c:\windows\system32\dllcache\kerberos.dll
    - 2007-03-01 03:53 . 2009-03-08 08:33 726528 c:\windows\system32\dllcache\jscript.dll
    + 2007-03-01 03:53 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
    + 2007-03-01 03:54 . 2010-01-29 15:08 683520 c:\windows\system32\dllcache\inetcomm.dll
    - 2007-03-01 03:54 . 2008-04-11 18:50 683520 c:\windows\system32\dllcache\inetcomm.dll
    + 2007-03-01 03:53 . 2010-05-06 10:41 184320 c:\windows\system32\dllcache\iepeers.dll
    + 2009-03-08 18:09 . 2010-05-06 10:41 387584 c:\windows\system32\dllcache\iedkcs32.dll
    - 2009-03-08 08:32 . 2009-03-08 08:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
    + 2009-03-08 08:32 . 2010-05-05 13:30 173056 c:\windows\system32\dllcache\ie4uinit.exe
    + 2009-10-20 14:58 . 2009-10-20 14:58 263552 c:\windows\system32\dllcache\http.sys
    + 2011-06-28 22:44 . 2010-06-14 14:30 743936 c:\windows\system32\dllcache\helpsvc.exe
    + 2011-06-28 22:44 . 2009-02-09 10:01 473088 c:\windows\system32\dllcache\fastprox.dll
    + 2010-04-20 05:51 . 2010-04-20 05:51 285696 c:\windows\system32\dllcache\atmfd.dll
    + 2011-06-28 22:44 . 2009-02-09 10:01 617984 c:\windows\system32\dllcache\advapi32.dll
    + 2011-06-28 22:44 . 2009-11-21 16:36 470528 c:\windows\system32\dllcache\aclayers.dll
    + 2007-06-26 13:43 . 2010-02-12 04:47 100864 c:\windows\system32\dllcache\6to4svc.dll
    + 2001-12-19 04:02 . 2001-12-19 04:02 569344 c:\windows\system32\DivX412.dll
    + 2002-05-13 13:49 . 2002-05-13 13:49 594432 c:\windows\system32\DivX.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 163840 c:\windows\system32\diskpart.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 181760 c:\windows\system32\dinput8.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 159232 c:\windows\system32\dinput.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 394240 c:\windows\system32\diactfrm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 370176 c:\windows\system32\dhcpmon.dll
    + 2004-08-10 17:50 . 2006-05-19 12:59 111616 c:\windows\system32\dhcpcsvc.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 111104 c:\windows\system32\dgnet.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 123904 c:\windows\system32\dfrgui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 104960 c:\windows\system32\dfrgntfs.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 282624 c:\windows\system32\devmgr.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 266240 c:\windows\system32\ddraw.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 110592 c:\windows\system32\dbnetlib.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 640000 c:\windows\system32\dbghelp.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 847872 c:\windows\system32\dbgeng.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 152064 c:\windows\system32\datime.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 350208 c:\windows\system32\d3drm.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 825344 c:\windows\system32\d3dim700.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 436224 c:\windows\system32\d3dim.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 326656 c:\windows\system32\cscui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 101888 c:\windows\system32\cscdll.dll
     
  25. bshaw

    bshaw TS Rookie Topic Starter Posts: 76

    + 2004-08-10 17:50 . 2004-08-04 10:00 512512 c:\windows\system32\cryptui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 597504 c:\windows\system32\crypt32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 149019 c:\windows\system32\crtdll.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 163840 c:\windows\system32\credui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 345600 c:\windows\system32\confmsp.dll
    - 2009-03-31 22:49 . 2009-03-31 22:49 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
    + 2009-03-31 22:49 . 2011-06-29 10:12 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
    + 2004-08-10 17:50 . 2004-08-04 10:00 792064 c:\windows\system32\comres.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 229376 c:\windows\system32\compstui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 252928 c:\windows\system32\compatUI.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 276992 c:\windows\system32\comdlg32.dll
    + 2004-08-10 17:50 . 2006-08-25 15:45 617472 c:\windows\system32\comctl32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 343040 c:\windows\system32\cmdial32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 388608 c:\windows\system32\cmd.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 109568 c:\windows\system32\cic.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 163328 c:\windows\system32\ciadmin.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 457728 c:\windows\system32\certmgr.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 194560 c:\windows\system32\certcli.dll
    + 2004-08-10 17:50 . 2008-10-16 10:37 151040 c:\windows\system32\cdfview.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 359936 c:\windows\system32\cards.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 142848 c:\windows\system32\capesnpn.dll
    + 2003-07-15 00:57 . 2003-07-15 00:57 143360 c:\windows\system32\AXBAR32N.DLL
    + 2003-07-15 00:57 . 2003-07-15 00:57 122880 c:\windows\system32\AX7R32N.DLL
    + 2003-07-15 00:57 . 2003-07-15 00:57 110592 c:\windows\system32\AX6R32N.DLL
    + 2003-07-15 00:57 . 2003-07-15 00:57 106496 c:\windows\system32\AX5R32N.DLL
    + 2004-08-10 17:50 . 2004-08-04 10:00 109456 c:\windows\system32\avifile.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 580608 c:\windows\system32\autofmt.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 602624 c:\windows\system32\autoconv.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 588800 c:\windows\system32\autochk.exe
    + 2004-08-10 17:50 . 2010-04-20 05:51 285696 c:\windows\system32\atmfd.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 126976 c:\windows\system32\apphelp.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 102912 c:\windows\system32\apcups.dll
    + 2004-08-10 17:50 . 2009-03-08 08:32 128512 c:\windows\system32\advpack.dll
    + 2004-08-10 17:50 . 2009-02-09 10:01 617984 c:\windows\system32\advapi32.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 263680 c:\windows\system32\adsnt.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 143360 c:\windows\system32\adsldpc.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 175616 c:\windows\system32\adsldp.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 101888 c:\windows\system32\actxprxy.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 194048 c:\windows\system32\activeds.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 114688 c:\windows\system32\aclui.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 129536 c:\windows\system32\acledit.dll
    + 2004-08-10 17:50 . 2010-02-12 04:47 100864 c:\windows\system32\6to4svc.dll
    + 2002-06-24 21:22 . 2002-06-24 21:22 106496 c:\windows\system32\3zlib10.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 361472 c:\windows\Resources\Themes\Luna\Shell\NormalColor\shellstyle.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 362496 c:\windows\Resources\Themes\Luna\Shell\Metallic\shellstyle.dll
    + 2004-08-10 17:51 . 2004-08-04 10:00 362496 c:\windows\Resources\Themes\Luna\Shell\Homestead\shellstyle.dll
    + 2004-08-10 18:02 . 2010-06-14 14:30 743936 c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    - 2004-08-10 18:02 . 2004-08-04 10:00 743936 c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
    + 2004-08-10 17:50 . 2006-10-12 11:09 256512 c:\windows\msagent\agentsvr.exe
    + 2004-08-10 17:50 . 2004-08-04 10:00 214016 c:\windows\msagent\agentctl.dll
    + 2010-03-31 04:16 . 2010-03-31 04:16 130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
    + 2010-04-08 03:48 . 2010-04-08 03:48 970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
    - 2008-07-30 00:16 . 2008-07-30 00:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
    + 2010-04-08 03:48 . 2010-04-08 03:48 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
    + 2010-03-23 09:31 . 2010-03-23 09:31 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    + 2010-02-09 16:22 . 2010-02-09 16:22 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    - 2008-07-25 16:17 . 2008-07-25 16:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    + 2009-08-08 03:51 . 2009-08-08 03:51 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2004-07-15 16:23 . 2004-07-15 16:23 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
    + 2004-07-15 19:31 . 2004-07-15 19:31 573440 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
    + 2004-07-15 19:31 . 2004-07-15 19:31 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
    + 2004-07-15 19:31 . 2004-07-15 19:31 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
    + 2004-07-15 19:31 . 2004-07-15 19:31 372736 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
    + 2004-07-15 19:31 . 2004-07-15 19:31 303104 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
    + 2004-07-15 05:35 . 2004-07-15 05:35 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
    + 2003-02-21 00:09 . 2003-02-21 00:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
    + 2003-02-21 00:09 . 2003-02-21 00:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
    + 2003-02-21 09:42 . 2003-02-21 09:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_msvcr71.dll
    + 2004-07-15 05:25 . 2004-07-15 05:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_mscorjit.dll
    + 2004-07-15 05:24 . 2004-07-15 05:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_fusion.dll
    + 2004-07-15 06:49 . 2004-07-15 06:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1096\_aspnet_isapi.dll
    + 2003-02-21 09:42 . 2003-02-21 09:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
    + 2004-07-15 05:33 . 2004-07-15 05:33 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
    + 2003-02-20 23:43 . 2003-02-20 23:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
    + 2010-03-31 18:51 . 2010-03-31 18:51 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    - 2007-04-14 00:58 . 2007-04-14 00:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
    - 2007-04-14 00:56 . 2007-04-14 00:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    + 2010-03-31 18:49 . 2010-03-31 18:49 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
    + 2004-07-15 05:32 . 2004-07-15 05:32 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
    + 2004-07-15 19:28 . 2004-07-15 19:28 720896 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
    + 2004-07-15 05:35 . 2004-07-15 05:35 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
    + 2004-07-15 05:24 . 2004-07-15 05:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
    + 2003-02-21 00:16 . 2003-02-21 00:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
    + 2003-02-21 15:21 . 2003-02-21 15:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
    + 2004-07-15 16:23 . 2004-07-15 16:23 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
    + 2002-07-29 16:11 . 2002-07-29 16:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
    - 2007-04-14 01:30 . 2007-04-14 01:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    + 2010-03-31 19:32 . 2010-03-31 19:32 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
    + 2003-02-21 10:04 . 2003-02-21 10:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
    + 2003-02-21 08:02 . 2003-02-21 08:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 969728 c:\windows\Installer\2e594f0.msi
    + 2010-02-25 04:14 . 2010-02-25 04:14 543232 c:\windows\Installer\2e59488.msp
    + 2011-06-29 07:02 . 2011-06-29 07:02 429568 c:\windows\Installer\2e59482.msi
    + 2003-08-06 18:31 . 2003-08-06 18:31 362552 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\SETLANG.EXE
    + 2003-07-15 03:43 . 2003-07-15 03:43 139320 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
    + 2003-07-15 03:45 . 2003-07-15 03:45 196152 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
    + 2003-07-15 08:14 . 2003-07-15 08:14 828472 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
    + 2003-07-15 08:14 . 2003-07-15 08:14 283696 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\OIS.EXE
    + 2003-07-24 03:40 . 2003-07-24 03:40 482872 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
    + 2003-07-15 03:56 . 2003-07-15 03:56 124984 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
    + 2003-07-15 04:02 . 2003-07-15 04:02 627256 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
    + 2003-07-24 03:35 . 2003-07-24 03:35 127032 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
    + 2003-07-15 08:14 . 2003-07-15 08:14 106552 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
    + 2002-04-10 01:14 . 2002-04-10 01:14 187560 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
    + 2002-12-18 00:08 . 2002-12-18 00:08 359600 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
    + 2003-07-15 03:51 . 2003-07-15 03:51 116288 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSCONV97.DLL
    + 2003-07-15 03:58 . 2003-07-15 03:58 230968 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
    + 2003-07-15 04:01 . 2003-07-15 04:01 445496 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MODHELP.DLL
    + 2003-06-18 22:31 . 2003-06-18 22:31 443904 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
    + 2003-06-18 22:31 . 2003-06-18 22:31 758784 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
    + 2003-07-24 03:32 . 2003-07-24 03:32 121400 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
    + 2003-07-15 03:53 . 2003-07-15 03:53 161336 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
    + 2003-07-26 00:14 . 2003-07-26 00:14 799288 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
    + 2003-07-15 04:36 . 2003-07-15 04:36 186424 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
    + 2003-07-31 20:19 . 2003-07-31 20:19 131648 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
    + 2003-07-15 08:14 . 2003-07-15 08:14 350264 c:\windows\Installer\$PatchCache$\Managed\9040311900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
    + 2011-06-29 07:09 . 2009-03-08 08:34 914944 c:\windows\ie8updates\KB982381-IE8\wininet.dll
    + 2011-06-29 07:09 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB982381-IE8\spuninst\updspapi.dll
    + 2011-06-29 07:09 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB982381-IE8\spuninst\spuninst.exe
    + 2011-06-29 07:09 . 2009-03-08 08:34 109568 c:\windows\ie8updates\KB982381-IE8\occache.dll
    + 2011-06-29 07:09 . 2009-03-08 08:32 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
    + 2011-06-29 07:09 . 2009-03-08 08:32 594432 c:\windows\ie8updates\KB982381-IE8\msfeeds.dll
    + 2011-06-29 07:09 . 2009-03-08 08:33 246784 c:\windows\ie8updates\KB982381-IE8\ieproxy.dll
    + 2011-06-29 07:09 . 2009-03-08 08:31 183808 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
    + 2011-06-29 07:09 . 2009-03-08 08:35 742912 c:\windows\ie8updates\KB982381-IE8\iedvtool.dll
    + 2011-06-29 07:09 . 2009-03-08 18:09 391536 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
    + 2011-06-29 07:09 . 2009-03-08 08:32 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
    + 2011-06-29 07:09 . 2009-03-08 08:33 420352 c:\windows\ie8updates\KB981332-IE8\vbscript.dll
    + 2011-06-29 07:09 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB981332-IE8\spuninst\updspapi.dll
    + 2011-06-29 07:09 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB981332-IE8\spuninst\spuninst.exe
    + 2011-06-29 07:20 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
    + 2011-06-29 07:20 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
    + 2011-06-29 07:20 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
    + 2011-06-29 07:04 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
    + 2011-06-29 07:04 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
    + 2011-06-29 07:04 . 2009-03-08 08:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
    + 2004-08-10 17:50 . 2004-08-04 10:00 152576 c:\windows\Help\bnts.dll
    + 2004-03-16 16:58 . 2004-03-16 16:58 136960 c:\windows\Driver Cache\i386\portcls.sys
    + 2007-03-01 03:53 . 2010-02-24 12:31 454016 c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2007-06-26 13:46 . 2009-10-20 14:58 263552 c:\windows\Driver Cache\i386\http.sys
    + 2010-01-26 14:40 . 2010-01-26 14:40 626688 c:\windows\assembly\temp\ZRGCM3WLHR\System.Drawing.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 261632 c:\windows\assembly\temp\NXT4XTWSOK\System.Transactions.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 113664 c:\windows\assembly\temp\LMISVJTWZ2\System.EnterpriseServices.Wrapper.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 258048 c:\windows\assembly\temp\LMISVJTWZ2\System.EnterpriseServices.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 303104 c:\windows\assembly\temp\LA01XRGK2Q\System.Runtime.Remoting.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 425984 c:\windows\assembly\temp\F6K2QK2QFX\System.configuration.dll
    + 2007-07-11 07:01 . 2007-07-11 07:01 835584 c:\windows\assembly\temp\DY9NCUK2B5\System.Drawing.dll
    + 2010-01-26 14:40 . 2010-01-26 14:40 114688 c:\windows\assembly\temp\96NPFC2YOL\System.ServiceProcess.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_d8dda28b\System.Drawing.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_67df7282\System.Drawing.Design.dll
    + 2011-06-29 07:19 . 2011-06-29 07:19 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_f530a714\CustomMarshalers.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\92b80715e4c83e43eb3a61f5a467bc57\WsatConfig.ni.exe
    + 2011-06-29 07:25 . 2011-06-29 07:25 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bf1ea85af5a83e54b25266c45a435b4e\WindowsFormsIntegration.ni.dll
    + 2011-06-29 07:25 . 2011-06-29 07:25 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\d3636894f6b04b5abf405f2505f2ee07\UIAutomationTypes.ni.dll
    + 2011-06-29 07:25 . 2011-06-29 07:25 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\7b7e32fc09d7fed073a6abe9b7990b80\UIAutomationClient.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\3ed88de6f7e586055adba84e09554b0d\System.Xml.Linq.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 116736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Inte#\33c966f14806c8ed39173c05593784d3\System.Windows.Interactivity.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\7427e315999f2e95ecf272f231ad7ff1\System.Web.Routing.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\e6f14704fd855bf159ac6f64927f990f\System.Web.RegularExpressions.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 858112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\40c1cb3846774c067c8f94ed3f12ccc1\System.Web.Extensions.Design.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\26fbf871f3d35ec159ff8587d4952703\System.Web.Entity.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 300544 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\9ccf86d7adb3baecd49cac736654eecd\System.Web.Entity.Design.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 542720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\12d505e1b6cd446e258d41230c38763b\System.Web.DynamicData.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\ffb5e950b6aa4ef83379a6646ae0b49b\System.Web.Abstractions.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\52afb37d620f83b71a527ad8218c4f49\System.Transactions.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7df79a3ca436590c00c9668876d603b\System.ServiceProcess.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\535e922720fe15fedc82677517d519bd\System.Security.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3d30cb853493a73448c8900ce01808f8\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\ad25e70847b6792ed5fe3ab7a2c522fe\System.Runtime.Remoting.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2c59b029aaee4fe58738918db318349e\System.Net.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\b3d780f8e5559640af0bdc41c6d60377\System.Management.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\8b2ab798592cf3e0555f384cef9c75f1\System.Management.Instrumentation.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\6b070433446d18fc3de133aa945d9765\System.IO.Log.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\71e4ab43e479611fbad7ade81442706c\System.IdentityModel.Selectors.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\1ebc26a635aaf5fc5a7abe54101c5ab7\System.EnterpriseServices.Wrapper.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\1ebc26a635aaf5fc5a7abe54101c5ab7\System.EnterpriseServices.ni.dll
    + 2011-06-29 07:25 . 2011-06-29 07:25 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\bfc8d1f183985b4fc6d7263b760a55fa\System.Drawing.Design.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\5f015ebb9f1914683a5038297ec78d64\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\35b648d515138fcf0bc48a2a5bb9918e\System.DirectoryServices.Protocols.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\d10f0d50ac7fa57088105925895bd9c2\System.Data.Services.Design.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 939520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a677802b4c15adafa8e6d39dcd63bb8e\System.Data.Services.Client.ni.dll
    + 2011-06-29 07:30 . 2011-06-29 07:30 755712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\db88ace0f0e6996aa37c388460333cfc\System.Data.Entity.Design.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\64ac10f4c427e0a3b1b002023d5a96a9\System.Data.DataSetExtensions.ni.dll
    + 2011-06-29 07:27 . 2011-06-29 07:27 970752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2fb45bb85014fd6e20222f95d9ada241\System.Configuration.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\8ec21296492788c476887018879b686c\System.Configuration.Install.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 632832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3fd330febb11ce18cc0e96251fcf9b39\System.AddIn.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 365056 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\e63c923dfa3d8247da8a012cb7880eae\SMSvcHost.ni.exe
    + 2011-06-29 07:29 . 2011-06-29 07:29 255488 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\cd29fca6cec5c4e543561afb42cccc6a\SMDiagnostics.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\4d042c909b8d202a6afc15d2ffcf953e\ServiceModelReg.ni.exe
    + 2011-06-29 07:24 . 2011-06-29 07:24 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\97bdd7f6ef0ca386f85cf2d526c58f03\PresentationFramework.Luna.ni.dll
    + 2011-06-29 07:24 . 2011-06-29 07:24 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\957fb68bcfcf0eac4b2f5187c4eacc22\PresentationFramework.Aero.ni.dll
    + 2011-06-29 07:24 . 2011-06-29 07:24 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7c76a4167eaeb6a5d96134b6bb3afd8b\PresentationFramework.Classic.ni.dll
    + 2011-06-29 07:24 . 2011-06-29 07:24 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\79fb84518a9b35c865ea1bb63d81d271\PresentationFramework.Royale.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\cca8196e55792d392f133326e83c311b\MSBuild.ni.exe
    + 2011-06-29 07:29 . 2011-06-29 07:29 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\619e62ed3c0cc747a849aa18b92b45df\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\d586ab7b689c6d2f0935b645a9dbc6b3\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\31ac48eaf98b9855df063ce65fb9a877\Microsoft.Build.Utilities.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 838656 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\f0ed931b22eb66126d11011759233629\Microsoft.Build.Engine.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\887688212d2240bfdc60e13cc6972474\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 696320 c:\windows\assembly\NativeImages_v2.0.50727_32\log4net\f24ca7c81aa880572e49a4f2b98965f3\log4net.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 657408 c:\windows\assembly\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Serv#\afb4b12400c7adc2128c90ee8ff4e2f0\Intuit.Ctg.Wte.Service.Interface.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 955392 c:\windows\assembly\NativeImages_v2.0.50727_32\Intuit.Ctg.Wte.Serv#\021674cff0ae016b9a641b683cf56818\Intuit.Ctg.Wte.Service.Interface.ni.dll
    + 2011-06-29 07:28 . 2011-06-29 07:28 801792 c:\windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Share#\2754ab31cc1629642ba41124e28af49d\Infragistics2.Shared.v8.2.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\ed7165f230179ddb231ebfc2a6177bc8\CustomMarshalers.ni.dll
    + 2011-06-29 07:29 . 2011-06-29 07:29 409600 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\15f6f239a784bd19120e0968ac64dcfb\ComSvcConfig.ni.exe
    + 2011-06-29 07:26 . 2011-06-29 07:26 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\68fba626a973b2747fd459f3a1f179da\AspNetMMCExt.ni.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2011-06-29 07:07 . 2011-06-29 07:07 970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2011-06-29 07:07 . 2011-06-29 07:07 438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2010-01-26 14:40 . 2010-01-26 14:40 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2011-06-29 07:07 . 2011-06-29 07:07 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
    - 2010-01-26 14:45 . 2010-01-26 14:45 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2011-06-29 07:22 . 2011-06-29 07:22 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2010-01-26 14:39 . 2010-01-26 14:39 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...