TechSpot

Google redirect "gethotresults" virus

Solved
By person15
Aug 31, 2012
  1. person15

    person15 TS Rookie Topic Starter Posts: 55

    + 2011-07-01 01:39 . 2010-11-05 01:53290816 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14290816 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-07-01 01:38 . 2010-11-05 01:58970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-07-01 01:38 . 2010-11-05 01:58745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2011-07-01 01:40 . 2010-11-05 01:53692224 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
    + 2011-07-01 01:40 . 2010-11-05 01:53163840 c:\windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
    + 2011-07-01 01:40 . 2010-11-05 01:53462848 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    + 2011-07-01 01:38 . 2010-11-05 01:53684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2011-07-01 01:38 . 2010-11-05 01:53229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
    + 2011-07-01 01:40 . 2010-11-05 01:53667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
    + 2011-07-01 01:38 . 2010-11-05 01:58425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
    + 2012-05-09 21:29 . 2012-01-04 02:50163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
    - 2009-07-14 05:35 . 2009-07-14 02:32200704 c:\windows\assembly\GAC_MSIL\SrpUxSnapIn.resources\6.1.0.0_en_31bf3856ad364e35\SrpUxSnapIn.resources.dll
    + 2011-07-01 01:38 . 2010-11-20 13:16200704 c:\windows\assembly\GAC_MSIL\SrpUxSnapIn.resources\6.1.0.0_en_31bf3856ad364e35\SrpUxSnapIn.resources.dll
    - 2009-07-14 00:36 . 2009-06-10 21:14128848 c:\windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b03f5f7f11d50a3a\SMSvcHost.exe
    + 2011-07-01 01:39 . 2010-11-05 01:52128848 c:\windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b03f5f7f11d50a3a\SMSvcHost.exe
    + 2011-07-01 01:38 . 2010-11-05 01:52110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
    - 2009-07-14 00:36 . 2009-06-10 21:14110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
    + 2011-07-01 01:39 . 2010-11-20 13:44167936 c:\windows\assembly\GAC_MSIL\SecurityAuditPoliciesSnapIn\6.1.0.0__31bf3856ad364e35\SecurityAuditPoliciesSnapIn.dll
    - 2009-07-13 21:39 . 2009-07-14 01:47167936 c:\windows\assembly\GAC_MSIL\SecurityAuditPoliciesSnapIn\6.1.0.0__31bf3856ad364e35\SecurityAuditPoliciesSnapIn.dll
    + 2012-05-09 21:29 . 2012-02-10 23:31532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
    - 2009-07-14 00:35 . 2009-06-10 21:14532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
    - 2009-07-14 00:35 . 2009-06-10 21:14397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    + 2011-07-01 01:38 . 2010-11-05 01:53397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    + 2011-07-01 01:39 . 2010-11-05 01:53598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
    - 2009-07-14 00:35 . 2009-06-10 21:14598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43448360 c:\windows\assembly\GAC_MSIL\office\14.0.0.0__71e9bce111e9429c\OFFICE.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:44286720 c:\windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
    - 2009-07-13 21:36 . 2009-07-14 01:50286720 c:\windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
    + 2012-04-21 23:47 . 2012-04-21 23:47363936 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43131072 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll
    + 2012-04-21 23:47 . 2012-04-21 23:47193472 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43143360 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll
    + 2012-04-21 23:47 . 2012-04-21 23:47153008 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43286720 c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll
    + 2011-07-01 01:39 . 2010-11-05 01:57610304 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23610304 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2011-07-01 01:38 . 2010-11-05 01:57372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43374640 c:\windows\assembly\GAC_MSIL\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
    + 2011-07-01 01:40 . 2010-11-20 13:44679936 c:\windows\assembly\GAC_MSIL\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard\6.1.0.0__31bf3856ad364e35\Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard.dll
    - 2009-07-13 21:38 . 2009-07-14 01:47991232 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Editor\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Editor.dll
    + 2011-07-01 01:40 . 2010-11-20 13:44991232 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Editor\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Editor.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44667648 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
    - 2009-07-13 21:37 . 2009-07-14 01:47667648 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44290816 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
    - 2009-07-13 21:37 . 2009-07-14 01:46290816 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44102400 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
    - 2009-07-13 21:14 . 2009-07-14 01:49102400 c:\windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43299008 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Tools.Word.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Word.v9.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43438272 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Tools.Excel.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Excel.v9.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43356352 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Tools.Common.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Common.v9.0.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43907120 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43386944 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2012-04-21 23:43 . 2012-04-21 23:43149368 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    + 2012-03-17 06:01 . 2012-03-17 06:01608136 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
    - 2009-07-13 22:36 . 2009-07-14 01:22385024 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
    + 2011-07-01 01:38 . 2010-11-20 12:35385024 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
    - 2009-07-13 22:36 . 2009-07-14 01:24241664 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.Sports\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Sports.dll
    + 2011-07-01 01:38 . 2010-11-20 12:35241664 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.Sports\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Sports.dll
    - 2009-07-14 05:35 . 2009-07-14 02:13471040 c:\windows\assembly\GAC_MSIL\Microsoft.GroupPolicy.Reporting.Resources\2.0.0.0_en_31bf3856ad364e35\Microsoft.GroupPolicy.Reporting.Resources.dll
    + 2011-07-01 01:38 . 2010-11-20 12:19471040 c:\windows\assembly\GAC_MSIL\Microsoft.GroupPolicy.Reporting.Resources\2.0.0.0_en_31bf3856ad364e35\Microsoft.GroupPolicy.Reporting.Resources.dll
    + 2011-07-01 01:38 . 2010-11-05 01:57655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
    + 2011-07-01 01:40 . 2010-11-05 01:53802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
    + 2011-07-01 01:38 . 2010-11-05 01:53733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2009-07-13 21:10 . 2009-06-10 21:14733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2009-07-13 20:46 . 2009-06-10 21:22348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2011-07-01 01:38 . 2010-11-05 01:57348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2009-07-13 21:41 . 2009-07-14 01:49339968 c:\windows\assembly\GAC_MSIL\Microsoft.ApplicationId.RuleWizard\6.1.0.0__31bf3856ad364e35\Microsoft.ApplicationId.RuleWizard.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44339968 c:\windows\assembly\GAC_MSIL\Microsoft.ApplicationId.RuleWizard\6.1.0.0__31bf3856ad364e35\Microsoft.ApplicationId.RuleWizard.dll
    - 2009-07-13 21:41 . 2009-07-14 01:49126976 c:\windows\assembly\GAC_MSIL\Microsoft.ApplicationId.Framework\6.1.0.0__31bf3856ad364e35\Microsoft.ApplicationId.Framework.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44126976 c:\windows\assembly\GAC_MSIL\Microsoft.ApplicationId.Framework\6.1.0.0__31bf3856ad364e35\Microsoft.ApplicationId.Framework.dll
    + 2011-07-01 01:40 . 2010-11-20 12:32638976 c:\windows\assembly\GAC_MSIL\mcstore\6.1.0.0__31bf3856ad364e35\mcstore.dll
    - 2010-10-27 13:43 . 2010-08-04 06:28638976 c:\windows\assembly\GAC_MSIL\mcstore\6.1.0.0__31bf3856ad364e35\mcstore.dll
    - 2009-07-14 00:25 . 2009-07-14 01:49207872 c:\windows\assembly\GAC_MSIL\mcplayerinterop\6.1.0.0__31bf3856ad364e35\mcplayerinterop.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44207872 c:\windows\assembly\GAC_MSIL\mcplayerinterop\6.1.0.0__31bf3856ad364e35\mcplayerinterop.dll
    + 2011-07-01 01:40 . 2010-11-20 13:44741376 c:\windows\assembly\GAC_MSIL\mcepg\6.1.0.0__31bf3856ad364e35\mcepg.dll
    - 2010-10-27 13:43 . 2010-08-04 07:14741376 c:\windows\assembly\GAC_MSIL\mcepg\6.1.0.0__31bf3856ad364e35\mcepg.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32368640 c:\windows\assembly\GAC_MSIL\EventViewer\6.1.0.0__31bf3856ad364e35\EventViewer.dll
    - 2009-07-13 21:46 . 2009-07-14 01:21368640 c:\windows\assembly\GAC_MSIL\EventViewer\6.1.0.0__31bf3856ad364e35\EventViewer.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32196608 c:\windows\assembly\GAC_MSIL\ehRecObj\6.1.0.0__31bf3856ad364e35\ehRecObj.dll
    - 2009-07-13 22:35 . 2009-07-14 01:21196608 c:\windows\assembly\GAC_MSIL\ehRecObj\6.1.0.0__31bf3856ad364e35\ehRecObj.dll
    - 2009-07-13 22:35 . 2009-07-14 01:20172032 c:\windows\assembly\GAC_MSIL\ehiProxy\6.1.0.0__31bf3856ad364e35\ehiProxy.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32172032 c:\windows\assembly\GAC_MSIL\ehiProxy\6.1.0.0__31bf3856ad364e35\ehiProxy.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32143360 c:\windows\assembly\GAC_MSIL\ehexthost\6.1.0.0__31bf3856ad364e35\ehexthost.exe
    - 2009-07-13 22:36 . 2009-07-14 01:20143360 c:\windows\assembly\GAC_MSIL\ehexthost\6.1.0.0__31bf3856ad364e35\ehexthost.exe
    + 2011-07-01 01:39 . 2010-11-05 01:52165720 c:\windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0__b03f5f7f11d50a3a\ComSvcConfig.exe
    + 2012-05-09 21:29 . 2012-02-10 23:29358912 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2009-07-13 20:37 . 2009-06-10 20:40133120 c:\windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-07-01 01:38 . 2010-11-05 01:57133120 c:\windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-07-01 01:38 . 2010-11-05 01:57245760 c:\windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2009-07-13 20:37 . 2009-06-10 20:40245760 c:\windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2011-07-01 01:39 . 2010-11-05 01:56502272 c:\windows\assembly\GAC_64\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    - 2009-07-13 20:37 . 2009-06-10 20:40502272 c:\windows\assembly\GAC_64\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    - 2009-07-14 00:09 . 2009-07-14 01:50133632 c:\windows\assembly\GAC_64\naphlpr\6.1.0.0__31bf3856ad364e35\NAPHLPR.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:44133632 c:\windows\assembly\GAC_64\naphlpr\6.1.0.0__31bf3856ad364e35\NAPHLPR.DLL
    + 2011-07-01 01:38 . 2010-11-05 01:52163840 c:\windows\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2009-07-14 01:01 . 2009-06-10 20:30163840 c:\windows\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44327168 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.TV.Tuners.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.TV.Tuners.Interop.dll
    - 2009-07-14 00:24 . 2009-07-14 01:52327168 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.TV.Tuners.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.TV.Tuners.Interop.dll
    + 2011-07-01 01:39 . 2010-11-20 13:44114688 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.Playback\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Playback.dll
    - 2010-10-27 13:43 . 2010-08-04 07:14114688 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.Playback\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Playback.dll
    - 2009-07-14 00:24 . 2009-07-14 01:51147968 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.iTV.Media\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.iTV.Media.dll
    + 2011-07-01 01:39 . 2010-11-20 13:44147968 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.iTV.Media\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.iTV.Media.dll
    + 2011-10-13 18:20 . 2011-08-17 05:28315392 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Interop.dll
    - 2009-07-14 00:24 . 2009-07-14 01:51315392 c:\windows\assembly\GAC_64\Microsoft.MediaCenter.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Interop.dll
    + 2011-07-01 01:39 . 2010-11-20 13:44151040 c:\windows\assembly\GAC_64\Microsoft.GroupPolicy.Interop\2.0.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.Interop.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44196096 c:\windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\6.1.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.AdmTmplEditor.dll
    - 2009-07-13 23:54 . 2009-07-14 01:50196096 c:\windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\6.1.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.AdmTmplEditor.dll
    + 2011-07-01 01:38 . 2010-11-20 13:44133120 c:\windows\assembly\GAC_64\Mcx2Dvcs\6.1.0.0__31bf3856ad364e35\Mcx2Dvcs.dll
    - 2009-07-14 00:24 . 2009-07-14 01:50133120 c:\windows\assembly\GAC_64\Mcx2Dvcs\6.1.0.0__31bf3856ad364e35\Mcx2Dvcs.dll
    - 2010-10-27 13:43 . 2010-08-04 07:14198656 c:\windows\assembly\GAC_64\mcupdate\6.1.0.0__31bf3856ad364e35\mcupdate.exe
    + 2011-07-01 01:39 . 2010-11-20 13:44198656 c:\windows\assembly\GAC_64\mcupdate\6.1.0.0__31bf3856ad364e35\mcupdate.exe
    + 2011-07-01 01:38 . 2010-11-20 13:44139264 c:\windows\assembly\GAC_64\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
    - 2009-07-14 00:24 . 2009-07-14 01:48139264 c:\windows\assembly\GAC_64\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
    + 2011-07-01 01:38 . 2010-11-20 13:39249344 c:\windows\assembly\GAC_64\BDATunePIA\6.1.0.0__31bf3856ad364e35\BDATunePIA.dll
    - 2009-07-14 00:21 . 2009-07-14 01:54249344 c:\windows\assembly\GAC_64\BDATunePIA\6.1.0.0__31bf3856ad364e35\BDATunePIA.dll
    + 2012-05-09 21:29 . 2012-02-10 23:31372736 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2011-07-01 01:38 . 2010-11-20 04:12113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2009-07-13 20:46 . 2009-07-13 20:46113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-07-01 01:38 . 2010-11-05 01:58258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2009-07-13 20:46 . 2009-06-10 21:23486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2011-07-01 01:39 . 2010-11-05 01:58486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    - 2009-07-13 23:53 . 2009-07-14 01:22107008 c:\windows\assembly\GAC_32\naphlpr\6.1.0.0__31bf3856ad364e35\NAPHLPR.DLL
    + 2011-07-01 01:38 . 2010-11-20 12:36107008 c:\windows\assembly\GAC_32\naphlpr\6.1.0.0__31bf3856ad364e35\NAPHLPR.DLL
    - 2009-07-14 00:36 . 2009-06-10 21:14163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-07-01 01:38 . 2010-11-05 01:52163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2012-07-20 15:26 . 2012-07-20 15:26117160 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
    + 2011-07-01 01:39 . 2010-11-20 12:35145920 c:\windows\assembly\GAC_32\Microsoft.GroupPolicy.Interop\2.0.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.Interop.dll
    + 2011-07-01 01:38 . 2010-11-20 12:35189952 c:\windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\6.1.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.AdmTmplEditor.dll
    - 2009-07-13 23:38 . 2009-07-14 01:21189952 c:\windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\6.1.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.AdmTmplEditor.dll
    - 2009-07-14 00:09 . 2009-07-14 01:20134656 c:\windows\assembly\GAC_32\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32134656 c:\windows\assembly\GAC_32\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
    - 2009-07-14 00:06 . 2009-07-14 01:25238080 c:\windows\assembly\GAC_32\BDATunePIA\6.1.0.0__31bf3856ad364e35\BDATunePIA.dll
    + 2011-07-01 01:38 . 2010-11-20 12:32238080 c:\windows\assembly\GAC_32\BDATunePIA\6.1.0.0__31bf3856ad364e35\BDATunePIA.dll
    + 2012-03-17 06:01 . 2012-03-17 06:01870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    - 2010-01-04 20:10 . 2010-01-04 20:10870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2011-12-15 16:04 . 2011-12-15 16:04350080 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2012-03-17 06:01 . 2012-03-17 06:01149368 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    - 2011-04-27 22:12 . 2011-03-04 06:17135168 c:\windows\AppPatch\AppPatch64\AcXtrnal.dll
    + 2011-04-27 22:12 . 2011-03-04 06:19135168 c:\windows\AppPatch\AppPatch64\AcXtrnal.dll
    + 2011-04-27 22:12 . 2011-03-04 06:19350208 c:\windows\AppPatch\AppPatch64\AcLayers.dll
    + 2011-04-27 22:12 . 2010-11-20 12:18562176 c:\windows\AppPatch\AcLayers.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211712640 c:\windows\SysWOW64\xpsservices.dll
    - 2009-07-14 00:22 . 2009-07-14 01:161712640 c:\windows\SysWOW64\xpsservices.dll
    - 2009-07-13 23:31 . 2009-07-14 01:161175040 c:\windows\SysWOW64\WsmSvc.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211175040 c:\windows\SysWOW64\WsmSvc.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212311168 c:\windows\SysWOW64\wpdshext.dll
    - 2009-07-14 00:07 . 2009-07-14 01:162311168 c:\windows\SysWOW64\wpdshext.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211619456 c:\windows\SysWOW64\WMVDECOD.DLL
    - 2010-12-03 05:01 . 2010-05-23 10:151619456 c:\windows\SysWOW64\WMVDECOD.DLL
    - 2009-07-14 00:41 . 2009-07-14 01:162504192 c:\windows\SysWOW64\WMVCORE.DLL
    + 2011-07-01 01:39 . 2010-11-20 12:202504192 c:\windows\SysWOW64\WMVCORE.DLL
    + 2011-07-01 01:39 . 2010-11-20 12:211624064 c:\windows\SysWOW64\WMPEncEn.dll
    - 2009-07-14 00:09 . 2009-07-14 01:161624064 c:\windows\SysWOW64\WMPEncEn.dll
    - 2009-07-14 00:09 . 2009-07-14 01:161003008 c:\windows\SysWOW64\WMNetMgr.dll
    + 2011-07-01 01:39 . 2010-11-20 12:211003008 c:\windows\SysWOW64\WMNetMgr.dll
    + 2011-07-01 01:39 . 2010-11-20 12:211326592 c:\windows\SysWOW64\wlanpref.dll
    - 2009-07-13 23:56 . 2009-07-14 01:161326592 c:\windows\SysWOW64\wlanpref.dll
    + 2012-08-16 07:06 . 2012-06-29 00:091129472 c:\windows\SysWOW64\wininet.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211010688 c:\windows\SysWOW64\WindowsCodecs.dll
    - 2009-07-13 23:20 . 2009-07-14 01:161227776 c:\windows\SysWOW64\wdc.dll
    + 2011-07-01 01:39 . 2010-11-20 12:211227776 c:\windows\SysWOW64\wdc.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211128448 c:\windows\SysWOW64\vssapi.dll
    + 2012-08-16 07:06 . 2012-06-29 00:091103872 c:\windows\SysWOW64\urlmon.dll
    - 2009-07-13 23:29 . 2009-07-14 01:101164800 c:\windows\SysWOW64\UIRibbonRes.dll
    + 2011-07-01 01:38 . 2010-11-20 12:071164800 c:\windows\SysWOW64\UIRibbonRes.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212983424 c:\windows\SysWOW64\UIRibbon.dll
    - 2009-07-13 23:43 . 2009-07-14 01:162983424 c:\windows\SysWOW64\UIRibbon.dll
    + 2011-06-29 02:09 . 2011-05-04 04:341549312 c:\windows\SysWOW64\tquery.dll
    - 2009-07-13 23:39 . 2009-07-14 01:162755072 c:\windows\SysWOW64\themeui.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212755072 c:\windows\SysWOW64\themeui.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212157568 c:\windows\SysWOW64\themecpl.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212146304 c:\windows\SysWOW64\SyncCenter.dll
    - 2009-07-13 23:40 . 2009-07-14 01:162146304 c:\windows\SysWOW64\SyncCenter.dll
    - 2009-07-14 00:14 . 2009-07-14 01:161202176 c:\windows\SysWOW64\Speech\Common\sapi.dll
    + 2011-07-01 01:39 . 2010-11-20 12:211202176 c:\windows\SysWOW64\Speech\Common\sapi.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211667584 c:\windows\SysWOW64\setupapi.dll
    + 2011-07-01 01:39 . 2010-11-20 12:212202624 c:\windows\SysWOW64\SensorsCpl.dll
    - 2009-07-13 23:45 . 2009-07-14 01:162202624 c:\windows\SysWOW64\SensorsCpl.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211115136 c:\windows\SysWOW64\RacEngn.dll
    + 2011-07-01 01:40 . 2010-11-20 12:211363456 c:\windows\SysWOW64\Query.dll
    - 2009-07-14 00:12 . 2009-07-14 01:161363456 c:\windows\SysWOW64\Query.dll
    + 2012-01-11 14:42 . 2011-10-26 04:321328128 c:\windows\SysWOW64\quartz.dll
    + 2011-07-01 01:39 . 2010-11-20 12:201750528 c:\windows\SysWOW64\pnidui.dll
    - 2009-07-13 23:52 . 2009-07-14 01:161750528 c:\windows\SysWOW64\pnidui.dll
    - 2009-07-13 23:20 . 2009-07-14 01:161508864 c:\windows\SysWOW64\pla.dll
    + 2011-07-01 01:39 . 2010-11-20 12:201508864 c:\windows\SysWOW64\pla.dll
    - 2009-07-14 00:21 . 2009-07-14 01:161160192 c:\windows\SysWOW64\OpcServices.dll
    + 2011-07-01 01:38 . 2010-11-20 12:201160192 c:\windows\SysWOW64\OpcServices.dll
    - 2009-07-13 23:51 . 2009-07-14 01:161111552 c:\windows\SysWOW64\onexui.dll
    + 2011-07-01 01:38 . 2010-11-20 12:201111552 c:\windows\SysWOW64\onexui.dll
    + 2011-07-01 01:40 . 2010-11-20 12:201414144 c:\windows\SysWOW64\ole32.dll
    + 2012-06-14 15:21 . 2012-05-04 10:033913072 c:\windows\SysWOW64\ntoskrnl.exe
    + 2012-06-14 15:21 . 2012-05-04 10:033968368 c:\windows\SysWOW64\ntkrnlpa.exe
    + 2012-01-11 14:42 . 2011-11-17 05:381292080 c:\windows\SysWOW64\ntdll.dll
    + 2011-07-01 01:39 . 2010-11-20 12:202130944 c:\windows\SysWOW64\networkmap.dll
    - 2009-07-13 23:53 . 2009-07-14 01:162130944 c:\windows\SysWOW64\networkmap.dll
    - 2009-07-13 23:53 . 2009-07-14 01:161661440 c:\windows\SysWOW64\networkexplorer.dll
    + 2011-07-01 01:38 . 2010-11-20 12:201661440 c:\windows\SysWOW64\networkexplorer.dll
    + 2011-07-01 01:39 . 2010-11-20 12:202494464 c:\windows\SysWOW64\netshell.dll
    - 2009-07-13 23:53 . 2009-07-14 01:162494464 c:\windows\SysWOW64\netshell.dll
    + 2011-07-01 01:39 . 2010-11-20 12:201644032 c:\windows\SysWOW64\netcenter.dll
    - 2009-07-13 23:56 . 2009-07-14 01:161644032 c:\windows\SysWOW64\netcenter.dll
    + 2011-07-01 01:40 . 2010-11-20 12:192291712 c:\windows\SysWOW64\MSVidCtl.dll
    - 2009-07-14 00:08 . 2009-07-14 01:152291712 c:\windows\SysWOW64\MSVidCtl.dll
    + 2011-07-01 01:40 . 2010-11-20 12:193215872 c:\windows\SysWOW64\mstscax.dll
    + 2011-07-01 01:40 . 2010-11-20 12:171049600 c:\windows\SysWOW64\mstsc.exe
    + 2011-06-29 02:09 . 2011-05-04 04:321401344 c:\windows\SysWOW64\mssrch.dll
    + 2012-06-14 15:21 . 2012-04-07 11:262342400 c:\windows\SysWOW64\msi.dll
    + 2011-07-01 01:40 . 2010-11-20 12:192151936 c:\windows\SysWOW64\mmcndmgr.dll
    - 2009-07-13 23:31 . 2009-07-14 01:152151936 c:\windows\SysWOW64\mmcndmgr.dll
    - 2009-07-13 23:18 . 2009-07-14 01:158826880 c:\windows\SysWOW64\migwiz\wet.dll
    + 2011-07-01 01:39 . 2010-11-20 12:198826880 c:\windows\SysWOW64\migwiz\wet.dll
    + 2011-07-01 01:40 . 2010-11-20 12:195766144 c:\windows\SysWOW64\migwiz\migcore.dll
    + 2011-04-14 18:51 . 2011-03-11 05:331164288 c:\windows\SysWOW64\mfc42u.dll
    - 2011-04-14 18:51 . 2011-03-11 05:401164288 c:\windows\SysWOW64\mfc42u.dll
    - 2011-04-14 18:51 . 2011-03-11 05:401137664 c:\windows\SysWOW64\mfc42.dll
    + 2011-04-14 18:51 . 2011-03-11 05:331137664 c:\windows\SysWOW64\mfc42.dll
    + 2011-07-01 01:40 . 2010-11-20 12:193207680 c:\windows\SysWOW64\mf.dll
    + 2012-08-22 17:31 . 2012-08-22 17:319465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
    + 2012-08-22 17:31 . 2012-08-22 17:311536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
    + 2011-08-10 16:05 . 2011-07-16 04:241114112 c:\windows\SysWOW64\kernel32.dll
    + 2012-08-16 07:06 . 2012-06-29 00:161800704 c:\windows\SysWOW64\jscript9.dll
    + 2011-07-01 01:38 . 2010-11-20 12:191013760 c:\windows\SysWOW64\IME\IMEJP10\IMJPTIP.DLL
    - 2009-07-13 23:26 . 2009-07-14 01:151013760 c:\windows\SysWOW64\IME\IMEJP10\IMJPTIP.DLL
    + 2012-08-16 07:06 . 2012-06-29 00:011793024 c:\windows\SysWOW64\iertutil.dll
    + 2012-08-16 07:06 . 2012-06-29 00:279737728 c:\windows\SysWOW64\ieframe.dll
    + 2011-07-01 01:39 . 2010-11-20 12:192576384 c:\windows\SysWOW64\gameux.dll
    - 2009-07-13 23:41 . 2009-07-14 01:152576384 c:\windows\SysWOW64\gameux.dll
    + 2010-10-20 16:44 . 2010-10-20 16:441207656 c:\windows\SysWOW64\FM20.DLL
    + 2011-07-01 01:40 . 2010-11-20 12:191493504 c:\windows\SysWOW64\ExplorerFrame.dll
    + 2011-04-27 22:12 . 2011-02-25 05:302616320 c:\windows\SysWOW64\explorer.exe
    + 2011-04-27 22:11 . 2011-03-11 05:331699328 c:\windows\SysWOW64\esent.dll
    + 2011-07-01 01:39 . 2010-11-20 12:181400320 c:\windows\SysWOW64\DxpTaskSync.dll
    - 2009-07-14 00:07 . 2009-07-14 01:151400320 c:\windows\SysWOW64\DxpTaskSync.dll
    + 2012-05-09 21:29 . 2012-03-03 05:311077248 c:\windows\SysWOW64\DWrite.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181371136 c:\windows\SysWOW64\dwmcore.dll
    - 2009-07-13 23:40 . 2009-07-14 01:151040384 c:\windows\SysWOW64\Display.dll
    + 2011-07-01 01:39 . 2010-11-20 12:181040384 c:\windows\SysWOW64\Display.dll
    + 2011-07-01 01:41 . 2010-11-05 01:581130824 c:\windows\SysWOW64\dfshim.dll
    - 2010-06-24 14:34 . 2009-11-25 16:471130824 c:\windows\SysWOW64\dfshim.dll
    + 2011-07-01 01:40 . 2010-11-20 12:182522624 c:\windows\SysWOW64\dbgeng.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181828352 c:\windows\SysWOW64\d3d9.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181171456 c:\windows\SysWOW64\d3d10warp.dll
    - 2009-07-13 23:33 . 2009-07-14 01:151003520 c:\windows\SysWOW64\cryptui.dll
    + 2011-07-01 01:39 . 2010-11-20 12:181003520 c:\windows\SysWOW64\cryptui.dll
    + 2012-06-14 15:21 . 2012-04-24 04:361158656 c:\windows\SysWOW64\crypt32.dll
    - 2009-07-13 23:29 . 2009-07-14 01:151555456 c:\windows\SysWOW64\certmgr.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181555456 c:\windows\SysWOW64\certmgr.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181334272 c:\windows\SysWOW64\CertEnroll.dll
    + 2011-07-01 01:40 . 2010-11-20 12:181792000 c:\windows\SysWOW64\authui.dll
    - 2009-07-13 23:42 . 2009-07-14 01:141792000 c:\windows\SysWOW64\authui.dll
    + 2011-07-01 01:40 . 2010-11-20 12:325066752 c:\windows\SysWOW64\AuthFWSnapin.dll
    - 2009-07-13 23:17 . 2009-07-14 01:152041344 c:\windows\SysWOW64\AdvancedInstallers\cmiv2.dll
    + 2011-07-01 01:37 . 2010-11-20 12:182041344 c:\windows\SysWOW64\AdvancedInstallers\cmiv2.dll
    + 2011-07-01 01:39 . 2010-11-20 12:183727872 c:\windows\SysWOW64\accessibilitycpl.dll
    + 2011-07-01 01:40 . 2010-11-20 13:273008000 c:\windows\system32\xpsservices.dll
    - 2009-07-14 00:45 . 2009-07-14 01:413008000 c:\windows\system32\xpsservices.dll
    + 2011-04-27 22:12 . 2011-03-12 12:081465344 c:\windows\system32\XpsPrint.dll
    + 2012-06-21 15:44 . 2012-06-02 22:152622464 c:\windows\system32\wucltux.dll
    + 2012-06-21 15:44 . 2012-06-02 22:192428952 c:\windows\system32\wuaueng.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272018304 c:\windows\system32\WsmSvc.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272543616 c:\windows\system32\wpdshext.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271888256 c:\windows\system32\WMVDECOD.DLL
    - 2010-12-03 05:01 . 2010-05-23 08:371888256 c:\windows\system32\WMVDECOD.DLL
    + 2011-07-01 01:40 . 2010-11-20 13:273027968 c:\windows\system32\WMVCORE.DLL
    + 2011-07-01 01:40 . 2010-11-20 13:271024512 c:\windows\system32\wmpmde.dll
    - 2010-10-13 14:43 . 2010-08-21 06:381024512 c:\windows\system32\wmpmde.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272072576 c:\windows\system32\WMPEncEn.dll
    - 2009-07-14 00:25 . 2009-07-14 01:412072576 c:\windows\system32\WMPEncEn.dll
    - 2009-07-14 00:24 . 2009-07-14 01:411243136 c:\windows\system32\WMNetMgr.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271243136 c:\windows\system32\WMNetMgr.dll
    - 2009-07-14 00:23 . 2009-07-14 01:411232896 c:\windows\system32\WMADMOD.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:271232896 c:\windows\system32\WMADMOD.DLL
    + 2011-07-01 01:40 . 2010-11-20 13:271441280 c:\windows\system32\wlanpref.dll
    - 2009-07-14 00:11 . 2009-07-14 01:411441280 c:\windows\system32\wlanpref.dll
    + 2011-07-01 01:40 . 2010-11-20 13:253957760 c:\windows\system32\WinSAT.exe
    - 2009-07-13 23:37 . 2009-07-14 01:393957760 c:\windows\system32\WinSAT.exe
    + 2012-08-16 07:06 . 2012-06-29 03:491392128 c:\windows\system32\wininet.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271190400 c:\windows\system32\WindowsCodecs.dll
    - 2009-07-13 23:49 . 2009-07-14 01:411646080 c:\windows\system32\wevtsvc.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271646080 c:\windows\system32\wevtsvc.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271281024 c:\windows\system32\werconcpl.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271158656 c:\windows\system32\webservices.dll
    - 2009-07-13 23:32 . 2009-07-14 01:411363968 c:\windows\system32\wdc.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271363968 c:\windows\system32\wdc.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251504256 c:\windows\system32\wbengine.exe
    + 2011-07-01 01:34 . 2010-11-20 13:271225216 c:\windows\system32\wbem\wbemcore.dll
    + 2011-07-01 01:40 . 2010-11-20 13:252058240 c:\windows\system32\wbem\cimwin32.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251600512 c:\windows\system32\VSSVC.exe
    + 2011-07-01 01:40 . 2010-11-20 13:271753088 c:\windows\system32\vssapi.dll
    - 2009-07-13 23:53 . 2009-07-14 01:411098240 c:\windows\system32\Vault.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271098240 c:\windows\system32\Vault.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271008128 c:\windows\system32\user32.dll
    + 2012-08-16 07:06 . 2012-06-29 03:491346048 c:\windows\system32\urlmon.dll
    + 2011-07-01 01:38 . 2010-11-20 13:151164800 c:\windows\system32\UIRibbonRes.dll
  2. person15

    person15 TS Rookie Topic Starter Posts: 55

    - 2009-07-13 23:43 . 2009-07-14 01:331164800 c:\windows\system32\UIRibbonRes.dll
    + 2011-07-01 01:40 . 2010-11-20 13:273860992 c:\windows\system32\UIRibbon.dll
    + 2011-06-29 02:09 . 2011-05-04 05:252315776 c:\windows\system32\tquery.dll
    + 2011-07-01 01:39 . 2010-11-20 13:272851840 c:\windows\system32\themeui.dll
    + 2011-07-01 01:39 . 2010-11-20 13:272193920 c:\windows\system32\themecpl.dll
    - 2009-07-13 23:56 . 2009-07-14 01:412193920 c:\windows\system32\themecpl.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271197056 c:\windows\system32\taskschd.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271743360 c:\windows\system32\sysmain.dll
    - 2009-07-13 23:55 . 2009-07-14 01:412262528 c:\windows\system32\SyncCenter.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272262528 c:\windows\system32\SyncCenter.dll
    - 2009-07-14 01:05 . 2009-07-14 01:393524608 c:\windows\system32\sppsvc.exe
    + 2011-07-01 01:39 . 2010-11-20 13:253524608 c:\windows\system32\sppsvc.exe
    + 2011-07-01 01:40 . 2010-11-20 13:271082880 c:\windows\system32\sppobjs.dll
    - 2009-07-13 23:52 . 2009-07-14 01:411082880 c:\windows\system32\sppobjs.dll
    + 2012-04-21 23:41 . 2010-11-20 13:271576448 c:\windows\system32\spool\drivers\x64\XpsSvcs.dll
    + 2012-08-24 19:36 . 2012-08-24 19:362332160 c:\windows\system32\spool\drivers\x64\hpmux115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:362506752 c:\windows\system32\spool\drivers\x64\hpmsn115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361196544 c:\windows\system32\spool\drivers\x64\hpmsl115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361064960 c:\windows\system32\spool\drivers\x64\hpmdp115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:363718144 c:\windows\system32\spool\drivers\x64\hpcur115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:364083712 c:\windows\system32\spool\drivers\x64\hpcui115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:364500480 c:\windows\system32\spool\drivers\x64\hpcst115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361013248 c:\windows\system32\spool\drivers\x64\hpcss115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361668608 c:\windows\system32\spool\drivers\x64\hpcls115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361257016 c:\windows\system32\spool\drivers\x64\hpbuio64.dll
    - 2009-07-14 00:42 . 2009-07-14 01:411576448 c:\windows\system32\spool\drivers\x64\3\XPSSVCS.DLL
    + 2009-07-14 00:42 . 2010-11-20 13:271576448 c:\windows\system32\spool\drivers\x64\3\XpsSvcs.dll
    - 2009-07-14 01:18 . 2009-07-14 01:301057792 c:\windows\system32\spool\drivers\x64\3\PCL5ERES.DLL
    + 2009-07-14 01:18 . 2010-11-20 13:091057792 c:\windows\system32\spool\drivers\x64\3\PCL5ERES.DLL
    + 2012-05-09 21:29 . 2012-03-31 05:401402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
    - 2009-07-14 00:03 . 2009-07-14 01:411402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll
    + 2012-08-24 19:36 . 2012-08-24 19:362332160 c:\windows\system32\spool\drivers\x64\3\hpmux115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:362506752 c:\windows\system32\spool\drivers\x64\3\hpmsn115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361196544 c:\windows\system32\spool\drivers\x64\3\hpmsl115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361064960 c:\windows\system32\spool\drivers\x64\3\hpmdp115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:363718144 c:\windows\system32\spool\drivers\x64\3\hpcur115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:364083712 c:\windows\system32\spool\drivers\x64\3\hpcui115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:364500480 c:\windows\system32\spool\drivers\x64\3\hpcst115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361013248 c:\windows\system32\spool\drivers\x64\3\hpcss115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361668608 c:\windows\system32\spool\drivers\x64\3\hpcls115.dll
    + 2012-08-24 19:36 . 2012-08-24 19:361257016 c:\windows\system32\spool\drivers\x64\3\hpbuio64.dll
    + 2009-07-14 01:19 . 2010-11-20 13:086566400 c:\windows\system32\spool\drivers\x64\3\FXSRES.DLL
    - 2009-07-14 00:35 . 2009-07-14 01:411126912 c:\windows\system32\Speech\SpeechUX\SpeechUX.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271126912 c:\windows\system32\Speech\SpeechUX\SpeechUX.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271435648 c:\windows\system32\Speech\Common\sapi.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271900544 c:\windows\system32\setupapi.dll
    - 2009-07-14 00:00 . 2009-07-14 01:412250752 c:\windows\system32\SensorsCpl.dll
    + 2011-07-01 01:39 . 2010-11-20 13:272250752 c:\windows\system32\SensorsCpl.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271120768 c:\windows\system32\sdengin2.dll
    - 2009-07-13 23:37 . 2009-07-14 01:411120768 c:\windows\system32\sdengin2.dll
    + 2011-07-01 01:39 . 2010-11-20 13:251264640 c:\windows\system32\sdclt.exe
    - 2009-07-13 23:37 . 2009-07-14 01:391264640 c:\windows\system32\sdclt.exe
    + 2011-07-01 01:40 . 2010-11-20 13:271110016 c:\windows\system32\schedsvc.dll
    - 2011-03-08 20:50 . 2010-12-23 06:071118720 c:\windows\system32\sbe.dll
    + 2011-03-08 20:50 . 2010-12-23 10:421118720 c:\windows\system32\sbe.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271219584 c:\windows\system32\rpcrt4.dll
    - 2009-07-14 00:16 . 2009-07-14 01:411031680 c:\windows\system32\rdpcore.dll
    + 2012-03-14 17:29 . 2012-02-17 06:381031680 c:\windows\system32\rdpcore.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271556992 c:\windows\system32\RacEngn.dll
    - 2009-07-13 23:37 . 2009-07-14 01:411556992 c:\windows\system32\RacEngn.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272055680 c:\windows\system32\Query.dll
    - 2009-07-14 00:29 . 2009-07-14 01:412055680 c:\windows\system32\Query.dll
    + 2012-01-11 14:42 . 2011-10-26 05:251572864 c:\windows\system32\quartz.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271212416 c:\windows\system32\propsys.dll
    - 2009-07-13 23:56 . 2009-07-14 01:411212416 c:\windows\system32\propsys.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271050624 c:\windows\system32\printui.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271808384 c:\windows\system32\pnidui.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271389056 c:\windows\system32\pla.dll
    + 2011-07-01 01:38 . 2010-11-20 13:271911808 c:\windows\system32\OpcServices.dll
    - 2009-07-14 00:43 . 2009-07-14 01:411911808 c:\windows\system32\OpcServices.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272199040 c:\windows\system32\oobe\winsetup.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271161728 c:\windows\system32\oobe\msoobeui.dll
    - 2009-07-14 00:07 . 2009-07-14 01:411080320 c:\windows\system32\onexui.dll
    + 2011-07-01 01:38 . 2010-11-20 13:271080320 c:\windows\system32\onexui.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272086912 c:\windows\system32\ole32.dll
    + 2012-06-14 15:21 . 2012-05-04 11:065559664 c:\windows\system32\ntoskrnl.exe
    + 2012-01-11 14:42 . 2011-11-17 06:411731920 c:\windows\system32\ntdll.dll
    + 2011-07-01 01:39 . 2010-11-20 13:272146816 c:\windows\system32\networkmap.dll
    - 2009-07-14 00:08 . 2009-07-14 01:412146816 c:\windows\system32\networkmap.dll
    - 2009-07-14 00:08 . 2009-07-14 01:411672704 c:\windows\system32\networkexplorer.dll
    + 2011-07-01 01:38 . 2010-11-20 13:271672704 c:\windows\system32\networkexplorer.dll
    + 2011-07-01 01:40 . 2010-11-20 13:272652160 c:\windows\system32\netshell.dll
    - 2009-07-14 00:12 . 2009-07-14 01:411689600 c:\windows\system32\netcenter.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271689600 c:\windows\system32\netcenter.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271326080 c:\windows\system32\NaturalLanguage6.dll
    + 2011-07-01 01:39 . 2010-11-20 13:441077248 c:\windows\system32\Narrator.exe
    + 2011-07-01 01:40 . 2010-11-20 13:273650560 c:\windows\system32\MSVidCtl.dll
    + 2011-07-01 01:41 . 2010-11-20 13:273715584 c:\windows\system32\mstscax.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251116672 c:\windows\system32\mstsc.exe
    + 2011-06-29 02:09 . 2011-05-04 05:222223616 c:\windows\system32\mssrch.dll
    + 2011-07-01 01:39 . 2010-11-20 13:271160192 c:\windows\system32\MSMPEG2ENC.DLL
    - 2009-07-14 00:23 . 2009-07-14 01:411160192 c:\windows\system32\MSMPEG2ENC.DLL
    + 2012-06-14 15:21 . 2012-04-07 12:313216384 c:\windows\system32\msi.dll
    + 2011-07-01 01:40 . 2010-11-20 13:271509888 c:\windows\system32\msdtctm.dll
    - 2009-07-14 00:00 . 2009-07-14 01:411509888 c:\windows\system32\msdtctm.dll
    + 2011-07-01 01:40 . 2010-11-20 13:263205120 c:\windows\system32\mmcndmgr.dll
    - 2009-07-13 23:48 . 2009-07-14 01:413205120 c:\windows\system32\mmcndmgr.dll
    + 2011-07-01 01:40 . 2010-11-20 13:261205760 c:\windows\system32\migwiz\migstore.dll
    + 2011-07-01 01:40 . 2010-11-20 13:268032768 c:\windows\system32\migwiz\migcore.dll
    - 2011-04-14 18:51 . 2011-03-11 06:191359872 c:\windows\system32\mfc42u.dll
    + 2011-04-14 18:51 . 2011-03-11 06:341359872 c:\windows\system32\mfc42u.dll
    + 2011-04-14 18:51 . 2011-03-11 06:341395712 c:\windows\system32\mfc42.dll
    - 2011-04-14 18:51 . 2011-03-11 06:191395712 c:\windows\system32\mfc42.dll
    + 2011-07-01 01:40 . 2010-11-20 13:264120064 c:\windows\system32\mf.dll
    - 2009-07-14 00:19 . 2009-07-14 01:411009152 c:\windows\system32\mcmde.dll
    + 2011-07-01 01:40 . 2010-11-20 13:261009152 c:\windows\system32\mcmde.dll
    + 2012-01-11 18:31 . 2011-11-17 06:351447936 c:\windows\system32\lsasrv.dll
    + 2011-08-10 16:05 . 2011-07-16 05:371162752 c:\windows\system32\kernel32.dll
    + 2012-08-16 07:06 . 2012-06-29 03:562312704 c:\windows\system32\jscript9.dll
    - 2009-07-13 23:40 . 2009-07-14 01:411242112 c:\windows\system32\IME\IMEJP10\IMJPTIP.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:261242112 c:\windows\system32\IME\IMEJP10\IMJPTIP.DLL
    + 2011-07-01 01:40 . 2010-11-20 13:261244160 c:\windows\system32\imapi2fs.dll
    - 2009-07-14 00:01 . 2009-07-14 01:411244160 c:\windows\system32\imapi2fs.dll
    + 2012-08-16 07:06 . 2012-06-29 03:422144768 c:\windows\system32\iertutil.dll
    + 2011-07-01 01:39 . 2010-11-20 13:262746880 c:\windows\system32\gameux.dll
    + 2011-03-08 20:50 . 2011-02-19 12:051139200 c:\windows\system32\FntCache.dll
    + 2011-07-01 01:40 . 2010-11-20 13:261866240 c:\windows\system32\ExplorerFrame.dll
    + 2011-04-27 22:11 . 2011-03-11 06:332565632 c:\windows\system32\esent.dll
    - 2009-07-14 00:22 . 2009-07-14 01:401457664 c:\windows\system32\DxpTaskSync.dll
    + 2011-07-01 01:39 . 2010-11-20 13:261457664 c:\windows\system32\DxpTaskSync.dll
    + 2012-05-09 21:29 . 2012-03-03 06:351544704 c:\windows\system32\DWrite.dll
    + 2011-07-01 01:40 . 2010-11-20 13:261632256 c:\windows\system32\dwmcore.dll
    + 2011-05-10 12:06 . 2011-05-10 12:064517664 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_f9d62789100b9e9b\usbaaplrc.dll
    + 2011-07-01 01:38 . 2010-11-20 13:086566400 c:\windows\system32\DriverStore\FileRepository\prnms002.inf_amd64_neutral_d834e48846616289\Amd64\FXSRES.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:271576448 c:\windows\system32\DriverStore\FileRepository\ntprint.inf_amd64_neutral_4616c3de1949be6d\Amd64\XPSSVCS.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:091058304 c:\windows\system32\DriverStore\FileRepository\ntprint.inf_amd64_neutral_4616c3de1949be6d\Amd64\PCL5URES.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:091057792 c:\windows\system32\DriverStore\FileRepository\ntprint.inf_amd64_neutral_4616c3de1949be6d\Amd64\PCL5ERES.DLL
    + 2011-04-08 18:59 . 2011-04-08 18:591721576 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_dc2cbd989eec1514\wdfcoinstaller01009.dll
    + 2009-07-13 21:59 . 2009-07-14 01:404772352 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumdva.dll
    + 2009-07-13 21:59 . 2009-07-14 01:404030976 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumdag.dll
    + 2009-07-13 21:59 . 2009-07-14 01:404763136 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumd6a.dll
    + 2009-06-10 20:36 . 2009-07-14 01:405492736 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumd64.dll
    + 2009-07-13 21:59 . 2009-07-13 21:595020672 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atikmdag.sys
    + 2009-07-13 21:59 . 2009-07-14 01:403115008 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atidxx64.dll
    + 2009-07-13 21:59 . 2009-07-14 01:402342400 c:\windows\system32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atidxx32.dll
    + 2012-05-09 21:29 . 2012-03-30 11:351918320 c:\windows\system32\drivers\tcpip.sys
    + 2011-04-27 22:11 . 2011-03-11 06:411659776 c:\windows\system32\drivers\ntfs.sys
    - 2009-07-13 23:56 . 2009-07-14 01:401066496 c:\windows\system32\Display.dll
    + 2011-07-01 01:39 . 2010-11-20 13:261066496 c:\windows\system32\Display.dll
    + 2011-07-01 01:40 . 2010-11-20 13:261340416 c:\windows\system32\diagperf.dll
    + 2011-07-01 01:39 . 2010-11-20 13:261202176 c:\windows\system32\DiagCpl.dll
    - 2009-07-13 23:31 . 2009-07-14 01:401202176 c:\windows\system32\DiagCpl.dll
    - 2010-06-24 14:34 . 2009-11-25 16:471942856 c:\windows\system32\dfshim.dll
    + 2011-07-01 01:41 . 2010-11-05 01:571942856 c:\windows\system32\dfshim.dll
    + 2011-07-01 01:38 . 2010-11-20 13:261087488 c:\windows\system32\dbghelp.dll
    - 2009-07-14 00:13 . 2009-07-14 01:401087488 c:\windows\system32\dbghelp.dll
    + 2011-07-01 01:40 . 2010-11-20 13:263391488 c:\windows\system32\dbgeng.dll
    + 2011-07-01 01:40 . 2010-11-20 13:262067456 c:\windows\system32\d3d9.dll
    + 2011-07-01 01:41 . 2010-11-20 13:261838080 c:\windows\system32\d3d10warp.dll
    + 2011-07-01 01:39 . 2010-11-20 13:251065984 c:\windows\system32\cryptui.dll
    - 2009-07-13 23:49 . 2009-07-14 01:401065984 c:\windows\system32\cryptui.dll
    + 2012-06-14 15:21 . 2012-04-24 05:371462272 c:\windows\system32\crypt32.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251796096 c:\windows\system32\certmgr.dll
    - 2010-01-08 16:53 . 2009-09-03 07:361975296 c:\windows\system32\CertEnroll.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251975296 c:\windows\system32\CertEnroll.dll
    + 2011-07-01 01:39 . 2010-11-20 13:322217856 c:\windows\system32\bootres.dll
    + 2011-07-01 01:40 . 2010-11-20 13:251927680 c:\windows\system32\authui.dll
    + 2011-07-01 01:40 . 2010-11-20 13:395066752 c:\windows\system32\AuthFWSnapin.dll
    + 2011-07-01 01:39 . 2010-11-20 13:253745792 c:\windows\system32\accessibilitycpl.dll
    - 2009-07-14 00:34 . 2009-07-14 01:403745792 c:\windows\system32\accessibilitycpl.dll
    + 2009-07-14 04:45 . 2012-08-29 14:327568600 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2011-09-08 00:30 . 2012-06-16 16:381220812 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-816525379-3359804378-3665389369-1003-12288.dat
    + 2012-01-19 17:08 . 2012-01-19 17:081369872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
    + 2012-01-19 17:08 . 2012-01-19 17:086429992 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
    + 2012-01-19 17:52 . 2012-01-19 17:523825952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
    + 2012-03-15 17:17 . 2012-03-15 17:175029672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll
    + 2011-12-15 17:08 . 2011-12-15 17:083512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
    + 2011-12-15 18:01 . 2011-12-15 18:014970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
    + 2011-12-15 18:01 . 2011-12-15 18:011455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
    + 2011-12-15 18:01 . 2011-12-15 18:011515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
    + 2011-12-15 18:01 . 2011-12-15 18:011512712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
    + 2011-12-15 18:01 . 2011-12-15 18:019793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
    + 2011-07-01 01:40 . 2010-11-05 01:532361160 c:\windows\Microsoft.NET\Framework64\v3.5\vbc.exe
    + 2011-07-01 01:39 . 2010-11-05 01:532287432 c:\windows\Microsoft.NET\Framework64\v3.5\csc.exe
    - 2009-07-13 20:54 . 2009-06-10 20:312287432 c:\windows\Microsoft.NET\Framework64\v3.5\csc.exe
    + 2012-05-09 21:29 . 2012-02-10 23:292256152 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll
    + 2011-07-01 01:41 . 2010-11-05 01:525328896 c:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.dll
    + 2011-07-01 01:40 . 2010-11-05 01:571800520 c:\windows\Microsoft.NET\Framework64\v2.0.50727\vbc.exe
    - 2009-07-13 20:37 . 2009-06-10 20:402048000 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.XML.dll
    + 2011-07-01 01:40 . 2010-11-05 01:572048000 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.XML.dll
    - 2011-06-29 03:39 . 2011-03-29 22:265025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
    + 2012-06-14 15:21 . 2012-03-21 22:305025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll
    + 2012-01-11 14:33 . 2011-12-25 20:405263360 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
    + 2012-05-09 21:29 . 2012-01-04 03:343190784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
    - 2009-07-13 20:37 . 2009-06-10 20:404927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
    + 2012-06-14 15:21 . 2012-03-21 22:304927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll
    + 2011-07-01 01:40 . 2010-11-05 01:563095552 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Data.dll
    + 2012-05-09 21:29 . 2012-01-04 03:349992464 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
    + 2012-05-09 21:29 . 2012-01-04 03:344567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    - 2011-06-29 03:39 . 2011-03-29 22:264567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    + 2012-05-09 21:29 . 2012-01-04 03:341577232 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
    + 2012-05-09 21:29 . 2012-01-04 03:341756432 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
    + 2011-07-01 01:40 . 2010-11-05 01:561983304 c:\windows\Microsoft.NET\Framework64\v2.0.50727\cscomp.dll
    + 2012-01-19 17:08 . 2012-01-19 17:081369872 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
    + 2012-01-19 17:08 . 2012-01-19 17:086429992 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
    + 2012-01-19 17:08 . 2012-01-19 17:083790112 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
    + 2012-03-15 17:17 . 2012-03-15 17:175029672 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
    + 2011-12-15 17:08 . 2011-12-15 17:083512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
    + 2011-12-15 17:08 . 2011-12-15 17:085201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    + 2011-12-15 17:08 . 2011-12-15 17:081143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
    + 2011-12-15 17:08 . 2011-12-15 17:086727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
    + 2011-07-01 01:39 . 2010-11-05 01:531717576 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
    + 2011-07-01 01:39 . 2010-11-05 01:531545032 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
    + 2012-05-09 21:29 . 2012-02-10 23:311737496 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
    + 2011-07-01 01:41 . 2010-11-05 01:525988352 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
    + 2011-07-01 01:39 . 2010-11-05 01:581340752 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
    - 2009-07-13 20:46 . 2009-06-10 21:231169224 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
    + 2011-07-01 01:40 . 2010-11-05 01:581169224 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
    + 2011-07-01 01:40 . 2010-11-05 01:582048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
    - 2009-07-13 20:46 . 2009-06-10 21:232048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
    - 2011-06-29 03:39 . 2011-03-29 22:315025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
    + 2012-06-14 15:21 . 2012-03-21 22:325025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
    + 2012-01-11 14:33 . 2011-12-25 20:425255168 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    + 2012-05-09 21:29 . 2012-01-04 02:513190784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    - 2009-07-13 20:46 . 2009-06-10 21:234927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
    + 2012-06-14 15:21 . 2012-03-21 22:324927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
    + 2011-07-01 01:40 . 2010-11-05 01:582927616 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
    + 2012-05-09 21:29 . 2012-01-04 02:515925136 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2011-06-29 03:39 . 2011-03-29 22:314550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2012-05-09 21:29 . 2012-01-04 02:504550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-07-01 01:40 . 2010-11-05 01:571160008 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
    + 2012-06-16 15:41 . 2012-06-16 15:411369872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    + 2012-06-16 15:40 . 2012-06-16 15:403512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    + 2012-06-16 15:40 . 2012-06-16 15:402207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    - 2011-09-18 15:00 . 2011-09-18 15:002207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    + 2012-06-16 15:40 . 2012-06-16 15:405029672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-06-16 15:40 . 2012-06-16 15:401711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    - 2011-09-18 15:00 . 2011-09-18 15:001711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    + 2012-06-16 15:40 . 2012-06-16 15:406097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
  3. person15

    person15 TS Rookie Topic Starter Posts: 55

    - 2011-09-18 15:00 . 2011-09-18 15:006097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    + 2012-06-16 15:40 . 2012-06-16 15:401026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-09-18 15:00 . 2011-09-18 15:001026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-09-18 15:00 . 2011-09-18 15:004464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2012-06-16 15:40 . 2012-06-16 15:404464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    - 2011-09-18 15:00 . 2011-09-18 15:001354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    + 2012-06-16 15:40 . 2012-06-16 15:401354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    - 2011-09-18 15:00 . 2011-09-18 15:001199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    + 2012-06-16 15:40 . 2012-06-16 15:401199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    - 2011-09-18 15:00 . 2011-09-18 15:001462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    + 2012-06-16 15:40 . 2012-06-16 15:401462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    + 2012-06-16 15:40 . 2012-06-16 15:406429992 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2012-06-16 15:40 . 2012-06-16 15:403116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-09-18 15:00 . 2011-09-18 15:003116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-06-16 15:40 . 2012-06-16 15:403825952 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-06-16 15:40 . 2012-06-16 15:404970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-06-16 15:40 . 2012-06-16 15:403563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-09-18 15:00 . 2011-09-18 15:003563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-09-18 15:00 . 2011-09-18 15:002975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-06-16 15:39 . 2012-06-16 15:392975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-06-16 15:40 . 2012-06-16 15:403790112 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-06-16 15:39 . 2012-06-16 15:395201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-06-16 15:39 . 2012-06-16 15:392989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-09-18 15:00 . 2011-09-18 15:002989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-07-21 16:34 . 2011-07-21 16:343456000 c:\windows\Installer\c6b6c83.msp
    + 2011-11-01 18:34 . 2011-11-01 18:344250112 c:\windows\Installer\b2c8e.msp
    + 2011-11-01 18:34 . 2011-11-01 18:342247168 c:\windows\Installer\b2c65.msp
    + 2011-11-11 21:14 . 2011-11-11 21:149096192 c:\windows\Installer\b2c3c.msp
    + 2011-11-01 18:34 . 2011-11-01 18:344225536 c:\windows\Installer\b2c13.msp
    + 2011-11-01 18:34 . 2011-11-01 18:342531840 c:\windows\Installer\b2be5.msp
    + 2012-04-23 14:32 . 2012-04-23 14:323460096 c:\windows\Installer\951fa09.msp
    + 2012-04-05 02:38 . 2012-04-05 02:382831360 c:\windows\Installer\951f9e1.msp
    + 2012-04-29 01:44 . 2012-04-29 01:449101824 c:\windows\Installer\951f9b8.msp
    + 2012-04-29 01:44 . 2012-04-29 01:449586176 c:\windows\Installer\951f98f.msp
    + 2012-04-30 18:38 . 2012-04-30 18:385011456 c:\windows\Installer\951f958.msp
    + 2012-04-05 02:38 . 2012-04-05 02:383620864 c:\windows\Installer\951f90c.msp
    + 2012-03-15 06:24 . 2012-03-15 06:241795584 c:\windows\Installer\951f8bd.msp
    + 2012-04-29 01:43 . 2012-04-29 01:438459264 c:\windows\Installer\951f894.msp
    + 2012-02-17 12:45 . 2012-02-17 12:452299392 c:\windows\Installer\951f86b.msp
    + 2012-03-15 17:12 . 2012-03-15 17:124968960 c:\windows\Installer\951f855.msp
    + 2012-03-15 17:11 . 2012-03-15 17:111989632 c:\windows\Installer\951f827.msp
    + 2012-05-17 06:58 . 2012-05-17 06:583462144 c:\windows\Installer\8cff66e.msp
    + 2012-05-30 11:17 . 2012-05-30 11:175010432 c:\windows\Installer\8cff646.msp
    + 2012-04-23 02:46 . 2012-04-23 02:461187328 c:\windows\Installer\8cff630.msp
    + 2012-03-15 18:26 . 2012-03-15 18:264212736 c:\windows\Installer\8cff627.msp
    + 2012-01-22 14:20 . 2012-01-22 14:201707520 c:\windows\Installer\896a0b79.msp
    + 2012-03-27 04:28 . 2012-03-27 04:285009920 c:\windows\Installer\896a0b5d.msp
    + 2012-03-23 18:59 . 2012-03-23 18:597899648 c:\windows\Installer\896a0b34.msp
    + 2011-11-01 17:34 . 2011-11-01 17:341169920 c:\windows\Installer\896a0b0c.msp
    + 2012-06-26 22:03 . 2012-06-26 22:033875840 c:\windows\Installer\89356877.msp
    + 2012-07-19 06:45 . 2012-07-19 06:453464704 c:\windows\Installer\89356854.msp
    + 2012-07-04 12:04 . 2012-07-04 12:041292288 c:\windows\Installer\89356816.msp
    + 2012-07-04 12:12 . 2012-07-04 12:124772352 c:\windows\Installer\893567e4.msp
    + 2012-07-04 12:09 . 2012-07-04 12:091284096 c:\windows\Installer\893567cd.msp
    + 2012-07-04 12:01 . 2012-07-04 12:019082368 c:\windows\Installer\893567b7.msp
    + 2012-07-04 11:58 . 2012-07-04 11:586163456 c:\windows\Installer\89356799.msp
    + 2012-07-18 19:53 . 2012-07-18 19:535009920 c:\windows\Installer\89356747.msp
    + 2006-12-02 11:09 . 2006-12-02 11:092818048 c:\windows\Installer\7d08ae.msi
    + 2012-05-30 11:18 . 2012-05-30 11:181739264 c:\windows\Installer\7396ec1e.msp
    + 2012-06-19 16:54 . 2012-06-19 16:542239488 c:\windows\Installer\7396ec02.msp
    + 2012-06-19 16:54 . 2012-06-19 16:545009920 c:\windows\Installer\7396ebd9.msp
    + 2012-06-20 05:29 . 2012-06-20 05:295262848 c:\windows\Installer\7396ebc2.msp
    + 2012-06-20 06:00 . 2012-06-20 06:003461120 c:\windows\Installer\7396eba9.msp
    + 2012-04-05 05:56 . 2012-04-05 05:562820096 c:\windows\Installer\7396eb93.msp
    + 2012-04-05 02:37 . 2012-04-05 02:372540544 c:\windows\Installer\7396eb6b.msp
    + 2012-06-20 06:06 . 2012-06-20 06:061839104 c:\windows\Installer\7396eb46.msp
    + 2012-04-05 02:37 . 2012-04-05 02:373149824 c:\windows\Installer\7396eb30.msp
    + 2011-12-26 11:24 . 2011-12-26 11:248835072 c:\windows\Installer\6d09f8fd.msp
    + 2011-12-09 00:24 . 2011-12-09 00:244989952 c:\windows\Installer\6d09f8e1.msp
    + 2011-11-05 15:15 . 2011-11-05 15:152682368 c:\windows\Installer\670619dd.msi
    + 2011-11-02 19:50 . 2011-11-02 19:501412096 c:\windows\Installer\588bdaa7.msi
    + 2011-10-26 21:36 . 2011-10-26 21:362829312 c:\windows\Installer\56d8fb16.msp
    + 2012-02-03 20:13 . 2012-02-03 20:134988928 c:\windows\Installer\56d8faef.msp
    + 2012-08-17 21:23 . 2012-08-17 21:237945216 c:\windows\Installer\46da9b3.msi
    + 2012-06-15 15:25 . 2012-06-15 15:251567744 c:\windows\Installer\39fdadf.msi
    + 2011-10-21 20:28 . 2011-10-21 20:284771840 c:\windows\Installer\2856b4c2.msi
    + 2011-09-15 22:40 . 2011-09-15 22:407959552 c:\windows\Installer\27b4c36f.msp
    + 2011-09-15 22:34 . 2011-09-15 22:348499712 c:\windows\Installer\27b4c34e.msp
    + 2011-09-15 22:35 . 2011-09-15 22:351411072 c:\windows\Installer\27b4c0f2.msp
    + 2012-03-01 03:45 . 2012-03-01 03:454989440 c:\windows\Installer\27b4c0d4.msp
    + 2011-06-12 12:47 . 2011-06-12 12:473994624 c:\windows\Installer\23fef2b4.msp
    + 2011-06-12 12:47 . 2011-06-12 12:473459584 c:\windows\Installer\23fef2a5.msp
    + 2011-06-12 12:47 . 2011-06-12 12:472426880 c:\windows\Installer\23fef18f.msp
    + 2012-04-21 23:40 . 2012-04-21 23:403025408 c:\windows\Installer\23fef053.msi
    + 2012-04-21 23:39 . 2012-04-21 23:391819648 c:\windows\Installer\23fef04a.msi
    + 2012-04-21 23:39 . 2012-04-21 23:391810944 c:\windows\Installer\23fef024.msi
    + 2012-04-21 23:39 . 2012-04-21 23:391813504 c:\windows\Installer\23fef018.msi
    + 2012-04-21 23:39 . 2012-04-21 23:391800704 c:\windows\Installer\23fef011.msi
    + 2012-04-21 23:39 . 2012-04-21 23:392115584 c:\windows\Installer\23feefe6.msi
    + 2012-04-21 23:39 . 2012-04-21 23:391802240 c:\windows\Installer\23feefe0.msi
    + 2012-04-21 23:38 . 2012-04-21 23:381800704 c:\windows\Installer\23feefd9.msi
    + 2012-04-21 23:38 . 2012-04-21 23:382863104 c:\windows\Installer\23feefcb.msi
    + 2011-11-11 21:15 . 2011-11-11 21:151795584 c:\windows\Installer\22e77a15.msp
    + 2011-11-11 21:16 . 2011-11-11 21:168458240 c:\windows\Installer\22e779ec.msp
    + 2011-11-18 22:52 . 2011-11-18 22:529183232 c:\windows\Installer\1b246790.msp
    + 2012-01-05 10:21 . 2012-01-05 10:214964864 c:\windows\Installer\1b246761.msp
    + 2012-03-07 19:01 . 2012-03-07 19:011907712 c:\windows\Installer\1b246743.msp
    + 2011-10-16 18:28 . 2011-10-16 18:281138688 c:\windows\Installer\1b2466f3.msp
    + 2011-07-21 16:45 . 2011-07-21 16:453809792 c:\windows\Installer\1b2466d5.msp
    + 2011-10-27 03:23 . 2011-10-27 03:238821760 c:\windows\Installer\1b2466bf.msp
    + 2012-04-01 20:27 . 2012-04-01 20:273463168 c:\windows\Installer\1b2466a0.msp
    + 2011-07-21 16:41 . 2011-07-21 16:418413696 c:\windows\Installer\1b24668a.msp
    + 2012-02-17 07:50 . 2012-02-17 07:501236480 c:\windows\Installer\1b246674.msp
    + 2011-10-27 02:46 . 2011-10-27 02:461833472 c:\windows\Installer\1b24661c.msp
    + 2012-03-21 09:57 . 2012-03-21 09:571591808 c:\windows\Installer\1b2465cf.msp
    + 2012-03-27 15:47 . 2012-03-27 15:474959232 c:\windows\Installer\16a3eda.msp
    + 2012-07-31 16:18 . 2012-07-31 16:185018624 c:\windows\Installer\16a3ed9.msp
    + 2012-01-04 07:05 . 2012-01-04 07:053979776 c:\windows\Installer\16a3dfd.msi
    + 2011-09-21 20:18 . 2011-09-21 20:184985856 c:\windows\Installer\12c7c5b5.msp
    + 2011-01-12 21:01 . 2011-01-12 21:016255616 c:\windows\Installer\1116d9.msi
    - 2010-01-04 20:07 . 2011-09-16 15:421172240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
    + 2010-01-04 20:07 . 2012-08-16 07:101172240 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-01-04 20:07 . 2011-09-16 15:421165584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
    + 2010-01-04 20:07 . 2012-08-16 07:101165584 c:\windows\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
    + 2012-04-21 23:43 . 2012-08-16 07:081479520 c:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\xlicons.exe
    + 2012-04-21 23:43 . 2012-08-16 07:081858400 c:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe
    + 2012-04-21 23:43 . 2012-08-16 07:084525408 c:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\promoicon.exe
    + 2012-04-21 23:43 . 2012-08-16 07:083792736 c:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\pptico.exe
    + 2012-04-21 23:43 . 2012-08-16 07:081449312 c:\windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\accicons.exe
    + 2010-01-06 17:36 . 2012-08-16 07:091172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-01-06 17:36 . 2011-09-16 15:411172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-01-06 17:36 . 2011-09-16 15:411165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    + 2010-01-06 17:36 . 2012-08-16 07:091165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    + 2012-01-03 12:18 . 2012-01-03 12:182405784 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0500000010\9.5.0\rt3d.dll
    + 2011-11-17 20:50 . 2011-11-17 20:506543872 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0500000010\9.5.0\authplay.dll
    + 2011-01-31 01:16 . 2011-01-31 01:165713408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0500000010\9.5.0\AGM.dll
    + 2010-10-20 17:35 . 2010-10-20 17:351479520 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\XLICONS.EXE
    + 2011-02-04 17:41 . 2011-02-04 17:412672456 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\VBE7.DLL
    + 2010-10-20 17:35 . 2010-10-20 17:353792736 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\PPTICO.EXE
    + 2011-04-07 01:09 . 2011-04-07 01:099701736 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\PPCORE.DLL
    + 2010-10-22 18:55 . 2010-10-22 18:552162024 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\POWERPNT.EXE
    + 2011-03-19 02:59 . 2011-03-19 02:599221992 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\ONMAIN.DLL
    + 2011-03-03 00:21 . 2011-03-03 00:211683808 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\ONENOTE.EXE
    + 2010-10-22 21:12 . 2010-10-22 21:125496688 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\IPEDITOR.DLL
    + 2011-03-17 05:22 . 2011-03-17 05:224301184 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\GRAPH.EXE
    + 2010-10-22 22:55 . 2010-10-22 22:553049376 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\ACEWDAT.DLL
    + 2011-03-11 21:46 . 2011-03-11 21:462194312 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\ACECORE.DLL
    + 2010-03-25 00:28 . 2010-03-25 00:281479520 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\XLICONS.EXE
    + 2010-03-27 12:45 . 2010-03-27 12:455460312 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\WRD12CNV.DLL
    + 2010-03-25 00:28 . 2010-03-25 00:281858400 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\WORDICON.EXE
    + 2010-02-18 01:56 . 2010-02-18 01:561199008 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\WKCONV.EXE
    + 2010-03-27 12:38 . 2010-03-27 12:381422168 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\WINWORD.EXE
    + 2010-02-25 15:07 . 2010-02-25 15:072672456 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\VBE7.DLL
    + 2010-03-01 09:07 . 2010-03-01 09:072831768 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\STSLIST.DLL
    + 2010-03-11 04:44 . 2010-03-11 04:441100664 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\SETUP.EXE
    + 2010-02-28 06:14 . 2010-02-28 06:144520288 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\PROMO.EXE
    + 2010-03-25 00:28 . 2010-03-25 00:283792736 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\PPTICO.EXE
    + 2010-03-09 13:57 . 2010-03-09 13:579696616 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\PPCORE.DLL
    + 2010-03-09 13:57 . 2010-03-09 13:572162024 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\POWERPNT.EXE
    + 2009-07-23 14:01 . 2009-07-23 14:013670016 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OUTLFLTR.DAT
    + 2010-03-11 04:44 . 2010-03-11 04:445789544 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OSETUP.DLL
    + 2010-03-30 12:29 . 2010-03-30 12:299182056 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ONMAIN.DLL
    + 2010-03-30 12:29 . 2010-03-30 12:291177968 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ONFILTER.DLL
    + 2010-03-30 12:29 . 2010-03-30 12:291676128 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ONENOTE.EXE
    + 2010-01-10 01:24 . 2010-01-10 01:243483000 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OIMG.DLL
    + 2010-02-28 06:19 . 2010-02-28 06:197277440 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OFFOWC.DLL
    + 2010-03-30 12:36 . 2010-03-30 12:365496688 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\IPEDITOR.DLL
    + 2010-03-13 02:45 . 2010-03-13 02:454299648 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\GRAPH.EXE
    + 2010-03-01 09:20 . 2010-03-01 09:202323840 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\GKWORD.DLL
    + 2010-03-01 09:20 . 2010-03-01 09:202102656 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\GKPOWERPOINT.DLL
    + 2010-03-01 09:20 . 2010-03-01 09:203355008 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\GKEXCEL.DLL
    + 2010-03-01 09:08 . 2010-03-01 09:081746280 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\GFX.DLL
    + 2010-02-20 21:20 . 2010-02-20 21:201207144 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\FM20.DLL
    + 2010-01-19 00:59 . 2010-01-19 00:592182040 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ASSAPIFE.DLL
    + 2010-03-23 14:55 . 2010-03-23 14:553049376 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ACEWDAT.DLL
    + 2010-03-23 14:55 . 2010-03-23 14:552193800 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\ACECORE.DLL
    + 2011-01-14 11:10 . 2011-01-14 11:102395008 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD.DLL
    + 2011-01-14 11:10 . 2011-01-14 11:102180992 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKPOWERPOINT.DLL
    + 2011-01-14 11:10 . 2011-01-14 11:103443072 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL.DLL
    + 2011-08-17 13:49 . 2011-08-17 13:494683624 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2011-07-20 12:12 . 2011-07-20 12:123750776 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\VVIEWER.DLL
    + 2011-06-29 11:02 . 2011-06-29 11:021846656 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\VVIEWDWG.DLL
    + 2009-10-10 03:10 . 2009-10-10 03:102594632 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-07-27 22:15 . 2011-07-27 22:152335648 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\STSLIST.DLL
    + 2011-07-27 08:59 . 2011-07-27 08:596540136 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OSETUP.DLL
    + 2011-07-27 08:55 . 2011-07-27 08:553004800 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OLMAPI32.DLL
    + 2011-07-07 06:58 . 2011-07-07 06:581616240 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-07-27 09:51 . 2011-07-27 09:517040896 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OFFOWC.DLL
    + 2011-08-03 04:14 . 2011-08-03 04:148579448 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2011-07-20 09:31 . 2011-07-20 09:311523632 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\NLSD0000.DLL
    + 2011-05-26 23:28 . 2011-05-26 23:286637952 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\MSORES.DLL
    + 2011-07-27 08:40 . 2011-07-27 08:409894768 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\MSACCESS.EXE
    + 2011-07-27 09:09 . 2011-07-27 09:095310848 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
    + 2011-06-22 12:16 . 2011-06-22 12:161681784 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\FPSRVUTL.DLL
    + 2011-07-07 06:28 . 2011-07-07 06:281193320 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\FM20.DLL
    + 2011-08-03 22:27 . 2011-08-03 22:271415072 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\ACECORE.DLL
    + 2011-08-17 13:49 . 2011-08-17 13:494683624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2009-10-10 03:10 . 2009-10-10 03:102594632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-07-27 08:55 . 2011-07-27 08:553004800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OLMAPI32.DLL
    + 2011-07-07 06:58 . 2011-07-07 06:581616240 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-07-27 09:09 . 2011-07-27 09:095310848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
    + 2011-07-27 09:09 . 2011-07-27 09:095484416 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPDESIGN.DLL
    + 2011-07-27 09:09 . 2011-07-27 09:091460088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\INFOPATH.EXE
    + 2006-10-27 01:25 . 2006-10-27 01:252172688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
    + 2011-04-27 22:12 . 2011-02-25 06:192871808 c:\windows\explorer.exe
    - 2010-10-27 13:43 . 2010-08-04 06:161551872 c:\windows\ehome\wow\ehuihlp.dll
    + 2011-07-01 01:39 . 2010-11-20 12:181551872 c:\windows\ehome\wow\ehuihlp.dll
    + 2011-07-01 01:38 . 2010-11-20 12:352596864 c:\windows\ehome\Microsoft.MediaCenter.UI.dll
    - 2009-07-13 22:35 . 2009-07-14 01:262596864 c:\windows\ehome\Microsoft.MediaCenter.UI.dll
    - 2009-07-13 22:35 . 2009-07-14 01:231572864 c:\windows\ehome\Microsoft.MediaCenter.Shell.dll
    + 2011-07-01 01:38 . 2010-11-20 12:351572864 c:\windows\ehome\Microsoft.MediaCenter.Shell.dll
    + 2011-07-01 01:40 . 2010-11-20 13:262613248 c:\windows\ehome\Mcx2Filter.dll
    - 2010-10-27 13:43 . 2010-08-04 07:071668608 c:\windows\ehome\ehuihlp.dll
    + 2011-07-01 01:39 . 2010-11-20 13:261668608 c:\windows\ehome\ehuihlp.dll
    + 2011-07-01 01:39 . 2010-11-20 13:261195520 c:\windows\ehome\ehui.dll
    - 2009-07-14 00:26 . 2009-07-14 01:401195520 c:\windows\ehome\ehui.dll
    - 2010-10-27 13:43 . 2010-08-04 06:286307840 c:\windows\ehome\ehshell.dll
    + 2011-07-01 01:40 . 2010-11-20 12:326307840 c:\windows\ehome\ehshell.dll
    - 2009-07-13 23:20 . 2009-07-13 23:201474560 c:\windows\Boot\DVD\EFI\en-US\efisys.bin
    + 2011-07-01 01:40 . 2010-11-20 09:191474560 c:\windows\Boot\DVD\EFI\en-US\efisys.bin
    + 2012-05-10 21:15 . 2012-05-10 21:155237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e41f5739292f4771c64a55940369efd2\WindowsBase.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:025237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e286701acf74012d3aa4a21953f03b6b\WindowsBase.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:191430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\6ee9d76d9f1e618cd6fb94b13355bcc9\UIAutomationClientsideProviders.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:157037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\28ca4f076264ab07f1d00a6c9623dc49\System.Xml.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:162449408 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\df013cbfec0defc7e9997cdaa90b89bc\System.Xaml.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:195645824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\9e50e3bca6cb19f9acab815d46f5e7e5\System.Windows.Forms.DataVisualization.ni.dll
    + 2012-06-16 17:04 . 2012-06-16 17:045645824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\950f64ba9fb22ca06c5b2b9cf6f5f4b4\System.Windows.Forms.DataVisualization.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:192236416 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bc6df78c506c89659ab7be738179b2ba\System.Web.Services.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:192735616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\cd7c3aed4408c3554c30a8f0236b90e1\System.Speech.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:191918976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\94289b88c5b494f572cd7114fa995487\System.ServiceModel.Activities.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:191579008 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\2dbc7aabd92cc0d470acb455c498d919\System.ServiceModel.Discovery.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:163412992 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\affb28e2d9cc3c19de0758e7e8c68e8f\System.Runtime.Serialization.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:161348096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\b37e6f4b1d742031f328504eb99d0f6c\System.Runtime.DurableInstancing.ni.dll
    + 2012-06-16 17:04 . 2012-06-16 17:041467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\d2de16284459454472a6875185c64d08\System.Printing.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:171467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\682ea473b36fc9043d982c4f5a667568\System.Printing.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:181470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\b83f2453b4538b2e80fe09cfd94dce00\System.Management.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:181416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\60bf6251873ef465abcebeb9a24b7932\System.IdentityModel.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:161098752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:162303488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\dadeee26c90fecbf3196eba10dc077b4\System.Drawing.ni.dll
    + 2012-06-16 17:03 . 2012-06-16 17:032305024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1225ef41527a975de83f22328d0a3b93\System.Drawing.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:181217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:171622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:172403328 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\f20144fba069563333d0f6be2e0b6e06\System.Deployment.ni.dll
    + 2012-06-16 17:03 . 2012-06-16 17:032403328 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\ad9ff5d55f7ea22e80c39e0ff0240984\System.Deployment.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:178601600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\0ec8effb7b9d03ae69d37922813bc880\System.Data.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:153390976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\0eb72df497fad5c273ff16f88b0fb950\System.Data.SqlXml.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:181799168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:183386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\86553c1d7f3e66c17fc3e0274de7a2de\System.Data.Linq.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151257472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\6aea67f24827961ce1d48356715389d8\System.Configuration.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:171007616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\eac19ca5a18a6d08cd247e68b618ba68\System.ComponentModel.Composition.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:175695488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\3869077874ba987242c791b3a18b2f8b\System.Activities.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:175048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\a7c19841c70fbce3b17ad3a46ee410d8\System.Activities.Presentation.ni.dll
    + 2012-06-16 17:04 . 2012-06-16 17:045048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\707f90689caf41ad429bf3ad373503cb\System.Activities.Presentation.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:172064896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\96083298999a677341c98fc2bf01b248\System.Activities.Core.Presentation.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:174233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\fe1704ff12348776e6b70dd4a2c69163\ReachFramework.ni.dll
    + 2012-06-16 17:04 . 2012-06-16 17:044233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\16c9569b75a9f47c38b60ba733936e1a\ReachFramework.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:162056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\b0b05b1ecbfb813474f685de13027585\PresentationUI.ni.dll
    + 2012-06-16 17:03 . 2012-06-16 17:032056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\9c3d6b3ddef66cac069b6ab1fec514f8\PresentationUI.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e4d308f69077903e24de92fe4fc06d29\Microsoft.VisualBasic.Compatibility.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\a36cd27bd492b55a5f443a4b4029f569\Microsoft.VisualBasic.Compatibility.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:152317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\93536d93a44ce7d5a60faf1aeb55f49e\Microsoft.VisualBasic.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:022317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\70e2694fe050bd480b9f61f935ca2da5\Microsoft.VisualBasic.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151623040 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\16425c121db8083cbaa51f619c9e51e7\Microsoft.VisualBasic.Activities.Compiler.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151526784 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\5284682fcf04815a86233bcaf696da66\Microsoft.Transactions.Bridge.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:152035200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\fdadaa0305b53d119f89db87f95ab11b\Microsoft.Office.Tools.Excel.Implementation.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021118208 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\aeea1da534996c8a86e581e5b3eb194e\Microsoft.Office.Tools.Common.Implementation.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151470464 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\97157c3a657cf4dc9e2ade2d87be86b6\Microsoft.Office.Tools.Word.Implementation.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021070080 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\8da91be67f85f2d15c39ff4857bf123e\Microsoft.Office.Tools.Word.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151118208 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\3d2a3ff0d1d3bb37731442f3b9514e45\Microsoft.Office.Tools.Common.Implementation.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021470464 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\3d0889d40c799c375e562fb90a0d692f\Microsoft.Office.Tools.Word.Implementation.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:151070080 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\2addc9e043f4007adc64e3a617c780e0\Microsoft.Office.Tools.Word.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:022035200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Office.To#\0cde2e5efef312f8bd908462713489fb\Microsoft.Office.Tools.Excel.Implementation.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:183313664 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\4b1d24a96b3882f9e77445e48a7c59ee\Microsoft.JScript.ni.dll
    + 2012-05-10 21:15 . 2012-05-10 21:152009600 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\1ff62486cdefbfc2dab41b686a9aa4e2\Microsoft.CSharp.ni.dll
    + 2012-06-16 15:41 . 2012-06-16 15:413858432 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:141063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\24ed0e1df6a605cdb2088f87ae2ab8ff\UIAutomationClientsideProviders.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:229091584 c:\windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:225617664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121782272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:594587008 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\7f0476e4df01ca2219f7db531408e91c\System.Windows.Forms.DataVisualization.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:141885696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\b37cc0aa41e7feaba9f290da4da91d71\System.Web.Services.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:142012160 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\f368c85283c4e6c9650dd1c8d369dcc5\System.Speech.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:141140736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ec057796972ce41b751eaa3a8306fbcb\System.ServiceModel.Discovery.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:141393152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\5055b60e339143bbace5871f5fe4b114\System.ServiceModel.Activities.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:122647040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\8a9fac9cb825b5d2db0bdb867fff940e\System.Runtime.Serialization.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121021952 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\79ac99fe5274fb82ffcff2c15f71854c\System.Runtime.DurableInstancing.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\f87f8bc0bc9563096150f23f6c220e7b\System.Printing.ni.dll
    + 2012-05-10 21:13 . 2012-05-10 21:131218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\0c2b0d52156447592f33edf4116b7e7d\System.Management.ni.dll
    + 2012-05-10 21:13 . 2012-05-10 21:131072640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\bd28f26b18b8ffeee1a0fbaa98f5810e\System.IdentityModel.ni.dll
    + 2012-06-16 15:41 . 2012-06-16 15:411666048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\0fe1e56d17858b6156a3a46330f75f27\System.DirectoryServices.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591880064 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\e899cda47704280f54949c69b78c55cc\System.Deployment.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:226815232 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\99d0f7ba920eea1117e45dcd9fec0eb5\System.Data.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:222550272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\fdb98c6d783fe167c1dc0022f27b7cd6\System.Data.SqlXml.ni.dll
    + 2012-05-10 21:13 . 2012-05-10 21:131343488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\b894a1df3e6d58ada8f1aa303465ca23\System.Data.Services.Client.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:222517504 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\82c0c56ff8259e1440cfd0d5727a26d8\System.Data.Linq.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:227069184 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:124129280 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\51025a1c89f6fd752a5396a059d608b2\System.Activities.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:593757568 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\36299fad6b7b591cfb6bd9e50dbd33df\System.Activities.Presentation.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121546752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\66893548d2b2cad29cabf3b3578f356f\System.Activities.Core.Presentation.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:592906624 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\442af6f7c8b447bdec3ad8d23da89c5a\ReachFramework.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591641984 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\cf455da9b8fedf66767c1a7ab3eea9c9\PresentationUI.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\42a7f127f3fda82fb12c6a6e144d08c1\Microsoft.VisualBasic.Activities.Compiler.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591139712 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2ed0173a2e75b1a3943bd2d96649a50c\Microsoft.VisualBasic.Compatibility.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591838080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\09c2f8f606e09d85cfe6e0ad89fbe729\Microsoft.VisualBasic.ni.dll
    + 2012-05-10 21:12 . 2012-05-10 21:121085952 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9a37f4e64ce5b856ac3892fef064c7de\Microsoft.Transactions.Bridge.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591117696 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\e3d6a53f4f0ff4c6846aa107166b74d7\Microsoft.Office.Tools.Word.Implementation.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591551872 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Office.To#\7cfb808ac13b9432c5b771d64ff37f8d\Microsoft.Office.Tools.Excel.Implementation.ni.dll
    + 2012-05-10 21:13 . 2012-05-10 21:132452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\cfcc92c125ddfaabad24abe61cfc0471\Microsoft.JScript.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:221616896 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\9912b6d76c1017b5af6ef24730f550ca\Microsoft.CSharp.ni.dll
    + 2012-05-11 00:11 . 2012-05-11 00:114962816 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\4bcc5a6e9e9d25e068fc304bd7eda6af\WindowsBase.ni.dll
    + 2012-05-11 16:18 . 2012-05-11 16:181459712 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\783df1ee260d3df406fa80afa38502d4\UIAutomationClientsideProviders.ni.dll
    + 2012-05-11 00:10 . 2012-05-11 00:106948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\24d1b7ccbedaa3602bae6a6acea9929e\System.Xml.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021818112 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\70cc5e8a5a3372fe0b104c1b20392cd2\System.WorkflowServices.ni.dll
  4. person15

    person15 TS Rookie Topic Starter Posts: 55

    + 2012-06-16 16:45 . 2012-06-16 16:452711040 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\aa638ba79250284eb4af4adaa4a4117b\System.Workflow.Runtime.ni.dll
    + 2012-06-16 16:45 . 2012-06-16 16:455957632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\996dc2af3b9e5c111130935f298908c6\System.Workflow.ComponentModel.ni.dll
    + 2012-06-16 16:45 . 2012-06-16 16:453895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\178797db84abae2eeaed835bd28ca52c\System.Workflow.Activities.ni.dll
    + 2012-06-16 16:45 . 2012-06-16 16:452292224 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\a32734087cd0db5607d5744ca63235d7\System.Web.Services.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:023336704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\af7689e8cbec5d2755497be23c30e293\System.Web.Mobile.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:013044352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\768ea257d75839979b4efb2d49d653f6\System.Web.Extensions.ni.dll
    + 2012-06-16 17:02 . 2012-06-16 17:021155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\2c47bc5d426a7cf9ffef1425eda08184\System.Web.Extensions.Design.ni.dll
    + 2012-05-11 16:10 . 2012-05-11 16:102727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\ca51f026916139f886519fdf6d6c73e9\System.Speech.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:092312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\56ee9b5f220583c1c7374a61ad904044\System.ServiceModel.Web.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:383073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\265531568722647aab229a2cec195b3d\System.Runtime.Serialization.ni.dll
    + 2012-05-11 00:12 . 2012-05-11 00:121022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\2a02b172fa4cf3d93ce7388b67b2a199\System.Runtime.Remoting.ni.dll
    + 2012-06-16 16:44 . 2012-06-16 16:441463808 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\b964519964d302b4977e1380d8d15f1a\System.Printing.ni.dll
    + 2012-05-11 16:07 . 2012-05-11 16:071472000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\fd4a8227569e64d657b80483da8ffe78\System.Management.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:381444352 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\d1f21a29e79e73b5401fae156f339f67\System.IdentityModel.ni.dll
    + 2012-05-11 00:12 . 2012-05-11 00:121081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:432318848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\222eb8aa336953a6b0216db2b0c4770d\System.Drawing.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:091230848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll
    + 2012-05-11 00:12 . 2012-05-11 00:121640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:432444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\6e4e9b07f376d445df1718c0011fa99b\System.Deployment.ni.dll
    + 2012-05-11 00:12 . 2012-05-11 00:128681472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\ea1848ec07c70f3d3c3445f4fbdae87a\System.Data.ni.dll
    + 2012-05-11 00:10 . 2012-05-11 00:103463680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\7f6f74f1cc0ea6c40a2d6707b12af818\System.Data.SqlXml.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:092805760 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:091868288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll
    + 2012-05-11 00:13 . 2012-05-11 00:131506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\97429a1c70c94c49850be3f944a32a2e\System.Data.OracleClient.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:093480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\2ec3d436b861d35c586b710a570e170d\System.Data.Linq.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:091080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7b5364bc524988f7ca5b8c20a24119d\System.Data.Entity.Design.ni.dll
    + 2012-05-11 15:37 . 2012-05-11 15:373315200 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\766ce7ee1a2e4f2a85fd90e7572f5d53\System.Core.ni.dll
    + 2012-05-11 00:10 . 2012-05-11 00:101308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\193d03ca60573c92f92d9b07fa5bc243\System.Configuration.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:011530368 c:\windows\assembly\NativeImages_v2.0.50727_64\SrpUxSnapIn\78d5f2d52e06f6ea47b359bf4ceb7b65\SrpUxSnapIn.ni.dll
    + 2012-06-16 16:44 . 2012-06-16 16:443116032 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\1f88a3693c8ddd527a130aff49dc58b3\ReachFramework.ni.dll
    + 2012-06-16 16:44 . 2012-06-16 16:442109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\b91c32fab08ba62d8c7681cc596895be\PresentationUI.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:091884160 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\4fbff79b8ebf082d08c0080923ff5036\PresentationBuildTasks.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:013601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\ac1ba76ed19d668ce53a74593f040453\Narrator.ni.exe
    + 2012-06-16 17:01 . 2012-06-16 17:012327552 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\df2557ab1b8e4389d846e13dc82eba57\MMCEx.ni.dll
    + 2012-06-16 17:00 . 2012-06-16 17:007970304 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\61812970c4743b686a67f28687e1dcb6\MIGUIControls.ni.dll
    + 2012-05-11 16:08 . 2012-05-11 16:081877504 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualStu#\1dcc7a3940f5e4be8da3dd0b66bc38c0\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\1586ee919f86130df9771cf9b8d95d3a\Microsoft.VisualBasic.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:381598976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\28ba52bc122353647f1b547506e2df7c\Microsoft.Transactions.Bridge.ni.dll
    + 2012-05-11 16:08 . 2012-05-11 16:081131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f5790625975320b1ffad63b476da9132\Microsoft.PowerShell.Commands.Management.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:015350912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ca7e936eed0de2436d87b2601ee3a20a\Microsoft.PowerShell.Editor.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012176512 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\6caa366471176a065a96d77e8ba01eeb\Microsoft.PowerShell.Commands.Utility.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\3040e2de07177c0a6a66a49de61fdc59\Microsoft.PowerShell.GPowerShell.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:011186304 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\91391297ea9428993774313f05e98dd2\Microsoft.Office.Tools.Word.v9.0.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:011875456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\6ecfa88a42ba7c5c3a4580cd479d0d21\Microsoft.Office.Tools.Excel.v9.0.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:011093632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.To#\0929a1a8f19d58cca0ff9bf5f9086dc1\Microsoft.Office.Tools.Common.v9.0.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:381170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c057be8bb6614cce013af3721fe34983\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll
    + 2012-06-16 17:00 . 2012-06-16 17:001516544 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b2afc0af3d89ae00e973b4e6e9db382c\Microsoft.MediaCenter.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:011508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\73bfbdccdc1b0ae87f70a0ec594fee3c\Microsoft.MediaCenter.Bml.ni.dll
    + 2012-06-16 17:00 . 2012-06-16 17:008979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\653e1ee01f10d658d52ca42e17e74283\Microsoft.MediaCenter.UI.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:381142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\260d83ee2128a3388051cf416d4450b0\Microsoft.MediaCenter.Shell.ni.dll
    + 2012-05-11 16:07 . 2012-05-11 16:073213312 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\094f6a515ca31504f96b4bad5848d692\Microsoft.JScript.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\dac69844e6333484159a4cf544190906\Microsoft.Ink.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:015054976 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.GroupPoli#\2dace3e1a3fbdd679501e1c7c868ac3e\Microsoft.GroupPolicy.Reporting.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\4b362e9e25c33e371f06403edec8849a\Microsoft.Build.Tasks.ni.dll
    + 2012-06-16 17:01 . 2012-06-16 17:012682880 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\33730d136a34d2f4e56a0322f49ee9b6\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2012-05-11 16:07 . 2012-05-11 16:071137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\f1a0df6a86ceb708c5e50338f12b77ba\Microsoft.Build.Engine.ni.dll
    + 2012-05-11 16:07 . 2012-05-11 16:072544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\6b727c7aa69ae3e04a869908bfbae696\Microsoft.Build.Engine.ni.dll
    + 2012-06-16 17:00 . 2012-06-16 17:002801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\cc4844e7242c1e35d145bf2439f944c5\mcstore.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:384088320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\596902addad034f4df2caf291b12d61d\mcepg.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:382184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\cdad46cd58389f53308b735e6f29ce1f\ehiVidCtl.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:381201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\0423915e377ec85d71ac216fafa77ab0\ehiProxy.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:572102272 c:\windows\assembly\NativeImages_v2.0.50727_32\Xceed.Grid\4a07f0412025b2a53bc72b889b0efc79\Xceed.Grid.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:571105408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b711e4f9c27aab65278296a924e29ee6\WindowsLive.Writer.ApplicationFramework.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:572002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\579e9f2d0d25b50996964b4976002535\WindowsLive.Writer.CoreServices.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:576394368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\15957be56fa7f94a83dd1b1d61341c71\WindowsLive.Writer.PostEditor.ni.dll
    + 2012-05-11 00:14 . 2012-05-11 00:143347968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
    + 2012-05-11 16:30 . 2012-05-11 16:301047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\3b452cde57280624e1085699fe8beb03\UIAutomationClientsideProviders.ni.dll
    + 2012-04-21 23:51 . 2012-04-21 23:512479104 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD6FC.tmp\Microsoft.Interop.eCRM.Excel.dll
    + 2012-04-21 23:48 . 2012-04-21 23:482831360 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPBAF4.tmp\Microsoft.BusinessSolutions.eCRM.Reports2.dll
    + 2012-06-16 16:47 . 2012-06-16 16:472359808 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA8CC.tmp\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.dll
    + 2012-05-11 00:14 . 2012-05-11 00:147967232 c:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
    + 2012-05-11 00:14 . 2012-05-11 00:145452800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c764ad83cd3287fc59a3dc02e08ad1ea\System.Xml.ni.dll
    + 2012-06-16 16:59 . 2012-06-16 16:591358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\e3e5aa45736b95804bf6bb7eca08a57b\System.WorkflowServices.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:431917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\88bfc62ac0195a8ae673c444a3339505\System.Workflow.Runtime.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:434516352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\cfb739be21092d5b8f7b4fde529e6aaa\System.Workflow.ComponentModel.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:432994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\a815fffab98375c1919df68b5b292725\System.Workflow.Activities.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:421840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\761fd1afc17f11bf6d49c3a7d16465ca\System.Web.Services.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:582209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4a90802e36dee6e10d9bf54832cbf549\System.Web.Mobile.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:582404352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c45efc7ec92c1da8e67eb597559ec39c\System.Web.Extensions.ni.dll
    + 2012-05-11 16:30 . 2012-05-11 16:301917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\83053c3eeb3255672d84c1ddc0ce8ef3\System.Speech.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:291707008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ed560b26f2f86b3f07b7f6d384f92275\System.ServiceModel.Web.ni.dll
    + 2012-05-11 16:27 . 2012-05-11 16:272347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\72a24b45e11d64eb2bc840aae9419ba5\System.Runtime.Serialization.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:421044480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\991dbe40be5b114ed705bb5b48e6b330\System.Printing.ni.dll
    + 2012-05-11 00:17 . 2012-05-11 00:171051136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
    + 2012-05-11 16:28 . 2012-05-11 16:288872960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
    + 2012-05-11 16:27 . 2012-05-11 16:271083392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2ce8210219c7123610072357358df470\System.IdentityModel.ni.dll
    + 2012-06-16 16:41 . 2012-06-16 16:411591808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
    + 2012-05-11 00:14 . 2012-05-11 00:141117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
    + 2012-06-16 16:41 . 2012-06-16 16:411806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll
    + 2012-05-11 00:14 . 2012-05-11 00:146611456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
    + 2012-05-11 00:14 . 2012-05-11 00:142508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\1e8aadc5b2e725e2370348a1ab6806c8\System.Data.SqlXml.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:292029568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:291378816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll
    + 2012-05-11 00:15 . 2012-05-11 00:151116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\0f4e07fb8b1b7e7133a98f478856f70c\System.Data.OracleClient.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:292516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2fe1658f05b0a96fe25c956a31d27b06\System.Data.Linq.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:299921536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\51a2589d5ee1c9c40fb6c56391570f9e\System.Data.Entity.ni.dll
    + 2012-05-11 00:16 . 2012-05-11 00:162297856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581351168 c:\windows\assembly\NativeImages_v2.0.50727_32\SrpUxSnapIn\0f05778da82962003762ac22f0ab4b91\SrpUxSnapIn.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:422157056 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87f73de6e080d37be93adfc7d5c31d7a\ReachFramework.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:421658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\163517c8a195fb48f7ef6ee17c585bdb\PresentationUI.ni.dll
    + 2012-05-11 16:29 . 2012-05-11 16:291451520 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b3f13707cbd5d48aabaa9ef5264c8a30\PresentationBuildTasks.ni.dll
    + 2012-05-11 00:17 . 2012-05-11 00:171017856 c:\windows\assembly\NativeImages_v2.0.50727_32\office\1062242d01650a5282324a3018e754d4\office.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:582623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\17add09c98fa34255142d42697db53df\Narrator.ni.exe
    + 2012-06-16 16:58 . 2012-06-16 16:581545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\21abde8efab609732b2ade3f05234e79\MMCEx.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:586438912 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\0e7da0df83f0619e3b0e0a7d7ee05fa3\MIGUIControls.ni.dll
    + 2012-05-11 16:28 . 2012-05-11 16:281300992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualStu#\0849dd848383994c63dc00278f64ddae\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.ni.dll
    + 2012-06-16 16:46 . 2012-06-16 16:461670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
    + 2012-05-11 16:28 . 2012-05-11 16:281093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cd9e47effec6549cdec61eb3aef99f7c\Microsoft.Transactions.Bridge.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\99ae5f32cd1dc3618659bc3c77f2b2a9\Microsoft.PowerShell.Commands.Utility.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581704960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\77b5496d214dd5034294b058c0bb0e8d\Microsoft.PowerShell.GPowerShell.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:583724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\72765e5fab12761eb6d3f58180fa34d7\Microsoft.PowerShell.Editor.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581354752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.To#\63513a219edd166209b039f0681f1d59\Microsoft.Office.Tools.Excel.v9.0.ni.dll
    + 2012-05-11 16:27 . 2012-05-11 16:272027008 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\a67991393b6a009f8e9f13d75771e90e\Microsoft.Office.Interop.Word.ni.dll
    + 2012-05-11 00:17 . 2012-05-11 00:172267136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\70b9f8843caa81aabae46a96f6a70518\Microsoft.Office.Interop.Outlook.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:586499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\8ce1d10f94b40f054017865757552f2d\Microsoft.MediaCenter.UI.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:571009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7fab1ec8f5ed6a55a8a73b2c590bd7cd\Microsoft.MediaCenter.ni.dll
    + 2012-05-11 00:17 . 2012-05-11 00:172335744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\e3d2577e00aef6bc9b3e235eb83634f3\Microsoft.JScript.ni.dll
    + 2012-06-16 16:46 . 2012-06-16 16:461040896 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.M#\fbc0feb4b206da7eb439ef53f83d2520\Microsoft.Interop.Mapi.Impl.ni.dll
    + 2012-05-11 16:27 . 2012-05-11 16:272479104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.e#\d9094e847c3c739b5587b44fe9105193\Microsoft.Interop.eCRM.Excel.ni.dll
    + 2012-05-11 00:17 . 2012-05-11 00:171486848 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Interop.e#\8ff672a9ee1d7f3a92f945965985fd29\Microsoft.Interop.eCRM.Word.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\4d381048e3b9c0914c0f72c6aa0a599d\Microsoft.Ink.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:584071424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.GroupPoli#\efbe64bfafaaaec44b5c0e487c0b2c4a\Microsoft.GroupPolicy.Reporting.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:572359808 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\fc24c56ae5186f831c704a74ad5b3a44\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.ni.dll
    + 2012-06-16 16:57 . 2012-06-16 16:572831360 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\45ac7a38ab29e011b7a0d9734c80d7c0\Microsoft.BusinessSolutions.eCRM.Reports2.ni.dll
    + 2012-06-16 16:46 . 2012-06-16 16:464466688 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.BusinessS#\3d024ca6b8586cf83a4256e9edbd9ccc\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3893fa9a19b52dee8b2cc424840d5d08\Microsoft.Build.Tasks.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:581970176 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\1d2250044b1ecff755e26ed12f6d27cb\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2012-05-11 16:28 . 2012-05-11 16:281888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6b66f52dbd8f87e53c3c9a1de7ca5bba\Microsoft.Build.Engine.ni.dll
    + 2012-06-16 16:58 . 2012-06-16 16:582035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\3a4e56a8d1075cf0af0619c383b3e592\mcstore.ni.dll
    + 2012-05-11 16:28 . 2012-05-11 16:283025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\69b8de21b08c3412422c5918399ed702\mcepg.ni.dll
    + 2012-06-16 16:46 . 2012-06-16 16:463826688 c:\windows\assembly\NativeImages_v2.0.50727_32\BusinessLayer\7b1f248e8753c27984bff4fc66a1e49e\BusinessLayer.ni.dll
    + 2012-06-16 16:46 . 2012-06-16 16:461526272 c:\windows\assembly\NativeImages_v2.0.50727_32\BCMRes\48ea8ca1ef0452ddbddbbe1ee0f633db\BCMRes.ni.dll
    + 2012-05-09 21:29 . 2012-02-10 23:311253376 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
    + 2012-05-09 21:29 . 2012-01-04 02:513190784 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2011-07-01 01:40 . 2010-11-05 01:582048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    - 2009-07-13 20:46 . 2009-06-10 21:232048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    + 2011-07-01 01:40 . 2010-11-05 01:531630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
    - 2009-07-14 00:36 . 2009-06-10 21:151630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
    + 2011-07-01 01:38 . 2010-11-05 01:531142784 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
    - 2009-07-14 00:36 . 2009-06-10 21:151142784 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
    - 2011-06-29 03:39 . 2011-03-29 22:315025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-06-14 15:21 . 2012-03-21 22:325025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-01-11 14:33 . 2011-12-25 20:421277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    - 2010-10-03 15:32 . 2010-09-23 22:311277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    + 2011-07-01 01:41 . 2010-11-05 01:525988352 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    + 2011-07-01 01:40 . 2010-11-20 13:443010560 c:\windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
    - 2009-07-13 21:37 . 2009-07-14 01:533010560 c:\windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
    + 2012-06-14 15:21 . 2012-03-21 22:324927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    - 2009-07-13 20:46 . 2009-06-10 21:234927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2011-07-01 01:40 . 2010-11-05 01:532879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
    - 2009-07-13 21:10 . 2009-06-10 21:142879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2011-07-01 01:40 . 2010-11-20 13:441048576 c:\windows\assembly\GAC_MSIL\SrpUxSnapIn\6.1.0.0__31bf3856ad364e35\SrpUxSnapIn.dll
    - 2009-07-13 21:42 . 2009-07-14 01:491048576 c:\windows\assembly\GAC_MSIL\SrpUxSnapIn\6.1.0.0__31bf3856ad364e35\SrpUxSnapIn.dll
    + 2012-05-09 21:29 . 2012-02-10 23:315283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2011-07-01 01:39 . 2010-11-20 13:441077248 c:\windows\assembly\GAC_MSIL\Narrator\6.1.0.0__31bf3856ad364e35\Narrator.exe
    - 2009-07-13 21:46 . 2009-07-14 01:273416064 c:\windows\assembly\GAC_MSIL\MiguiControls\1.0.0.0__31bf3856ad364e35\MIGUIControls.dll
    + 2011-07-01 01:40 . 2010-11-20 12:363416064 c:\windows\assembly\GAC_MSIL\MiguiControls\1.0.0.0__31bf3856ad364e35\MIGUIControls.dll
    + 2012-04-21 23:43 . 2012-04-21 23:431550200 c:\windows\assembly\GAC_MSIL\Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    + 2011-07-01 01:38 . 2010-11-20 12:352596864 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
    - 2009-07-13 22:35 . 2009-07-14 01:262596864 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
    + 2011-07-01 01:38 . 2010-11-20 12:351572864 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.Shell\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Shell.dll
    - 2009-07-13 22:35 . 2009-07-14 01:231572864 c:\windows\assembly\GAC_MSIL\Microsoft.MediaCenter.Shell\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Shell.dll
    + 2011-07-01 01:39 . 2010-11-20 12:351851392 c:\windows\assembly\GAC_MSIL\Microsoft.GroupPolicy.Reporting\2.0.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.Reporting.dll
    - 2009-07-13 21:53 . 2009-07-14 01:221851392 c:\windows\assembly\GAC_MSIL\Microsoft.GroupPolicy.Reporting\2.0.0.0__31bf3856ad364e35\Microsoft.GroupPolicy.Reporting.dll
    - 2010-10-27 13:43 . 2010-08-04 06:286307840 c:\windows\assembly\GAC_MSIL\ehshell\6.1.0.0__31bf3856ad364e35\ehshell.dll
    + 2011-07-01 01:40 . 2010-11-20 12:326307840 c:\windows\assembly\GAC_MSIL\ehshell\6.1.0.0__31bf3856ad364e35\ehshell.dll
    + 2012-01-11 14:33 . 2011-12-25 20:405263360 c:\windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2011-07-01 01:40 . 2010-11-05 01:563095552 c:\windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-05-09 21:29 . 2012-02-10 23:292256152 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
    + 2012-05-09 21:29 . 2012-02-10 23:293998208 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-05-09 21:29 . 2012-01-04 03:344567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-29 03:39 . 2011-03-29 22:264567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-01-11 14:33 . 2011-12-25 20:425255168 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2011-07-01 01:40 . 2010-11-05 01:582927616 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-05-09 21:29 . 2012-02-10 23:311737496 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
    + 2012-05-09 21:29 . 2012-02-10 23:314218880 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-05-09 21:29 . 2012-01-04 02:504550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-29 03:39 . 2011-03-29 22:314550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-03-17 06:01 . 2012-03-17 06:011279864 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    - 2009-07-13 23:27 . 2009-07-14 01:142175488 c:\windows\AppPatch\AcGenral.dll
    + 2011-07-01 01:39 . 2010-11-20 12:182175488 c:\windows\AppPatch\AcGenral.dll
    + 2011-07-01 01:38 . 2010-11-20 12:0812625408 c:\windows\SysWOW64\wmploc.DLL
    - 2010-10-13 14:42 . 2010-09-01 04:2312625408 c:\windows\SysWOW64\wmploc.DLL
    + 2011-07-01 01:40 . 2010-11-20 12:2111410432 c:\windows\SysWOW64\wmp.dll
    + 2012-07-11 15:19 . 2012-06-09 04:4112873728 c:\windows\SysWOW64\shell32.dll
    + 2012-08-16 07:06 . 2012-06-29 00:5212317184 c:\windows\SysWOW64\mshtml.dll
    - 2010-10-13 14:42 . 2010-09-01 05:1212625920 c:\windows\system32\wmploc.DLL
    + 2011-07-01 01:38 . 2010-11-20 13:1612625920 c:\windows\system32\wmploc.DLL
    + 2011-07-01 01:40 . 2010-11-20 13:2714633472 c:\windows\system32\wmp.dll
    + 2009-07-14 02:34 . 2012-08-16 07:2611010048 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
    + 2012-08-16 07:06 . 2012-06-29 04:5517809920 c:\windows\system32\mshtml.dll
    - 2009-07-13 23:33 . 2009-07-14 01:4110085888 c:\windows\system32\migwiz\wet.dll
    + 2011-07-01 01:39 . 2010-11-20 13:2610085888 c:\windows\system32\migwiz\wet.dll
    + 2012-08-22 17:31 . 2012-08-22 17:3112315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll
    + 2012-08-16 07:06 . 2012-06-29 04:0910925568 c:\windows\system32\ieframe.dll
    + 2012-08-16 07:27 . 2012-09-03 03:3912865856 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    + 2010-01-08 20:09 . 2012-09-03 03:3935896568 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-816525379-3359804378-3665389369-1003-8192.dat
    + 2011-03-21 20:57 . 2012-04-27 20:0564560896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-816525379-3359804378-3665389369-1003-4096.dat
    + 2012-01-19 18:20 . 2012-01-19 18:2011997696 c:\windows\Installer\951f978.msp
    + 2011-12-15 18:54 . 2011-12-15 18:5439732736 c:\windows\Installer\951f942.msp
    + 2012-03-15 17:09 . 2012-03-15 17:0917165312 c:\windows\Installer\951f8ed.msp
    + 2012-03-15 17:11 . 2012-03-15 17:1166812928 c:\windows\Installer\951f83e.msp
    + 2012-03-28 22:10 . 2012-03-28 22:1012098048 c:\windows\Installer\896a0af5.msp
    + 2012-07-17 14:17 . 2012-07-17 14:1722363136 c:\windows\Installer\89356860.msp
    + 2012-07-25 20:59 . 2012-07-25 20:5911032064 c:\windows\Installer\8935682c.msp
    + 2012-07-18 19:53 . 2012-07-18 19:5310937344 c:\windows\Installer\89356770.msp
    + 2012-05-30 11:18 . 2012-05-30 11:1811885056 c:\windows\Installer\7396ec4e.msp
    + 2011-11-05 15:24 . 2011-11-05 15:2426820096 c:\windows\Installer\6706271e.msi
    + 2012-02-18 16:51 . 2012-02-18 16:5144700672 c:\windows\Installer\5c13573a.msi
    + 2012-02-18 16:49 . 2012-02-18 16:4911081728 c:\windows\Installer\5c134b97.msi
    + 2012-02-18 16:48 . 2012-02-18 16:4820304896 c:\windows\Installer\5c134b6b.msi
    + 2012-07-23 20:02 . 2012-07-23 20:0212752896 c:\windows\Installer\42a21425.msi
    + 2012-05-21 14:50 . 2012-05-21 14:5053217792 c:\windows\Installer\2b68d650.msp
    + 2011-09-15 22:39 . 2011-09-15 22:3911163136 c:\windows\Installer\27b4c365.msp
    + 2011-09-15 22:38 . 2011-09-15 22:3810838528 c:\windows\Installer\27b4c359.msp
    + 2011-09-15 22:37 . 2011-09-15 22:3716691712 c:\windows\Installer\27b4c0fa.msp
    + 2011-09-15 22:37 . 2011-09-15 22:3734428416 c:\windows\Installer\27b4c0f3.msp
  5. person15

    person15 TS Rookie Topic Starter Posts: 55

    + 2011-06-12 12:47 . 2011-06-12 12:4713031936 c:\windows\Installer\23fef188.msp
    + 2011-06-12 12:47 . 2011-06-12 12:4711056128 c:\windows\Installer\23fef161.msp
    + 2011-06-12 12:47 . 2011-06-12 12:4716972800 c:\windows\Installer\23fef14e.msp
    + 2011-06-12 12:47 . 2011-06-12 12:4711155456 c:\windows\Installer\23fef139.msp
    + 2011-06-12 12:47 . 2011-06-12 12:4714467072 c:\windows\Installer\23fef100.msp
    + 2012-04-21 23:39 . 2012-04-21 23:3926604032 c:\windows\Installer\23fef0f8.msi
    + 2011-10-27 02:45 . 2011-10-27 02:4566426368 c:\windows\Installer\1b246778.msp
    + 2012-03-07 19:03 . 2012-03-07 19:0323710208 c:\windows\Installer\1b24673c.msp
    + 2011-07-21 16:36 . 2011-07-21 16:3666808320 c:\windows\Installer\1b24671e.msp
    + 2011-06-20 03:28 . 2011-06-20 03:2818457088 c:\windows\Installer\1b2466dd.msp
    + 2011-10-27 02:51 . 2011-10-27 02:5116885760 c:\windows\Installer\1b246639.msp
    + 2011-10-27 02:47 . 2011-10-27 02:4710328064 c:\windows\Installer\1b246606.msp
    + 2011-10-27 02:49 . 2011-10-27 02:4916245760 c:\windows\Installer\1b2465fc.msp
    + 2011-10-27 02:49 . 2011-10-27 02:4910427392 c:\windows\Installer\1b2465f4.msp
    + 2011-10-27 02:46 . 2011-10-27 02:4611580928 c:\windows\Installer\1b2465ec.msp
    + 2011-07-11 21:33 . 2011-07-11 21:3323254016 c:\windows\Installer\12c7c5db.msp
    + 2011-11-22 04:42 . 2011-11-22 04:4233189888 c:\windows\Installer\12a13ab8.msp
    + 2011-10-10 23:02 . 2011-10-10 23:0224069568 c:\windows\Installer\1116dd.msi
    + 2012-01-04 02:15 . 2012-01-04 02:1520559288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0500000010\9.5.0\AcroRd32.dll
    + 2011-03-18 09:55 . 2011-03-18 09:5517812320 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\XL12CNV.EXE
    + 2011-03-18 09:21 . 2011-03-18 09:2111128696 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\OARTCONV.DLL
    + 2011-03-19 03:01 . 2011-03-19 03:0120525416 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\OART.DLL
    + 2011-04-07 00:53 . 2011-04-07 00:5372521600 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\MSORES.DLL
    + 2011-03-19 03:10 . 2011-03-19 03:1020767072 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.6029\EXCEL.EXE
    + 2010-03-13 04:50 . 2010-03-13 04:5017800544 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\XL12CNV.EXE
    + 2010-03-27 12:38 . 2010-03-27 12:3819370840 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\WWLIB.DLL
    + 2010-03-13 04:05 . 2010-03-13 04:0511121528 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OARTCONV.DLL
    + 2010-03-13 19:08 . 2010-03-13 19:0820516712 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\OART.DLL
    + 2010-03-23 00:36 . 2010-03-23 00:3672521600 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\MSORES.DLL
    + 2010-03-13 18:53 . 2010-03-13 18:5320753760 c:\windows\Installer\$PatchCache$\Managed\00004109D30000000000000000F01FEC\14.0.4763\EXCEL.EXE
    + 2011-09-16 00:42 . 2011-09-16 00:4218115432 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\WWLIB.DLL
    + 2011-08-03 22:18 . 2011-08-03 22:1812997488 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OUTLOOK.EXE
    + 2011-08-17 14:01 . 2011-08-17 14:0116149352 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\OART.DLL
    + 2011-08-03 23:53 . 2011-08-03 23:5317324928 c:\windows\Installer\$PatchCache$\Managed\00002119130000000000000000F01FEC\12.0.6612\MSO.DLL
    + 2011-09-16 00:42 . 2011-09-16 00:4218115432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WWLIB.DLL
    + 2011-08-03 22:18 . 2011-08-03 22:1812997488 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLOOK.EXE
    + 2011-08-03 23:53 . 2011-08-03 23:5317324928 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSO.DLL
    + 2011-07-01 01:41 . 2010-11-20 13:2515697920 c:\windows\ehome\CreateDisc\SBEServer.exe
    - 2009-07-14 00:47 . 2009-07-14 01:3915697920 c:\windows\ehome\CreateDisc\SBEServer.exe
    + 2012-05-10 14:21 . 2012-05-10 14:2111880448 c:\windows\assembly\NativeImages_v4.0.30319_64\System\935aea6e7eae16674abdd96a68ec97af\System.ni.dll
    + 2012-06-16 17:04 . 2012-06-16 17:0417355264 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\e883d90a0210bf99ca88f3b4ade53a24\System.Windows.Forms.ni.dll
    + 2012-05-10 21:17 . 2012-05-10 21:1717353728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\401ebcc2dd54ce1e0d63a544f7ed7b8a\System.Windows.Forms.ni.dll
    + 2012-05-10 21:19 . 2012-05-10 21:1924551936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\c4cc7eb7733c4221c32caccfd66ae320\System.ServiceModel.ni.dll
    + 2012-05-10 21:18 . 2012-05-10 21:1818479616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\9df4e7ae75baa7bbb1af30c8061a6e9b\System.Data.Entity.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:1410440192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b64f213e823a591607c45fac4997801e\System.Core.ni.dll
    + 2012-06-16 17:03 . 2012-06-16 17:0324407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a3c3789d54894008501ce5891f1eeb40\PresentationFramework.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:1624407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\34c2013b5f730680bd610d6a98d2977f\PresentationFramework.ni.dll
    + 2012-06-16 17:03 . 2012-06-16 17:0315908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\9d69a7a407bbc43a1bcb2da603af5840\PresentationCore.ni.dll
    + 2012-05-10 21:16 . 2012-05-10 21:1615908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\4464e9df7184e3393b4cbb0f6dc286ba\PresentationCore.ni.dll
    + 2012-05-10 14:21 . 2012-05-10 14:2119353600 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll
    + 2012-06-16 15:41 . 2012-06-16 15:4113198336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
    + 2012-05-10 21:14 . 2012-05-10 21:1418058752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\cfece6f67593b4d8bb58d23b7fdcc470\System.ServiceModel.ni.dll
    + 2012-05-10 21:13 . 2012-05-10 21:1313345792 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\7aa839fb16503243d6ae454ab334bcf4\System.Data.Entity.ni.dll
    + 2012-06-16 15:42 . 2012-06-16 15:4218000896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll
    + 2012-06-16 15:41 . 2012-06-16 15:4111451904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll
    + 2012-05-10 14:22 . 2012-05-10 14:2214412800 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
    + 2012-05-11 00:10 . 2012-05-11 00:1010624512 c:\windows\assembly\NativeImages_v2.0.50727_64\System\c40ec0f4cd203c880298f94c0427dd54\System.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:4317383424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\dc5bb74eefdbf954cdfb70dd534d5564\System.Windows.Forms.ni.dll
    + 2012-06-16 16:44 . 2012-06-16 16:4415270912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\95f38e7485bbe2b73b6055c45196fedd\System.Web.ni.dll
    + 2012-05-11 15:38 . 2012-05-11 15:3823913984 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\f74b2d1b8cf279ff6bfe479f79e70fe9\System.ServiceModel.ni.dll
    + 2012-05-11 16:08 . 2012-05-11 16:0811900928 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\00c4a761d0a5cafc00f34d763fe76ac4\System.Management.Automation.ni.dll
    + 2012-06-16 16:45 . 2012-06-16 16:4513609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\582144c0ee317038621aebc626187b56\System.Design.ni.dll
    + 2012-05-11 16:09 . 2012-05-11 16:0913760000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\daaff9fe9c85fc171d426a3cb6766dbb\System.Data.Entity.ni.dll
    + 2012-06-16 16:44 . 2012-06-16 16:4419198464 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\47054c4d5b7e522c21a9d57797410302\PresentationFramework.ni.dll
    + 2012-06-16 16:43 . 2012-06-16 16:4316543232 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\3a9d13514a8c4c710fa5ce8e9b5393fe\PresentationCore.ni.dll
    + 2012-05-11 00:09 . 2012-05-11 00:0915570944 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\f73f0a9c9a83dcd3ff428be509a7992f\mscorlib.ni.dll
    + 2012-06-16 17:00 . 2012-06-16 17:0025470976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\0c1f96a4136efe532bbb8eb91d3de300\ehshell.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:4212436480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:4211833344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
    + 2012-05-11 16:27 . 2012-05-11 16:2717478656 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\36adb4b0a5ebbe454b04030ce2e7291a\System.ServiceModel.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:4210580480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\7c144f89b1f8f292d6940a1b2f8ffbec\System.Design.ni.dll
    + 2012-06-16 16:42 . 2012-06-16 16:4214340608 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
    + 2012-06-16 16:40 . 2012-06-16 16:4012237824 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
    + 2012-05-11 00:13 . 2012-05-11 00:1311492864 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
    + 2011-09-15 22:34 . 2011-09-15 22:34428804608 c:\windows\Installer\27b4c300.msp
    + 2011-06-12 12:47 . 2011-06-12 12:47425345024 c:\windows\Installer\23fef28f.msp
    + 2011-10-16 18:38 . 2011-10-16 18:38100966912 c:\windows\Installer\1b2465c7.msp
    .
    -- Snapshot reset to current date --
  6. person15

    person15 TS Rookie Topic Starter Posts: 55

    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0294208----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-07-20 12218904]
    "F.lux"="c:\users\Vivek\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-12-11 1092968]
    "Message Center Plus"="c:\program files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
    "RotateImage"="c:\program files (x86)\RotateImage\RCIMGDIR.exe" [2008-10-30 55808]
    "McAfeeUpdaterUI"="c:\program files (x86)\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
    "ShStatEXE"="c:\program files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-12 215360]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-06-15 296056]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
    .
    c:\users\Vivek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Vivek\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2009-7-1 1079584]
    Digital Line Detect.lnk - c:\program files (x86)\Digital Line Detect\DLG.exe [2010-1-4 50688]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "DisableCAD"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "HideSCAHealth"= 1 (0x1)
    .
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "DisallowCpl"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
    @=""
    .
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-12 135664]
    R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
    R3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2009-10-15 130048]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-22 250056]
    R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2009-09-01 551936]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-12 135664]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-10 97960]
    R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
    R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
    R3 PCDSRVC{127174DC-C366ED8B-06020200}_0;PCDSRVC{127174DC-C366ED8B-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2011-06-27 25584]
    R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-12-11 75112]
    R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-08-05 1124848]
    R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
    R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
    R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-02-26 1255736]
    S0 DzHDD64;DzHDD64;c:\windows\System32\DRIVERS\DzHDD64.sys [2009-12-11 30320]
    S0 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\DRIVERS\iaNvStor.sys [2009-08-21 344600]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-10 281544]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-07-12 55856]
    S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [2009-10-09 23592]
    S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [2008-05-12 15400]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-24 202752]
    S2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2009-10-15 2505976]
    S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
    S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
    S2 DozeSvc;Lenovo Doze Mode Service;c:\program files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2009-12-11 161128]
    S2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2009-10-15 117760]
    S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-10-10 156248]
    S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-08-04 2058776]
    S3 5U875UVC;Integrated Camera;c:\windows\system32\DRIVERS\RCUVCMNP.sys [2009-10-23 220032]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2009-08-24 6104064]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2009-08-24 135680]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
    S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-06-30 292864]
    S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [2008-08-23 316544]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-06-23 56344]
    S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2009-09-22 7369728]
    S3 LenovoRd;LenovoRd;c:\windows\system32\Drivers\LenovoRd.sys [2009-05-11 118016]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
    S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
    S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2009-07-02 41536]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - mfeavfk01
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-09-03 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-28 17:31]
    .
    2012-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-12 23:57]
    .
    2012-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-12 23:57]
    .
    2012-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-816525379-3359804378-3665389369-1003Core.job
    - c:\users\Vivek\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-07 23:39]
    .
    2012-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-816525379-3359804378-3665389369-1003UA.job
    - c:\users\Vivek\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-07 23:39]
    .
    2012-08-21 c:\windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
    - c:\program files\PC-Doctor\uaclauncher.exe [2011-03-31 15:06]
    .
    2012-08-22 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
    - c:\program files\PC-Doctor\uaclauncher.exe [2011-03-31 15:06]
    .
    2012-09-03 c:\windows\Tasks\SystemToolsDailyTest.job
    - c:\program files\PC-Doctor\uaclauncher.exe [2011-03-31 15:06]
    .
    .
    --------- X64 Entries -----------
    .
    .
  7. person15

    person15 TS Rookie Topic Starter Posts: 55

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0297792----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0297792----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0297792----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2011-10-31 21:0297792----a-w-c:\users\Vivek\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
    2012-07-20 19:17755544----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
    2012-07-20 19:17755544----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
    2012-07-20 19:17755544----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
    2012-07-20 19:17755544----a-w-c:\program files (x86)\Google\Drive\googledrivesync64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
    "FingerPrintSoftwareSplashScreen"="c:\program files\Lenovo Fingerprint Software\SplashScreen.exe \s" [X]
    "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
    "LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
    "picon"="c:\program files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-08-04 358424]
    "TpShocks"="TpShocks.exe" [2009-12-11 380776]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-22 387608]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-22 365592]
    "AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
    "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-07 186904]
    "IaNvSrv"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2009-10-06 33304]
    "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
    IE: Send image to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
    TCP: DhcpNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
    FF - ProfilePath - c:\users\Vivek\AppData\Roaming\Mozilla\Firefox\Profiles\o4wix96c.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=Z192&install_date=20110905
    FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20110905&q=
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    .
    .
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06020200}_0]
    "ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    c:\program files (x86)\MATLAB\webserver\bin\win32\matlabserver.exe
    c:\program files (x86)\McAfee\Common Framework\FrameworkService.exe
    c:\program files (x86)\MATLAB\bin\win32\MATLAB.exe
    c:\program files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    c:\progra~2\PHAROS~1\Core\CTskMstr.exe
    c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
    c:\program files (x86)\Lenovo\Access Connections\AcSvc.exe
    c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    c:\program files (x86)\McAfee\Common Framework\naPrdMgr.exe
    c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files (x86)\Intel\AMT\LMS.exe
    c:\program files (x86)\Lenovo\System Update\SUService.exe
    c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    .
    **************************************************************************
    .
    Completion time: 2012-09-03 00:00:34 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-09-03 04:00
    ComboFix2.txt 2011-09-30 01:23
    .
    Pre-Run: 149,138,743,296 bytes free
    Post-Run: 151,310,692,352 bytes free
    .
    - - End Of File - - 0A417F5F9978C0281DFE970CE86D4806
  8. person15

    person15 TS Rookie Topic Starter Posts: 55

    That should be it for the log file from ComboFix. Sorry it took so many posts, and I am looking forward to your reply. Thanks in advance for helping me try to clear up this very irritating problem!
  9. person15

    person15 TS Rookie Topic Starter Posts: 55

    Hi Broni,

    As a note, I do have a system restore point a week or so before the infection began. Do you think it would be worthwhile (or effective) to restore to this point?

    Thanks,
    Vivek
  10. Broni

    Broni Malware Annihilator Posts: 46,797   +254

    No.

    Combofix log looks good.

    Which browser is getting redirected?
    Did you check different browser?
  11. person15

    person15 TS Rookie Topic Starter Posts: 55

    Chrome is still having a redirect problem. I have tried to replicate the problem in IE, but it hasn't happened. (It only happens intermittently on Chrome). Both browsers seem to be working slower.
     
  12. person15

    person15 TS Rookie Topic Starter Posts: 55

    IE is having the same problem too. (Symptoms have not changed, therefore.)
  13. Broni

    Broni Malware Annihilator Posts: 46,797   +254

    Open IE, go Tools>Internet options>Advanced tab and click on "Reset" button.

    As for Chrome uninstall it.
    1. Go to Start > All Programs > Google Chrome > Uninstall Google Chrome.
    2. Delete your user profile information, like your browser preferences, bookmarks, and history, by selecting the "Also delete browser data" checkbox.
    3. Select the default browser you'd like to use.
    4. Click OK in the confirmation prompt.
    The uninstall process will begin.

    Install fresh copy.

    Let me know how it went.
  14. person15

    person15 TS Rookie Topic Starter Posts: 55

    Thanks. I did that, and the redirect thing hasn't happened for a while in either Chrome or IE. I have tried searching lots of things and clicking on about 5-10 links for each search, and the redirect hasn't happened in a while.

    However, my internet connection seems to be extremely slow. Loading my inbox gmail takes well over 10 seconds (whereas it happens almost instantly for my roommates, who are on the same connection). Many web pages also take a while to load. Downloading Google Chrome took about 10 minutes, whereas it has always taken a handful on seconds in the past.

    How would I be able to tell if there are other things wrong with my computer?
  15. Broni

    Broni Malware Annihilator Posts: 46,797   +254

    We'll run couple more scans.
    I just wanted to know if resetting both browsers fixes the issue.

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  16. person15

    person15 TS Rookie Topic Starter Posts: 55

    I am having trouble posting OTL.txt and Extras.txt onto this forum for some reason. I will try again soon.
  17. person15

    person15 TS Rookie Topic Starter Posts: 55

    OTL logfile created on: 9/3/2012 9:07:47 PM - Run 1
    OTL by OldTimer - Version 3.2.60.0 Folder = C:\Users\Vivek\Desktop
    64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.90 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 57.84% Memory free
    7.80 Gb Paging File | 5.83 Gb Available in Paging File | 74.83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 287.15 Gb Total Space | 141.20 Gb Free Space | 49.17% Space Free | Partition Type: NTFS
    Drive Q: | 9.77 Gb Total Space | 2.26 Gb Free Space | 23.12% Space Free | Partition Type: NTFS

    Computer Name: VIVEKW500 | User Name: Vivek | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/09/03 21:06:28 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Vivek\Desktop\OTL.exe
    PRC - [2012/08/22 12:53:35 | 000,690,888 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
    PRC - [2012/07/20 15:17:14 | 012,218,904 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/06/15 11:20:58 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    PRC - [2012/05/24 14:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Vivek\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    PRC - [2011/01/12 16:05:00 | 000,185,664 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
    PRC - [2011/01/12 16:05:00 | 000,161,088 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
    PRC - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    PRC - [2011/01/12 16:05:00 | 000,075,072 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
    PRC - [2011/01/12 08:08:00 | 000,215,360 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
    PRC - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    PRC - [2011/01/12 08:08:00 | 000,033,648 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
    PRC - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems International) -- C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
    PRC - [2010/11/20 08:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    PRC - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
    PRC - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
    PRC - [2009/12/11 12:58:56 | 000,344,064 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
    PRC - [2009/09/28 03:27:20 | 000,144,752 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    PRC - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe
    PRC - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\AMT\LMS.exe
    PRC - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    PRC - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    PRC - [2009/08/19 20:38:30 | 000,062,752 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
    PRC - [2009/08/07 06:29:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    PRC - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    PRC - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    PRC - [2009/07/14 21:18:02 | 000,062,320 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    PRC - [2009/07/01 22:54:04 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
    PRC - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    PRC - [2009/03/13 04:32:48 | 000,068,976 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    PRC - [2009/02/02 05:04:10 | 000,067,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    PRC - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    PRC - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/09/03 18:21:07 | 000,571,392 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pysqlite2._sqlite.pyd
    MOD - [2012/09/03 18:21:07 | 000,263,168 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32com.shell.shell.pyd
    MOD - [2012/09/03 18:21:07 | 000,096,256 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32api.pyd
    MOD - [2012/09/03 18:21:07 | 000,086,016 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_elementtree.pyd
    MOD - [2012/09/03 18:21:07 | 000,070,656 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._html2.pyd
    MOD - [2012/09/03 18:21:07 | 000,040,448 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_socket.pyd
    MOD - [2012/09/03 18:21:07 | 000,011,776 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32crypt.pyd
    MOD - [2012/09/03 18:21:06 | 001,018,368 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\windows._cacheinvalidation.pyd
    MOD - [2012/09/03 18:21:06 | 000,792,576 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._gdi_.pyd
    MOD - [2012/09/03 18:21:06 | 000,354,304 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pythoncom26.dll
    MOD - [2012/09/03 18:21:06 | 000,153,088 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pyexpat.pyd
    MOD - [2012/09/03 18:21:06 | 000,073,728 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ctypes.pyd
    MOD - [2012/09/03 18:21:04 | 000,731,136 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._misc_.pyd
    MOD - [2012/09/03 18:21:04 | 000,645,120 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ssl.pyd
    MOD - [2012/09/03 18:21:04 | 000,110,592 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\PyWinTypes26.dll
    MOD - [2012/09/03 18:21:04 | 000,036,352 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32process.pyd
    MOD - [2012/09/03 18:21:04 | 000,022,528 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32pdh.pyd
    MOD - [2012/09/03 18:21:03 | 001,169,408 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._core_.pyd
    MOD - [2012/09/03 18:21:03 | 001,056,256 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._controls_.pyd
    MOD - [2012/09/03 18:21:03 | 000,807,424 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._windows_.pyd
    MOD - [2012/09/03 18:21:03 | 000,311,808 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_hashlib.pyd
    MOD - [2012/09/03 18:21:03 | 000,121,856 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._wizard.pyd
    MOD - [2012/09/03 18:21:03 | 000,111,104 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32file.pyd
    MOD - [2012/09/03 18:21:03 | 000,039,424 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32inet.pyd
    MOD - [2012/09/03 18:21:02 | 000,585,728 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\unicodedata.pyd
    MOD - [2012/09/03 18:21:02 | 000,017,920 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32event.pyd
    MOD - [2012/09/03 18:21:01 | 000,011,776 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\select.pyd
    MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    MOD - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    MOD - [2007/04/18 19:30:46 | 000,471,040 | ---- | M] () -- C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll
    MOD - [2007/04/18 19:30:46 | 000,393,216 | ---- | M] () -- C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2011/10/10 19:03:44 | 000,156,248 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
    SRV:64bit: - [2011/10/10 19:03:41 | 000,190,256 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
    SRV:64bit: - [2009/11/18 15:04:24 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
    SRV:64bit: - [2009/10/15 16:50:08 | 002,505,976 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- C:\Windows\SysNative\AtService.exe -- (ATService)
    SRV:64bit: - [2009/10/15 16:50:00 | 000,117,760 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\DTS.exe -- (dtsvc)
    SRV:64bit: - [2009/10/15 16:49:54 | 000,130,048 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\ADMonitor.exe -- (ADMonitor)
    SRV:64bit: - [2009/10/09 13:12:52 | 000,047,656 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
    SRV:64bit: - [2009/09/21 20:24:40 | 001,420,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
    SRV:64bit: - [2009/09/21 20:00:44 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
    SRV:64bit: - [2009/08/24 00:00:14 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2009/07/14 21:18:02 | 000,062,320 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV:64bit: - [2009/07/03 05:47:10 | 000,045,424 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
    SRV:64bit: - [2009/07/01 22:54:02 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
    SRV - [2012/08/22 13:31:07 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011/10/21 16:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
    SRV - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
    SRV - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
    SRV - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
    SRV - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems International) [Auto | Running] -- C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe -- (Pharos Systems ComTaskMaster)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
    SRV - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
    SRV - [2009/12/11 04:11:00 | 000,161,128 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE -- (DozeSvc)
    SRV - [2009/12/11 04:11:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
    SRV - [2009/10/20 14:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
    SRV - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
    SRV - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\AMT\LMS.exe -- (LMS)
    SRV - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
    SRV - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
    SRV - [2009/08/05 01:32:42 | 001,124,848 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
    SRV - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/04/28 22:21:18 | 000,436,736 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
    SRV - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
    SRV - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
    SRV - [2005/07/27 08:53:00 | 000,536,576 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\MATLAB\webserver\bin\win32\matlabserver.exe -- (matlabserver)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2011/10/10 19:03:44 | 000,281,544 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,607,152 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,097,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,217,696 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,153,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
    DRV:64bit: - [2011/06/27 11:06:54 | 000,025,584 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020200}_0)
    DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2010/07/12 14:36:10 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2010/04/23 01:17:40 | 000,318,000 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2010/01/04 15:52:24 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,030,320 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DZHDD64.SYS -- (DzHDD64)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
    DRV:64bit: - [2009/11/18 15:04:04 | 000,032,880 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
    DRV:64bit: - [2009/10/23 14:42:54 | 000,220,032 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RCUVCMNP.sys -- (5U875UVC)
    DRV:64bit: - [2009/10/20 14:19:54 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
    DRV:64bit: - [2009/10/09 13:11:38 | 000,136,744 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
    DRV:64bit: - [2009/10/09 13:10:00 | 000,023,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
    DRV:64bit: - [2009/10/05 18:58:18 | 000,649,216 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/09/15 16:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
    DRV:64bit: - [2009/09/03 07:14:00 | 000,057,856 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2009/09/03 06:59:00 | 000,054,784 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2009/09/03 06:37:00 | 000,067,072 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2009/09/01 05:44:16 | 000,551,936 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ATSwpWDF.sys -- (ATSwpWDF)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
    DRV:64bit: - [2009/08/23 23:10:06 | 000,135,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2009/08/21 14:59:20 | 000,344,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaNvStor.sys -- (iaNvStor)
    DRV:64bit: - [2009/08/06 16:24:14 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 19:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
    DRV:64bit: - [2009/07/02 14:16:10 | 000,041,536 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tvti2c.sys -- (TVTI2C)
    DRV:64bit: - [2009/06/30 23:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2009/06/30 23:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - [2009/06/30 23:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
    DRV:64bit: - [2009/06/30 00:05:16 | 001,486,848 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2009/06/30 00:01:16 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2009/06/29 23:59:54 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2009/06/22 23:50:36 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
    DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
    DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/05/10 22:33:56 | 000,118,016 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LenovoRd.sys -- (LenovoRd)
    DRV:64bit: - [2009/04/28 22:21:08 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2009/04/07 02:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - [2008/08/22 23:10:26 | 000,316,544 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
    DRV:64bit: - [2008/05/12 05:04:26 | 000,015,400 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
    DRV:64bit: - [2006/06/18 09:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
    DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}
    IE:64bit: - HKLM\..\SearchScopes\{C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {FC869BDA-8531-46AB-9D34-4062113049EC}
    IE - HKLM\..\SearchScopes\{FC869BDA-8531-46AB-9D34-4062113049EC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66 8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66 8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  18. person15

    person15 TS Rookie Topic Starter Posts: 55

    ========== FireFox ==========

    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll (Wolfram Research, Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Vivek\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll (Move Networks)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 0.9\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2012/06/15 11:21:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 0.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2012/08/16 10:10:11 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\moveplayer@movenetworks.com: C:\Users\Vivek\AppData\Roaming\Move Networks [2010/01/13 20:01:38 | 000,000,000 | ---D | M]

    [2010/01/06 17:56:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vivek\AppData\Roaming\Mozilla\Sunbird\Profiles\p8uafadg.default\extensions
    [2010/01/06 17:56:34 | 000,000,000 | ---D | M] (Lightning stub extension for Sunbird) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
    [2010/01/06 17:56:18 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\CALENDAR-TIMEZONES@MOZILLA.ORG
    [2010/01/06 17:56:22 | 000,000,000 | ---D | M] (Talkback) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\TALKBACK@MOZILLA.ORG
    [2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2010/08/23 12:35:04 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
    [2012/06/15 11:21:06 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
    [2011/08/21 15:52:22 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old

    ========== Chrome ==========

    CHR - homepage: http://lenovo.msn.com/
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://lenovo.msn.com/
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
    CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
    CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
    CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
    CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
    CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    CHR - plugin: Move Streaming Media Player (Enabled) = C:\Users\Vivek\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
  19. person15

    person15 TS Rookie Topic Starter Posts: 55

    I could not upload them from my computer. Please ignore the above posts. Here they are (from a friend's computer). For reference, the problem started on August 31st around 5 pm or so.

    OTL logfile created on: 9/3/2012 9:07:47 PM - Run 1
    OTL by OldTimer - Version 3.2.60.0 Folder = C:\Users\Vivek\Desktop
    64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date
    Format: M/d/yyyy

    3.90 Gb Total Physical Memory | 2.25 Gb Available Physical Memory |
    57.84% Memory free
    7.80 Gb Paging File | 5.83 Gb Available in Paging File | 74.83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% =
    C:\Program Files (x86)
    Drive C: | 287.15 Gb Total Space | 141.20 Gb Free Space | 49.17% Space
    Free | Partition Type: NTFS
    Drive Q: | 9.77 Gb Total Space | 2.26 Gb Free Space | 23.12% Space
    Free | Partition Type: NTFS

    Computer Name: VIVEKW500 | User Name: Vivek | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company
    Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/09/03 21:06:28 | 000,599,040 | ---- | M] (OldTimer Tools)
    -- C:\Users\Vivek\Desktop\OTL.exe
    PRC - [2012/08/22 12:53:35 | 000,690,888 | ---- | M] (Adobe Systems
    Incorporated) --
    C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
    PRC - [2012/07/20 15:17:14 | 012,218,904 | ---- | M] (Google) --
    C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes
    Corporation) -- C:\Program Files (x86)\Malwarebytes'
    Anti-Malware\mbamservice.exe
    PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes
    Corporation) -- C:\Program Files (x86)\Malwarebytes'
    Anti-Malware\mbamgui.exe
    PRC - [2012/06/15 11:20:58 | 000,296,056 | ---- | M] (RealNetworks,
    Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    PRC - [2012/05/24 14:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.)
    -- C:\Users\Vivek\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft
    Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    PRC - [2011/01/12 16:05:00 | 000,185,664 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
    PRC - [2011/01/12 16:05:00 | 000,161,088 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
    PRC - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    PRC - [2011/01/12 16:05:00 | 000,075,072 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
    PRC - [2011/01/12 08:08:00 | 000,215,360 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
    PRC - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    PRC - [2011/01/12 08:08:00 | 000,033,648 | ---- | M] (McAfee, Inc.) --
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
    PRC - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems
    International) -- C:\Program Files
    (x86)\PharosSystems\Core\CTskMstr.exe
    PRC - [2010/11/20 08:17:55 | 000,257,536 | ---- | M] (Microsoft
    Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    PRC - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) --
    C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
    PRC - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) --
    C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
    PRC - [2009/12/11 12:58:56 | 000,344,064 | ---- | M] (Lenovo) --
    C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
    PRC - [2009/09/28 03:27:20 | 000,144,752 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    PRC - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group
    Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe
    PRC - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel
    Corporation) -- C:\Program Files (x86)\Intel\AMT\LMS.exe
    PRC - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () --
    C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    PRC - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files (x86)\Common
    Files\Lenovo\tvt_reg_monitor_svc.exe
    PRC - [2009/08/19 20:38:30 | 000,062,752 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
    PRC - [2009/08/07 06:29:54 | 000,186,904 | ---- | M] (Intel
    Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage
    Manager\IAAnotif.exe
    PRC - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel
    Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage
    Manager\IAANTmon.exe
    PRC - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel
    Corporation) -- C:\Program Files (x86)\Common Files\Intel\Privacy
    Icon\UNS\UNS.exe
    PRC - [2009/07/14 21:18:02 | 000,062,320 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    PRC - [2009/07/01 22:54:04 | 000,013,600 | ---- | M] (Broadcom
    Corporation.) -- C:\Program Files\ThinkPad\Bluetooth
    Software\BluetoothHeadsetProxy.exe
    PRC - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program
    Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    PRC - [2009/03/13 04:32:48 | 000,068,976 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    PRC - [2009/02/02 05:04:10 | 000,067,432 | ---- | M] (Lenovo Group
    Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    PRC - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft
    Corporation) -- C:\Program Files (x86)\Microsoft Small
    Business\Business Contact Manager\BcmSqlStartupSvc.exe
    PRC - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo) --
    C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/09/03 18:21:07 | 000,571,392 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pysqlite2._sqlite.pyd
    MOD - [2012/09/03 18:21:07 | 000,263,168 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32com.shell.shell.pyd
    MOD - [2012/09/03 18:21:07 | 000,096,256 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32api.pyd
    MOD - [2012/09/03 18:21:07 | 000,086,016 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_elementtree.pyd
    MOD - [2012/09/03 18:21:07 | 000,070,656 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._html2.pyd
    MOD - [2012/09/03 18:21:07 | 000,040,448 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_socket.pyd
    MOD - [2012/09/03 18:21:07 | 000,011,776 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32crypt.pyd
    MOD - [2012/09/03 18:21:06 | 001,018,368 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\windows._cacheinvalidation.pyd
    MOD - [2012/09/03 18:21:06 | 000,792,576 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._gdi_.pyd
    MOD - [2012/09/03 18:21:06 | 000,354,304 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pythoncom26.dll
    MOD - [2012/09/03 18:21:06 | 000,153,088 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pyexpat.pyd
    MOD - [2012/09/03 18:21:06 | 000,073,728 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ctypes.pyd
    MOD - [2012/09/03 18:21:04 | 000,731,136 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._misc_.pyd
    MOD - [2012/09/03 18:21:04 | 000,645,120 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ssl.pyd
    MOD - [2012/09/03 18:21:04 | 000,110,592 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\PyWinTypes26.dll
    MOD - [2012/09/03 18:21:04 | 000,036,352 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32process.pyd
    MOD - [2012/09/03 18:21:04 | 000,022,528 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32pdh.pyd
    MOD - [2012/09/03 18:21:03 | 001,169,408 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._core_.pyd
    MOD - [2012/09/03 18:21:03 | 001,056,256 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._controls_.pyd
    MOD - [2012/09/03 18:21:03 | 000,807,424 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._windows_.pyd
    MOD - [2012/09/03 18:21:03 | 000,311,808 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_hashlib.pyd
    MOD - [2012/09/03 18:21:03 | 000,121,856 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._wizard.pyd
    MOD - [2012/09/03 18:21:03 | 000,111,104 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32file.pyd
    MOD - [2012/09/03 18:21:03 | 000,039,424 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32inet.pyd
    MOD - [2012/09/03 18:21:02 | 000,585,728 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\unicodedata.pyd
    MOD - [2012/09/03 18:21:02 | 000,017,920 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32event.pyd
    MOD - [2012/09/03 18:21:01 | 000,011,776 | ---- | M] () --
    C:\Users\Vivek\AppData\Local\Temp\_MEI38242\select.pyd
    MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program
    Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program
    Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () --
    C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    MOD - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program
    Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    MOD - [2007/04/18 19:30:46 | 000,471,040 | ---- | M] () -- C:\Program
    Files (x86)\McAfee\Common Framework\ccme_base.dll
    MOD - [2007/04/18 19:30:46 | 000,393,216 | ---- | M] () -- C:\Program
    Files (x86)\McAfee\Common Framework\cryptocme2.dll
  20. person15

    person15 TS Rookie Topic Starter Posts: 55

    ========== Services (SafeList) ==========

    SRV:64bit: - [2011/10/10 19:03:44 | 000,156,248 | ---- | M]
    (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe --
    (mfevtp)
    SRV:64bit: - [2011/10/10 19:03:41 | 000,190,256 | ---- | M] ()
    [Auto | Running] -- C:\Program Files\Common
    Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
    SRV:64bit: - [2009/11/18 15:04:24 | 000,045,928 | ---- | M]
    (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe --
    (IBMPMSVC)
    SRV:64bit: - [2009/10/15 16:50:08 | 002,505,976 | ---- | M]
    (AuthenTec, Inc.) [Auto | Running] --
    C:\Windows\SysNative\AtService.exe -- (ATService)
    SRV:64bit: - [2009/10/15 16:50:00 | 000,117,760 | ---- | M] ()
    [Auto | Running] -- C:\Windows\SysNative\DTS.exe -- (dtsvc)
    SRV:64bit: - [2009/10/15 16:49:54 | 000,130,048 | ---- | M] ()
    [On_Demand | Stopped] -- C:\Windows\SysNative\ADMonitor.exe --
    (ADMonitor)
    SRV:64bit: - [2009/10/09 13:12:52 | 000,047,656 | ---- | M]
    (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe
    -- (TPHDEXLGSVC)
    SRV:64bit: - [2009/09/21 20:24:40 | 001,420,560 | ---- | M]
    (Intel(R) Corporation) [Auto | Running] -- C:\Program
    Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
    SRV:64bit: - [2009/09/21 20:00:44 | 000,831,760 | ---- | M]
    (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common
    Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
    SRV:64bit: - [2009/08/24 00:00:14 | 000,202,752 | ---- | M]
    (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD
    External Events Utility)
    SRV:64bit: - [2009/07/14 21:18:02 | 000,062,320 | ---- | M]
    (Lenovo Group Limited) [Auto | Running] -- C:\Program
    Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M]
    (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program
    Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M]
    (Microsoft Corporation) [On_Demand | Stopped] --
    C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV:64bit: - [2009/07/03 05:47:10 | 000,045,424 | ---- | M]
    (Lenovo Group Limited) [Auto | Stopped] -- C:\Program
    Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
    SRV:64bit: - [2009/07/01 22:54:02 | 000,864,032 | ---- | M]
    (Broadcom Corporation.) [Auto | Running] -- C:\Program
    Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
    SRV - [2012/08/22 13:31:07 | 000,250,056 | ---- | M] (Adobe Systems
    Incorporated) [On_Demand | Stopped] --
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe --
    (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes
    Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes'
    Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011/10/21 16:23:42 | 000,196,176 | ---- | M] (Microsoft
    Corporation.) [Auto | Stopped] -- C:\Program Files
    (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
    SRV - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft
    Corporation) [Auto | Running] -- C:\Program Files
    (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
    SRV - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.)
    [Auto | Running] -- C:\Program Files (x86)\McAfee\Common
    Framework\FrameworkService.exe -- (McAfeeFramework)
    SRV - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.)
    [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan
    Enterprise\vstskmgr.exe -- (McTaskManager)
    SRV - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems
    International) [Auto | Running] -- C:\Program Files
    (x86)\PharosSystems\Core\CTskMstr.exe -- (Pharos Systems
    ComTaskMaster)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft
    Corporation) [Auto | Stopped] --
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe --
    (clr_optimization_v4.0.30319_32)
    SRV - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) [Auto |
    Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
    -- (AcSvc)
    SRV - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) [Auto |
    Running] -- C:\Program Files (x86)\Lenovo\Access
    Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
    SRV - [2009/12/11 04:11:00 | 000,161,128 | ---- | M] (Lenovo.) [Auto |
    Running] -- C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE --
    (DozeSvc)
    SRV - [2009/12/11 04:11:00 | 000,075,112 | ---- | M] (Lenovo)
    [On_Demand | Stopped] -- C:\Program Files
    (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
    SRV - [2009/10/20 14:19:48 | 000,117,264 | ---- | M] (CACE
    Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files
    (x86)\WinPcap\rpcapd.exe -- (rpcapd)
    SRV - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group
    Limited) [Auto | Running] -- c:\Program Files (x86)\Lenovo\System
    Update\SUService.exe -- (SUService)
    SRV - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel
    Corporation) [Auto | Running] -- C:\Program Files
    (x86)\Intel\AMT\LMS.exe -- (LMS)
    SRV - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group
    Limited) [Auto | Running] -- C:\Program Files (x86)\Common
    Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor
    Service)
    SRV - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel
    Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel
    Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
    SRV - [2009/08/05 01:32:42 | 001,124,848 | ---- | M] (Sonic Solutions)
    [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio
    Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
    SRV - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel
    Corporation) [Auto | Running] -- C:\Program Files (x86)\Common
    Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft
    Corporation) [Disabled | Stopped] --
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe --
    (clr_optimization_v2.0.50727_32)
    SRV - [2009/04/28 22:21:18 | 000,436,736 | ---- | M] (Conexant
    Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\XAudio64.dll --
    (HsfXAudioService)
    SRV - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft
    Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft
    Small Business\Business Contact Manager\BcmSqlStartupSvc.exe --
    (BcmSqlStartupSvc)
    SRV - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo)
    [Auto | Running] -- C:\Program Files (x86)\Common
    Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
    SRV - [2005/07/27 08:53:00 | 000,536,576 | ---- | M] () [Auto |
    Stopped] -- C:\Program Files
    (x86)\MATLAB\webserver\bin\win32\matlabserver.exe -- (matlabserver)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M]
    (Malwarebytes Corporation) [File_System | On_Demand | Running] --
    C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M]
    (Microsoft Corporation) [Recognizer | Boot | Unknown] --
    C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2011/10/10 19:03:44 | 000,281,544 | ---- | M]
    (McAfee, Inc.) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,607,152 | ---- | M]
    (McAfee, Inc.) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,097,960 | ---- | M]
    (McAfee, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,217,696 | ---- | M]
    (McAfee, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,153,952 | ---- | M]
    (McAfee, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
    DRV:64bit: - [2011/06/27 11:06:54 | 000,025,584 | ---- | M]
    (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program
    Files\PC-Doctor\pcdsrvc_x64.pkms --
    (PCDSRVC{127174DC-C366ED8B-06020200}_0)
    DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M]
    (Apple, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M]
    (Advanced Micro Devices) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M]
    (Advanced Micro Devices) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M]
    (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M]
    (Microsoft Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M]
    (Microsoft Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2010/07/12 14:36:10 | 000,055,856 | ---- | M]
    (Sonic Solutions) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2010/04/23 01:17:40 | 000,318,000 | ---- | M]
    (Synaptics Incorporated) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2010/01/04 15:52:24 | 000,040,512 | ---- | M]
    (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,030,320 | ---- | M]
    (Lenovo.) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\DZHDD64.SYS -- (DzHDD64)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,013,104 | ---- | M] ()
    [Kernel | System | Running] --
    C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
    DRV:64bit: - [2009/11/18 15:04:04 | 000,032,880 | ---- | M]
    (Lenovo.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
    DRV:64bit: - [2009/10/23 14:42:54 | 000,220,032 | ---- | M]
    (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\RCUVCMNP.sys -- (5U875UVC)
    DRV:64bit: - [2009/10/20 14:19:54 | 000,047,632 | ---- | M]
    (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\npf.sys -- (NPF)
    DRV:64bit: - [2009/10/09 13:11:38 | 000,136,744 | ---- | M]
    (Lenovo.) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
    DRV:64bit: - [2009/10/09 13:10:00 | 000,023,592 | ---- | M]
    (Lenovo.) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
    DRV:64bit: - [2009/10/05 18:58:18 | 000,649,216 | ---- | M]
    (Conexant Systems Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/09/15 16:40:42 | 006,952,960 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
    DRV:64bit: - [2009/09/03 07:14:00 | 000,057,856 | ---- | M]
    (REDC) [Kernel | Auto | Running] --
    C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2009/09/03 06:59:00 | 000,054,784 | ---- | M]
    (REDC) [Kernel | Auto | Running] --
    C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2009/09/03 06:37:00 | 000,067,072 | ---- | M]
    (REDC) [Kernel | Auto | Running] --
    C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2009/09/01 05:44:16 | 000,551,936 | ---- | M]
    (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\ATSwpWDF.sys -- (ATSwpWDF)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M]
    (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M]
    (ATI Technologies Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
    DRV:64bit: - [2009/08/23 23:10:06 | 000,135,680 | ---- | M]
    (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2009/08/21 14:59:20 | 000,344,600 | ---- | M]
    (Intel Corporation) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\iaNvStor.sys -- (iaNvStor)
    DRV:64bit: - [2009/08/06 16:24:14 | 000,408,600 | ---- | M]
    (Intel Corporation) [Kernel | Boot | Running] --
    C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M]
    (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M]
    (LSI Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M]
    (Promise Technology) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 19:21:48 | 000,038,400 | ---- | M]
    (Microsoft Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
    DRV:64bit: - [2009/07/02 14:16:10 | 000,041,536 | ---- | M]
    (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\tvti2c.sys -- (TVTI2C)
    DRV:64bit: - [2009/06/30 23:46:52 | 000,098,344 | ---- | M]
    (Broadcom Corporation.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2009/06/30 23:46:48 | 000,132,648 | ---- | M]
    (Broadcom Corporation.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - [2009/06/30 23:46:40 | 000,021,160 | ---- | M]
    (Broadcom Corporation.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
    DRV:64bit: - [2009/06/30 00:05:16 | 001,486,848 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2009/06/30 00:01:16 | 000,292,864 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2009/06/29 23:59:54 | 000,740,864 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2009/06/22 23:50:36 | 000,056,344 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
    DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
    DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M]
    (Broadcom Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M]
    (Broadcom Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M]
    (Broadcom Corporation) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M]
    (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] --
    C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M]
    (GEAR Software Inc.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/05/10 22:33:56 | 000,118,016 | ---- | M]
    (Lenovo) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\LenovoRd.sys -- (LenovoRd)
    DRV:64bit: - [2009/04/28 22:21:08 | 000,010,240 | ---- | M]
    (Conexant Systems, Inc.) [Kernel | Auto | Running] --
    C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2009/04/07 02:33:08 | 000,035,104 | ---- | M]
    (Broadcom Corporation.) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - [2008/08/22 23:10:26 | 000,316,544 | ---- | M]
    (Intel Corporation) [Kernel | On_Demand | Running] --
    C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
    DRV:64bit: - [2008/05/12 05:04:26 | 000,015,400 | ---- | M]
    (Lenovo Group Limited) [Kernel | System | Running] --
    C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
    DRV:64bit: - [2006/06/18 09:27:24 | 000,017,024 | ---- | M]
    (Conexant) [Kernel | Auto | Running] --
    C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
    DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft
    Corporation) [File_System | On_Demand | Stopped] --
    C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  21. person15

    person15 TS Rookie Topic Starter Posts: 55

    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
    {C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}
    IE:64bit: -
    HKLM\..\SearchScopes\{C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}: "URL" =
    http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
    C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {FC869BDA-8531-46AB-9D34-4062113049EC}
    IE - HKLM\..\SearchScopes\{FC869BDA-8531-46AB-9D34-4062113049EC}:
    "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet
    Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet
    Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet
    Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66
    8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet
    Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66
    8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet
    Explorer\Main,Default_Page_URL = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet
    Explorer\Main,Default_Secondary_Page_URL =
    http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet
    Explorer\Main,Search Bar = Preserve
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet
    Explorer\Main,Secondary Start Pages =
    http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet
    Explorer\Main,Start Page = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\..\SearchScopes,DefaultScope
    = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\Software\Microsoft\Windows\CurrentVersion\Internet
    Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - user.js - File not found

    FF:64bit: -
    HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
    C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not
    found
    FF:64bit: -
    HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not
    found
    FF:64bit: -
    HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:
    c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll (
    Microsoft Corporation)
    FF:64bit: -
    HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:
    C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
    C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0:
    C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin:
    C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program
    Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems,
    Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled
    File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:
    c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll (
    Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:
    C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:
    C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709:
    C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53:
    c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
    (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53:
    c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
    (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53:
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53:
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669:
    C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
    (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53:
    c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
    (RealPlayer)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:
    File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google
    Update;version=3: C:\Program Files
    (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google
    Update;version=9: C:\Program Files
    (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program
    Files (x86)\Common Files\Wolfram
    Research\Browser\8.0.1.2063897\npmathplugin.dll (Wolfram Research,
    Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files
    (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media
    Player: C:\Users\Vivek\AppData\Roaming\Move
    Networks\plugins\npqmp071705000014.dll (Move Networks)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin:
    C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin:
    C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google
    Update;version=3:
    C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google
    Update;version=9:
    C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}:
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
    [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}:
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
    [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird
    0.9\extensions\\Components: C:\Program Files (x86)\Mozilla
    Sunbird\components [2012/06/15 11:21:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird
    0.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla
    Sunbird\plugins [2012/08/16 10:10:11 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\moveplayer@movenetworks.com:
    C:\Users\Vivek\AppData\Roaming\Move Networks [2010/01/13 20:01:38 |
    000,000,000 | ---D | M]

    [2010/01/06 17:56:33 | 000,000,000 | ---D | M] (No name found) --
    C:\Users\Vivek\AppData\Roaming\Mozilla\Sunbird\Profiles\p8uafadg.default\extensions
    [2010/01/06 17:56:34 | 000,000,000 | ---D | M] (Lightning stub
    extension for Sunbird) -- C:\PROGRAM FILES (X86)\MOZILLA
    SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
    [2010/01/06 17:56:18 | 000,000,000 | ---D | M] (Timezone Definitions
    for Mozilla Calendar) -- C:\PROGRAM FILES (X86)\MOZILLA
    SUNBIRD\EXTENSIONS\CALENDAR-TIMEZONES@MOZILLA.ORG
    [2010/01/06 17:56:22 | 000,000,000 | ---D | M] (Talkback) --
    C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\TALKBACK@MOZILLA.ORG
    [2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems,
    Inc.) -- C:\Program Files (x86)\mozilla
    firefox\plugins\npdeployJava1.dll
    [2010/08/23 12:35:04 | 000,075,208 | ---- | M] (Foxit Software
    Company) -- C:\Program Files (x86)\mozilla
    firefox\plugins\npFoxitReaderPlugin.dll
    [2012/06/15 11:21:06 | 000,129,144 | ---- | M] (RealPlayer) --
    C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
    [2011/08/21 15:52:22 | 000,002,252 | ---- | M] () -- C:\Program Files
    (x86)\mozilla firefox\searchplugins\bing.xml.old

    ========== Chrome ==========

    CHR - homepage: http://lenovo.msn.com/
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url =
    {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url =
    {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://lenovo.msn.com/
    CHR - plugin: Shockwave Flash (Enabled) =
    C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
    CHR - plugin: Shockwave Flash (Enabled) =
    C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) =
    C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) =
    C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) =
    C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files
    (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) =
    C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files
    (x86)\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program
    Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
    (Enabled) = C:\Program Files (x86)\Mozilla
    Firefox\plugins\nppl3260.dll
    CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\nprpjplug.dll
    CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\nprpplugin.dll
    CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)
    (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files
    (x86)\Mozilla Firefox\plugins\nprjplug.dll
    CHR - plugin: Google Talk Plugin (Enabled) =
    C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) =
    C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: Microsoft Office 2010 (Enabled) =
    C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) =
    C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
    CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files
    (x86)\Common Files\Wolfram
    Research\Browser\8.0.1.2063897\npmathplugin.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files
    (x86)\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files
    (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program
    Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files
    (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In
    (32-bit) (Enabled) =
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    CHR - plugin: Move Streaming Media Player (Enabled) =
    C:\Users\Vivek\AppData\Roaming\Move
    Networks\plugins\npqmp071705000014.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files
    (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - Extension: RealPlayer HTML5Video Downloader Extension =
    C:\Users\Vivek\AppData\Local\Google\Chrome\User
    Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

    O1 HOSTS File: ([2012/09/02 23:42:48 | 000,000,027 | ---- | M]) -
    C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (scriptproxy) -
    {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common
    Files\McAfee\SystemCore\ScriptSn.20111010195856.dll (McAfee, Inc.)
    O2 - BHO: (RealPlayer Download and Record Plugin for Internet
    Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} -
    C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    (RealPlayer)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No
    CLSID value found.
    O2 - BHO: (Java(tm) Plug-In SSV Helper) -
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
    (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -
    C:\Program Files (x86)\Common
    Files\McAfee\SystemCore\ScriptSn.20111010195856.dll (McAfee, Inc.)
    O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
    C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft
    Corporation.)
  22. Broni

    Broni Malware Annihilator Posts: 46,797   +254

    You need to disable "word wrap" in Notepad.
    I can't read the above log.
  23. person15

    person15 TS Rookie Topic Starter Posts: 55

    Sorry. I'll try again.
  24. person15

    person15 TS Rookie Topic Starter Posts: 55

    OTL logfile created on: 9/3/2012 9:07:47 PM - Run 1
    OTL by OldTimer - Version 3.2.60.0 Folder = C:\Users\Vivek\Desktop
    64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.90 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 57.84% Memory free
    7.80 Gb Paging File | 5.83 Gb Available in Paging File | 74.83% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 287.15 Gb Total Space | 141.20 Gb Free Space | 49.17% Space Free | Partition Type: NTFS
    Drive Q: | 9.77 Gb Total Space | 2.26 Gb Free Space | 23.12% Space Free | Partition Type: NTFS

    Computer Name: VIVEKW500 | User Name: Vivek | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/09/03 21:06:28 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Vivek\Desktop\OTL.exe
    PRC - [2012/08/22 12:53:35 | 000,690,888 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
    PRC - [2012/07/20 15:17:14 | 012,218,904 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/06/15 11:20:58 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    PRC - [2012/05/24 14:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Vivek\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    PRC - [2011/01/12 16:05:00 | 000,185,664 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
    PRC - [2011/01/12 16:05:00 | 000,161,088 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
    PRC - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    PRC - [2011/01/12 16:05:00 | 000,075,072 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
    PRC - [2011/01/12 08:08:00 | 000,215,360 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
    PRC - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    PRC - [2011/01/12 08:08:00 | 000,033,648 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe
    PRC - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems International) -- C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe
    PRC - [2010/11/20 08:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    PRC - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
    PRC - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
    PRC - [2009/12/11 12:58:56 | 000,344,064 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
    PRC - [2009/09/28 03:27:20 | 000,144,752 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    PRC - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group Limited) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe
    PRC - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\AMT\LMS.exe
    PRC - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    PRC - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    PRC - [2009/08/19 20:38:30 | 000,062,752 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
    PRC - [2009/08/07 06:29:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    PRC - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    PRC - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    PRC - [2009/07/14 21:18:02 | 000,062,320 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    PRC - [2009/07/01 22:54:04 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
    PRC - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    PRC - [2009/03/13 04:32:48 | 000,068,976 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    PRC - [2009/02/02 05:04:10 | 000,067,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    PRC - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    PRC - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/09/03 18:21:07 | 000,571,392 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pysqlite2._sqlite.pyd
    MOD - [2012/09/03 18:21:07 | 000,263,168 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32com.shell.shell.pyd
    MOD - [2012/09/03 18:21:07 | 000,096,256 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32api.pyd
    MOD - [2012/09/03 18:21:07 | 000,086,016 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_elementtree.pyd
    MOD - [2012/09/03 18:21:07 | 000,070,656 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._html2.pyd
    MOD - [2012/09/03 18:21:07 | 000,040,448 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_socket.pyd
    MOD - [2012/09/03 18:21:07 | 000,011,776 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32crypt.pyd
    MOD - [2012/09/03 18:21:06 | 001,018,368 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\windows._cacheinvalidation.pyd
    MOD - [2012/09/03 18:21:06 | 000,792,576 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._gdi_.pyd
    MOD - [2012/09/03 18:21:06 | 000,354,304 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pythoncom26.dll
    MOD - [2012/09/03 18:21:06 | 000,153,088 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\pyexpat.pyd
    MOD - [2012/09/03 18:21:06 | 000,073,728 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ctypes.pyd
    MOD - [2012/09/03 18:21:04 | 000,731,136 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._misc_.pyd
    MOD - [2012/09/03 18:21:04 | 000,645,120 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_ssl.pyd
    MOD - [2012/09/03 18:21:04 | 000,110,592 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\PyWinTypes26.dll
    MOD - [2012/09/03 18:21:04 | 000,036,352 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32process.pyd
    MOD - [2012/09/03 18:21:04 | 000,022,528 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32pdh.pyd
    MOD - [2012/09/03 18:21:03 | 001,169,408 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._core_.pyd
    MOD - [2012/09/03 18:21:03 | 001,056,256 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._controls_.pyd
    MOD - [2012/09/03 18:21:03 | 000,807,424 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._windows_.pyd
    MOD - [2012/09/03 18:21:03 | 000,311,808 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\_hashlib.pyd
    MOD - [2012/09/03 18:21:03 | 000,121,856 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\wx._wizard.pyd
    MOD - [2012/09/03 18:21:03 | 000,111,104 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32file.pyd
    MOD - [2012/09/03 18:21:03 | 000,039,424 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32inet.pyd
    MOD - [2012/09/03 18:21:02 | 000,585,728 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\unicodedata.pyd
    MOD - [2012/09/03 18:21:02 | 000,017,920 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\win32event.pyd
    MOD - [2012/09/03 18:21:01 | 000,011,776 | ---- | M] () -- C:\Users\Vivek\AppData\Local\Temp\_MEI38242\select.pyd
    MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2009/08/29 02:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Vivek\Local Settings\Apps\F.lux\flux.exe
    MOD - [2009/05/28 02:09:36 | 000,049,976 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
    MOD - [2007/04/18 19:30:46 | 000,471,040 | ---- | M] () -- C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll
    MOD - [2007/04/18 19:30:46 | 000,393,216 | ---- | M] () -- C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2011/10/10 19:03:44 | 000,156,248 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
    SRV:64bit: - [2011/10/10 19:03:41 | 000,190,256 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
    SRV:64bit: - [2009/11/18 15:04:24 | 000,045,928 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Windows\SysNative\ibmpmsvc.exe -- (IBMPMSVC)
    SRV:64bit: - [2009/10/15 16:50:08 | 002,505,976 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- C:\Windows\SysNative\AtService.exe -- (ATService)
    SRV:64bit: - [2009/10/15 16:50:00 | 000,117,760 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\DTS.exe -- (dtsvc)
    SRV:64bit: - [2009/10/15 16:49:54 | 000,130,048 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\ADMonitor.exe -- (ADMonitor)
    SRV:64bit: - [2009/10/09 13:12:52 | 000,047,656 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Windows\SysNative\TPHDEXLG64.exe -- (TPHDEXLGSVC)
    SRV:64bit: - [2009/09/21 20:24:40 | 001,420,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
    SRV:64bit: - [2009/09/21 20:00:44 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
    SRV:64bit: - [2009/08/24 00:00:14 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2009/07/14 21:18:02 | 000,062,320 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV:64bit: - [2009/07/03 05:47:10 | 000,045,424 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
    SRV:64bit: - [2009/07/01 22:54:02 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe -- (btwdins)
    SRV - [2012/08/22 13:31:07 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2011/10/21 16:23:42 | 000,196,176 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
    SRV - [2011/10/13 18:21:52 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
    SRV - [2011/01/12 16:05:00 | 000,120,128 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
    SRV - [2011/01/12 08:08:00 | 000,209,760 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
    SRV - [2010/12/22 21:25:46 | 000,339,456 | ---- | M] (Pharos Systems International) [Auto | Running] -- C:\Program Files (x86)\PharosSystems\Core\CTskMstr.exe -- (Pharos Systems ComTaskMaster)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009/12/11 13:22:06 | 000,255,336 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
    SRV - [2009/12/11 13:22:04 | 000,124,264 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
    SRV - [2009/12/11 04:11:00 | 000,161,128 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE -- (DozeSvc)
    SRV - [2009/12/11 04:11:00 | 000,075,112 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
    SRV - [2009/10/20 14:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
    SRV - [2009/09/25 02:55:56 | 000,015,872 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe -- (SUService)
    SRV - [2009/09/14 01:14:28 | 000,174,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\AMT\LMS.exe -- (LMS)
    SRV - [2009/08/28 18:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
    SRV - [2009/08/07 06:29:36 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
    SRV - [2009/08/05 01:32:42 | 001,124,848 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
    SRV - [2009/08/03 23:00:14 | 002,058,776 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe -- (UNS)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/04/28 22:21:18 | 000,436,736 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
    SRV - [2008/01/11 21:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
    SRV - [2007/01/04 23:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
    SRV - [2005/07/27 08:53:00 | 000,536,576 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\MATLAB\webserver\bin\win32\matlabserver.exe -- (matlabserver)
  25. person15

    person15 TS Rookie Topic Starter Posts: 55

    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2011/10/10 19:03:44 | 000,281,544 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,607,152 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
    DRV:64bit: - [2011/10/10 19:03:43 | 000,097,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,217,696 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
    DRV:64bit: - [2011/10/10 19:03:42 | 000,153,952 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
    DRV:64bit: - [2011/06/27 11:06:54 | 000,025,584 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms -- (PCDSRVC{127174DC-C366ED8B-06020200}_0)
    DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2010/07/12 14:36:10 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2010/04/23 01:17:40 | 000,318,000 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2010/01/04 15:52:24 | 000,040,512 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\psadd.sys -- (psadd)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,030,320 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DZHDD64.SYS -- (DzHDD64)
    DRV:64bit: - [2009/12/11 04:11:00 | 000,013,104 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\TPPWR64V.SYS -- (TPPWRIF)
    DRV:64bit: - [2009/11/18 15:04:04 | 000,032,880 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibmpmdrv.sys -- (IBMPMDRV)
    DRV:64bit: - [2009/10/23 14:42:54 | 000,220,032 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RCUVCMNP.sys -- (5U875UVC)
    DRV:64bit: - [2009/10/20 14:19:54 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
    DRV:64bit: - [2009/10/09 13:11:38 | 000,136,744 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsX64.sys -- (Shockprf)
    DRV:64bit: - [2009/10/09 13:10:00 | 000,023,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ApsHM64.sys -- (TPDIGIMN)
    DRV:64bit: - [2009/10/05 18:58:18 | 000,649,216 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
    DRV:64bit: - [2009/09/21 22:47:16 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/09/15 16:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
    DRV:64bit: - [2009/09/03 07:14:00 | 000,057,856 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2009/09/03 06:59:00 | 000,054,784 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2009/09/03 06:37:00 | 000,067,072 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2009/09/01 05:44:16 | 000,551,936 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ATSwpWDF.sys -- (ATSwpWDF)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/08/24 00:33:30 | 006,104,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
    DRV:64bit: - [2009/08/23 23:10:06 | 000,135,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2009/08/21 14:59:20 | 000,344,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaNvStor.sys -- (iaNvStor)
    DRV:64bit: - [2009/08/06 16:24:14 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 19:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
    DRV:64bit: - [2009/07/02 14:16:10 | 000,041,536 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tvti2c.sys -- (TVTI2C)
    DRV:64bit: - [2009/06/30 23:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2009/06/30 23:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - [2009/06/30 23:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
    DRV:64bit: - [2009/06/30 00:05:16 | 001,486,848 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2009/06/30 00:01:16 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2009/06/29 23:59:54 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2009/06/22 23:50:36 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
    DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
    DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
    DRV:64bit: - [2009/06/10 16:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/05/10 22:33:56 | 000,118,016 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LenovoRd.sys -- (LenovoRd)
    DRV:64bit: - [2009/04/28 22:21:08 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2009/04/07 02:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - [2008/08/22 23:10:26 | 000,316,544 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
    DRV:64bit: - [2008/05/12 05:04:26 | 000,015,400 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\smiifx64.sys -- (lenovo.smi)
    DRV:64bit: - [2006/06/18 09:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
    DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}
    IE:64bit: - HKLM\..\SearchScopes\{C55D45F4-6DAD-40BD-A7CB-82C9DED7958C}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {FC869BDA-8531-46AB-9D34-4062113049EC}
    IE - HKLM\..\SearchScopes\{FC869BDA-8531-46AB-9D34-4062113049EC}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LEMDF8&pc=MALC&src=IE-SearchBox;


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66 8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F5 F5 3E 10 CC 06 C8 46 A6 23 66 8F E3 6D 73 AC [binary data]

    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad [binary data]
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-816525379-3359804378-3665389369-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll (Wolfram Research, Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Vivek\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll (Move Networks)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Vivek\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/15 11:21:23 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 0.9\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2012/06/15 11:21:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 0.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2012/08/16 10:10:11 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\moveplayer@movenetworks.com: C:\Users\Vivek\AppData\Roaming\Move Networks [2010/01/13 20:01:38 | 000,000,000 | ---D | M]

    [2010/01/06 17:56:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vivek\AppData\Roaming\Mozilla\Sunbird\Profiles\p8uafadg.default\extensions
    [2010/01/06 17:56:34 | 000,000,000 | ---D | M] (Lightning stub extension for Sunbird) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\{E2FDA1A4-762B-4020-B5AD-A41DF1933103}
    [2010/01/06 17:56:18 | 000,000,000 | ---D | M] (Timezone Definitions for Mozilla Calendar) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\CALENDAR-TIMEZONES@MOZILLA.ORG
    [2010/01/06 17:56:22 | 000,000,000 | ---D | M] (Talkback) -- C:\PROGRAM FILES (X86)\MOZILLA SUNBIRD\EXTENSIONS\TALKBACK@MOZILLA.ORG
    [2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2010/08/23 12:35:04 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
    [2012/06/15 11:21:06 | 000,129,144 | ---- | M] (RealPlayer) -- C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
    [2011/08/21 15:52:22 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old

    ========== Chrome ==========

    CHR - homepage: http://lenovo.msn.com/
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://lenovo.msn.com/
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Vivek\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
    CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
    CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
    CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
    CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
    CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Vivek\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
    CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
    CHR - plugin: Move Streaming Media Player (Enabled) = C:\Users\Vivek\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.