TechSpot

FBI warning malware straight to boot-looping

Solved
By Eric Witzling
Nov 15, 2012
  1. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    Sorry, I went through the "scan one time" path so that seems to have disrupted the rest. I saved the text log from it, if that's good enough. Seems to have not found anything, but if I need to install the full version for it to scan completely, let me know.

    Code:
    HitmanPro 3.6.2.174
    [URL='http://www.hitmanpro.com']www.hitmanpro.com[/URL]
       Computer name . . . . : PAF-TC7269-001
       Windows . . . . . . . : 5.1.3.2600.X86/2
       User name . . . . . . : CP\mike
       License . . . . . . . : Free
       Scan date . . . . . . : 2012-12-02 15:59:53
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 2m 58s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : Internet
       Reboot  . . . . . . . : No
       Threats . . . . . . . : 0
       Traces  . . . . . . . : 37
       Objects scanned . . . : 1,221,196
       Files scanned . . . . : 14,743
       Remnants scanned  . . : 213,204 files / 993,249 keys
    Cookies _____________________________________________________________________
       C:\Documents and Settings\mike\Cookies\0HWV8OB6.txt
       C:\Documents and Settings\mike\Cookies\15TT4Q63.txt
       C:\Documents and Settings\mike\Cookies\50CQERX2.txt
       C:\Documents and Settings\mike\Cookies\5K40HPH5.txt
       C:\Documents and Settings\mike\Cookies\B35PVPDS.txt
       C:\Documents and Settings\mike\Cookies\EIODDX9U.txt
       C:\Documents and Settings\mike\Cookies\LK81N2TZ.txt
       C:\Documents and Settings\mike\Cookies\PI4QQU7P.txt
       C:\Documents and Settings\mike\Cookies\RQ2PD52Z.txt
       C:\Documents and Settings\mike\Cookies\VJYBO7PQ.txt
       C:\Documents and Settings\mike\Cookies\YOLK47M1.txt
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:247realmedia.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:adbrite.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.al.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.cleveland.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.masslive.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.mlive.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.nj.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.nola.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.oregonlive.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.pennlive.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.profitsdeluxe.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.syracuse.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.undertone.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:ads.yvmads.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:adserver.adtechus.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:adultfriendfinder.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:advertising.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:atdmt.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:collective-media.net
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:interclick.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:invitemedia.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:realmedia.com
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:revsci.net
       C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies:trafficmp.com
    
    
     
  2. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    Oh, and something I forgot to mention earlier. Combofix identified and removed "Rootkit.ZeroAccess" on its run. TDSSKiller hadn't picked up anything before or afterward. None of that seems to be in evidence now, which is good. Windows Update was waffling a bit and there a few updates that still refuse to run (not important ones), so the only remaining thing seems to be whatever was making that ui.dll call that caused it to crash in Normal mode, that was probably infected and impacted by the cleanup.

    I've been turning on startup items and services bit-by-bit, with only what they need to run with, and so far that hasn't crashed on my again yet either.
     
  3. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Please download a new copy of FRST and run a scan as we did in the beginning. :)
     
  4. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    It's like we're getting the old band back together! :D Heck, I almost booted into OTLPE again, even though I no longer have to!



    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-12-2012
    Ran by mike at 03-12-2012 14:06:52
    Running from C:\download
    Service Pack 3 (X86) OS Language: English(US)
    Attention: Could not load system hive.
    Error: The process cannot access the file because it is being used by another process.
    ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


    ==================== One Month Created Files and Folders ========

    2012-12-02 16:03 - 2012-12-02 16:03 - 00009110 ____A C:\Documents and Settings\mike\Desktop\HitmanPro_20121202_1603.log
    2012-12-02 15:59 - 2012-12-02 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
    2012-12-02 14:31 - 2012-12-02 14:31 - 00016188 ____A C:\Documents and Settings\mike\Desktop\attach.txt
    2012-12-02 14:31 - 2012-12-02 14:30 - 00014721 ____A C:\Documents and Settings\mike\Desktop\dds.txt
    2012-12-02 14:18 - 2012-12-02 14:18 - 00001027 ____A C:\AdwCleaner[S1].txt
    2012-12-02 14:16 - 2012-12-02 14:32 - 00033613 ____A C:\cleanup.txt
    2012-12-02 14:12 - 2012-12-02 14:12 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
    2012-12-02 14:05 - 2012-12-02 14:05 - 00000000 __SHD C:\Documents and Settings\mike\PrivacIE
    2012-12-02 14:05 - 2012-12-02 14:05 - 00000000 __SHD C:\Documents and Settings\mike\IECompatCache
    2012-12-02 14:04 - 2012-12-02 14:04 - 00006912 ____A C:\Windows\KB2510531-IE8.log
    2012-12-02 14:03 - 2012-12-02 14:04 - 00006818 ____A C:\Windows\KB2544521-IE8.log
    2012-11-29 17:47 - 2012-11-29 17:47 - 00000000 __HDC C:\Windows\$NtUninstallKB970430$
    2012-11-29 17:47 - 2012-11-29 17:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2345886$
    2012-11-29 17:41 - 2012-11-29 17:41 - 00000000 ____D C:\Documents and Settings\mike\Local Settings\Application Data\PCHealth
    2012-11-29 17:39 - 2012-11-29 17:47 - 00012345 ____A C:\Windows\KB2345886.log
    2012-11-29 17:37 - 2012-11-29 17:37 - 00000000 __SHD C:\Documents and Settings\NetworkService\IETldCache
    2012-11-29 17:37 - 2012-11-29 17:37 - 00000000 __SHD C:\Documents and Settings\mike\IETldCache
    2012-11-29 17:34 - 2012-11-29 17:34 - 00101189 ____A C:\Windows\KB2744842-IE8.log
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB959426$
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB952954$
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB951376-v2$
    2012-11-29 17:34 - 2012-08-28 10:14 - 00521728 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsdbgui.dll
    2012-11-29 17:33 - 2012-11-29 17:34 - 00103531 ____A C:\Windows\KB2618444-IE8.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00109398 ____A C:\Windows\KB982381-IE8.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00092956 ____A C:\Windows\KB2598845-IE8.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00000000 __HDC C:\Windows\$NtUninstallKB2467659$
    2012-11-29 17:33 - 2012-11-29 17:33 - 00000000 ____D C:\Windows\ie8updates
    2012-11-29 17:33 - 2012-08-28 20:44 - 11111424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieframe.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 02000384 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iertutil.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 00743424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedvtool.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 00630272 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeeds.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 00247808 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieproxy.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 00055296 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeedsbs.dll
    2012-11-29 17:33 - 2012-08-28 10:14 - 00012800 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\xpshims.dll
    2012-11-29 17:33 - 2011-08-16 05:45 - 00006144 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iecompat.dll
    2012-11-29 17:31 - 2012-11-29 17:33 - 00105269 ____A C:\Windows\ie8.log
    2012-11-29 17:31 - 2012-11-29 17:32 - 00000000 __HDC C:\Windows\ie8
    2012-11-29 17:29 - 2012-11-29 17:34 - 00063268 ____A C:\Windows\ie8_main.log
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB960859$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB946648$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB2712808$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB2387149$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00043910 ____A C:\Windows\KB2536276-v2.log
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2691442$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2659262$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2646524$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2631813$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2585542$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2564958$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2544893-v2$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2536276-v2$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2479943$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2478971$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2296011$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB974318$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB969059$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB955759$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB951978$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB2443105$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB2115168$
    2012-11-29 17:26 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB2655992$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB975713$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB950974$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2724197$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2598479$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2485663$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2481109$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2229593$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00039437 ____A C:\Windows\KB2736233.log
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB982132$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB978338$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB971657$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2736233$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2686509$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2440591$
    2012-11-29 17:24 - 2012-11-29 17:24 - 00000000 __HDC C:\Windows\$NtUninstallKB961118$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB972270$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB2510581$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB2507938$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB974112$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956844$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956744$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956572$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2483185$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2476490$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2347290$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00030086 ____A C:\Windows\KB2756822.log
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB979687$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB975560$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB975025$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB974571$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB973869$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB952004$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2756822$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2719985$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2624667$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2592799$
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB973507$
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB941569$
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB2535512$
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB977816$
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB950762$
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB2570947$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB981322$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB973904$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB952287$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB2603381$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB2507618$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB974392$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2653956$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2508429$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2419632$
    2012-11-29 17:16 - 2012-11-29 17:16 - 00000000 __HDC C:\Windows\$NtUninstallKB971029$
    2012-11-29 17:16 - 2012-11-29 17:16 - 00000000 __HDC C:\Windows\$NtUninstallKB2506212$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00023148 ____A C:\Windows\KB2698365.log
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB977914$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2705219-v2$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2698365$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2619339$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00020858 ____A C:\Windows\KB2723135-v2.log
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB981997$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB979482$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB979309$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB978706$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB978542$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB973815$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB960803$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2723135-v2$
    2012-11-29 17:10 - 2012-11-29 17:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
    2012-11-29 17:10 - 2012-11-29 17:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2661254-v2$
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB956802$
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB2676562$
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB2509553$
    2012-11-29 17:08 - 2012-11-29 17:08 - 00000000 __HDC C:\Windows\$NtUninstallKB982665$
    2012-11-29 17:08 - 2012-11-29 17:08 - 00000000 __HDC C:\Windows\$NtUninstallKB2744842$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00014428 ____A C:\Windows\KB2393802.log
    2012-11-29 17:06 - 2012-11-29 17:06 - 00012689 ____A C:\Windows\KB2544521.log
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB923561$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2620712$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2544521$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2478960$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2393802$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB975467$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB968389$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2584146$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2566454$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2423089$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2360937$
    2012-11-29 16:45 - 2011-07-15 08:29 - 00456320 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mrxsmb.sys
    2012-11-29 16:45 - 2010-09-18 01:53 - 00953856 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mfc40u.dll
    2012-11-29 16:45 - 2008-06-13 06:05 - 00272128 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\bthport.sys
    2012-11-29 16:44 - 2012-11-29 17:28 - 00049537 ____A C:\Windows\KB2585542.log
    2012-11-29 16:44 - 2012-11-29 17:26 - 00047815 ____A C:\Windows\KB2724197.log
    2012-11-29 16:44 - 2010-08-23 11:12 - 00617472 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\comctl32.dll
    2012-11-29 16:44 - 2010-06-14 09:31 - 00744448 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\helpsvc.exe
    2012-11-29 16:44 - 2009-11-21 10:51 - 00471552 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\aclayers.dll
    2012-11-29 16:43 - 2010-11-02 10:17 - 00040960 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ndproxy.sys
    2012-11-29 16:43 - 2010-08-27 03:02 - 00119808 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\t2embed.dll
    2012-11-29 16:43 - 2009-10-15 11:28 - 00081920 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\fontsub.dll
    2012-11-29 16:43 - 2009-01-09 14:19 - 01089593 ____C C:\Windows\System32\dllcache\ntprint.cat
    2012-11-29 16:42 - 2009-07-27 17:27 - 00128512 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\dhtmled.ocx
    2012-11-29 16:42 - 2009-06-21 16:44 - 00153088 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\triedit.dll
    2012-11-29 16:42 - 2009-03-06 09:22 - 00284160 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\pdh.dll
    2012-11-29 16:42 - 2009-02-09 07:10 - 00617472 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\advapi32.dll
    2012-11-29 16:42 - 2009-02-09 07:10 - 00473600 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\fastprox.dll
    2012-11-29 16:42 - 2009-02-09 07:10 - 00453120 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wmiprvsd.dll
    2012-11-29 16:42 - 2009-02-09 07:10 - 00401408 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\rpcss.dll
    2012-11-29 16:42 - 2009-02-06 06:11 - 00110592 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\services.exe
    2012-11-29 16:42 - 2009-02-06 05:10 - 00227840 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wmiprvse.exe
    2012-11-29 16:41 - 2011-04-21 08:37 - 00105472 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mup.sys
    2012-11-29 16:41 - 2008-05-08 09:02 - 00203136 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\rmcast.sys
    2012-11-29 16:41 - 2008-05-01 09:33 - 00331776 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msadce.dll
    2012-11-29 16:40 - 2012-11-29 17:17 - 00029248 ____A C:\Windows\KB2749655.log
    2012-11-29 16:40 - 2012-11-29 17:17 - 00028933 ____A C:\Windows\KB971029.log
    2012-11-29 16:39 - 2012-11-29 17:10 - 00025148 ____A C:\Windows\KB2761226.log
    2012-11-29 16:39 - 2012-11-29 17:10 - 00024991 ____A C:\Windows\KB2661254-v2.log
    2012-11-29 16:39 - 2012-11-29 17:09 - 00025064 ____A C:\Windows\KB2509553.log
    2012-11-29 16:39 - 2012-11-29 17:08 - 00023483 ____A C:\Windows\KB2744842.log
    2012-11-29 16:39 - 2011-04-29 22:01 - 00758784 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\vgx.dll
    2012-11-29 16:38 - 2012-11-29 17:11 - 00024686 ____A C:\Windows\KB2727528.log
    2012-11-29 16:38 - 2012-07-04 09:05 - 00139784 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\rdpwd.sys
    2012-11-29 16:38 - 2012-05-28 13:16 - 00536576 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msado15.dll
    2012-11-29 16:38 - 2010-06-18 08:36 - 03558912 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\moviemk.exe
    2012-11-29 16:37 - 2012-08-21 08:33 - 02148864 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlmp.exe
    2012-11-29 16:37 - 2012-08-21 08:29 - 02192896 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntoskrnl.exe
    2012-11-29 16:37 - 2012-08-21 07:58 - 02069632 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlpa.exe
    2012-11-29 16:37 - 2012-08-21 07:58 - 02027520 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrpamp.exe
    2012-11-29 16:37 - 2011-07-08 09:02 - 00010496 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ndistapi.sys
    2012-11-29 16:37 - 2010-12-09 10:15 - 00718336 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntdll.dll
    2012-11-29 16:37 - 2010-07-12 07:55 - 00218112 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wordpad.exe
    2012-11-29 16:37 - 2009-11-21 10:51 - 01206508 ____C C:\Windows\System32\dllcache\sysmain.sdb
    2012-11-29 16:31 - 2010-10-11 09:59 - 00045568 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wab.exe
    2012-11-29 16:30 - 2010-08-16 03:45 - 00590848 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\rpcrt4.dll
    2012-11-29 16:26 - 2012-06-02 15:19 - 00015384 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll.mui
    2012-11-29 16:19 - 2012-11-29 16:19 - 00000187 ____A C:\Windows\spupdsvc.log.1.log
    2012-11-29 16:19 - 2012-11-29 16:19 - 00000090 ____A C:\Windows\System32\spupdwxp.log
    2012-11-29 16:04 - 2012-11-29 16:04 - 00000000 ____D C:\Windows\System32\bits
    2012-11-29 16:04 - 2012-06-05 10:50 - 01372672 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 04274816 ____N (NVIDIA Corporation) C:\Windows\System32\nv4_disp.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 01737856 ____N (Matrox Graphics Inc.) C:\Windows\System32\mtxparhd.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00397056 ____N (S3 Graphics, Inc.) C:\Windows\System32\s3gnb.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00286792 ____N (Smart Link) C:\Windows\System32\slextspk.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00188508 ____N (Smart Link) C:\Windows\System32\slgen.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00073832 ____N (Smart Link) C:\Windows\System32\slcoinst.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00073796 ____N (Smart Link) C:\Windows\System32\slserv.exe
    2012-11-29 16:04 - 2008-04-14 05:42 - 00032866 ____N (Smart Link) C:\Windows\System32\slrundll.exe
    2012-11-29 16:04 - 2008-04-14 05:42 - 00032866 ____N (Smart Link) C:\Windows\slrundll.exe
    2012-11-29 16:04 - 2008-04-14 05:42 - 00028672 ____N (Microsoft Corporation) C:\Windows\System32\vidcap.ax
    2012-11-29 16:04 - 2008-04-14 05:42 - 00023040 ____N (ATI Technologies Inc.) C:\Windows\System32\ativmvxx.ax
    2012-11-29 16:04 - 2008-04-14 05:42 - 00010752 ____N (Microsoft Corporation) C:\Windows\System32\smtpapi.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00009728 ____N (Microsoft Corporation) C:\Windows\System32\rwnh.dll
    2012-11-29 16:04 - 2008-04-14 05:42 - 00009728 ____N (ATI Technologies Inc.) C:\Windows\System32\ativdaxx.ax
    2012-11-29 16:04 - 2008-04-14 05:41 - 01888992 ____N (ATI Technologies Inc. ) C:\Windows\System32\ati3duag.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00870784 ____N (ATI Technologies Inc. ) C:\Windows\System32\ati3d1ag.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00516768 ____N (ATI Technologies Inc. ) C:\Windows\System32\ativvaxx.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00377984 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2dvaa.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00229376 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2cqag.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00201728 ____N (ATI Technologies Inc.) C:\Windows\System32\ati2dvag.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00086016 ____N (Conexant) C:\Windows\System32\mdmxsdk.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00032768 ____N (ATI Technologies Inc.) C:\Windows\System32\ativtmxx.dll
    2012-11-29 16:04 - 2008-04-14 05:41 - 00032285 ____N (Conexant Systems, Inc.) C:\Windows\System32\hsfcisp2.dll
    2012-11-29 16:04 - 2008-04-14 00:15 - 00046592 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\irbus.sys
    2012-11-29 16:04 - 2008-04-14 00:13 - 00009728 ____N (Microsoft Corporation) C:\Windows\System32\comsdupd.exe
    2012-11-29 16:04 - 2008-04-13 22:57 - 00079872 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msxml6r.dll
    2012-11-29 16:03 - 2012-11-29 16:03 - 00000000 ____D C:\Windows\ServicePackFiles
    2012-11-29 16:01 - 2008-04-14 05:42 - 00011325 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\vchnt5.dll
    2012-11-29 16:01 - 2008-04-14 05:42 - 00003901 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\siint5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00025471 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv04nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00021183 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv01nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00017279 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv10nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00015423 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\ch7xxnt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00014143 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv06nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00011359 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\atv02nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00004255 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv01nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003967 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv02nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003775 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv11nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003711 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv09nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003647 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv07nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003615 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv05nt5.dll
    2012-11-29 16:01 - 2008-04-14 05:41 - 00003135 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\adv08nt5.dll
    2012-11-29 16:01 - 2008-04-14 00:26 - 00030592 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\rndismpx.sys
    2012-11-29 16:01 - 2008-04-14 00:26 - 00012800 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023x.sys
    2012-11-29 16:01 - 2008-04-14 00:21 - 00101120 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthpan.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00121984 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\usbvideo.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00059136 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\rfcomm.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00037888 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthmodem.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00036480 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthprint.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00025600 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00018944 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthusb.sys
    2012-11-29 16:01 - 2008-04-14 00:16 - 00017024 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\bthenum.sys
    2012-11-29 16:01 - 2008-04-14 00:15 - 00019200 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\hidir.sys
    2012-11-29 16:01 - 2008-04-14 00:13 - 00014208 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\wacompen.sys
    2012-11-29 16:01 - 2008-04-14 00:13 - 00012672 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\mutohpen.sys
    2012-11-29 16:01 - 2008-04-14 00:06 - 00005888 ____N (Microsoft Corporation) C:\Windows\System32\Drivers\smbali.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 01309184 ____N (Smart Link) C:\Windows\System32\Drivers\mtlstrm.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 01041536 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfdpsp2.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00685056 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfcxts2.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00404990 ____N (Smart Link) C:\Windows\System32\Drivers\slntamr.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00220032 ____N (Conexant Systems, Inc.) C:\Windows\System32\Drivers\hsfbs2s2.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00180360 ____N (Smart Link) C:\Windows\System32\Drivers\ntmtlfax.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00129535 ____N (Smart Link) C:\Windows\System32\Drivers\slnt7554.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00126686 ____N (Smart Link) C:\Windows\System32\Drivers\mtlmnt5.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00095424 ____N (Smart Link) C:\Windows\System32\Drivers\slnthal.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00013776 ____N (Smart Link) C:\Windows\System32\Drivers\recagent.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00013240 ____N (Smart Link) C:\Windows\System32\Drivers\slwdmsup.sys
    2012-11-29 16:01 - 2008-04-13 23:53 - 00011868 ____N (Conexant) C:\Windows\System32\Drivers\mdmxsdk.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 01897408 ____N (NVIDIA Corporation) C:\Windows\System32\Drivers\nv4_mini.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00701440 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati2mtag.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00452736 ____N (Matrox Graphics Inc.) C:\Windows\System32\Drivers\mtxparhm.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00327040 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati2mtaa.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00166912 ____N (S3 Graphics, Inc.) C:\Windows\System32\Drivers\s3gnbm.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00104960 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinrvxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00073216 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atintuxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00063663 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1rvxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00063488 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinxsxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00057856 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinbtxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00056623 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1btxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00052224 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinraxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00036463 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1tuxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00034735 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1xsxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00031744 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinxbxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00030671 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1raxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00029455 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1xbxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00028672 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinsnxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00026367 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1snxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00025471 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\watv10nt.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00022271 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\watv06nt.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00021343 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1ttxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00014336 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinpdxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00013824 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinttxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00013824 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\atinmdxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00012047 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1pdxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00011935 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv11nt.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00011871 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv09nt.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00011807 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv07nt.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00011615 ____N (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati1mdxx.sys
    2012-11-29 16:01 - 2008-04-13 22:04 - 00011295 ____N (Intel(R) Corporation) C:\Windows\System32\Drivers\wadv08nt.sys
     
  5. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    2012-11-29 16:01 - 2007-04-02 21:36 - 00129045 ____N C:\Windows\System32\Drivers\cxthsfs2.cty
    2012-11-29 16:01 - 2006-12-29 20:21 - 00064352 ____N C:\Windows\System32\Drivers\ativmc20.cod
    2012-11-29 16:01 - 2006-12-29 20:02 - 00067866 ____N C:\Windows\System32\Drivers\netwlan5.img
    2012-11-29 16:00 - 2006-12-29 00:31 - 00019569 ____A C:\Windows\003358_.tmp
    2012-11-29 15:58 - 2012-11-29 16:00 - 00000000 __HDC C:\Windows\$NtServicePackUninstall$
    2012-11-29 15:56 - 2012-11-29 16:18 - 00506697 ____A C:\Windows\svcpack.log
    2012-11-29 15:25 - 2012-11-29 15:25 - 00013724 ____A C:\Windows\System32\wpa.bak
    2012-11-29 15:05 - 2012-12-03 14:06 - 02716480 ____A C:\Windows\System32\ICAutoUpdate.log
    2012-11-29 15:05 - 2012-12-03 13:47 - 00000618 ____A C:\Windows\System32\gotomon.log
    2012-11-29 13:27 - 2012-11-29 13:19 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20121129-132722.backup
    2012-11-29 13:20 - 2012-11-29 13:20 - 00012712 ____A C:\ComboFix.txt
    2012-11-29 13:00 - 2011-06-26 01:45 - 00256000 ____A C:\Windows\PEV.exe
    2012-11-29 13:00 - 2010-11-07 12:20 - 00208896 ____A C:\Windows\MBR.exe
    2012-11-29 13:00 - 2009-04-19 23:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00212480 ____A (SteelWerX) C:\Windows\SWXCACLS.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00098816 ____A C:\Windows\sed.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00080412 ____A C:\Windows\grep.exe
    2012-11-29 13:00 - 2000-08-30 19:00 - 00068096 ____A C:\Windows\zip.exe
    2012-11-29 12:59 - 2012-11-29 13:20 - 00000000 ____D C:\Qoobox
    2012-11-29 12:59 - 2012-11-29 13:19 - 00000000 ____D C:\Windows\erdnt
    2012-11-29 12:46 - 2012-11-29 12:46 - 00065536 ____A C:\Windows\Minidump\Mini112912-02.dmp
    2012-11-29 12:35 - 2012-11-29 12:35 - 00065536 ____A C:\Windows\Minidump\Mini112912-01.dmp
    2012-11-29 12:35 - 2012-11-29 12:35 - 00000000 ____D C:\Windows\Minidump
    2012-11-29 12:29 - 2012-11-29 12:29 - 00000052 ____A C:\Windows\oobeact.log
    2012-11-29 12:29 - 2012-11-29 12:29 - 00000000 ____D C:\df37febdd5368d193e66dcbd9fa8c14a
    2012-11-29 12:28 - 2012-12-03 13:46 - 00001768 ____A C:\Windows\System32\InoRpcInit.log
    2012-11-29 12:28 - 2012-11-29 12:28 - 00000112 ____A C:\Windows\System32\config\netlogon.ftl
    2012-11-29 12:25 - 2008-04-14 05:41 - 00571392 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tintlgnt.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00426041 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\voicepad.dll
    2012-11-29 12:25 - 2008-04-14 05:41 - 00156672 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\winzm.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00156672 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\winsp.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00156672 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\winpy.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00086073 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\voicesub.dll
    2012-11-29 12:25 - 2008-04-14 05:41 - 00079360 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\winar30.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00076288 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\uniime.dll
    2012-11-29 12:25 - 2008-04-14 05:41 - 00072704 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\wingb.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00065536 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\winime.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00065024 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\unicdime.ime
    2012-11-29 12:25 - 2008-04-14 05:41 - 00010240 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tmigrate.dll
    2012-11-29 12:25 - 2004-08-03 06:32 - 00455168 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tintsetp.exe
    2012-11-29 12:25 - 2004-08-03 06:32 - 00044032 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tintlphr.exe
    2012-11-29 12:25 - 2001-08-18 07:00 - 00185344 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\thawbrkr.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00073728 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\w3ext.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00048256 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\w32.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00041600 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\weitekp9.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00031232 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\weitekp9.sys
    2012-11-29 12:25 - 2001-08-18 07:00 - 00028288 ___AC C:\Windows\System32\dllcache\xjis.nls
    2012-11-29 12:25 - 2001-08-18 07:00 - 00021896 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tdipx.sys
    2012-11-29 12:25 - 2001-08-18 07:00 - 00019464 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tdspx.sys
    2012-11-29 12:25 - 2001-08-18 07:00 - 00014336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tsprof.exe
    2012-11-29 12:25 - 2001-08-18 07:00 - 00013192 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tdasync.sys
    2012-11-29 12:25 - 2001-08-18 07:00 - 00009216 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\wamps51.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\w3svapi.dll
    2012-11-29 12:25 - 2001-08-18 07:00 - 00004608 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\w3ctrs51.dll
    2012-11-29 12:24 - 2008-04-14 05:41 - 00482304 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pintlgnt.ime
    2012-11-29 12:24 - 2008-04-14 05:41 - 00079360 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\phon.ime
    2012-11-29 12:24 - 2008-04-14 05:41 - 00078848 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\dayi.ime
    2012-11-29 12:24 - 2008-04-14 05:41 - 00077824 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\quick.ime
    2012-11-29 12:24 - 2008-04-14 05:41 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\romanime.ime
    2012-11-29 12:24 - 2008-04-14 05:40 - 00175104 ___AC C:\Windows\System32\dllcache\pintlcsa.dll
    2012-11-29 12:24 - 2008-04-14 05:40 - 00067584 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pmigrate.dll
    2012-11-29 12:24 - 2008-04-14 05:40 - 00053760 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pintlcsd.dll
    2012-11-29 12:24 - 2008-04-14 05:40 - 00015872 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\padrs404.dll
    2012-11-29 12:24 - 2008-04-14 05:40 - 00015360 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\padrs804.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 13463552 ___AC C:\Windows\System32\dllcache\hwxjpn.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00811064 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjp81k.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00716856 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpcus.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00368696 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpcic.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00340023 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjp81.ime
    2012-11-29 12:24 - 2008-04-14 05:39 - 00315455 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imskf.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00274489 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjputyc.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00106496 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imekrcic.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00102456 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imlang.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00094720 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imekr61.ime
    2012-11-29 12:24 - 2008-04-14 05:39 - 00086016 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imekrmbx.dll
    2012-11-29 12:24 - 2008-04-14 05:39 - 00081976 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpdct.dll
    2012-11-29 12:24 - 2008-04-13 22:13 - 00070144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pintlphr.exe
    2012-11-29 12:24 - 2004-08-03 06:32 - 00262200 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjputy.exe
    2012-11-29 12:24 - 2004-08-03 06:32 - 00233527 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjprw.exe
    2012-11-29 12:24 - 2004-08-03 06:32 - 00208952 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpmig.exe
    2012-11-29 12:24 - 2004-08-03 06:31 - 00307257 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpdct.exe
    2012-11-29 12:24 - 2004-08-03 06:31 - 00196665 ___AC C:\Windows\System32\dllcache\imjpinst.exe
    2012-11-29 12:24 - 2004-08-03 06:31 - 00155705 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpdsvr.exe
    2012-11-29 12:24 - 2004-08-03 06:31 - 00059392 ___AC C:\Windows\System32\dllcache\imscinst.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 10129408 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\hwxkor.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 10096640 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\hwxcht.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 01875968 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\msir3jp.lex
    2012-11-29 12:24 - 2001-08-18 07:00 - 01158818 ___AC C:\Windows\System32\dllcache\korwbrkr.lex
    2012-11-29 12:24 - 2001-08-18 07:00 - 00471102 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imskdic.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00311359 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imepadsv.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00229439 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\multibox.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00143422 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\softkey.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00134339 ___AC C:\Windows\System32\dllcache\imekr.lex
    2012-11-29 12:24 - 2001-08-18 07:00 - 00132608 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\fxsclntr.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00131584 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pmxviceo.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00111104 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\fxscfgwz.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00108827 ___AC C:\Windows\System32\dllcache\hanja.lex
    2012-11-29 12:24 - 2001-08-18 07:00 - 00102463 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imepadsm.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00101376 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\srusbusd.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00098304 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\msir3jp.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00092416 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mga.sys
    2012-11-29 12:24 - 2001-08-18 07:00 - 00092032 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mga.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00083748 ___AC C:\Windows\System32\dllcache\prcp.nls
    2012-11-29 12:24 - 2001-08-18 07:00 - 00083748 ___AC C:\Windows\System32\dllcache\prc.nls
    2012-11-29 12:24 - 2001-08-18 07:00 - 00079872 ___AC (Ricoh Co., Ltd.) C:\Windows\System32\dllcache\rwia330.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00079872 ___AC (Ricoh Co., Ltd.) C:\Windows\System32\dllcache\rwia001.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00070656 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\korwbrkr.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00060928 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iisclex4.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00059904 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imkrinst.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00057856 ___AC (SEIKO EPSON CORP.) C:\Windows\System32\dllcache\esuimgd.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00057398 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpdadm.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00053248 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\nextlink.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00047066 ___AC C:\Windows\System32\dllcache\ksc.nls
    2012-11-29 12:24 - 2001-08-18 07:00 - 00045109 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imjpuex.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00045056 ___AC (SEIKO EPSON CORP.) C:\Windows\System32\dllcache\esunid.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00044032 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\imekrmig.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00038912 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm9aw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00036927 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\padrs411.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00036864 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\hanjadic.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00031744 ___AC (SEIKO EPSON CORP.) C:\Windows\System32\dllcache\esucmd.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00031744 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\smb6w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00031744 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sma3w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00031744 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pagecnt.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00031744 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\fxsroute.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00030208 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm87w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00030208 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm81w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00029184 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm8cw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026624 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm93w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026624 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm92w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026624 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mdsync.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm90w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm8dw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm8aw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm89w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00025856 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\et4000.sys
    2012-11-29 12:24 - 2001-08-18 07:00 - 00025088 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\sm59w.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00022016 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\logscrpt.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00020992 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\permchk.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00019456 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iiscrmap.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00018944 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\simptcp.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00018944 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\cprofile.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00018432 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\jupiw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00016896 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\status.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00016384 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\quser.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00015872 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\smierrsm.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00014848 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\register.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00014848 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\flattemp.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00014336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\padrs412.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00011264 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pmxmcro.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00011264 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\fxssend.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00010240 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\snmpstup.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00009728 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\query.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00009216 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdnecat.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00009216 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iwrps.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00008704 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\infoctrs.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00007680 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdnecnt.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00007680 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\ftpctrs2.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00007168 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdnec95.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00007168 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\isapips.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006656 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iissync.exe
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\pmxgl.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdth3.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdth2.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdinpun.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbd101a.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\ftlx041e.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\smimsgif.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\smierrsy.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdvntc.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdusa.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdurdu.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdth1.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdth0.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdsyr2.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdsyr1.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdintel.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdintam.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdinmar.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdinkan.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdinhin.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdinguj.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdindev.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdheb.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdfa.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbddiv2.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbddiv1.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbda3.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbda2.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbda1.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005120 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdgeo.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005120 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdarmw.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00005120 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\kbdarme.dll
    2012-11-29 12:24 - 2001-08-18 07:00 - 00003584 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iismui.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00065536 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_mailmsg.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00057856 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_scripto.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00043520 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_fcachdll.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00038912 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_ntfsdrv.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00026112 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_seos.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00023040 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_regtrace.exe
    2012-11-29 12:24 - 2001-08-17 22:36 - 00012288 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_smtpctrs.dll
    2012-11-29 12:24 - 2001-08-17 22:36 - 00007168 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_snprfdll.dll
    2012-11-29 12:23 - 2012-11-29 12:23 - 00262144 ____A C:\Windows\System32\config\userdifr
    2012-11-29 12:23 - 2012-11-29 12:23 - 00001024 ___AH C:\Windows\System32\config\userdifr.LOG
    2012-11-29 12:23 - 2008-04-14 05:41 - 00078336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chajei.ime
    2012-11-29 12:23 - 2008-04-14 05:41 - 00021504 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\cintlgnt.ime
    2012-11-29 12:23 - 2008-04-14 05:39 - 00198656 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\cintime.dll
    2012-11-29 12:23 - 2008-04-14 05:39 - 00173568 ___AC C:\Windows\System32\dllcache\chtskf.dll
    2012-11-29 12:23 - 2008-04-14 05:39 - 00097792 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chtmbx.dll
    2012-11-29 12:23 - 2008-04-14 05:39 - 00056320 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chtskdic.dll
    2012-11-29 12:23 - 2004-08-03 06:31 - 00480256 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\cintsetp.exe
    2012-11-29 12:23 - 2004-08-03 06:31 - 00057399 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\cplexe.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 01677824 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chsbrkr.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00838144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chtbrkr.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00195618 ___AC C:\Windows\System32\dllcache\c_10002.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00189986 ___AC C:\Windows\System32\dllcache\c_1361.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00187938 ___AC C:\Windows\System32\dllcache\c_20005.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00186402 ___AC C:\Windows\System32\dllcache\c_20001.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00185378 ___AC C:\Windows\System32\dllcache\c_20003.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00180770 ___AC C:\Windows\System32\dllcache\c_20932.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00180258 ___AC C:\Windows\System32\dllcache\c_20004.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00180258 ___AC C:\Windows\System32\dllcache\c_20000.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00177698 ___AC C:\Windows\System32\dllcache\c_20949.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00177698 ___AC C:\Windows\System32\dllcache\c_10003.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00173602 ___AC C:\Windows\System32\dllcache\c_20936.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00173602 ___AC C:\Windows\System32\dllcache\c_20002.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00173602 ___AC C:\Windows\System32\dllcache\c_10008.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00169984 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iisui.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00162850 ___AC C:\Windows\System32\dllcache\c_10001.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00094720 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\certmap.ocx
    2012-11-29 12:23 - 2001-08-18 07:00 - 00082172 ___AC C:\Windows\System32\dllcache\bopomofo.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066728 ___AC C:\Windows\System32\dllcache\big5.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066594 ___AC C:\Windows\System32\dllcache\c_864.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066594 ___AC C:\Windows\System32\dllcache\c_862.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066594 ___AC C:\Windows\System32\dllcache\c_858.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066594 ___AC C:\Windows\System32\dllcache\c_720.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_870.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_708.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_28596.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_21027.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_21025.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20924.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20880.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20871.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20838.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20833.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20424.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20423.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20420.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20297.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20290.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20285.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20284.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20280.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20278.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20277.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20273.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20269.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20108.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20107.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20106.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_20105.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1149.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1148.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1147.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1146.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1145.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1144.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1143.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1142.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1141.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1140.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_1047.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_10021.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_10005.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00066082 ___AC C:\Windows\System32\dllcache\c_10004.nls
    2012-11-29 12:23 - 2001-08-18 07:00 - 00056320 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\convlog.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00054528 ___AC (Philips Semiconductors GmbH) C:\Windows\System32\dllcache\cap7146.sys
    2012-11-29 12:23 - 2001-08-18 07:00 - 00049664 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\adrot.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00045568 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\browscap.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00033792 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\controt.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00029184 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\asptxn.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00020480 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\counters.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00019968 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\inetsloc.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00015872 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chgport.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00014336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iisreset.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00014336 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chgusr.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00013312 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\chglogon.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00010752 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\c_iscii.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00010240 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\aspperf.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00009728 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\change.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00009216 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\authfilt.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00007680 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\inetmgr.exe
    2012-11-29 12:23 - 2001-08-18 07:00 - 00007168 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\wamregps.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00006656 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\c_is2022.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\ftpsapi2.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00006144 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\admxprox.dll
    2012-11-29 12:23 - 2001-08-18 07:00 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\iisrstap.dll
    2012-11-29 12:23 - 2001-08-17 22:36 - 00045056 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_aqadmin.dll
    2012-11-29 12:23 - 2001-08-17 22:36 - 00005632 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\EXCH_adsiisex.dll
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\WindowsShell.Manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\wuaucpl.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\sapi.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\nwc.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\ncpa.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000488 __RAH C:\Windows\System32\logonui.exe.manifest
    2012-11-29 12:21 - 2001-08-18 07:00 - 00016384 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\isignup.exe
    2012-11-29 12:20 - 2012-11-29 12:20 - 00000793 ____A C:\Documents and Settings\Default User\Desktop\Windows Media Player.lnk
    2012-11-29 12:20 - 2004-08-03 06:59 - 00044544 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\tscupgrd.exe
    2012-11-29 12:20 - 2004-08-03 06:59 - 00044544 ____A (Microsoft Corporation) C:\Windows\System32\tscupgrd.exe
    2012-11-29 12:10 - 2004-08-03 10:03 - 01042903 ___AC C:\Windows\System32\dllcache\SP2.CAT
    2012-11-29 12:10 - 2004-08-03 09:58 - 00013753 ___RA C:\Windows\SET11D.tmp
    2012-11-29 12:10 - 2004-07-16 19:45 - 00007334 ___AC C:\Windows\System32\dllcache\wmerrenu.cat
    2012-11-29 12:10 - 2001-08-18 07:00 - 00797189 ___AC C:\Windows\System32\dllcache\NT5IIS.CAT
    2012-11-29 12:10 - 2001-08-18 07:00 - 00399645 ___AC C:\Windows\System32\dllcache\MAPIMIG.CAT
    2012-11-29 12:10 - 2001-08-18 07:00 - 00037484 ___AC C:\Windows\System32\dllcache\MW770.CAT
    2012-11-29 12:10 - 2001-08-18 07:00 - 00024661 ___AC (Perle Systems Ltd.) C:\Windows\System32\dllcache\spxcoins.dll
    2012-11-29 12:10 - 2001-08-18 07:00 - 00024661 ____A (Perle Systems Ltd.) C:\Windows\System32\spxcoins.dll
    2012-11-29 12:10 - 2001-08-18 07:00 - 00013472 ___AC C:\Windows\System32\dllcache\HPCRDP.CAT
    2012-11-29 12:10 - 2001-08-18 07:00 - 00013312 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\irclass.dll
    2012-11-29 12:10 - 2001-08-18 07:00 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\irclass.dll
    2012-11-29 12:10 - 2001-08-18 07:00 - 00008574 ___AC C:\Windows\System32\dllcache\IASNT4.CAT
    2012-11-29 12:09 - 2012-12-03 13:47 - 00410525 ____A C:\Windows\setupapi.log
    2012-11-29 12:09 - 2004-08-03 10:03 - 01042903 ___RA C:\Windows\SET110.tmp
    2012-11-29 12:09 - 2004-08-03 09:57 - 01086058 ___RA C:\Windows\SET111.tmp
    2012-11-29 12:08 - 2012-11-29 15:31 - 2145386496 ____A C:\Windows\MEMORY.DMP
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\ODiag.evt
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\Lenovo-M.evt
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\Internet.evt
    2012-11-21 08:35 - 2012-11-21 10:13 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
    2012-11-16 12:07 - 2012-12-03 14:06 - 00000000 ____D C:\FRST
    2012-11-15 11:38 - 2012-11-15 11:38 - 00000209 ____A C:\Documents and Settings\mike\Desktop\REATOGO.txt
    2012-11-15 11:11 - 2012-11-15 11:11 - 00049454 ____A C:\OTL.Txt
    2012-11-14 12:16 - 2012-11-21 10:12 - 00000000 ____D C:\Documents and Settings\mike\Application Data\Task Scheduler.bak
    2012-11-13 13:09 - 2012-11-13 13:09 - 00315072 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    ==================== One Month Modified Files and Folders ========
    2012-12-03 14:06 - 2012-11-29 15:05 - 02716480 ____A C:\Windows\System32\ICAutoUpdate.log
    2012-12-03 14:06 - 2012-11-16 12:07 - 00000000 ____D C:\FRST
    2012-12-03 14:06 - 2011-02-10 12:02 - 00000000 ____D C:\download
    2012-12-03 14:06 - 2010-06-06 12:06 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2012-12-03 14:02 - 2012-07-03 08:58 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-12-03 13:52 - 2010-08-09 14:09 - 00000000 ____D C:\Program Files\SAAZOD
    2012-12-03 13:48 - 2008-07-21 17:01 - 01170569 ____A C:\Windows\WindowsUpdate.log
    2012-12-03 13:47 - 2012-11-29 15:05 - 00000618 ____A C:\Windows\System32\gotomon.log
    2012-12-03 13:47 - 2012-11-29 12:09 - 00410525 ____A C:\Windows\setupapi.log
    2012-12-03 13:47 - 2010-06-06 12:06 - 00000878 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2012-12-03 13:47 - 2009-09-09 13:36 - 00000062 __ASH C:\Documents and Settings\mike\Local Settings\desktop.ini
    2012-12-03 13:47 - 2008-07-21 17:50 - 00013724 ____A C:\Windows\System32\wpa.dbl
    2012-12-03 13:46 - 2012-11-29 12:28 - 00001768 ____A C:\Windows\System32\InoRpcInit.log
    2012-12-03 13:46 - 2008-07-21 17:05 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
    2012-12-03 13:46 - 2008-07-21 17:05 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
    2012-12-03 13:46 - 2008-07-21 17:05 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-12-03 08:13 - 2009-09-09 15:53 - 00000000 ___AD C:\Documents and Settings\All Users\Application Data\LogMeIn
    2012-12-03 08:13 - 2009-09-09 13:36 - 00000178 ___SH C:\Documents and Settings\mike\ntuser.ini
    2012-12-03 08:13 - 2008-07-21 17:05 - 00032354 ____A C:\Windows\SchedLgU.Txt
    2012-12-03 07:44 - 2009-09-08 13:16 - 00000254 ____A C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
    2012-12-03 07:35 - 2012-03-28 11:20 - 00000974 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2610266335-1772602443-367391177-1118UA.job
    2012-12-03 00:15 - 2010-08-09 14:11 - 00001180 ____A C:\Windows\System32\ipstuffNew.txt
    2012-12-02 16:03 - 2012-12-02 16:03 - 00009110 ____A C:\Documents and Settings\mike\Desktop\HitmanPro_20121202_1603.log
    2012-12-02 15:59 - 2012-12-02 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
    2012-12-02 14:37 - 2012-03-28 11:21 - 00002284 ____A C:\Documents and Settings\mike\Desktop\Google Chrome.lnk
    2012-12-02 14:32 - 2012-12-02 14:16 - 00033613 ____A C:\cleanup.txt
    2012-12-02 14:31 - 2012-12-02 14:31 - 00016188 ____A C:\Documents and Settings\mike\Desktop\attach.txt
    2012-12-02 14:30 - 2012-12-02 14:31 - 00014721 ____A C:\Documents and Settings\mike\Desktop\dds.txt
    2012-12-02 14:18 - 2012-12-02 14:18 - 00001027 ____A C:\AdwCleaner[S1].txt
    2012-12-02 14:12 - 2012-12-02 14:12 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
    2012-12-02 14:11 - 2008-07-21 17:50 - 00000607 ____A C:\Windows\win.ini
    2012-12-02 14:11 - 2008-07-21 17:50 - 00000227 ____A C:\Windows\system.ini
    2012-12-02 14:05 - 2012-12-02 14:05 - 00000000 __SHD C:\Documents and Settings\mike\PrivacIE
    2012-12-02 14:05 - 2012-12-02 14:05 - 00000000 __SHD C:\Documents and Settings\mike\IECompatCache
    2012-12-02 14:05 - 2008-07-21 09:55 - 00596768 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-12-02 14:04 - 2012-12-02 14:04 - 00006912 ____A C:\Windows\KB2510531-IE8.log
    2012-12-02 14:04 - 2012-12-02 14:03 - 00006818 ____A C:\Windows\KB2544521-IE8.log
    2012-12-02 14:04 - 2009-07-23 14:12 - 00000000 ___HD C:\Windows\$hf_mig$
    2012-12-02 14:04 - 2008-07-21 09:55 - 02020450 ____A C:\Windows\FaxSetup.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00981501 ____A C:\Windows\ocgen.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00933863 ____A C:\Windows\tsoc.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00697895 ____A C:\Windows\comsetup.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00627974 ____A C:\Windows\msmqinst.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00419446 ____A C:\Windows\ntdtcsetup.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00353980 ____A C:\Windows\netfxocm.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00264894 ____A C:\Windows\iis6.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00140537 ____A C:\Windows\MedCtrOC.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00111713 ____A C:\Windows\ocmsn.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00102886 ____A C:\Windows\tabletoc.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00101140 ____A C:\Windows\msgsocm.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00001374 ____A C:\Windows\imsins.log
    2012-12-02 14:04 - 2008-07-21 09:55 - 00001374 ____A C:\Windows\imsins.BAK
    2012-12-02 14:02 - 2008-07-21 09:55 - 00301127 ____A C:\Windows\setupact.log
    2012-11-30 08:35 - 2012-03-28 11:20 - 00000922 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2610266335-1772602443-367391177-1118Core.job
    2012-11-29 17:47 - 2012-11-29 17:47 - 00000000 __HDC C:\Windows\$NtUninstallKB970430$
    2012-11-29 17:47 - 2012-11-29 17:47 - 00000000 __HDC C:\Windows\$NtUninstallKB2345886$
    2012-11-29 17:47 - 2012-11-29 17:39 - 00012345 ____A C:\Windows\KB2345886.log
    2012-11-29 17:47 - 2009-07-23 14:13 - 00291686 ____A C:\Windows\updspapi.log
    2012-11-29 17:41 - 2012-11-29 17:41 - 00000000 ____D C:\Documents and Settings\mike\Local Settings\Application Data\PCHealth
    2012-11-29 17:37 - 2012-11-29 17:37 - 00000000 __SHD C:\Documents and Settings\NetworkService\IETldCache
    2012-11-29 17:37 - 2012-11-29 17:37 - 00000000 __SHD C:\Documents and Settings\mike\IETldCache
    2012-11-29 17:37 - 2009-07-23 14:23 - 00050575 ____A C:\Windows\spupdsvc.log
    2012-11-29 17:36 - 2008-07-21 09:55 - 00451680 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-11-29 17:36 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\Media
    2012-11-29 17:36 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\Help
    2012-11-29 17:34 - 2012-11-29 17:34 - 00101189 ____A C:\Windows\KB2744842-IE8.log
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB959426$
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB952954$
    2012-11-29 17:34 - 2012-11-29 17:34 - 00000000 __HDC C:\Windows\$NtUninstallKB951376-v2$
    2012-11-29 17:34 - 2012-11-29 17:33 - 00103531 ____A C:\Windows\KB2618444-IE8.log
    2012-11-29 17:34 - 2012-11-29 17:29 - 00063268 ____A C:\Windows\ie8_main.log
    2012-11-29 17:34 - 2009-09-08 13:35 - 00100283 ____A C:\Windows\KB951376-v2.log
    2012-11-29 17:34 - 2009-09-08 13:28 - 00122305 ____A C:\Windows\KB959426.log
    2012-11-29 17:34 - 2009-09-08 13:27 - 00114389 ____A C:\Windows\KB952954.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00109398 ____A C:\Windows\KB982381-IE8.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00092956 ____A C:\Windows\KB2598845-IE8.log
    2012-11-29 17:33 - 2012-11-29 17:33 - 00000000 __HDC C:\Windows\$NtUninstallKB2467659$
    2012-11-29 17:33 - 2012-11-29 17:33 - 00000000 ____D C:\Windows\ie8updates
    2012-11-29 17:33 - 2012-11-29 17:31 - 00105269 ____A C:\Windows\ie8.log
    2012-11-29 17:33 - 2011-01-28 03:49 - 00097935 ____A C:\Windows\KB2467659.log
    2012-11-29 17:32 - 2012-11-29 17:31 - 00000000 __HDC C:\Windows\ie8
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB960859$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB946648$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB2712808$
    2012-11-29 17:29 - 2012-11-29 17:29 - 00000000 __HDC C:\Windows\$NtUninstallKB2387149$
    2012-11-29 17:29 - 2012-10-17 23:19 - 00058366 ____A C:\Windows\KB2712808.log
    2012-11-29 17:29 - 2010-11-13 00:42 - 00067606 ____A C:\Windows\KB2387149.log
    2012-11-29 17:29 - 2009-09-08 13:35 - 00056361 ____A C:\Windows\KB946648.log
    2012-11-29 17:29 - 2009-09-08 13:29 - 00116115 ____A C:\Windows\KB960859.log
    2012-11-29 17:29 - 2009-07-23 14:38 - 00000000 ___AD C:\Documents and Settings\All Users\Application Data\Microsoft Help
     
  6. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    2012-11-29 17:29 - 2008-07-21 16:59 - 00000000 ____D C:\Program Files\Messenger
    2012-11-29 17:28 - 2012-11-29 17:28 - 00043910 ____A C:\Windows\KB2536276-v2.log
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2691442$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2659262$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2646524$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2631813$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2585542$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2564958$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2544893-v2$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2536276-v2$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2479943$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2478971$
    2012-11-29 17:28 - 2012-11-29 17:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2296011$
    2012-11-29 17:28 - 2012-11-29 16:44 - 00049537 ____A C:\Windows\KB2585542.log
    2012-11-29 17:28 - 2012-08-17 23:08 - 00056552 ____A C:\Windows\KB2691442.log
    2012-11-29 17:28 - 2012-06-15 23:35 - 00047789 ____A C:\Windows\KB2659262.log
    2012-11-29 17:28 - 2012-02-16 00:27 - 00057105 ____A C:\Windows\KB2646524.log
    2012-11-29 17:28 - 2012-02-16 00:24 - 00055261 ____A C:\Windows\KB2631813.log
    2012-11-29 17:28 - 2011-11-18 00:25 - 00056971 ____A C:\Windows\KB2544893-v2.log
    2012-11-29 17:28 - 2011-11-18 00:24 - 00048672 ____A C:\Windows\KB2564958.log
    2012-11-29 17:28 - 2011-04-15 23:16 - 00057250 ____A C:\Windows\KB2479943.log
    2012-11-29 17:28 - 2011-03-16 23:01 - 00056909 ____A C:\Windows\KB2478971.log
    2012-11-29 17:28 - 2010-11-13 00:31 - 00047732 ____A C:\Windows\KB2296011.log
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB974318$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB969059$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB955759$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB951978$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB2443105$
    2012-11-29 17:27 - 2012-11-29 17:27 - 00000000 __HDC C:\Windows\$NtUninstallKB2115168$
    2012-11-29 17:27 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2655992$
    2012-11-29 17:27 - 2012-08-17 23:09 - 00054700 ____A C:\Windows\KB2655992.log
    2012-11-29 17:27 - 2011-01-16 00:14 - 00052795 ____A C:\Windows\KB2443105.log
    2012-11-29 17:27 - 2010-11-13 00:41 - 00060573 ____A C:\Windows\KB2378111.log
    2012-11-29 17:27 - 2010-11-13 00:29 - 00048736 ____A C:\Windows\KB975558.log
    2012-11-29 17:27 - 2010-09-15 23:31 - 00054391 ____A C:\Windows\KB2115168.log
    2012-11-29 17:27 - 2010-01-13 03:01 - 00055764 ____A C:\Windows\KB955759.log
    2012-11-29 17:27 - 2009-12-09 01:11 - 00070529 ____A C:\Windows\KB974318.log
    2012-11-29 17:27 - 2009-10-13 15:34 - 00070533 ____A C:\Windows\KB969059.log
    2012-11-29 17:27 - 2009-09-08 13:26 - 00065257 ____A C:\Windows\KB951978.log
    2012-11-29 17:27 - 2008-07-21 16:59 - 00082846 ____A C:\Windows\wmsetup.log
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB975713$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB950974$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2724197$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2598479$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2485663$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2481109$
    2012-11-29 17:26 - 2012-11-29 17:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2229593$
    2012-11-29 17:26 - 2012-11-29 16:44 - 00047815 ____A C:\Windows\KB2724197.log
    2012-11-29 17:26 - 2012-02-16 00:26 - 00053097 ____A C:\Windows\KB2598479.log
    2012-11-29 17:26 - 2011-05-18 23:25 - 00046401 ____A C:\Windows\KB2485663.log
    2012-11-29 17:26 - 2011-05-04 23:19 - 00054571 ____A C:\Windows\KB2481109.log
    2012-11-29 17:26 - 2011-01-16 00:15 - 00047008 ____A C:\Windows\KB2440591.log
    2012-11-29 17:26 - 2010-07-15 02:02 - 00049977 ____A C:\Windows\KB2229593.log
    2012-11-29 17:26 - 2010-02-09 18:20 - 00058122 ____A C:\Windows\KB975713.log
    2012-11-29 17:26 - 2009-09-08 13:27 - 00065058 ____A C:\Windows\KB950974.log
    2012-11-29 17:26 - 2008-07-21 09:55 - 02000175 ____A C:\Windows\iis6.BAK
    2012-11-29 17:25 - 2012-11-29 17:25 - 00039437 ____A C:\Windows\KB2736233.log
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB982132$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB978338$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB971657$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2736233$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2686509$
    2012-11-29 17:25 - 2012-11-29 17:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2440591$
    2012-11-29 17:25 - 2012-06-15 23:36 - 00047256 ____A C:\Windows\KB2686509.log
    2012-11-29 17:25 - 2010-11-13 00:43 - 00065190 ____A C:\Windows\KB982132.log
    2012-11-29 17:25 - 2010-04-14 04:34 - 00069401 ____A C:\Windows\KB978338.log
    2012-11-29 17:25 - 2009-09-08 14:22 - 00043079 ____A C:\Windows\KB961118.log
    2012-11-29 17:25 - 2009-09-08 13:28 - 00109941 ____A C:\Windows\KB971657.log
    2012-11-29 17:24 - 2012-11-29 17:24 - 00000000 __HDC C:\Windows\$NtUninstallKB961118$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB972270$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB2510581$
    2012-11-29 17:23 - 2012-11-29 17:23 - 00000000 __HDC C:\Windows\$NtUninstallKB2507938$
    2012-11-29 17:23 - 2011-08-17 23:11 - 00052503 ____A C:\Windows\KB2507938.log
    2012-11-29 17:23 - 2011-05-18 23:31 - 00056353 ____A C:\Windows\KB2510581.log
    2012-11-29 17:23 - 2009-10-14 02:04 - 00056926 ____A C:\Windows\KB954155.log
    2012-11-29 17:23 - 2009-09-08 13:49 - 00093216 ____A C:\Windows\KB956744.log
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB974112$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956844$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956744$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB956572$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2483185$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2476490$
    2012-11-29 17:22 - 2012-11-29 17:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2347290$
    2012-11-29 17:22 - 2011-03-16 23:02 - 00048277 ____A C:\Windows\KB2483185.log
    2012-11-29 17:22 - 2009-10-13 15:34 - 00066419 ____A C:\Windows\KB974112.log
    2012-11-29 17:22 - 2009-09-08 13:50 - 00089052 ____A C:\Windows\KB956844.log
    2012-11-29 17:22 - 2009-09-08 13:36 - 00059929 ____A C:\Windows\KB956572.log
    2012-11-29 17:21 - 2012-11-29 17:21 - 00030086 ____A C:\Windows\KB2756822.log
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB979687$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB975560$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB975025$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB974571$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB973869$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB952004$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2756822$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2719985$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2624667$
    2012-11-29 17:21 - 2012-11-29 17:21 - 00000000 __HDC C:\Windows\$NtUninstallKB2592799$
    2012-11-29 17:21 - 2012-08-17 23:11 - 00047611 ____A C:\Windows\KB2719985.log
    2012-11-29 17:21 - 2012-01-19 00:23 - 00048777 ____A C:\Windows\KB2624667.log
    2012-11-29 17:21 - 2011-11-18 00:23 - 00040042 ____A C:\Windows\KB2592799.log
    2012-11-29 17:21 - 2010-11-13 00:30 - 00049153 ____A C:\Windows\KB979687.log
    2012-11-29 17:21 - 2009-10-13 15:34 - 00062333 ____A C:\Windows\KB975025.log
    2012-11-29 17:21 - 2009-10-13 15:34 - 00052895 ____A C:\Windows\KB974571.log
    2012-11-29 17:21 - 2009-09-08 13:49 - 00088115 ____A C:\Windows\KB973869.log
    2012-11-29 17:21 - 2009-09-08 13:49 - 00018942 ____A C:\Windows\System32\TZLog.log
    2012-11-29 17:21 - 2009-09-08 13:28 - 00064440 ____A C:\Windows\KB952004.log
    2012-11-29 17:21 - 2009-07-23 14:38 - 00000000 ____D C:\Program Files\Microsoft Office
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB973507$
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB941569$
    2012-11-29 17:20 - 2012-11-29 17:20 - 00000000 __HDC C:\Windows\$NtUninstallKB2535512$
    2012-11-29 17:20 - 2011-07-16 23:31 - 00041254 ____A C:\Windows\KB2535512.log
    2012-11-29 17:20 - 2009-09-08 13:34 - 00042721 ____A C:\Windows\KB941569.log
    2012-11-29 17:20 - 2009-09-08 13:28 - 00102242 ____A C:\Windows\KB973507.log
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB977816$
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB950762$
    2012-11-29 17:19 - 2012-11-29 17:19 - 00000000 __HDC C:\Windows\$NtUninstallKB2570947$
    2012-11-29 17:19 - 2011-10-16 23:26 - 00038344 ____A C:\Windows\KB2570947.log
    2012-11-29 17:19 - 2010-04-14 04:34 - 00061416 ____A C:\Windows\KB977816.log
    2012-11-29 17:19 - 2009-09-08 13:35 - 00041362 ____A C:\Windows\KB950762.log
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB981322$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB973904$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB952287$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB2603381$
    2012-11-29 17:18 - 2012-11-29 17:18 - 00000000 __HDC C:\Windows\$NtUninstallKB2507618$
    2012-11-29 17:18 - 2012-02-16 00:25 - 00037150 ____A C:\Windows\KB2603381.log
    2012-11-29 17:18 - 2011-05-18 23:30 - 00045609 ____A C:\Windows\KB2507618.log
    2012-11-29 17:18 - 2010-10-15 23:24 - 00044867 ____A C:\Windows\KB981322.log
    2012-11-29 17:18 - 2010-06-09 02:07 - 00049809 ____A C:\Windows\KB978695.log
    2012-11-29 17:18 - 2009-12-09 03:02 - 00048947 ____A C:\Windows\KB973904.log
    2012-11-29 17:18 - 2009-09-08 13:35 - 00042109 ____A C:\Windows\KB952287.log
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB974392$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2653956$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2508429$
    2012-11-29 17:17 - 2012-11-29 17:17 - 00000000 __HDC C:\Windows\$NtUninstallKB2419632$
    2012-11-29 17:17 - 2012-11-29 16:40 - 00029248 ____A C:\Windows\KB2749655.log
    2012-11-29 17:17 - 2012-11-29 16:40 - 00028933 ____A C:\Windows\KB971029.log
    2012-11-29 17:17 - 2012-05-16 23:26 - 00038182 ____A C:\Windows\KB2653956.log
    2012-11-29 17:17 - 2011-05-18 23:26 - 00037945 ____A C:\Windows\KB2508429.log
    2012-11-29 17:17 - 2011-02-18 00:23 - 00050980 ____A C:\Windows\KB2419632.log
    2012-11-29 17:17 - 2009-12-09 01:11 - 00042093 ____A C:\Windows\KB974392.log
    2012-11-29 17:17 - 2008-07-21 17:06 - 00000000 ____D C:\Windows\Microsoft.NET
    2012-11-29 17:16 - 2012-11-29 17:16 - 00000000 __HDC C:\Windows\$NtUninstallKB971029$
    2012-11-29 17:16 - 2012-11-29 17:16 - 00000000 __HDC C:\Windows\$NtUninstallKB2506212$
    2012-11-29 17:16 - 2011-05-18 23:27 - 00035865 ____A C:\Windows\KB2506212.log
    2012-11-29 17:16 - 2009-09-08 13:36 - 00039513 ____A C:\Windows\KB952069.log
    2012-11-29 17:15 - 2008-07-21 09:55 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2012-11-29 17:12 - 2012-11-29 17:12 - 00023148 ____A C:\Windows\KB2698365.log
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB977914$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2705219-v2$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2698365$
    2012-11-29 17:12 - 2012-11-29 17:12 - 00000000 __HDC C:\Windows\$NtUninstallKB2619339$
    2012-11-29 17:12 - 2012-10-17 23:20 - 00034461 ____A C:\Windows\KB2705219-v2.log
    2012-11-29 17:12 - 2012-01-19 00:26 - 00033985 ____A C:\Windows\KB2619339.log
    2012-11-29 17:12 - 2010-05-12 05:30 - 00036626 ____A C:\Windows\KB978542.log
    2012-11-29 17:12 - 2010-02-09 18:19 - 00040129 ____A C:\Windows\KB977914.log
    2012-11-29 17:12 - 2008-07-21 17:00 - 00000000 ____D C:\Program Files\Outlook Express
    2012-11-29 17:11 - 2012-11-29 17:11 - 00020858 ____A C:\Windows\KB2723135-v2.log
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB981997$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB979482$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB979309$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB978706$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB978542$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB973815$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB960803$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2727528$
    2012-11-29 17:11 - 2012-11-29 17:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2723135-v2$
    2012-11-29 17:11 - 2012-11-29 16:38 - 00024686 ____A C:\Windows\KB2727528.log
    2012-11-29 17:11 - 2010-09-15 23:33 - 00027138 ____A C:\Windows\KB981997.log
    2012-11-29 17:11 - 2010-06-08 17:20 - 00048656 ____A C:\Windows\KB979482.log
    2012-11-29 17:11 - 2010-04-14 04:34 - 00048176 ____A C:\Windows\KB979309.log
    2012-11-29 17:11 - 2010-02-09 18:19 - 00035600 ____A C:\Windows\KB978706.log
    2012-11-29 17:11 - 2009-09-08 13:28 - 00088446 ____A C:\Windows\KB973815.log
    2012-11-29 17:11 - 2009-09-08 13:28 - 00049302 ____A C:\Windows\KB960803.log
    2012-11-29 17:11 - 2008-07-21 17:01 - 00000000 ____D C:\Program Files\Movie Maker
    2012-11-29 17:10 - 2012-11-29 17:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2761226$
    2012-11-29 17:10 - 2012-11-29 17:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2661254-v2$
    2012-11-29 17:10 - 2012-11-29 16:39 - 00025148 ____A C:\Windows\KB2761226.log
    2012-11-29 17:10 - 2012-11-29 16:39 - 00024991 ____A C:\Windows\KB2661254-v2.log
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB956802$
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB2676562$
    2012-11-29 17:09 - 2012-11-29 17:09 - 00000000 __HDC C:\Windows\$NtUninstallKB2509553$
    2012-11-29 17:09 - 2012-11-29 16:39 - 00025064 ____A C:\Windows\KB2509553.log
    2012-11-29 17:09 - 2012-06-15 23:34 - 00034534 ____A C:\Windows\KB2676562.log
    2012-11-29 17:09 - 2009-09-08 13:27 - 00041518 ____A C:\Windows\KB956802.log
    2012-11-29 17:08 - 2012-11-29 17:08 - 00000000 __HDC C:\Windows\$NtUninstallKB982665$
    2012-11-29 17:08 - 2012-11-29 17:08 - 00000000 __HDC C:\Windows\$NtUninstallKB2744842$
    2012-11-29 17:08 - 2012-11-29 16:39 - 00023483 ____A C:\Windows\KB2744842.log
    2012-11-29 17:08 - 2010-09-15 23:32 - 00027504 ____A C:\Windows\KB982665.log
    2012-11-29 17:06 - 2012-11-29 17:06 - 00014428 ____A C:\Windows\KB2393802.log
    2012-11-29 17:06 - 2012-11-29 17:06 - 00012689 ____A C:\Windows\KB2544521.log
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB923561$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2620712$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2544521$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2478960$
    2012-11-29 17:06 - 2012-11-29 17:06 - 00000000 __HDC C:\Windows\$NtUninstallKB2393802$
    2012-11-29 17:06 - 2012-01-19 00:28 - 00024204 ____A C:\Windows\KB2620712.log
    2012-11-29 17:06 - 2009-09-08 13:36 - 00027312 ____A C:\Windows\KB923561.log
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB975467$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB968389$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2584146$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2566454$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2423089$
    2012-11-29 17:05 - 2012-11-29 17:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2360937$
    2012-11-29 17:05 - 2012-02-16 00:22 - 00021321 ____A C:\Windows\KB2584146.log
    2012-11-29 17:05 - 2011-09-16 23:22 - 00027890 ____A C:\Windows\KB2566454.log
    2012-11-29 17:05 - 2011-01-16 00:13 - 00014024 ____A C:\Windows\KB2423089.log
    2012-11-29 17:05 - 2010-11-18 00:20 - 00016323 ____A C:\Windows\KB2360937.log
    2012-11-29 17:05 - 2009-10-13 15:33 - 00027937 ____A C:\Windows\KB975467.log
    2012-11-29 17:05 - 2009-09-08 13:34 - 00080252 ____A C:\Windows\KB968389.log
    2012-11-29 16:19 - 2012-11-29 16:19 - 00000187 ____A C:\Windows\spupdsvc.log.1.log
    2012-11-29 16:19 - 2012-11-29 16:19 - 00000090 ____A C:\Windows\System32\spupdwxp.log
    2012-11-29 16:19 - 2008-07-21 17:02 - 00316640 ____A C:\Windows\WMSysPr9.prx
    2012-11-29 16:19 - 2008-07-21 17:00 - 00000972 ____A C:\Windows\DtcInstall.log
    2012-11-29 16:18 - 2012-11-29 15:56 - 00506697 ____A C:\Windows\svcpack.log
    2012-11-29 16:18 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\security
    2012-11-29 16:04 - 2012-11-29 16:04 - 00000000 ____D C:\Windows\System32\bits
    2012-11-29 16:04 - 2008-07-21 17:00 - 00006439 ____A C:\Windows\sessmgr.setup.log
    2012-11-29 16:04 - 2008-07-21 16:59 - 00000546 ____A C:\Windows\cmsetacl.log
    2012-11-29 16:04 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\inetsrv
    2012-11-29 16:04 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\PeerNet
    2012-11-29 16:04 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\ime
    2012-11-29 16:03 - 2012-11-29 16:03 - 00000000 ____D C:\Windows\ServicePackFiles
    2012-11-29 16:02 - 2008-07-21 17:01 - 00000000 ____D C:\Windows\srchasst
    2012-11-29 16:02 - 2008-07-21 17:00 - 00000000 ____D C:\Windows\System32\Restore
    2012-11-29 16:02 - 2008-07-21 17:00 - 00000000 ____D C:\Program Files\NetMeeting
    2012-11-29 16:02 - 2008-07-21 17:00 - 00000000 ____D C:\Program Files\Common Files\System
    2012-11-29 16:02 - 2008-07-21 16:59 - 00000000 ____D C:\Windows\System32\Com
    2012-11-29 16:02 - 2008-07-21 16:59 - 00000000 ____D C:\Program Files\Windows NT
    2012-11-29 16:02 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\usmt
    2012-11-29 16:02 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\npp
    2012-11-29 16:02 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\system
    2012-11-29 16:02 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\mui
    2012-11-29 16:02 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\msagent
    2012-11-29 16:00 - 2012-11-29 15:58 - 00000000 __HDC C:\Windows\$NtServicePackUninstall$
    2012-11-29 15:31 - 2012-11-29 12:08 - 2145386496 ____A C:\Windows\MEMORY.DMP
    2012-11-29 15:31 - 2009-09-09 13:42 - 00000000 __SHD C:\Windows\CSC
    2012-11-29 15:25 - 2012-11-29 15:25 - 00013724 ____A C:\Windows\System32\wpa.bak
    2012-11-29 14:24 - 2010-08-09 14:21 - 00000000 ___AD C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2012-11-29 13:34 - 2011-02-10 11:34 - 00000000 ____D C:\Windows\pss
    2012-11-29 13:24 - 2011-02-10 12:03 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
    2012-11-29 13:23 - 2012-05-15 08:24 - 00001324 ____A C:\Windows\System32\d3d9caps.dat
    2012-11-29 13:20 - 2012-11-29 13:20 - 00012712 ____A C:\ComboFix.txt
    2012-11-29 13:20 - 2012-11-29 12:59 - 00000000 ____D C:\Qoobox
    2012-11-29 13:19 - 2012-11-29 13:27 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20121129-132722.backup
    2012-11-29 13:19 - 2012-11-29 12:59 - 00000000 ____D C:\Windows\erdnt
    2012-11-29 12:46 - 2012-11-29 12:46 - 00065536 ____A C:\Windows\Minidump\Mini112912-02.dmp
    2012-11-29 12:35 - 2012-11-29 12:35 - 00065536 ____A C:\Windows\Minidump\Mini112912-01.dmp
    2012-11-29 12:35 - 2012-11-29 12:35 - 00000000 ____D C:\Windows\Minidump
    2012-11-29 12:29 - 2012-11-29 12:29 - 00000052 ____A C:\Windows\oobeact.log
    2012-11-29 12:29 - 2012-11-29 12:29 - 00000000 ____D C:\df37febdd5368d193e66dcbd9fa8c14a
    2012-11-29 12:28 - 2012-11-29 12:28 - 00000112 ____A C:\Windows\System32\config\netlogon.ftl
    2012-11-29 12:23 - 2012-11-29 12:23 - 00262144 ____A C:\Windows\System32\config\userdifr
    2012-11-29 12:23 - 2012-11-29 12:23 - 00001024 ___AH C:\Windows\System32\config\userdifr.LOG
    2012-11-29 12:23 - 2008-07-21 17:02 - 00023392 ____A C:\Windows\System32\nscompat.tlb
    2012-11-29 12:23 - 2008-07-21 17:02 - 00016832 ____A C:\Windows\System32\amcompat.tlb
    2012-11-29 12:23 - 2008-07-21 17:01 - 00000000 __SHD C:\Documents and Settings\All Users\DRM
    2012-11-29 12:23 - 2008-07-21 17:00 - 00000000 ____D C:\Windows\Registration
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\WindowsShell.Manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\wuaucpl.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\sapi.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\nwc.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000749 __RAH C:\Windows\System32\ncpa.cpl.manifest
    2012-11-29 12:22 - 2012-11-29 12:22 - 00000488 __RAH C:\Windows\System32\logonui.exe.manifest
    2012-11-29 12:22 - 2008-07-21 17:01 - 00000749 __RAH C:\Windows\System32\cdplayer.exe.manifest
    2012-11-29 12:22 - 2008-07-21 17:01 - 00000488 __RAH C:\Windows\System32\WindowsLogon.manifest
    2012-11-29 12:22 - 2008-07-21 09:55 - 00004161 ____A C:\Windows\ODBCINST.INI
    2012-11-29 12:22 - 2008-07-21 09:51 - 00000000 ___RD C:\Windows\Web
    2012-11-29 12:21 - 2008-07-21 09:55 - 00000332 ____A C:\Windows\setuperr.log
    2012-11-29 12:20 - 2012-11-29 12:20 - 00000793 ____A C:\Documents and Settings\Default User\Desktop\Windows Media Player.lnk
    2012-11-29 12:20 - 2008-07-21 17:00 - 00023444 ____A C:\Windows\System32\emptyregdb.dat
    2012-11-29 12:15 - 2008-07-21 09:58 - 00000613 ____A C:\Windows\wiadebug.log
    2012-11-29 12:15 - 2008-07-21 09:58 - 00000050 ____A C:\Windows\wiaservc.log
    2012-11-29 12:10 - 2008-07-21 09:55 - 00004266 ____A C:\Windows\regopt.log
    2012-11-29 12:10 - 2008-07-21 09:55 - 00000062 __ASH C:\Documents and Settings\Default User\Local Settings\desktop.ini
    2012-11-29 12:10 - 2008-07-21 09:55 - 00000062 __ASH C:\Documents and Settings\Default User\Application Data\desktop.ini
    2012-11-29 12:10 - 2008-07-21 09:55 - 00000062 __ASH C:\Documents and Settings\All Users\Application Data\desktop.ini
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\ODiag.evt
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\Lenovo-M.evt
    2012-11-29 12:08 - 2012-11-29 12:08 - 00065536 ____A C:\Windows\System32\config\Internet.evt
    2012-11-29 11:45 - 2008-07-21 09:55 - 00262144 ____A C:\Windows\System32\config\security.sav
    2012-11-29 06:55 - 2008-07-21 17:50 - 00000228 _RASH C:\boot.ini.bak
    2012-11-29 06:55 - 2008-07-21 09:54 - 38305792 ____A C:\Windows\System32\config\software.sav
    2012-11-29 06:55 - 2008-07-21 09:54 - 02621440 ____A C:\Windows\System32\config\system.sav
    2012-11-29 06:55 - 2008-07-21 09:54 - 00262144 ____A C:\Windows\System32\config\userdiff
    2012-11-29 06:55 - 2008-07-21 09:54 - 00001024 ___AH C:\Windows\System32\config\userdiff.LOG
    2012-11-29 06:52 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\twain_32
    2012-11-29 06:51 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\icsxml
    2012-11-29 06:51 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\ias
    2012-11-29 06:51 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\System32\1033
    2012-11-29 06:50 - 2008-07-21 09:51 - 00000000 ____D C:\Windows\Driver Cache
    2012-11-29 06:41 - 2008-07-21 09:54 - 00303104 ____A C:\Windows\System32\config\default.sav
    2012-11-21 10:13 - 2012-11-21 08:35 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
    2012-11-21 10:12 - 2012-11-14 12:16 - 00000000 ____D C:\Documents and Settings\mike\Application Data\Task Scheduler.bak
    2012-11-15 11:38 - 2012-11-15 11:38 - 00000209 ____A C:\Documents and Settings\mike\Desktop\REATOGO.txt
    2012-11-15 11:11 - 2012-11-15 11:11 - 00049454 ____A C:\OTL.Txt
    2012-11-14 13:32 - 2009-09-09 14:32 - 00000178 __ASH C:\Documents and Settings\administrator.CP\ntuser.ini
    2012-11-14 13:11 - 2009-09-09 14:32 - 00000062 __ASH C:\Documents and Settings\administrator.CP\Local Settings\desktop.ini
    2012-11-14 13:09 - 2009-09-08 13:17 - 00000520 ____A C:\Windows\System32\ICAutoUpdate.log.bak
    2012-11-14 12:14 - 2009-09-28 08:11 - 00000000 ____D C:\Documents and Settings\mike\Application Data\Nitro PDF
    2012-11-14 10:32 - 2011-09-15 08:18 - 00001615 ____A C:\Documents and Settings\mike\Desktop\MGP SCANS - Shortcut.lnk
    2012-11-14 08:39 - 2009-09-09 15:51 - 00002341 ____A C:\Documents and Settings\mike\Desktop\WordPerfect.lnk
    2012-11-14 08:09 - 2009-09-09 14:11 - 00002521 ____A C:\Documents and Settings\mike\Desktop\Microsoft Office Outlook 2007.lnk
    2012-11-13 13:09 - 2012-11-13 13:09 - 00315072 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2012-11-10 20:00 - 2009-07-23 14:32 - 00000436 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
    2012-11-06 16:23 - 2010-08-09 15:26 - 00000000 ____D C:\Program Files\LogMeIn
    2012-11-06 16:22 - 2009-09-09 15:53 - 00092072 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
    2012-11-06 16:22 - 2009-09-09 15:53 - 00031144 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
    ==================== Bamital & volsnap Check =================
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== Restore Points (XP) =====================
    RP: -> 2012-12-02 15:06 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP9
    RP: -> 2012-12-02 14:06 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP8
    RP: -> 2012-12-02 14:03 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP7
    RP: -> 2012-11-30 18:19 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP6
    RP: -> 2012-11-29 17:46 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP5
    RP: -> 2012-11-29 17:04 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP4
    RP: -> 2012-11-29 15:25 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP3
    RP: -> 2012-11-29 15:24 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP2
    RP: -> 2012-12-03 03:00 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP11
    RP: -> 2012-12-03 00:15 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP10
    RP: -> 2012-11-29 15:21 - 032768 _restore{7471DDEE-C517-42CF-B462-8B6EFDC18CC5}\RP1
    ==================== Memory info ===========================
    Percentage of memory in use: 20%
    Total physical RAM: 3037.17 MB
    Available physical RAM: 2425.75 MB
    Total Pagefile: 4923.06 MB
    Available Pagefile: 4492.58 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1986.26 MB
    ==================== Partitions =============================
    1 Drive c: (Preload) (Fixed) (Total:229.47 GB) (Free:157.15 GB) NTFS
    Disk ### Status Size Free Dyn Gpt
    -------- ---------- ------- ------- --- ---
    Disk 0 Online 233 GB 0 B
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 229 GB 1024 KB
    Partition 2 OEM 3496 MB 229 GB
    =========================================================
    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C Preload NTFS Partition 229 GB Healthy System (partition with boot components)
    =========================================================
    Disk: 0
    Partition 2
    Type : 12
    Hidden: Yes
    Active: No
    There is no volume associated with this partition.
    =========================================================
    ==================== End Of Log ============================
    Farbar Recovery Scan Tool (x86) Version: 02-12-2012
    Ran by mike at 2012-12-03 14:07:53
    Running from C:\download
    ================== Search: "services.exe" ===================
    C:\WINDOWS\system32\services.exe
    [2004-08-03 08:56] - [2009-02-06 06:11] - 0110592 ____A (Microsoft Corporation) 65df52f5b8b6e9bbd183505225c37315
    C:\WINDOWS\system32\dllcache\services.exe
    [2012-11-29 16:42] - [2009-02-06 06:11] - 0110592 ____C (Microsoft Corporation) 65df52f5b8b6e9bbd183505225c37315
    C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
    [2012-11-29 16:42] - [2009-02-06 06:06] - 0110592 ____A (Microsoft Corporation) 020ceaaedc8eb655b6506b8c70d53bb6
    C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
    [2012-11-29 16:42] - [2009-02-06 06:11] - 0110592 ____A (Microsoft Corporation) 65df52f5b8b6e9bbd183505225c37315
    C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
    [2012-11-29 16:42] - [2009-02-06 05:22] - 0110592 ____A (Microsoft Corporation) 4712531ab7a01b7ee059853ca17d39bd
    C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
    [2012-11-29 16:42] - [2009-02-06 12:14] - 0110592 ____A (Microsoft Corporation) 37561f8d4160d62da86d24ae41fae8de
    C:\WINDOWS\ServicePackFiles\i386\services.exe
    [2012-11-29 16:03] - [2008-04-14 05:42] - 0108544 ____N (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185
    C:\WINDOWS\erdnt\cache\services.exe
    [2012-11-29 13:19] - [2004-08-03 08:56] - 0108032 ____A (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4
    C:\WINDOWS\$NtUninstallKB956572$\services.exe
    [2012-11-29 17:22] - [2008-04-14 05:42] - 0108544 ____C (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185
    C:\WINDOWS\$NtServicePackUninstall$\services.exe
    [2012-11-29 15:58] - [2004-08-03 08:56] - 0108032 ____C (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4
    C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
    [2009-09-08 13:28] - [2009-02-06 06:06] - 0110592 ____A (Microsoft Corporation) 020ceaaedc8eb655b6506b8c70d53bb6
    C:\RRbackups\FR\UF\WINDOWS\system32\services.exe
    [2009-09-08 13:17] - [2009-02-06 06:11] - 0110592 ____A (Microsoft Corporation) 65df52f5b8b6e9bbd183505225c37315
    C:\OLD PC\WINDOWS\system32\services.exe
    [2009-09-08 16:38] - [2009-02-06 12:14] - 0110592 ____N (Microsoft Corporation) 37561f8d4160d62da86d24ae41fae8de
    C:\OLD PC\WINDOWS\system32\dllcache\services.exe
    [2009-09-08 16:39] - [2009-02-06 12:14] - 0110592 ____N (Microsoft Corporation) 37561f8d4160d62da86d24ae41fae8de
    C:\OLD PC\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
    [2009-09-08 16:40] - [2008-04-13 19:12] - 0108544 ____N (Microsoft Corporation) 0e776ed5f7cc9f94299e70461b7b8185
    C:\OLD PC\WINDOWS\$NtUninstallKB956572$\services.exe
    [2009-09-08 16:43] - [2004-08-04 06:00] - 0108032 ____N (Microsoft Corporation) c6ce6eec82f187615d1002bb3bb50ed4
    C:\OLD PC\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
    [2009-09-08 16:44] - [2009-02-06 06:06] - 0110592 ____N (Microsoft Corporation) 020ceaaedc8eb655b6506b8c70d53bb6
    C:\OLD PC\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
    [2009-09-08 16:44] - [2009-02-06 06:11] - 0110592 ____N (Microsoft Corporation) 65df52f5b8b6e9bbd183505225c37315
    C:\OLD PC\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
    [2009-09-08 16:44] - [2009-02-06 05:22] - 0110592 ____N (Microsoft Corporation) 4712531ab7a01b7ee059853ca17d39bd
    === End Of Search ===
     
  7. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Hi there. It all appears to be good, so we will finish up to make sure your computer is protected from malware in the future.

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
    • Select Start > All Programs > Accessories > System tools > System Restore.
    • On the dialogue box that appears select Create a Restore Point
    • Click NEXT
    • Enter a name e.g. Clean
    • Click CREATE
    You now have a clean restore point, to get rid of the bad ones:
    • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
    • In the Drop down box that appears select your main drive e.g. C
    • Click OK
    • The System will do some calculation and the display a dialogue box with TABS
    • Select the More Options Tab.
    • At the bottom will be a system restore box with a CLEANUP button click this
    • Accept the Warning and select OK again, the program will close and you are done

    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    NOTE: If you already have this installed, you don't have to reinstall it.

    Please download CCleaner Slim and save it to your Desktop - Alternate download link

    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.

    • Double-click the CCleaner shortcut on the desktop to start the program.
    • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
    • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
    • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).

    Caution: Only use the Registry feature if you are very familiar with the registry.
    Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
     
  8. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    Looks good indeed. Which I am honestly very surprised about. :D


    Results of screen317's Security Check version 0.99.56
    Windows XP Service Pack 3 x86
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Security Center service is not running! This report may not be accurate!
    Windows Firewall Enabled!
    Please wait while WMIC compiles updated MOF files.d
    I
    s
    p
    l
    a
    y
    N
    a
    m
    e
    ECHO is off.
    e
    T
    r
    u
    s
    t
    ECHO is off.
    I
    T
    M
    ECHO is off.
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    MVPS Hosts File
    Malwarebytes Anti-Malware version 1.65.1.1000
    CCleaner
    Java(TM) 6 Update 15
    Java version out of Date!
    Adobe Flash Player 10 Flash Player out of Date!
    Adobe Reader 9 Adobe Reader out of Date!
    ````````Process Check: objlist.exe by Laurent````````
    CA eTrustITM InoRT.exe
    CA eTrustITM realmon.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:: 8%
    ````````````````````End of Log``````````````````````
     
  9. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    Windows Security Center is always off, as that's controlled by the Continuum remote management suite.

    Java, Flash, and Reader I'll go ahead and update, as I always do after infections. ^_^
     
  10. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    Results of screen317's Security Check version 0.99.56
    Windows XP Service Pack 3 x86
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Security Center service is not running! This report may not be accurate!
    Windows Firewall Enabled!
    eTrust ITM
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    MVPS Hosts File
    Malwarebytes Anti-Malware version 1.65.1.1000
    CCleaner
    Java 7 Update 9
    Adobe Reader 9
    Adobe Reader XI
    ````````Process Check: objlist.exe by Laurent````````
    CA eTrustITM InoRT.exe
    CA eTrustITM realmon.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:: 9%
    ````````````````````End of Log``````````````````````
     
  11. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Good job! :D Now, make sure to remove Adobe Reader 9 from the programs. :)

    Personal Tips on Preventing Malware

    See this page for more info about malware and prevention.


    Any other questions before I mark this topic solved?
     
     
  12. Eric Witzling

    Eric Witzling TS Rookie Topic Starter Posts: 94

    No other questions. Everything looks good from here. ^_^

    Thanks for all the help!
     
  13. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    You're welcome.

    Topic solved. √
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.