TechSpot

I have the "Hard drive clusters are partly damaged" virus

Solved
By Mominator
Mar 25, 2012
  1. Looks like my daughter's computer has the "Hard drive clusters are partly damaged" virus. Please help! Logs are pasted below. Thanks in advance.

    .......................................................................................................................
    Malwarebytes Anti-Malware 1.60.1.1000
    www.malwarebytes.org

    Database version: v2012.03.24.02

    Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
    Internet Explorer 9.0.8112.16421
    Jurcoi2 :: JURCOI2-PC [administrator]

    3/26/2012 1:16:22 AM
    mbam-log-2012-03-26 (01-16-22).txt

    Scan type: Custom scan
    Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P
    Objects scanned: 1
    Time elapsed: 8 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)

    .................................................................................................................................

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 1/28/2010 12:40:39 PM
    System Uptime: 3/26/2012 12:52:55 AM (1 hours ago)
    .
    Motherboard: Dell Inc. | | 0K138P
    Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz | Microprocessor | 2194/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 283 GiB total, 108.48 GiB free.
    D: is CDROM ()
    E: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Description: Security Processor Loader Driver
    Device ID: ROOT\LEGACY_SPLDR\0000
    Manufacturer:
    Name: Security Processor Loader Driver
    PNP Device ID: ROOT\LEGACY_SPLDR\0000
    Service: spldr
    .
    Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
    Description: Canon MX700 ser Network
    Device ID: ROOT\CANON_IJ_NETWORK\0000
    Manufacturer: Canon
    Name: Canon MX700 ser Network
    PNP Device ID: ROOT\CANON_IJ_NETWORK\0000
    Service: StillCam
    .
    ==== System Restore Points ===================
    .
    RP155: 3/21/2012 1:46:43 PM - Windows Update
    RP156: 3/22/2012 6:21:17 PM - Windows Update
    RP158: 3/24/2012 2:24:03 PM - Windows Update
    .
    ==== Hosts File Hijack ======================
    .
    Hosts: 149.5.18.172 www.google-analytics.com.
    Hosts: 149.5.18.172 ad-emea.doubleclick.net.
    Hosts: 149.5.18.172 www.statcounter.com.
    Hosts: 108.163.215.51 www.google-analytics.com.
    Hosts: 108.163.215.51 ad-emea.doubleclick.net.
    Hosts: 108.163.215.51 www.statcounter.com.
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    Adobe Common File Installer
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 11 ActiveX
    Adobe Help Center 2.1
    Adobe Photoshop Elements 5.0
    Adobe Photoshop Lightroom
    Adobe Premiere Elements 3.0
    Adobe Reader 9.1.2
    Adobe Shockwave Player 11.5
    Advanced Audio FX Engine
    Apple Application Support
    Apple Software Update
    Ask Toolbar
    Banctec Service Agreement
    CameraHelperMsi
    Canon IJ Network Scan Utility
    Canon IJ Network Tool
    Cisco EAP-FAST Module
    Cisco LEAP Module
    Cisco PEAP Module
    Compatibility Pack for the 2007 Office system
    CSE HTML Validator Lite v11.01
    CuteFTP 8 Home
    Dell DataSafe Local Backup - Support Software
    Dell Getting Started Guide
    Dell Webcam Central
    Digital Photo Navigator 1.5
    erLT
    Google Earth Plug-in
    Google Toolbar for Internet Explorer
    Google Update Helper
    GoToAssist 8.0.0.514
    IDT Audio
    Java Auto Updater
    Java(TM) 6 Update 23
    Junk Mail filter update
    Live! Cam Avatar Creator
    Logitech Vid HD
    Logitech Webcam Software
    LWS Facebook
    LWS Gallery
    LWS Help_main
    LWS Launcher
    LWS Motion Detection
    LWS Pictures And Video
    LWS Twitter
    LWS Video Mask Maker
    LWS Webcam Software
    LWS WLM Plugin
    LWS YouTube Plugin
    Macromedia Dreamweaver 8
    Macromedia Extension Manager
    Macromedia Fireworks 8
    Macromedia Flash 8
    Macromedia Flash 8 Video Encoder
    Malwarebytes Anti-Malware version 1.60.1.1000
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft Choice Guard
    Microsoft Default Manager
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Outlook Personal Folders Backup
    Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
    Microsoft Search Enhancement Pack
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft Works
    Mozilla Firefox (3.6.13)
    MSN Toolbar
    MSN Toolbar Platform
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MuseScore 1.0 MuseScore score typesetter
    Origin
    Pando Media Booster
    Picasa 3
    Pixel Ruler
    PowerCinema NE for Everio
    PowerDirector Express
    PowerDVD DX
    PowerISO
    PowerProducer
    QuickTime
    Roxio Burn
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
    Skype Toolbars
    Skype™ 5.0
    Spotify
    Super TextTwist
    The Lord of the Rings Online™ v03.02.05.8032
    The Sims™ 3 Pets Create A Pet Demo
    Unity Web Player
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    WildBit Viewer
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Movie Maker
    Windows Live Photo Gallery
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    .
    ==== Event Viewer Messages From Past Week ========
    .
    3/26/2012 12:58:06 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    3/26/2012 12:57:30 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
    3/26/2012 12:53:48 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    3/26/2012 12:53:48 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    3/26/2012 12:53:37 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error Code: 21
    3/26/2012 12:53:35 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    3/26/2012 12:53:29 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    3/26/2012 12:53:28 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache SCDEmu spldr Wanarpv6
    3/26/2012 12:40:51 AM, Error: Service Control Manager [7023] - The Software Protection service terminated with the following error: The media is write protected.
    3/26/2012 12:40:51 AM, Error: Service Control Manager [7023] - The Security Center service terminated with the following error: The authentication service is unknown.
    3/26/2012 12:22:15 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
    3/26/2012 1:00:14 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {395633B1-EED9-4DFC-B67F-9788B51C9F06}
    3/25/2012 6:07:46 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8000358d7da, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 032512-259757-01.
    3/25/2012 3:25:35 PM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0.
    3/25/2012 3:12:59 PM, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -93602 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->65.55.21.20:123) is working properly.
    3/25/2012 10:30:15 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
    3/25/2012 10:24:41 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffffa800811fde4, 0x0000000000000001, 0xfffff800032c5024, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 032512-63055-01.
    3/23/2012 6:54:18 PM, Error: Service Control Manager [7038] - The mfevtp service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    3/23/2012 6:54:18 PM, Error: Service Control Manager [7001] - The McAfee McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The service did not start due to a logon failure.
    3/23/2012 6:54:18 PM, Error: Service Control Manager [7000] - The McAfee Validation Trust Protection Service service failed to start due to the following error: The service did not start due to a logon failure.
    3/23/2012 6:54:13 PM, Error: Service Control Manager [7031] - The McAfee McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
    3/23/2012 6:45:03 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800032be32f, 0x0000000000000000, 0x000007fffffa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 032312-34304-01.
    3/23/2012 11:39:22 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
    3/22/2012 8:14:32 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
    3/22/2012 7:09:52 PM, Error: Service Control Manager [7022] - The SSDP Discovery service hung on starting.
    3/22/2012 7:09:52 PM, Error: Service Control Manager [7001] - The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: After starting, the service hung in a start-pending state.
    3/22/2012 7:08:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
    3/22/2012 7:06:46 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
    3/22/2012 7:04:31 PM, Error: Service Control Manager [7022] - The Function Discovery Resource Publication service hung on starting.
    3/22/2012 12:59:26 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024882
    3/22/2012 12:59:25 AM, Error: Service Control Manager [7001] - The Internet Connection Sharing (ICS) service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:59:24 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Adobe Active File Monitor V5 service to connect.
    3/22/2012 12:59:24 AM, Error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the Windows Firewall service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:59:24 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:59:24 AM, Error: Service Control Manager [7000] - The Adobe Active File Monitor V5 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    3/22/2012 12:59:23 AM, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:59:23 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the Network Store Interface Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:59:23 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Network Store Interface Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7038] - The wscsvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7038] - The sppsvc service was unable to log on as NT AUTHORITY\NetworkService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7038] - The FontCache service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not start due to a logon failure.
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7000] - The Software Protection service failed to start due to the following error: The service did not start due to a logon failure.
    3/22/2012 12:49:57 AM, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The service did not start due to a logon failure.
    3/22/2012 1:07:28 AM, Error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the Windows Firewall service which failed to start because of the following error: The dependency service or group failed to start.
    3/22/2012 1:07:27 AM, Error: Service Control Manager [7001] - The WLAN AutoConfig service depends on the Extensible Authentication Protocol service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 1:07:27 AM, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 1:07:27 AM, Error: Service Control Manager [7001] - The System Event Notification Service service depends on the COM+ Event System service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 1:07:26 AM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Multimedia Class Scheduler service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/22/2012 1:05:55 AM, Error: Service Control Manager [7001] - The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/20/2012 2:34:02 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
    3/19/2012 7:52:29 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000002000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff800032b0045). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 031912-45552-01.
    3/19/2012 3:36:02 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000005000000dd, 0x0000000000000002, 0x0000000000000001, 0xfffff800032fa045). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 031912-24133-01.
    .
    ==== End Of File ===========================
    ............................................................................................................................
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORK
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_23
    Run by Jurcoi2 at 1:06:15 on 2012-03-26
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4058.3428 [GMT -5:00]
    .
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\ctfmon.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    -netsvcs
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
    BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120325173457.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
    BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\npwinext.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
    TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\npwinext.dll
    TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
    uRun: [Logitech Vid] "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
    mRun: [MSN Toolbar] "C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\mswinext.exe"
    mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe"
    dRun: [Update] rundll32.exe "C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Microsoft\zchvwceaw.dll",DllRegisterServer
    dRun: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe
    StartupFolder: C:\Users\Jurcoi2\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    StartupFolder: C:\Users\Jurcoi2\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: Interfaces\{5DAB5A88-654E-4B40-97C5-C96328F19DA7} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{84ED95B0-A140-427F-BA25-FB085ADFDF03} : DhcpNameServer = 192.168.254.254 192.168.254.254
    TCP: Interfaces\{84ED95B0-A140-427F-BA25-FB085ADFDF03}\05F6E697E65647 : DhcpNameServer = 198.176.160.66 198.176.160.68
    TCP: Interfaces\{84ED95B0-A140-427F-BA25-FB085ADFDF03}\A4572736F696 : DhcpNameServer = 192.168.254.254 192.168.254.254
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
    BHO-X64: AskBar BHO - No File
    BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
    BHO-X64: McAfee Phishing Filter - No File
    BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    BHO-X64: Search Helper - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120325173457.dll
    BHO-X64: scriptproxy - No File
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
    BHO-X64: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\npwinext.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
    TB-X64: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
    TB-X64: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\npwinext.dll
    TB-X64: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB-X64: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
    mRun-x64: [MSN Toolbar] "C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\mswinext.exe"
    mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun-x64: [Adobe Photo Downloader] "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe"
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    Hosts: 149.5.18.172 www.google-analytics.com.
    Hosts: 149.5.18.172 ad-emea.doubleclick.net.
    Hosts: 149.5.18.172 www.statcounter.com.
    Hosts: 108.163.215.51 www.google-analytics.com.
    Hosts: 108.163.215.51 ad-emea.doubleclick.net.
    .
    Note: multiple HOSTS entries found. Please refer to Attach.txt
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Jurcoi2\AppData\Roaming\Mozilla\Firefox\Profiles\ft2v7rkg.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=MSGTDF&PC=MSNG&q=
    FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com
    FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=MSGTDF&PC=MSNG&q=
    FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0360.0\npwinext.dll
    FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Users\Jurcoi2\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
    FF - Ext: tektek.org GaiaOnline Toolbar 2.1: {0df7b3bb-9581-44bb-835f-061a29ec8a46} - %profile%\extensions\{0df7b3bb-9581-44bb-835f-061a29ec8a46}
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
    R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-8-27 249936]
    R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2010-8-14 208536]
    R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-8-14 161168]
    R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
    S2 AESTFilters;Andrea ST Filters Service;C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe [2010-1-21 89600]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
    S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-3-6 652360]
    S2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-8-27 249936]
    S2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-8-27 249936]
    S2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2010-8-14 199272]
    S2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-4-1 428640]
    S3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
    S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
    S3 LVUVC64;Logitech HD Webcam C510(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
    S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    S3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
    S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-12 136176]
    S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-12 136176]
    .
    =============== Created Last 30 ================
    .
    2012-03-26 05:54:13 20480 ----a-w- C:\Windows\svchost.exe
    2012-03-25 22:34:57 28760 ---ha-w- C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{D19CA586-DD6C-4a0a-96F8-14644F340D60}\components\scriptff.dll
    2012-03-17 04:35:41 5120 ---ha-w- C:\ProgramData\Microsoft\Windows\DRM\5AC8.tmp
    2012-03-17 04:35:41 5120 ---ha-w- C:\ProgramData\Microsoft\Windows\DRM\5AC7.tmp
    2012-03-14 05:48:19 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-03-14 05:48:18 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-14 05:48:18 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-13 21:52:45 3145728 ----a-w- C:\Windows\System32\win32k.sys
    2012-03-13 21:52:41 1544192 ----a-w- C:\Windows\System32\DWrite.dll
    2012-03-13 21:52:40 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-03-13 17:08:44 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-03-13 17:08:44 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-03-13 17:08:44 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-03-13 17:08:44 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-03-13 17:08:41 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2012-03-13 17:08:40 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-03-13 17:08:40 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-03-12 15:50:03 -------- d--h--w- C:\Users\Jurcoi2\AppData\Local\Spotify
    2012-03-12 15:48:42 -------- d--h--w- C:\Users\Jurcoi2\AppData\Roaming\Spotify
    2012-03-12 00:11:52 -------- d--h--w- C:\Users\Jurcoi2\AppData\Roaming\ColorCop
    2012-03-10 22:36:41 -------- d--h--w- C:\Users\Jurcoi2\AppData\Roaming\Desktop Apps
    2012-03-10 22:36:35 -------- d--h--w- C:\Program Files (x86)\Mioplanet
    2012-03-08 00:32:10 162664 ---ha-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
    2012-03-06 17:16:23 -------- d--h--w- C:\Program Files (x86)\HTMLValidatorLite110
    .
    ==================== Find3M ====================
    .
    2012-02-23 15:15:52 5055584 ----a-w- C:\Windows\SysWow64\csevalidator.dll
    2012-01-04 10:44:20 509952 ----a-w- C:\Windows\System32\ntshrui.dll
    2012-01-04 08:58:41 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2011-12-30 06:26:08 515584 ----a-w- C:\Windows\System32\timedate.cpl
    2011-12-30 05:27:56 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
    2011-12-28 03:59:24 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
    .
    ============= FINISH: 1:08:59.23 ===============
     
  2. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ====================================================================

    Any particular reason why all scans were run from safe mode?

    I still need GMER log.
     
  3. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Part of the issue on the computer is that "search" is not finding things, and files are not showing up under C: directories. I think this is why I didn't include one last night.
    I reran today and GMER seems not to be producing a log.

    I ran in safe mode last night because when not "safe" I would get the multiple multiple multiple virus error screens.
     
  4. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Also, now I am not able to get into safe mode on that computer.
     
  5. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    You can't boot into any mode?
     
  6. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    I can get into regular windows which seems to be working now, but for some reason I can't get into "safe" mode now. I don't think it's a "user" problem: F8 at startup, right?
     
  7. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

    ===============================================================

    Download Bootkit Remover to your desktop.

    • Unzip downloaded file to your Desktop.
    • Double-click on boot_cleaner.exe to run the program (Vista/7 users,right click on boot_cleaner.exe and click Run As Administrator).
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.
     
  8. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Here is the aswmbr log:
    ........................................................................................................
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-03-26 18:37:00
    -----------------------------
    18:37:00.645 OS Version: Windows x64 6.1.7601 Service Pack 1
    18:37:00.645 Number of processors: 2 586 0x170A
    18:37:00.646 ComputerName: JURCOI2-PC UserName: Jurcoi2
    18:37:01.620 Initialize success
    18:37:06.630 AVAST engine download error: 0
    18:37:13.486 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
    18:37:13.489 Disk 0 Vendor: WDC_WD3200BEVT-75ZCT2 11.01A11 Size: 305245MB BusType: 11
    18:37:13.491 Device \Driver\atapi -> MajorFunction fffffa8004ad75c4
    18:37:13.494 Disk 0 MBR read successfully
    18:37:13.498 Disk 0 MBR scan
    18:37:13.501 Disk 0 TDL4@MBR code has been found
    18:37:13.504 Disk 0 Windows 7 default MBR code found via API
    18:37:13.507 Disk 0 MBR hidden
    18:37:13.511 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
    18:37:13.529 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 81920
    18:37:13.539 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290204 MB offset 30801920
    18:37:13.544 Disk 0 MBR [TDL4] **ROOTKIT**
    18:37:13.549 Disk 0 trace - called modules:
    18:37:13.557 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8004ad75c4]<<
    18:37:13.563 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045ff060]
    18:37:13.569 3 CLASSPNP.SYS[fffff88001b9943f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800412e060]
    18:37:13.575 \Driver\atapi[0xfffffa800465ed40] -> IRP_MJ_CREATE -> 0xfffffa8004ad75c4
    18:37:13.581 Scan finished successfully
    18:37:40.573 Disk 0 MBR has been saved successfully to "F:\MBR.dat"
    18:37:40.604 The log file has been saved successfully to "F:\aswMBR.txt"
     
  9. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  10. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    The Bootkit remover says some of the physical disk is hidden by a rootkit.
    I should disinfect by issuing the command remover.exe <device name>.
    Where do i find the device name?
     
  11. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    No.
    Go ahead with TDSSKiller.
     
     
  12. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    I ran TDSKiller and it found and removed a rootkit.
    I boooted the computer back up and it still looks the same: few programs and files are listed. Ie, programs and files appear to be missing so it seems a virus is still active?
     
  13. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    [​IMG]

    I need TDSSKiller log.
     
  14. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Here is part one (too long for one post):
    .............................................................................................................
    20:59:59.0919 3060 TDSS rootkit removing tool 2.7.22.0 Mar 21 2012 17:40:00
    20:59:59.0945 3060 ============================================================
    20:59:59.0945 3060 Current date / time: 2012/03/26 20:59:59.0945
    20:59:59.0945 3060 SystemInfo:
    20:59:59.0945 3060
    20:59:59.0945 3060 OS Version: 6.1.7601 ServicePack: 1.0
    20:59:59.0945 3060 Product type: Workstation
    20:59:59.0945 3060 ComputerName: JURCOI2-PC
    20:59:59.0946 3060 UserName: Jurcoi2
    20:59:59.0946 3060 Windows directory: C:\Windows
    20:59:59.0946 3060 System windows directory: C:\Windows
    20:59:59.0946 3060 Running under WOW64
    20:59:59.0946 3060 Processor architecture: Intel x64
    20:59:59.0946 3060 Number of processors: 2
    20:59:59.0946 3060 Page size: 0x1000
    20:59:59.0946 3060 Boot type: Normal boot
    20:59:59.0946 3060 ============================================================
    21:00:01.0442 3060 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    21:00:01.0458 3060 Drive \Device\Harddisk1\DR2 - Size: 0xEEF80000 (3.73 Gb), SectorSize: 0x200, Cylinders: 0x1E7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    21:00:01.0461 3060 \Device\Harddisk0\DR0:
    21:00:01.0461 3060 MBR used
    21:00:01.0461 3060 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000
    21:00:01.0461 3060 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x236CE2B0
    21:00:01.0461 3060 \Device\Harddisk1\DR2:
    21:00:01.0462 3060 MBR used
    21:00:01.0462 3060 \Device\Harddisk1\DR2\Partition0: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0x777BE0
    21:00:01.0502 3060 Initialize success
    21:00:01.0502 3060 ============================================================
    21:00:08.0415 4600 ============================================================
    21:00:08.0415 4600 Scan started
    21:00:08.0415 4600 Mode: Manual;
    21:00:08.0415 4600 ============================================================
    21:00:10.0234 4600 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
    21:00:10.0280 4600 1394ohci - ok
    21:00:10.0366 4600 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
    21:00:10.0368 4600 ACPI - ok
    21:00:10.0389 4600 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
    21:00:10.0432 4600 AcpiPmi - ok
    21:00:10.0544 4600 AdobeActiveFileMonitor5.0 (177ff6608b48638d4066726f3a3f8444) C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    21:00:10.0545 4600 AdobeActiveFileMonitor5.0 - ok
    21:00:10.0698 4600 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    21:00:10.0710 4600 adp94xx - ok
    21:00:10.0778 4600 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    21:00:10.0790 4600 adpahci - ok
    21:00:10.0814 4600 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    21:00:10.0822 4600 adpu320 - ok
    21:00:10.0855 4600 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    21:00:10.0857 4600 AeLookupSvc - ok
    21:00:10.0961 4600 AESTFilters (a6fb9db8f1a86861d955fd6975977ae0) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
    21:00:10.0962 4600 AESTFilters - ok
    21:00:11.0044 4600 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
    21:00:11.0095 4600 AFD - ok
    21:00:11.0175 4600 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
    21:00:11.0180 4600 agp440 - ok
    21:00:11.0243 4600 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    21:00:11.0249 4600 ALG - ok
    21:00:11.0292 4600 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
    21:00:11.0297 4600 aliide - ok
    21:00:11.0308 4600 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
    21:00:11.0311 4600 amdide - ok
    21:00:11.0375 4600 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    21:00:11.0379 4600 AmdK8 - ok
    21:00:11.0403 4600 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    21:00:11.0407 4600 AmdPPM - ok
    21:00:11.0452 4600 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
    21:00:11.0499 4600 amdsata - ok
    21:00:11.0549 4600 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    21:00:11.0558 4600 amdsbs - ok
    21:00:11.0581 4600 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
    21:00:11.0627 4600 amdxata - ok
    21:00:11.0696 4600 ApfiltrService (3cc4531f11648a6081a7ba3aa4924d04) C:\Windows\system32\DRIVERS\Apfiltr.sys
    21:00:11.0745 4600 ApfiltrService - ok
    21:00:11.0816 4600 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
    21:00:11.0859 4600 AppID - ok
    21:00:11.0886 4600 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    21:00:11.0890 4600 AppIDSvc - ok
    21:00:11.0940 4600 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
    21:00:11.0941 4600 Appinfo - ok
    21:00:12.0026 4600 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    21:00:12.0030 4600 arc - ok
    21:00:12.0046 4600 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    21:00:12.0053 4600 arcsas - ok
    21:00:12.0176 4600 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    21:00:12.0182 4600 AsyncMac - ok
    21:00:12.0240 4600 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
    21:00:12.0241 4600 atapi - ok
    21:00:12.0335 4600 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
    21:00:12.0348 4600 AudioEndpointBuilder - ok
    21:00:12.0360 4600 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
    21:00:12.0365 4600 AudioSrv - ok
    21:00:12.0452 4600 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
    21:00:12.0487 4600 AxInstSV - ok
    21:00:12.0573 4600 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    21:00:12.0584 4600 b06bdrv - ok
    21:00:12.0685 4600 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    21:00:12.0694 4600 b57nd60a - ok
    21:00:12.0734 4600 BCM42RLY (e001dd475a7c27ebe5a0db45c11bad71) C:\Windows\system32\drivers\BCM42RLY.sys
    21:00:12.0779 4600 BCM42RLY - ok
    21:00:12.0884 4600 BCM43XX (37394d3553e220fb732c21e217e1bd8b) C:\Windows\system32\DRIVERS\bcmwl664.sys
    21:00:12.0902 4600 BCM43XX - ok
    21:00:12.0992 4600 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    21:00:12.0998 4600 BDESVC - ok
    21:00:13.0020 4600 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    21:00:13.0025 4600 Beep - ok
    21:00:13.0104 4600 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
    21:00:13.0121 4600 BFE - ok
    21:00:13.0216 4600 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
    21:00:13.0238 4600 BITS - ok
    21:00:13.0364 4600 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    21:00:13.0370 4600 blbdrive - ok
    21:00:13.0441 4600 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
    21:00:13.0484 4600 bowser - ok
    21:00:13.0505 4600 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    21:00:13.0511 4600 BrFiltLo - ok
    21:00:13.0526 4600 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    21:00:13.0532 4600 BrFiltUp - ok
    21:00:13.0577 4600 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
    21:00:13.0579 4600 Browser - ok
    21:00:13.0611 4600 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    21:00:13.0620 4600 Brserid - ok
    21:00:13.0646 4600 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    21:00:13.0651 4600 BrSerWdm - ok
    21:00:13.0683 4600 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    21:00:13.0687 4600 BrUsbMdm - ok
    21:00:13.0701 4600 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    21:00:13.0705 4600 BrUsbSer - ok
    21:00:13.0724 4600 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    21:00:13.0728 4600 BTHMODEM - ok
    21:00:13.0764 4600 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    21:00:13.0768 4600 bthserv - ok
    21:00:13.0809 4600 catchme - ok
    21:00:13.0855 4600 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    21:00:13.0861 4600 cdfs - ok
    21:00:13.0928 4600 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
    21:00:13.0972 4600 cdrom - ok
    21:00:14.0033 4600 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
    21:00:14.0035 4600 CertPropSvc - ok
    21:00:14.0113 4600 cfwids (ed0263b2eb24f0f4e3898036fa1d28a1) C:\Windows\system32\drivers\cfwids.sys
    21:00:14.0158 4600 cfwids - ok
    21:00:14.0246 4600 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    21:00:14.0249 4600 circlass - ok
    21:00:14.0312 4600 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    21:00:14.0324 4600 CLFS - ok
    21:00:14.0444 4600 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    21:00:14.0447 4600 clr_optimization_v2.0.50727_32 - ok
    21:00:14.0503 4600 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    21:00:14.0505 4600 clr_optimization_v2.0.50727_64 - ok
    21:00:14.0564 4600 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    21:00:14.0567 4600 clr_optimization_v4.0.30319_32 - ok
    21:00:14.0615 4600 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    21:00:14.0617 4600 clr_optimization_v4.0.30319_64 - ok
    21:00:14.0762 4600 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    21:00:14.0766 4600 CmBatt - ok
    21:00:14.0800 4600 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
    21:00:14.0804 4600 cmdide - ok
    21:00:14.0847 4600 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
    21:00:14.0888 4600 CNG - ok
    21:00:14.0932 4600 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    21:00:14.0938 4600 Compbatt - ok
    21:00:15.0063 4600 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
    21:00:15.0113 4600 CompositeBus - ok
    21:00:15.0143 4600 COMSysApp - ok
    21:00:15.0176 4600 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    21:00:15.0179 4600 crcdisk - ok
    21:00:15.0252 4600 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
    21:00:15.0288 4600 CryptSvc - ok
    21:00:15.0394 4600 CtClsFlt (ed5cf92396a62f4c15110dcdb5e854d9) C:\Windows\system32\DRIVERS\CtClsFlt.sys
    21:00:15.0439 4600 CtClsFlt - ok
    21:00:15.0548 4600 dc3d (db0459afd124ce5ccb649e33f95d715f) C:\Windows\system32\DRIVERS\dc3d.sys
    21:00:15.0592 4600 dc3d - ok
    21:00:15.0660 4600 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
    21:00:15.0678 4600 DcomLaunch - ok
    21:00:15.0784 4600 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    21:00:15.0794 4600 defragsvc - ok
    21:00:15.0875 4600 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
    21:00:15.0918 4600 DfsC - ok
    21:00:15.0981 4600 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
    21:00:16.0019 4600 Dhcp - ok
    21:00:16.0055 4600 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    21:00:16.0059 4600 discache - ok
    21:00:16.0118 4600 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    21:00:16.0124 4600 Disk - ok
    21:00:16.0166 4600 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
    21:00:16.0169 4600 Dnscache - ok
    21:00:16.0258 4600 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe
    21:00:16.0260 4600 DockLoginService - ok
    21:00:16.0307 4600 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
    21:00:16.0345 4600 dot3svc - ok
    21:00:16.0390 4600 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
    21:00:16.0394 4600 DPS - ok
    21:00:16.0517 4600 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    21:00:16.0522 4600 drmkaud - ok
    21:00:16.0588 4600 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
    21:00:16.0620 4600 DXGKrnl - ok
    21:00:16.0682 4600 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    21:00:16.0684 4600 EapHost - ok
    21:00:16.0803 4600 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    21:00:16.0963 4600 ebdrv - ok
    21:00:17.0003 4600 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
    21:00:17.0005 4600 EFS - ok
    21:00:17.0091 4600 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
    21:00:17.0110 4600 ehRecvr - ok
    21:00:17.0147 4600 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    21:00:17.0150 4600 ehSched - ok
    21:00:17.0216 4600 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    21:00:17.0239 4600 elxstor - ok
    21:00:17.0273 4600 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
    21:00:17.0278 4600 ErrDev - ok
    21:00:17.0356 4600 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    21:00:17.0362 4600 EventSystem - ok
    21:00:17.0411 4600 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    21:00:17.0419 4600 exfat - ok
    21:00:17.0451 4600 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    21:00:17.0459 4600 fastfat - ok
    21:00:17.0527 4600 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
    21:00:17.0543 4600 Fax - ok
    21:00:17.0565 4600 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    21:00:17.0569 4600 fdc - ok
    21:00:17.0606 4600 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    21:00:17.0607 4600 fdPHost - ok
    21:00:17.0644 4600 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    21:00:17.0648 4600 FDResPub - ok
    21:00:17.0662 4600 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    21:00:17.0665 4600 FileInfo - ok
    21:00:17.0685 4600 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    21:00:17.0688 4600 Filetrace - ok
    21:00:17.0717 4600 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    21:00:17.0721 4600 flpydisk - ok
    21:00:17.0789 4600 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
    21:00:17.0826 4600 FltMgr - ok
    21:00:17.0870 4600 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
    21:00:17.0937 4600 FontCache - ok
    21:00:18.0018 4600 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    21:00:18.0019 4600 FontCache3.0.0.0 - ok
    21:00:18.0054 4600 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    21:00:18.0059 4600 FsDepends - ok
    21:00:18.0073 4600 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    21:00:18.0076 4600 Fs_Rec - ok
    21:00:18.0155 4600 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
    21:00:18.0203 4600 fvevol - ok
    21:00:18.0223 4600 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    21:00:18.0229 4600 gagp30kx - ok
    21:00:18.0299 4600 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
    21:00:18.0300 4600 GoToAssist - ok
    21:00:18.0359 4600 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
    21:00:18.0411 4600 gpsvc - ok
    21:00:18.0546 4600 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:00:18.0547 4600 gupdate - ok
    21:00:18.0576 4600 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:00:18.0577 4600 gupdatem - ok
    21:00:18.0709 4600 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    21:00:18.0711 4600 gusvc - ok
    21:00:18.0806 4600 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    21:00:18.0810 4600 hcw85cir - ok
    21:00:18.0916 4600 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
    21:00:18.0965 4600 HdAudAddService - ok
    21:00:19.0021 4600 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
    21:00:19.0022 4600 HDAudBus - ok
    21:00:19.0048 4600 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    21:00:19.0051 4600 HidBatt - ok
    21:00:19.0098 4600 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    21:00:19.0102 4600 HidBth - ok
    21:00:19.0152 4600 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    21:00:19.0155 4600 HidIr - ok
    21:00:19.0199 4600 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
    21:00:19.0205 4600 hidserv - ok
    21:00:19.0252 4600 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
    21:00:19.0296 4600 HidUsb - ok
    21:00:19.0354 4600 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
    21:00:19.0357 4600 hkmsvc - ok
    21:00:19.0407 4600 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
    21:00:19.0412 4600 HomeGroupListener - ok
    21:00:19.0463 4600 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
    21:00:19.0500 4600 HomeGroupProvider - ok
    21:00:19.0532 4600 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
    21:00:19.0578 4600 HpSAMD - ok
    21:00:19.0646 4600 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
    21:00:19.0663 4600 HTTP - ok
    21:00:19.0716 4600 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
    21:00:19.0750 4600 hwpolicy - ok
    21:00:19.0811 4600 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
    21:00:19.0818 4600 i8042prt - ok
    21:00:19.0900 4600 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
    21:00:19.0953 4600 iaStorV - ok
    21:00:20.0040 4600 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    21:00:20.0057 4600 idsvc - ok
    21:00:20.0325 4600 igfx (677aa5991026a65ada128c4b59cf2bad) C:\Windows\system32\DRIVERS\igdkmd64.sys
    21:00:20.0621 4600 igfx - ok
    21:00:20.0821 4600 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    21:00:20.0827 4600 iirsp - ok
    21:00:20.0904 4600 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
    21:00:20.0924 4600 IKEEXT - ok
    21:00:20.0977 4600 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
    21:00:20.0980 4600 intelide - ok
    21:00:21.0050 4600 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    21:00:21.0051 4600 intelppm - ok
    21:00:21.0095 4600 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    21:00:21.0102 4600 IPBusEnum - ok
    21:00:21.0167 4600 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:00:21.0211 4600 IpFilterDriver - ok
    21:00:21.0250 4600 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
    21:00:21.0268 4600 iphlpsvc - ok
    21:00:21.0321 4600 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
    21:00:21.0365 4600 IPMIDRV - ok
    21:00:21.0407 4600 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    21:00:21.0414 4600 IPNAT - ok
    21:00:21.0470 4600 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    21:00:21.0474 4600 IRENUM - ok
    21:00:21.0494 4600 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
    21:00:21.0498 4600 isapnp - ok
    21:00:21.0531 4600 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
    21:00:21.0581 4600 iScsiPrt - ok
    21:00:21.0634 4600 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
    21:00:21.0641 4600 kbdclass - ok
    21:00:21.0693 4600 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
    21:00:21.0736 4600 kbdhid - ok
    21:00:21.0840 4600 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    21:00:21.0842 4600 KeyIso - ok
    21:00:21.0865 4600 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
    21:00:21.0901 4600 KSecDD - ok
    21:00:21.0955 4600 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
    21:00:22.0002 4600 KSecPkg - ok
    21:00:22.0074 4600 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    21:00:22.0078 4600 ksthunk - ok
    21:00:22.0118 4600 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    21:00:22.0131 4600 KtmRm - ok
    21:00:22.0213 4600 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
    21:00:22.0218 4600 LanmanServer - ok
    21:00:22.0288 4600 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
    21:00:22.0292 4600 LanmanWorkstation - ok
    21:00:22.0385 4600 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    21:00:22.0390 4600 lltdio - ok
    21:00:22.0434 4600 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    21:00:22.0443 4600 lltdsvc - ok
    21:00:22.0467 4600 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    21:00:22.0473 4600 lmhosts - ok
    21:00:22.0533 4600 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    21:00:22.0538 4600 LSI_FC - ok
    21:00:22.0561 4600 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    21:00:22.0565 4600 LSI_SAS - ok
    21:00:22.0592 4600 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    21:00:22.0596 4600 LSI_SAS2 - ok
    21:00:22.0617 4600 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    21:00:22.0623 4600 LSI_SCSI - ok
    21:00:22.0671 4600 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    21:00:22.0675 4600 luafv - ok
    21:00:22.0788 4600 LVRS64 (ef586b959f747e74c76603ff16ae417b) C:\Windows\system32\DRIVERS\lvrs64.sys
    21:00:22.0839 4600 LVRS64 - ok
    21:00:23.0001 4600 LVUVC64 (edf73bfa1bd24d74d1d64dc0ed28a7cd) C:\Windows\system32\DRIVERS\lvuvc64.sys
    21:00:23.0214 4600 LVUVC64 - ok
    21:00:23.0357 4600 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
    21:00:23.0401 4600 MBAMProtector - ok
    21:00:23.0545 4600 MBAMService (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    21:00:23.0550 4600 MBAMService - ok
    21:00:23.0654 4600 McMPFSvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:23.0656 4600 McMPFSvc - ok
    21:00:23.0664 4600 mcmscsvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:23.0665 4600 mcmscsvc - ok
    21:00:23.0677 4600 McNaiAnn (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:23.0678 4600 McNaiAnn - ok
    21:00:23.0686 4600 McNASvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:23.0687 4600 McNASvc - ok
    21:00:23.0738 4600 McODS (07b89e7de2f7971cf7eef0262207c4de) C:\Program Files\McAfee\VirusScan\mcods.exe
    21:00:23.0744 4600 McODS - ok
    21:00:23.0768 4600 McProxy (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:23.0770 4600 McProxy - ok
    21:00:23.0876 4600 McShield (325b166bf78d8a8ad93e44ca7a6fc332) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
    21:00:23.0879 4600 McShield - ok
    21:00:23.0998 4600 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
    21:00:24.0036 4600 Mcx2Svc - ok
    21:00:24.0100 4600 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    21:00:24.0105 4600 megasas - ok
    21:00:24.0149 4600 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    21:00:24.0158 4600 MegaSR - ok
    21:00:24.0267 4600 mfeapfk (ef3acfb7e3f82d5f7cde9ef5f0a4e2e2) C:\Windows\system32\drivers\mfeapfk.sys
    21:00:24.0314 4600 mfeapfk - ok
    21:00:24.0374 4600 mfeavfk (e7a60bdb4365b561d896019b82fb7dd0) C:\Windows\system32\drivers\mfeavfk.sys
    21:00:24.0425 4600 mfeavfk - ok
    21:00:24.0455 4600 mfeavfk01 - ok
    21:00:24.0564 4600 mfefire (7d8fdc43972d059907e09ee4022f77e8) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
    21:00:24.0566 4600 mfefire - ok
    21:00:24.0608 4600 mfefirek (670dffe55e2f9ab99d9169c428bcece9) C:\Windows\system32\drivers\mfefirek.sys
    21:00:24.0661 4600 mfefirek - ok
    21:00:24.0692 4600 mfehidk (1892616b7f9291fd77c3fa0a5811fe9f) C:\Windows\system32\drivers\mfehidk.sys
    21:00:24.0780 4600 mfehidk - ok
    21:00:24.0831 4600 mfenlfk (1721261c77f6e7a9e0cb51b7d9f31b60) C:\Windows\system32\DRIVERS\mfenlfk.sys
    21:00:24.0876 4600 mfenlfk - ok
    21:00:24.0939 4600 mferkdet (65776bd8029e409935b90de30bf99526) C:\Windows\system32\drivers\mferkdet.sys
    21:00:24.0985 4600 mferkdet - ok
    21:00:25.0155 4600 mfevtp (8a78905057308b084eaa29a9fe1b4f58) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    21:00:25.0156 4600 mfevtp - ok
    21:00:25.0267 4600 mfewfpk (4f17d8b85b903d96ef7033bb6ef50516) C:\Windows\system32\drivers\mfewfpk.sys
    21:00:25.0318 4600 mfewfpk - ok
    21:00:25.0448 4600 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
    21:00:25.0450 4600 Microsoft Office Groove Audit Service - ok
    21:00:25.0512 4600 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    21:00:25.0514 4600 MMCSS - ok
    21:00:25.0548 4600 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    21:00:25.0551 4600 Modem - ok
    21:00:25.0595 4600 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    21:00:25.0596 4600 monitor - ok
    21:00:25.0657 4600 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
    21:00:25.0663 4600 mouclass - ok
    21:00:25.0721 4600 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    21:00:25.0726 4600 mouhid - ok
    21:00:25.0749 4600 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
    21:00:25.0796 4600 mountmgr - ok
    21:00:25.0830 4600 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
    21:00:25.0877 4600 mpio - ok
    21:00:25.0897 4600 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    21:00:25.0904 4600 mpsdrv - ok
    21:00:25.0962 4600 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
    21:00:25.0983 4600 MpsSvc - ok
    21:00:26.0050 4600 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
    21:00:26.0100 4600 MRxDAV - ok
    21:00:26.0142 4600 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:00:26.0186 4600 mrxsmb - ok
    21:00:26.0241 4600 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:00:26.0288 4600 mrxsmb10 - ok
    21:00:26.0306 4600 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:00:26.0350 4600 mrxsmb20 - ok
    21:00:26.0382 4600 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
    21:00:26.0383 4600 msahci - ok
    21:00:26.0418 4600 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
    21:00:26.0472 4600 msdsm - ok
    21:00:26.0522 4600 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    21:00:26.0530 4600 MSDTC - ok
    21:00:26.0598 4600 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    21:00:26.0603 4600 Msfs - ok
    21:00:26.0619 4600 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    21:00:26.0624 4600 mshidkmdf - ok
    21:00:26.0645 4600 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
    21:00:26.0648 4600 msisadrv - ok
    21:00:26.0700 4600 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    21:00:26.0708 4600 MSiSCSI - ok
    21:00:26.0716 4600 msiserver - ok
    21:00:26.0833 4600 MSK80Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    21:00:26.0835 4600 MSK80Service - ok
    21:00:26.0964 4600 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    21:00:26.0970 4600 MSKSSRV - ok
    21:00:27.0010 4600 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    21:00:27.0015 4600 MSPCLOCK - ok
    21:00:27.0074 4600 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    21:00:27.0075 4600 MSPQM - ok
    21:00:27.0124 4600 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
    21:00:27.0163 4600 MsRPC - ok
    21:00:27.0189 4600 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
    21:00:27.0190 4600 mssmbios - ok
    21:00:27.0200 4600 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    21:00:27.0206 4600 MSTEE - ok
    21:00:27.0228 4600 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    21:00:27.0233 4600 MTConfig - ok
    21:00:27.0266 4600 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    21:00:27.0273 4600 Mup - ok
    21:00:27.0355 4600 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
    21:00:27.0363 4600 napagent - ok
    21:00:27.0417 4600 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    21:00:27.0426 4600 NativeWifiP - ok
    21:00:27.0465 4600 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
    21:00:27.0471 4600 NDIS - ok
    21:00:27.0526 4600 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    21:00:27.0532 4600 NdisCap - ok
    21:00:27.0582 4600 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    21:00:27.0587 4600 NdisTapi - ok
    21:00:27.0642 4600 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
    21:00:27.0685 4600 Ndisuio - ok
    21:00:27.0703 4600 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
    21:00:27.0748 4600 NdisWan - ok
    21:00:27.0797 4600 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
     
  15. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    and part two:
    .............................................................................................................................
    21:00:27.0841 4600 NDProxy - ok
    21:00:27.0902 4600 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    21:00:27.0907 4600 NetBIOS - ok
    21:00:27.0954 4600 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
    21:00:28.0000 4600 NetBT - ok
    21:00:28.0043 4600 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    21:00:28.0045 4600 Netlogon - ok
    21:00:28.0109 4600 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    21:00:28.0115 4600 Netman - ok
    21:00:28.0160 4600 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    21:00:28.0164 4600 netprofm - ok
    21:00:28.0244 4600 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    21:00:28.0246 4600 NetTcpPortSharing - ok
    21:00:28.0293 4600 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    21:00:28.0297 4600 nfrd960 - ok
    21:00:28.0362 4600 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
    21:00:28.0367 4600 NlaSvc - ok
    21:00:28.0408 4600 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    21:00:28.0411 4600 Npfs - ok
    21:00:28.0441 4600 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    21:00:28.0445 4600 nsi - ok
    21:00:28.0479 4600 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    21:00:28.0483 4600 nsiproxy - ok
    21:00:28.0562 4600 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
    21:00:28.0608 4600 Ntfs - ok
    21:00:28.0699 4600 NuidFltr (d4012918d3a3847b44b888d56bc095d6) C:\Windows\system32\DRIVERS\NuidFltr.sys
    21:00:28.0744 4600 NuidFltr - ok
    21:00:28.0776 4600 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    21:00:28.0781 4600 Null - ok
    21:00:28.0869 4600 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
    21:00:28.0917 4600 nvraid - ok
    21:00:28.0955 4600 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
    21:00:29.0004 4600 nvstor - ok
    21:00:29.0044 4600 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
    21:00:29.0052 4600 nv_agp - ok
    21:00:29.0152 4600 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    21:00:29.0155 4600 odserv - ok
    21:00:29.0208 4600 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
    21:00:29.0214 4600 ohci1394 - ok
    21:00:29.0286 4600 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    21:00:29.0287 4600 ose - ok
    21:00:29.0344 4600 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    21:00:29.0350 4600 p2pimsvc - ok
    21:00:29.0406 4600 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    21:00:29.0410 4600 p2psvc - ok
    21:00:29.0472 4600 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    21:00:29.0477 4600 Parport - ok
    21:00:29.0528 4600 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
    21:00:29.0574 4600 partmgr - ok
    21:00:29.0600 4600 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    21:00:29.0604 4600 PcaSvc - ok
    21:00:29.0717 4600 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\dell support center\pcdsrvc_x64.pkms
    21:00:29.0718 4600 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
    21:00:29.0768 4600 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
    21:00:29.0769 4600 pci - ok
    21:00:29.0798 4600 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
    21:00:29.0804 4600 pciide - ok
    21:00:29.0829 4600 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    21:00:29.0836 4600 pcmcia - ok
    21:00:29.0859 4600 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    21:00:29.0863 4600 pcw - ok
    21:00:29.0896 4600 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    21:00:29.0921 4600 PEAUTH - ok
    21:00:29.0978 4600 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    21:00:29.0980 4600 PerfHost - ok
    21:00:30.0062 4600 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
    21:00:30.0149 4600 pla - ok
    21:00:30.0214 4600 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
    21:00:30.0222 4600 PlugPlay - ok
    21:00:30.0279 4600 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    21:00:30.0286 4600 PNRPAutoReg - ok
    21:00:30.0312 4600 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    21:00:30.0315 4600 PNRPsvc - ok
    21:00:30.0368 4600 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
    21:00:30.0409 4600 PolicyAgent - ok
    21:00:30.0458 4600 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    21:00:30.0463 4600 Power - ok
    21:00:30.0571 4600 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
    21:00:30.0615 4600 PptpMiniport - ok
    21:00:30.0664 4600 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    21:00:30.0668 4600 Processor - ok
    21:00:30.0752 4600 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
    21:00:30.0757 4600 ProfSvc - ok
    21:00:30.0789 4600 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    21:00:30.0791 4600 ProtectedStorage - ok
    21:00:30.0835 4600 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
    21:00:30.0837 4600 Psched - ok
    21:00:30.0926 4600 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys
    21:00:30.0975 4600 PxHlpa64 - ok
    21:00:31.0025 4600 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    21:00:31.0060 4600 ql2300 - ok
    21:00:31.0087 4600 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    21:00:31.0092 4600 ql40xx - ok
    21:00:31.0137 4600 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    21:00:31.0145 4600 QWAVE - ok
    21:00:31.0168 4600 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    21:00:31.0173 4600 QWAVEdrv - ok
    21:00:31.0193 4600 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    21:00:31.0196 4600 RasAcd - ok
    21:00:31.0252 4600 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    21:00:31.0255 4600 RasAgileVpn - ok
    21:00:31.0307 4600 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    21:00:31.0315 4600 RasAuto - ok
    21:00:31.0348 4600 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:00:31.0392 4600 Rasl2tp - ok
    21:00:31.0441 4600 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
    21:00:31.0481 4600 RasMan - ok
    21:00:31.0498 4600 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    21:00:31.0505 4600 RasPppoe - ok
    21:00:31.0566 4600 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    21:00:31.0570 4600 RasSstp - ok
    21:00:31.0618 4600 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
    21:00:31.0666 4600 rdbss - ok
    21:00:31.0696 4600 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    21:00:31.0701 4600 rdpbus - ok
    21:00:31.0736 4600 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:00:31.0739 4600 RDPCDD - ok
    21:00:31.0812 4600 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    21:00:31.0815 4600 RDPENCDD - ok
    21:00:31.0834 4600 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    21:00:31.0837 4600 RDPREFMP - ok
    21:00:31.0882 4600 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
    21:00:31.0928 4600 RDPWD - ok
    21:00:32.0001 4600 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
    21:00:32.0051 4600 rdyboost - ok
    21:00:32.0077 4600 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    21:00:32.0087 4600 RemoteAccess - ok
    21:00:32.0148 4600 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    21:00:32.0155 4600 RemoteRegistry - ok
    21:00:32.0285 4600 RichVideo (4d05898896ec49cf663dda61041ab096) C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    21:00:32.0290 4600 RichVideo - ok
    21:00:32.0334 4600 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    21:00:32.0338 4600 RpcEptMapper - ok
    21:00:32.0379 4600 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    21:00:32.0386 4600 RpcLocator - ok
    21:00:32.0415 4600 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\System32\rpcss.dll
    21:00:32.0422 4600 RpcSs - ok
    21:00:32.0509 4600 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    21:00:32.0514 4600 rspndr - ok
    21:00:32.0541 4600 RSUSBSTOR (4a25dc970c58104602ed274dacafd784) C:\Windows\System32\Drivers\RtsUStor.sys
    21:00:32.0586 4600 RSUSBSTOR - ok
    21:00:32.0636 4600 RTL8167 (b49dc435ae3695bac5623dd94b05732d) C:\Windows\system32\DRIVERS\Rt64win7.sys
    21:00:32.0681 4600 RTL8167 - ok
    21:00:32.0735 4600 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    21:00:32.0736 4600 SamSs - ok
    21:00:32.0783 4600 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
    21:00:32.0830 4600 sbp2port - ok
    21:00:32.0895 4600 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    21:00:32.0903 4600 SCardSvr - ok
    21:00:33.0018 4600 SCDEmu (d3022dba20029f1899b555298a5e95a3) C:\Windows\system32\drivers\SCDEmu.sys
    21:00:33.0064 4600 SCDEmu - ok
    21:00:33.0099 4600 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
    21:00:33.0147 4600 scfilter - ok
    21:00:33.0200 4600 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
    21:00:33.0284 4600 Schedule - ok
    21:00:33.0322 4600 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
    21:00:33.0324 4600 SCPolicySvc - ok
    21:00:33.0390 4600 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
    21:00:33.0394 4600 SDRSVC - ok
    21:00:33.0515 4600 SeaPort (4a5809a1d796e2675ac0332bf7b0cb11) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    21:00:33.0517 4600 SeaPort - ok
    21:00:33.0651 4600 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    21:00:33.0654 4600 secdrv - ok
    21:00:33.0707 4600 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
    21:00:33.0743 4600 seclogon - ok
    21:00:33.0780 4600 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
    21:00:33.0783 4600 SENS - ok
    21:00:33.0870 4600 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    21:00:33.0874 4600 SensrSvc - ok
    21:00:33.0975 4600 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    21:00:33.0979 4600 Serenum - ok
    21:00:34.0027 4600 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    21:00:34.0031 4600 Serial - ok
    21:00:34.0128 4600 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    21:00:34.0132 4600 sermouse - ok
    21:00:34.0194 4600 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
    21:00:34.0231 4600 SessionEnv - ok
    21:00:34.0284 4600 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
    21:00:34.0288 4600 sffdisk - ok
    21:00:34.0325 4600 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
    21:00:34.0330 4600 sffp_mmc - ok
    21:00:34.0341 4600 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
    21:00:34.0384 4600 sffp_sd - ok
    21:00:34.0436 4600 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    21:00:34.0440 4600 sfloppy - ok
    21:00:34.0508 4600 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    21:00:34.0519 4600 SharedAccess - ok
    21:00:34.0583 4600 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
    21:00:34.0589 4600 ShellHWDetection - ok
    21:00:34.0613 4600 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    21:00:34.0618 4600 SiSRaid2 - ok
    21:00:34.0641 4600 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    21:00:34.0647 4600 SiSRaid4 - ok
    21:00:34.0698 4600 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    21:00:34.0705 4600 Smb - ok
    21:00:34.0758 4600 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    21:00:34.0765 4600 SNMPTRAP - ok
    21:00:34.0778 4600 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    21:00:34.0783 4600 spldr - ok
    21:00:34.0835 4600 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
    21:00:34.0894 4600 Spooler - ok
    21:00:35.0023 4600 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
    21:00:35.0046 4600 sppsvc - ok
    21:00:35.0078 4600 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    21:00:35.0085 4600 sppuinotify - ok
    21:00:35.0189 4600 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
    21:00:35.0238 4600 srv - ok
    21:00:35.0292 4600 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
    21:00:35.0339 4600 srv2 - ok
    21:00:35.0419 4600 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
    21:00:35.0464 4600 srvnet - ok
    21:00:35.0513 4600 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    21:00:35.0522 4600 SSDPSRV - ok
    21:00:35.0550 4600 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    21:00:35.0556 4600 SstpSvc - ok
    21:00:35.0656 4600 STacSV (444109453a2b87e6c16bcda5953e81a9) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
    21:00:35.0658 4600 STacSV - ok
    21:00:35.0713 4600 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    21:00:35.0717 4600 stexstor - ok
    21:00:35.0776 4600 STHDA (02e784fa49032f84964db90a3ed81890) C:\Windows\system32\DRIVERS\stwrt64.sys
    21:00:35.0825 4600 STHDA - ok
    21:00:35.0888 4600 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
    21:00:35.0890 4600 StillCam - ok
    21:00:35.0941 4600 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
    21:00:36.0018 4600 stisvc - ok
    21:00:36.0051 4600 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
    21:00:36.0056 4600 swenum - ok
    21:00:36.0133 4600 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    21:00:36.0173 4600 swprv - ok
    21:00:36.0262 4600 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
    21:00:36.0309 4600 SysMain - ok
    21:00:36.0348 4600 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
    21:00:36.0385 4600 TabletInputService - ok
    21:00:36.0447 4600 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
    21:00:36.0486 4600 TapiSrv - ok
    21:00:36.0523 4600 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    21:00:36.0525 4600 TBS - ok
    21:00:36.0619 4600 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
    21:00:36.0665 4600 Tcpip - ok
    21:00:36.0745 4600 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
    21:00:36.0757 4600 TCPIP6 - ok
    21:00:36.0802 4600 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
    21:00:36.0845 4600 tcpipreg - ok
    21:00:36.0888 4600 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    21:00:36.0894 4600 TDPIPE - ok
    21:00:36.0935 4600 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
    21:00:36.0978 4600 TDTCP - ok
    21:00:37.0029 4600 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
    21:00:37.0073 4600 tdx - ok
    21:00:37.0134 4600 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
    21:00:37.0170 4600 TermDD - ok
    21:00:37.0246 4600 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
    21:00:37.0263 4600 TermService - ok
    21:00:37.0323 4600 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    21:00:37.0326 4600 Themes - ok
    21:00:37.0375 4600 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    21:00:37.0377 4600 THREADORDER - ok
    21:00:37.0396 4600 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    21:00:37.0400 4600 TrkWks - ok
    21:00:37.0466 4600 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
    21:00:37.0467 4600 TrustedInstaller - ok
    21:00:37.0523 4600 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:00:37.0567 4600 tssecsrv - ok
    21:00:37.0620 4600 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
    21:00:37.0663 4600 TsUsbFlt - ok
    21:00:37.0723 4600 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
    21:00:37.0768 4600 tunnel - ok
    21:00:37.0794 4600 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    21:00:37.0799 4600 uagp35 - ok
    21:00:37.0839 4600 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
    21:00:37.0887 4600 udfs - ok
    21:00:37.0931 4600 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    21:00:37.0938 4600 UI0Detect - ok
    21:00:37.0970 4600 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
    21:00:37.0975 4600 uliagpkx - ok
    21:00:38.0027 4600 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
    21:00:38.0071 4600 umbus - ok
    21:00:38.0087 4600 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    21:00:38.0090 4600 UmPass - ok
    21:00:38.0275 4600 UMVPFSrv (8b802b483cbde06f62dbc04dc7afaf8e) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    21:00:38.0278 4600 UMVPFSrv - ok
    21:00:38.0451 4600 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    21:00:38.0461 4600 upnphost - ok
    21:00:38.0564 4600 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
    21:00:38.0608 4600 usbaudio - ok
    21:00:38.0652 4600 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
    21:00:38.0696 4600 usbccgp - ok
    21:00:38.0763 4600 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
    21:00:38.0769 4600 usbcir - ok
    21:00:38.0789 4600 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
    21:00:38.0834 4600 usbehci - ok
    21:00:38.0896 4600 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
    21:00:38.0898 4600 usbhub - ok
    21:00:38.0919 4600 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
    21:00:38.0964 4600 usbohci - ok
    21:00:39.0009 4600 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    21:00:39.0013 4600 usbprint - ok
    21:00:39.0058 4600 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
    21:00:39.0062 4600 usbscan - ok
    21:00:39.0081 4600 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    21:00:39.0083 4600 USBSTOR - ok
    21:00:39.0119 4600 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
    21:00:39.0165 4600 usbuhci - ok
    21:00:39.0295 4600 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
    21:00:39.0341 4600 usbvideo - ok
    21:00:39.0416 4600 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    21:00:39.0419 4600 UxSms - ok
    21:00:39.0451 4600 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    21:00:39.0453 4600 VaultSvc - ok
    21:00:39.0552 4600 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
    21:00:39.0557 4600 vdrvroot - ok
    21:00:39.0649 4600 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
    21:00:39.0711 4600 vds - ok
    21:00:39.0780 4600 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    21:00:39.0785 4600 vga - ok
    21:00:39.0811 4600 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    21:00:39.0816 4600 VgaSave - ok
    21:00:39.0857 4600 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
    21:00:39.0906 4600 vhdmp - ok
    21:00:39.0932 4600 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
    21:00:39.0936 4600 viaide - ok
    21:00:39.0960 4600 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
    21:00:40.0007 4600 volmgr - ok
    21:00:40.0037 4600 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
    21:00:40.0091 4600 volmgrx - ok
    21:00:40.0123 4600 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
    21:00:40.0173 4600 volsnap - ok
    21:00:40.0197 4600 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    21:00:40.0205 4600 vsmraid - ok
    21:00:40.0280 4600 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
    21:00:40.0327 4600 VSS - ok
    21:00:40.0394 4600 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
    21:00:40.0397 4600 vwifibus - ok
    21:00:40.0468 4600 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    21:00:40.0474 4600 vwififlt - ok
    21:00:40.0563 4600 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
    21:00:40.0564 4600 vwifimp - ok
    21:00:40.0627 4600 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    21:00:40.0634 4600 W32Time - ok
    21:00:40.0664 4600 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    21:00:40.0669 4600 WacomPen - ok
    21:00:40.0750 4600 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    21:00:40.0795 4600 WANARP - ok
    21:00:40.0828 4600 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    21:00:40.0829 4600 Wanarpv6 - ok
    21:00:40.0931 4600 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    21:00:41.0005 4600 WatAdminSvc - ok
    21:00:41.0076 4600 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
    21:00:41.0157 4600 wbengine - ok
    21:00:41.0225 4600 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    21:00:41.0235 4600 WbioSrvc - ok
    21:00:41.0291 4600 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
    21:00:41.0330 4600 wcncsvc - ok
    21:00:41.0370 4600 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    21:00:41.0375 4600 WcsPlugInService - ok
    21:00:41.0463 4600 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    21:00:41.0469 4600 Wd - ok
    21:00:41.0519 4600 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    21:00:41.0567 4600 Wdf01000 - ok
    21:00:41.0666 4600 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    21:00:41.0669 4600 WdiServiceHost - ok
    21:00:41.0674 4600 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    21:00:41.0677 4600 WdiSystemHost - ok
    21:00:41.0741 4600 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
    21:00:41.0780 4600 WebClient - ok
    21:00:41.0829 4600 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    21:00:41.0839 4600 Wecsvc - ok
    21:00:41.0861 4600 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    21:00:41.0865 4600 wercplsupport - ok
    21:00:41.0910 4600 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    21:00:41.0913 4600 WerSvc - ok
    21:00:41.0989 4600 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    21:00:41.0992 4600 WfpLwf - ok
    21:00:42.0055 4600 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
    21:00:42.0103 4600 WimFltr - ok
    21:00:42.0153 4600 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    21:00:42.0156 4600 WIMMount - ok
    21:00:42.0212 4600 WinDefend - ok
    21:00:42.0217 4600 WinHttpAutoProxySvc - ok
    21:00:42.0313 4600 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    21:00:42.0320 4600 Winmgmt - ok
    21:00:42.0410 4600 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
    21:00:42.0541 4600 WinRM - ok
    21:00:42.0817 4600 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
    21:00:42.0862 4600 WinUsb - ok
    21:00:42.0921 4600 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    21:00:42.0964 4600 Wlansvc - ok
    21:00:43.0122 4600 wlidsvc (98f138897ef4246381d197cb81846d62) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    21:00:43.0137 4600 wlidsvc - ok
    21:00:43.0181 4600 wltrysvc (13b0a570e1ae451c92da550085d72cf3) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    21:00:43.0182 4600 wltrysvc - ok
    21:00:43.0261 4600 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
    21:00:43.0262 4600 WmiAcpi - ok
    21:00:43.0324 4600 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    21:00:43.0327 4600 wmiApSrv - ok
    21:00:43.0361 4600 WMPNetworkSvc - ok
    21:00:43.0406 4600 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    21:00:43.0415 4600 WPCSvc - ok
    21:00:43.0473 4600 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
    21:00:43.0479 4600 WPDBusEnum - ok
    21:00:43.0565 4600 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    21:00:43.0571 4600 ws2ifsl - ok
    21:00:43.0671 4600 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll
    21:00:43.0681 4600 wscsvc - ok
    21:00:43.0694 4600 WSearch - ok
    21:00:43.0833 4600 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
    21:00:43.0905 4600 wuauserv - ok
    21:00:44.0017 4600 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
    21:00:44.0095 4600 WudfPf - ok
    21:00:44.0135 4600 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:00:44.0139 4600 WUDFRd - ok
    21:00:44.0190 4600 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
    21:00:44.0252 4600 wudfsvc - ok
    21:00:44.0286 4600 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    21:00:44.0297 4600 WwanSvc - ok
    21:00:44.0365 4600 MBR (0x1B8) (0f84f2562620c40d8a3e1908c8075675) \Device\Harddisk0\DR0
    21:00:44.0396 4600 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
    21:00:44.0396 4600 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
    21:00:44.0402 4600 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk1\DR2
    21:00:47.0503 4600 \Device\Harddisk1\DR2 - ok
    21:00:47.0550 4600 Boot (0x1200) (844c807994e1622088c74b59aca5fb41) \Device\Harddisk0\DR0\Partition0
    21:00:47.0552 4600 \Device\Harddisk0\DR0\Partition0 - ok
    21:00:47.0572 4600 Boot (0x1200) (87be2bbf7a62d7aaddf58d962791d09e) \Device\Harddisk0\DR0\Partition1
    21:00:47.0573 4600 \Device\Harddisk0\DR0\Partition1 - ok
    21:00:47.0579 4600 Boot (0x1200) (738d2eff6164ee8f91a148496f56e594) \Device\Harddisk1\DR2\Partition0
    21:00:47.0580 4600 \Device\Harddisk1\DR2\Partition0 - ok
    21:00:47.0582 4600 ============================================================
    21:00:47.0582 4600 Scan finished
    21:00:47.0582 4600 ============================================================
    21:00:47.0753 3044 Detected object count: 1
    21:00:47.0753 3044 Actual detected object count: 1
    21:01:03.0253 3044 \Device\Harddisk0\DR0\# - copied to quarantine
    21:01:03.0264 3044 \Device\Harddisk0\DR0 - copied to quarantine
    21:01:03.0450 3044 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
    21:01:11.0335 3044 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
    21:01:16.0992 3044 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
    21:01:17.0137 3044 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
    21:01:17.0286 3044 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
    21:01:22.0914 3044 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
    21:01:23.0023 3044 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
    21:01:23.0036 3044 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
    21:01:23.0061 3044 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
    21:01:23.0074 3044 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
    21:01:28.0647 3044 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
    21:01:34.0289 3044 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
    21:01:34.0316 3044 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
    21:01:34.0317 3044 \Device\Harddisk0\DR0 - ok
    21:01:34.0324 3044 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
    21:02:19.0794 1444 Deinitialize success
     
  16. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Let's see, if we can recover your missing features.
    Download and run UnHide
    Let me know, if it worked.

    Post fresh aswMBR log.
     
  17. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Here is the Aswmbr log:
    ........................................................................................................................
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-03-26 22:17:49
    -----------------------------
    22:17:49.501 OS Version: Windows x64 6.1.7601 Service Pack 1
    22:17:49.501 Number of processors: 2 586 0x170A
    22:17:49.502 ComputerName: JURCOI2-PC UserName: Jurcoi2
    22:17:51.398 Initialize success
    22:17:57.011 AVAST engine download error: 0
    22:18:01.827 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
    22:18:01.831 Disk 0 Vendor: WDC_WD3200BEVT-75ZCT2 11.01A11 Size: 305245MB BusType: 11
    22:18:01.845 Disk 0 MBR read successfully
    22:18:01.849 Disk 0 MBR scan
    22:18:01.854 Disk 0 Windows 7 default MBR code
    22:18:01.859 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
    22:18:01.884 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 81920
    22:18:01.905 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290204 MB offset 30801920
    22:18:01.924 Disk 0 scanning C:\Windows\system32\drivers
    22:18:12.177 Service scanning
    22:18:35.781 Modules scanning
    22:18:35.795 Disk 0 trace - called modules:
    22:18:35.843 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
    22:18:35.854 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045dd060]
    22:18:35.862 3 CLASSPNP.SYS[fffff8800165a43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80040ce060]
    22:18:35.871 Scan finished successfully
    22:19:01.480 Disk 0 MBR has been saved successfully to "E:\MBR.dat"
    22:19:01.513 The log file has been saved successfully to "E:\aswMBR2.txt"
     
  18. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Looks good.

    What about UnHide?
     
  19. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Yup, unhide seems to have worked. I say seems because I'm not sure exactly what my daughters has - but everything I try or look for is there. I suspect the rest are visible as well.

    Does the aswMBR log give us a good grade?
     
  20. Broni

    Broni Malware Annihilator Posts: 47,986   +271

    Good news :)

    Yes aswMBR looks good.

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  21. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Here is the ComboFix log 1 of about 5 :
    ..............................................................................................................................
    ComboFix 12-03-25.01 - Jurcoi2 03/26/2012 23:26:20.3.2 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4058.2345 [GMT -5:00]
    Running from: C:\Users\Jurcoi2\Desktop\ComboFix.exe
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Users\Jurcoi2\AppData\Local\assembly\tmp
    C:\Users\Jurcoi2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
    C:\Users\Jurcoi2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check\System Check.lnk
    C:\Users\Jurcoi2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check\Uninstall System Check.lnk
    C:\Users\Jurcoi2\Desktop\System Check.lnk
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    C:\Windows\svchost.exe
    C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Microsoft\zchvwceaw.dll


    ((((((((((((((((((((((((( Files Created from 2012-02-27 to 2012-03-27 )))))))))))))))))))))))))))))))


    2012-03-27 04:37:42 . 2012-03-27 04:37:42 -------- d-----w- C:\Users\Public\AppData\Local\temp
    2012-03-27 04:37:42 . 2012-03-27 04:37:42 -------- d-----w- C:\Users\Default\AppData\Local\temp
    2012-03-27 02:01:03 . 2012-03-27 02:01:03 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-03-25 22:34:57 . 2011-12-06 23:22:38 28760 ----a-w- C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{D19CA586-DD6C-4a0a-96F8-14644F340D60}\components\scriptff.dll
    2012-03-19 04:09:30 . 2012-03-19 04:09:30 -------- d-----w- C:\Windows\SysWow64\config\systemprofile\Librarys
    2012-03-19 04:08:36 . 2012-03-19 04:08:36 -------- d-----w- C:\Windows\Sun
    2012-03-17 04:35:41 . 2012-03-17 04:35:41 5120 ----a-w- C:\ProgramData\Microsoft\Windows\DRM\5AC8.tmp
    2012-03-17 04:35:41 . 2012-03-17 04:35:41 5120 ----a-w- C:\ProgramData\Microsoft\Windows\DRM\5AC7.tmp
    2012-03-14 05:48:19 . 2011-11-19 15:20:37 5559152 ----a-w- C:\Windows\system32\ntoskrnl.exe
    2012-03-14 05:48:18 . 2011-11-19 14:50:02 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-14 05:48:18 . 2011-11-19 14:50:02 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-13 21:52:45 . 2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\system32\win32k.sys
    2012-03-13 21:52:41 . 2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\system32\DWrite.dll
    2012-03-13 21:52:40 . 2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-03-13 17:08:44 . 2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\system32\rdpcore.dll
    2012-03-13 17:08:44 . 2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-03-13 17:08:44 . 2012-02-17 04:58:24 210944 ----a-w- C:\Windows\system32\drivers\rdpwd.sys
    2012-03-13 17:08:44 . 2012-02-17 04:57:32 23552 ----a-w- C:\Windows\system32\drivers\tdtcp.sys
    2012-03-13 17:08:41 . 2012-01-25 06:33:30 9216 ----a-w- C:\Windows\system32\rdrmemptylst.exe
    2012-03-13 17:08:40 . 2012-01-25 06:38:39 77312 ----a-w- C:\Windows\system32\rdpwsx.dll
    2012-03-13 17:08:40 . 2012-01-25 06:38:38 149504 ----a-w- C:\Windows\system32\rdpcorekmts.dll
    2012-03-12 15:50:03 . 2012-03-15 22:17:04 -------- d-----w- C:\Users\Jurcoi2\AppData\Local\Spotify
    2012-03-12 15:48:42 . 2012-03-15 22:17:04 -------- d-----w- C:\Users\Jurcoi2\AppData\Roaming\Spotify
    2012-03-12 00:11:52 . 2012-03-12 02:17:46 -------- d-----w- C:\Users\Jurcoi2\AppData\Roaming\ColorCop
    2012-03-10 22:36:41 . 2012-03-10 22:36:41 -------- d-----w- C:\Users\Jurcoi2\AppData\Roaming\Desktop Apps
    2012-03-10 22:36:35 . 2012-03-10 22:36:35 -------- d-----w- C:\Program Files (x86)\Mioplanet
    2012-03-08 00:32:10 . 2012-03-08 00:32:10 162664 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
    2012-03-06 17:16:23 . 2012-03-06 17:16:27 -------- d-----w- C:\Program Files (x86)\HTMLValidatorLite110
    .


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2012-02-23 15:15:52 . 2010-07-06 20:57:08 5055584 ----a-w- C:\Windows\SysWow64\csevalidator.dll
    2012-01-04 10:44:20 . 2012-02-14 18:54:37 509952 ----a-w- C:\Windows\system32\ntshrui.dll
    2012-01-04 08:58:41 . 2012-02-14 18:54:37 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2011-12-30 06:26:08 . 2012-02-14 18:54:17 515584 ----a-w- C:\Windows\system32\timedate.cpl
    2011-12-30 05:27:56 . 2012-02-14 18:54:16 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl


    ((((((((((((((((((((((((((((( SnapShot@2011-10-09_01.51.29 )))))))))))))))))))))))))))))))))))))))))

    - 2011-06-11 00:33:13 . 2010-11-20 12:08:57 96768 C:\Windows\SysWOW64\sspicli.dll
    + 2012-01-18 17:32:36 . 2011-11-17 05:28:48 96768 C:\Windows\SysWOW64\sspicli.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 76800 C:\Windows\SysWOW64\SetIEInstalledDate.exe
    + 2012-01-18 17:32:36 . 2011-11-17 05:34:52 22016 C:\Windows\SysWOW64\secur32.dll
    - 2011-06-11 00:33:10 . 2010-11-20 12:21:07 22016 C:\Windows\SysWOW64\secur32.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 74752 C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 54272 C:\Windows\SysWOW64\pngfilt.dll
    + 2012-01-11 14:12:11 . 2011-11-19 14:01:00 67072 C:\Windows\SysWOW64\packager.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 48640 C:\Windows\SysWOW64\mshtmler.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 72704 C:\Windows\SysWOW64\mshtmled.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 11776 C:\Windows\SysWOW64\mshta.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 10752 C:\Windows\SysWOW64\msfeedssync.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 41472 C:\Windows\SysWOW64\msfeedsbs.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 66048 C:\Windows\SysWOW64\migration\WininetPlugin.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 23552 C:\Windows\SysWOW64\licmgr10.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 65024 C:\Windows\SysWOW64\jsproxy.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 78848 C:\Windows\SysWOW64\inseng.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 35840 C:\Windows\SysWOW64\imgutil.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 86528 C:\Windows\SysWOW64\iesysprep.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 74752 C:\Windows\SysWOW64\iesetup.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 31744 C:\Windows\SysWOW64\iernonce.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 74240 C:\Windows\SysWOW64\ie4uinit.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 66048 C:\Windows\SysWOW64\icardie.dll
    + 2012-03-20 03:18:18 . 2012-03-20 03:18:18 84643 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin
    + 2012-03-26 05:28:26 . 2012-03-26 03:25:35 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012032620120327\index.dat
    + 2012-03-25 20:14:04 . 2012-03-26 03:25:35 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012032520120326\index.dat
    + 2012-03-23 15:24:57 . 2012-03-23 14:41:24 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012032320120324\index.dat
    + 2012-03-26 05:28:26 . 2012-03-26 03:25:35 49152 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012031920120326\index.dat
    + 2012-03-20 03:18:25 . 2012-03-20 03:18:25 65536 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012031220120319\index.dat
    + 2011-10-01 02:26:37 . 2012-03-25 20:13:02 49120 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT
    - 2011-10-01 02:28:04 . 2011-10-01 02:30:58 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
    + 2011-10-01 02:28:04 . 2012-03-26 03:25:35 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
    + 2010-01-21 21:22:45 . 2012-03-26 23:35:19 63974 C:\Windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10:35 . 2012-03-27 03:27:17 41938 C:\Windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2010-01-28 20:25:54 . 2012-03-27 03:27:17 17868 C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-661016940-2190693489-1753151072-1001_UserData.bin
    - 2011-06-11 00:33:36 . 2010-11-20 13:27:26 29184 C:\Windows\system32\sspisrv.dll
    + 2012-01-18 17:32:36 . 2011-11-17 06:35:26 29184 C:\Windows\system32\sspisrv.dll
    + 2010-01-29 01:16:27 . 2009-02-27 08:42:04 66440 C:\Windows\system32\spool\drivers\x64\msonpui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 91648 C:\Windows\system32\SetIEInstalledDate.exe
    + 2012-01-18 17:32:37 . 2011-11-17 06:35:25 28160 C:\Windows\system32\secur32.dll
    - 2011-06-11 00:33:32 . 2010-11-20 13:27:25 28160 C:\Windows\system32\secur32.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 89088 C:\Windows\system32\RegisterIEPKEYs.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 65024 C:\Windows\system32\pngfilt.dll
    + 2012-01-11 14:12:11 . 2011-11-19 14:58:00 77312 C:\Windows\system32\packager.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 48640 C:\Windows\system32\mshtmler.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 96256 C:\Windows\system32\mshtmled.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 12288 C:\Windows\system32\mshta.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 10752 C:\Windows\system32\msfeedssync.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 55296 C:\Windows\system32\msfeedsbs.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 86528 C:\Windows\system32\migration\WininetPlugin.dll
    - 2009-07-13 23:20:54 . 2009-07-14 01:39:16 31232 C:\Windows\system32\lsass.exe
    + 2012-01-18 17:32:38 . 2011-11-17 06:33:55 31232 C:\Windows\system32\lsass.exe
    - 2011-08-14 17:30:02 . 2011-09-08 01:32:02 67584 C:\Windows\system32\LogFiles\Srt\bootstat.dat
    + 2011-08-14 17:30:02 . 2012-03-24 04:14:47 67584 C:\Windows\system32\LogFiles\Srt\bootstat.dat
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 30720 C:\Windows\system32\licmgr10.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 85504 C:\Windows\system32\jsproxy.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 49664 C:\Windows\system32\imgutil.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 85504 C:\Windows\system32\iesetup.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 39936 C:\Windows\system32\iernonce.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 89088 C:\Windows\system32\ie4uinit.exe
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 82432 C:\Windows\system32\icardie.dll
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 75808 C:\Windows\system32\drivers\mfenlfk.sys
    + 2010-08-15 04:48:39 . 2011-10-15 19:16:16 10248 C:\Windows\system32\drivers\mfeclnk.sys
    + 2011-08-28 03:42:36 . 2011-12-10 21:24:08 23152 C:\Windows\system32\drivers\mbam.sys
    + 2012-01-18 17:32:38 . 2011-11-17 06:49:14 95600 C:\Windows\system32\drivers\ksecdd.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 65264 C:\Windows\system32\drivers\cfwids.sys
    - 2009-07-13 23:19:25 . 2009-07-14 01:40:24 43520 C:\Windows\system32\csrsrv.dll
    + 2011-12-16 01:18:50 . 2011-10-26 05:21:20 43520 C:\Windows\system32\csrsrv.dll
    - 2010-01-28 18:36:51 . 2011-10-09 01:50:24 32768 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-01-28 18:36:51 . 2012-03-27 03:25:24 32768 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2010-01-28 18:36:51 . 2011-10-09 01:50:24 32768 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-01-28 18:36:51 . 2012-03-27 03:25:24 32768 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-07-14 04:54:19 . 2011-10-09 01:50:24 16384 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:54:19 . 2012-03-27 03:25:24 16384 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2010-01-28 19:12:32 . 2012-03-24 19:19:39 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2010-01-28 19:12:32 . 2011-10-05 23:13:22 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-07-14 04:46:26 . 2012-03-25 20:35:40 91888 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    + 2012-03-17 04:37:19 . 2012-03-24 19:22:27 32768 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
    + 2012-03-17 04:37:19 . 2012-03-24 19:20:08 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
    + 2012-03-17 04:37:19 . 2012-03-24 19:20:08 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
    - 2010-01-28 19:12:32 . 2011-10-05 23:13:22 32768 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-01-28 19:12:32 . 2012-03-24 19:22:27 32768 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-01-28 19:12:32 . 2012-03-24 19:19:39 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2010-01-28 19:12:32 . 2011-10-05 23:13:22 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2010-01-28 20:19:50 . 2011-10-05 23:10:47 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-01-28 20:19:50 . 2012-03-24 19:19:49 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-01-28 20:19:50 . 2012-03-24 19:19:49 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2010-01-28 20:19:50 . 2011-10-05 23:10:47 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 68880 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
    + 2011-12-31 02:15:54 . 2011-12-25 20:40:47 43280 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_wp.exe
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 57616 C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
    + 2011-12-31 02:15:54 . 2011-12-25 20:42:14 31504 C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    + 2012-03-24 19:31:55 . 2012-03-24 19:31:55 87408 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 87408 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 93024 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    + 2012-03-24 19:31:54 . 2012-03-24 19:31:54 93024 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    + 2012-03-24 19:31:54 . 2012-03-24 19:31:54 35688 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 35688 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    + 2012-03-24 19:31:59 . 2012-03-24 19:31:59 11120 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
    - 2011-09-18 05:09:38 . 2011-09-18 05:09:38 11120 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
    + 2012-03-24 19:31:55 . 2012-03-24 19:31:55 17784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 17784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 58240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    + 2012-03-24 19:31:55 . 2012-03-24 19:31:55 58240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 44920 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    + 2012-03-24 19:31:38 . 2012-03-24 19:31:38 44920 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    - 2011-09-18 05:09:32 . 2011-09-18 05:09:32 37240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 37240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 64352 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    + 2012-03-24 19:31:38 . 2012-03-24 19:31:38 64352 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    + 2012-03-24 19:31:38 . 2012-03-24 19:31:38 51032 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 51032 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    + 2012-03-24 19:31:36 . 2012-03-24 19:31:36 50552 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    - 2011-09-18 05:09:26 . 2011-09-18 05:09:26 50552 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    + 2012-03-24 19:31:29 . 2012-03-24 19:31:29 81784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2011-09-18 05:09:21 . 2011-09-18 05:09:21 81784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2011-09-18 05:09:25 . 2011-09-18 05:09:25 81800 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    + 2012-03-24 19:31:35 . 2012-03-24 19:31:35 81800 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    - 2011-09-18 05:09:25 . 2011-09-18 05:09:25 39784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    + 2012-03-24 19:31:35 . 2012-03-24 19:31:35 39784 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    - 2011-09-18 05:09:29 . 2011-09-18 05:09:29 68952 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    + 2012-03-24 19:31:42 . 2012-03-24 19:31:42 68952 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    - 2011-09-18 05:09:29 . 2011-09-18 05:09:29 62880 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    + 2012-03-24 19:31:42 . 2012-03-24 19:31:42 62880 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    - 2011-09-18 05:09:20 . 2011-09-18 05:09:20 12128 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2012-03-24 19:31:28 . 2012-03-24 19:31:28 12128 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2012-03-24 19:31:39 . 2012-03-24 19:31:39 97680 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 97680 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2012-03-24 19:31:27 . 2012-03-24 19:31:27 17240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2011-09-18 05:09:19 . 2011-09-18 05:09:19 17240 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2011-09-18 05:09:18 . 2011-09-18 05:09:18 94552 C:\Windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-03-24 19:31:24 . 2012-03-24 19:31:24 94552 C:\Windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-03-24 19:31:27 . 2012-03-24 19:31:27 91488 C:\Windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-09-18 05:09:20 . 2011-09-18 05:09:20 91488 C:\Windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-09-18 05:08:50 . 2011-09-18 05:08:50 78168 C:\Windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2012-03-24 19:30:18 . 2012-03-24 19:30:18 78168 C:\Windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-09-18 05:08:54 . 2011-09-18 05:08:54 81248 C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2012-03-24 19:30:31 . 2012-03-24 19:30:31 81248 C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2012-03-21 01:17:25 . 2012-03-21 01:17:25 25600 C:\Windows\Installer\ec2362.msi
    + 2012-03-24 19:36:03 . 2012-03-24 19:36:03 49936 C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    - 2011-09-17 08:11:17 . 2011-09-17 08:11:17 49936 C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:33 35088 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 35088 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 18704 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 18704 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 20240 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 20240 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:58 35088 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 35088 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 18704 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 18704 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 20240 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 20240 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
    + 2012-03-24 19:51:52 . 2012-03-24 19:51:52 35600 C:\Windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2011-09-17 08:11:13 . 2011-09-17 08:11:13 35600 C:\Windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    + 2011-11-14 22:39:06 . 2011-11-14 22:39:06 65536 C:\Windows\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
    + 2011-11-14 22:39:06 . 2011-11-14 22:39:06 65536 C:\Windows\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}\ARPPRODUCTICON.exe
    + 2009-02-26 18:09:02 . 2009-02-26 18:09:02 10120 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XLCALL32.DLL
    + 2009-02-26 23:43:40 . 2009-02-26 23:43:40 71520 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XL12CNVP.DLL
    + 2009-02-26 22:45:10 . 2009-02-26 22:45:10 20808 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12EXE.EXE
    + 2011-05-31 21:31:32 . 2011-05-31 21:31:32 32128 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VPREVIEW.EXE
    + 2006-07-24 15:50:40 . 2006-07-24 15:50:40 47920 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBAME.DLL
    + 2009-02-26 03:05:50 . 2009-02-26 03:05:50 76168 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWSTRUCT.DLL
    + 2009-02-26 03:05:50 . 2009-02-26 03:05:50 18808 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWRECS.DLL
    + 2009-02-26 03:05:50 . 2009-02-26 03:05:50 50544 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWRECE.DLL
    + 2009-02-26 03:05:48 . 2009-02-26 03:05:48 26488 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWORIENT.DLL
    + 2009-02-26 03:05:48 . 2009-02-26 03:05:48 57192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWLAY32.DLL
    + 2009-02-26 03:05:48 . 2009-02-26 03:05:48 86896 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWCUTLIN.DLL
    + 2009-02-26 03:05:46 . 2009-02-26 03:05:46 29000 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\THOCRAPI.DLL
    + 2011-07-20 10:17:00 . 2011-07-20 10:17:00 33152 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\SETLANG.EXE
    + 2009-02-26 03:05:46 . 2009-02-26 03:05:46 18808 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\REVERSE.DLL
    + 2011-07-27 09:53:58 . 2011-07-27 09:53:58 39464 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\REFIEBAR.DLL
    + 2009-02-27 00:21:28 . 2009-02-27 00:21:28 38224 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\REFEDIT.DLL
    + 2009-02-26 03:05:46 . 2009-02-26 03:05:46 76176 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PSOM.DLL
    + 2009-02-26 20:24:50 . 2009-02-26 20:24:50 71536 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONFILTER.DLL
    + 2009-02-26 20:24:50 . 2009-02-26 20:24:50 97680 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
    + 2011-07-27 10:17:00 . 2011-07-27 10:17:00 22432 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OISCTRL.DLL
    + 2011-07-27 10:25:06 . 2011-07-27 10:25:06 53728 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OFFRHD.DLL
    + 2011-07-27 09:53:58 . 2011-07-27 09:53:58 64872 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\NAME.DLL
    + 2009-02-27 08:42:04 . 2009-02-27 08:42:04 66440 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSONPUI.DLL
    + 2009-02-27 08:42:02 . 2009-02-27 08:42:02 31640 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSONPMON.DLL
    + 2009-02-26 22:07:12 . 2009-02-26 22:07:12 67440 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSOHTMED.EXE
    + 2009-02-26 22:07:10 . 2009-02-26 22:07:10 75120 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSOHEV.DLL
    + 2009-02-27 00:21:28 . 2009-02-27 00:21:28 25968 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSOEURO.DLL
    + 2011-07-27 09:34:34 . 2011-07-27 09:34:34 13712 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSOCFU.DLL
    + 2006-07-24 15:50:38 . 2006-07-24 15:50:38 92976 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
    + 2011-05-31 21:26:52 . 2011-05-31 21:26:52 88448 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\METCONV.DLL
    + 2009-02-26 03:05:46 . 2009-02-26 03:05:46 75120 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\FORM.DLL
    + 2011-07-27 22:49:22 . 2011-07-27 22:49:22 56696 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\EXP_XPS.DLL
    + 2011-07-27 22:49:22 . 2011-07-27 22:49:22 95608 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\EXP_PDF.DLL
    + 2009-02-26 22:07:02 . 2009-02-26 22:07:02 53120 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\AUTHZAX.DLL
    + 2011-07-27 09:41:28 . 2011-07-27 09:41:28 55168 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACERCLR.DLL
    + 2009-02-26 16:18:12 . 2009-02-26 16:18:12 14192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEODTXT.DLL
    + 2009-02-26 16:18:12 . 2009-02-26 16:18:12 14192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEODPDX.DLL
    + 2009-02-26 16:18:12 . 2009-02-26 16:18:12 14192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEODEXL.DLL
    + 2009-02-26 16:18:12 . 2009-02-26 16:18:12 14192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEODDBS.DLL
    + 2011-07-27 09:41:22 . 2011-07-27 09:41:22 47024 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEERR.DLL
    + 2011-07-27 09:41:18 . 2011-07-27 09:41:18 55240 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACECNFLT.EXE
    + 2009-04-02 17:01:44 . 2009-04-02 17:01:44 56680 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_XPS.DLL
    + 2009-04-03 23:46:26 . 2009-04-03 23:46:26 97640 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\EXP_PDF.DLL
    + 2009-03-06 07:48:04 . 2009-03-06 07:48:04 55152 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACERCLR.DLL
    + 2006-10-27 01:13:24 . 2006-10-27 01:13:24 56192 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
    + 2006-07-24 15:50:40 . 2006-07-24 15:50:40 47920 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBAME.DLL
    + 2009-02-26 20:24:50 . 2009-02-26 20:24:50 71536 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONFILTER.DLL
    + 2009-02-26 20:24:50 . 2009-02-26 20:24:50 97680 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
    + 2006-07-24 15:50:38 . 2006-07-24 15:50:38 92976 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
    + 2010-05-19 17:19:15 . 2010-05-19 17:19:15 35648 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLCTLPIA.DLL
    + 2009-04-02 17:01:44 . 2009-04-02 17:01:44 56680 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXP_XPS.DLL
    + 2009-04-03 23:46:26 . 2009-04-03 23:46:26 97640 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXP_PDF.DLL
    + 2006-10-27 01:13:24 . 2006-10-27 01:13:24 56192 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
    + 2009-02-26 23:43:40 . 2009-02-26 23:43:40 71520 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\XL12CNVP.DLL
    + 2009-02-26 22:45:10 . 2009-02-26 22:45:10 20808 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\WRD12EXE.EXE
    + 2009-02-26 18:06:32 . 2009-02-26 18:06:32 16712 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\PXBPROXY.DLL
    + 2009-02-26 18:06:32 . 2009-02-26 18:06:32 68488 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\PXBCOM.EXE
    + 2012-03-25 22:26:28 . 2012-03-25 22:26:28 10240 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\f137c53afae3903f20eba1fa0f8f8dad\System.Xml.Serialization.ni.dll
    + 2012-03-25 22:26:19 . 2012-03-25 22:26:19 43520 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\ef151d5b49d8b0d0052d05fc56d25107\System.Windows.Presentation.ni.dll
    + 2012-03-25 22:25:18 . 2012-03-25 22:25:18 86016 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\c5b08a1a9a7a97922af50f30b5e32268\System.Web.ApplicationServices.ni.dll
    + 2012-03-25 22:13:57 . 2012-03-25 22:13:57 97792 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\5b53a87f7799ee5454e4fb8faece3a82\System.AddIn.Contract.ni.dll
    + 2012-03-25 22:06:36 . 2012-03-25 22:06:36 14336 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\a4e98103e5d36bf22ef19c64442543f2\Microsoft.VisualC.ni.dll
    + 2012-03-25 21:31:04 . 2012-03-25 21:31:04 10752 C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc\cbd21f19057f07ec2cb55b2bef91f344\dfsvc.ni.exe
    + 2012-03-25 21:31:03 . 2012-03-25 21:31:03 58368 C:\Windows\assembly\NativeImages_v4.0.30319_64\Accessibility\52890eb2a4f8d822bff7e9cddc713fb5\Accessibility.ni.dll
    + 2012-03-25 21:44:34 . 2012-03-25 21:44:34 96768 C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\8dd565cc0b374e1eec73cf7eaba91e92\UIAutomationProvider.ni.dll
    + 2012-03-25 22:05:14 . 2012-03-25 22:05:14 35328 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\077e75015456f75a0495f65cfcf140cb\System.Windows.Presentation.ni.dll
    + 2012-03-25 22:04:41 . 2012-03-25 22:04:41 71680 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\22a9aa847a8e4e651a35b63270ce8999\System.Web.ApplicationServices.ni.dll
    + 2012-03-25 21:48:57 . 2012-03-25 21:48:57 82432 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\fdeb5ca04943da59f732d3001d6a0df0\System.ServiceModel.Channels.ni.dll
    + 2012-03-25 21:45:32 . 2012-03-25 21:45:32 78848 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\9688786618bf6390637c283b5bd1c9b3\System.AddIn.Contract.ni.dll
    + 2012-03-25 21:43:55 . 2012-03-25 21:43:55 11776 C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\6ffc3ac04451b4978519218fd266403e\Microsoft.VisualC.ni.dll
    + 2012-03-25 21:43:24 . 2012-03-25 21:43:24 44544 C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\8cbc15b63aa3f06453f1aaa8659cf809\Accessibility.ni.dll
    + 2012-02-27 23:33:29 . 2012-02-27 23:33:29 60416 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\265f654b8eed2ac1e42d225a30433c37\System.Windows.Presentation.ni.dll
    + 2012-02-27 23:33:15 . 2012-02-27 23:33:15 54784 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\62889e05923a83fa32400e7f3b28f9c6\System.Web.DynamicData.Design.ni.dll
    + 2011-11-26 01:56:21 . 2011-11-26 01:56:21 90624 C:\Windows\assembly\NativeImages_v2.0.50727_64\stdole\968c30c131b94a1b5e834fbc333b177b\stdole.ni.dll
    + 2012-02-27 23:31:38 . 2012-02-27 23:31:38 72192 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\c1577aa4e5874f1debc9a63343e5a0d7\PresentationFontCache.ni.exe
    + 2012-02-17 14:34:59 . 2012-02-17 14:34:59 61952 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\697c9c4ec947a0a5e21bc9e4c6471b74\PresentationCFFRasterizer.ni.dll
    + 2012-02-27 23:31:22 . 2012-02-27 23:31:22 33792 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\2d80e48139b13bf06e85c0c1db06bc20\Microsoft.WSMan.Runtime.ni.dll
    + 2012-02-27 23:31:18 . 2012-02-27 23:31:18 45056 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\df5c0dac9e7db175acc8a9755942f87f\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
    + 2012-02-27 23:31:18 . 2012-02-27 23:31:18 36864 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\8a9356f77bd1d1155202f59119ee57c9\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
    + 2011-11-28 04:20:40 . 2011-11-28 04:20:40 59904 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\8260ae5a7d4a7e7cd907c958858da284\Microsoft.Windows.Diagnosis.SDHost.ni.dll
    + 2012-02-27 23:31:18 . 2012-02-27 23:31:18 40448 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4e53199f22c13aa3e4bc6f063da0aee7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
    + 2011-11-28 04:20:43 . 2011-11-28 04:20:43 70144 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\371120a0816ba5ce909b8e1341da376f\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
    + 2012-02-27 23:31:17 . 2012-02-27 23:31:17 43520 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\0f361440d7cbda4bf5b44bfbd4623812\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
    + 2011-10-16 02:12:39 . 2011-10-16 02:12:39 32256 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\e6aabbfb38a14559712fdf51064ff3a1\Microsoft.VisualC.ni.dll
    + 2012-02-27 23:28:58 . 2012-02-27 23:28:58 65536 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\f8f0b08845fb76dfcf57e00d86fc13fc\Microsoft.MediaCenter.iTv.Hosting.ni.dll
    + 2012-02-27 23:29:57 . 2012-02-27 23:29:57 40960 C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\8cd347067dbe1ec5a79c9d261d2d75d9\LoadMxf.ni.exe
    + 2011-11-26 01:56:24 . 2011-11-26 01:56:24 49664 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\50cda8ab4cd566b222342c3da14302d3\ehiUPnP.ni.dll
    + 2012-02-27 23:28:57 . 2012-02-27 23:28:57 93184 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\4089bf2cec6e1a1539076c5bd6d95ce7\ehiTVMSMusic.ni.dll
    + 2011-11-26 01:56:00 . 2011-11-26 01:56:00 28672 C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc\7de9a8137a33d06dad01c8405d960037\dfsvc.ni.exe
    + 2011-10-16 02:19:33 . 2011-10-16 02:19:33 78848 C:\Windows\assembly\NativeImages_v2.0.50727_64\Accessibility\d301e1d96d4f39f15482db09206f1fb1\Accessibility.ni.dll
    + 2012-02-28 01:04:15 . 2012-02-28 01:04:15 47616 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\c22781f6201c8db16b404644884e48b8\WindowsLiveWriter.ni.exe
    + 2012-02-28 01:04:28 . 2012-02-28 01:04:28 99840 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b018eb1e5276252053c62766b66978e9\WindowsLive.Writer.Api.ni.dll
    + 2011-10-16 02:23:44 . 2011-10-16 02:23:44 60928 C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\bb1d36ae26e7cadf563061596682e747\UIAutomationProvider.ni.dll
    + 2012-02-28 01:07:35 . 2012-02-28 01:07:35 37888 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\df6e2f050af3e7a7676650240ef9d7e5\System.Windows.Presentation.ni.dll
    + 2012-02-28 01:07:27 . 2012-02-28 01:07:27 36864 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\e66fcffbc602b284e20b6c49f4ac64b6\System.Web.DynamicData.Design.ni.dll
    + 2012-02-28 01:06:23 . 2012-02-28 01:06:23 94208 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\2463cb2600fc129e38f67974f3553368\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-19 00:12:37 . 2011-10-19 00:12:37 82944 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\32d21563937263ee3ae9eecfa59fdc3d\System.AddIn.Contract.ni.dll
    + 2011-10-19 00:10:13 . 2011-10-19 00:10:13 44032 C:\Windows\assembly\NativeImages_v2.0.50727_32\stdole\17b4308b0e6d35c1230135ed25fffbfe\stdole.ni.dll
    + 2012-02-28 01:06:20 . 2012-02-28 01:06:20 47104 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\bef92fc6725738f2a261600dab88cd66\PresentationFontCache.ni.exe
    + 2012-02-17 14:39:37 . 2012-02-17 14:39:37 39424 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\dcdbd6714f689d7be2a15fe8ed1bc095\PresentationCFFRasterizer.ni.dll
    + 2011-10-19 00:12:14 . 2011-10-19 00:12:14 79872 C:\Windows\assembly\NativeImages_v2.0.50727_32\napcrypt\a38f8e60cdbca2d158d8daaea9577934\napcrypt.ni.dll
    + 2012-02-28 01:06:10 . 2012-02-28 01:06:10 17920 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\7834abeef71f9188bb9d9253d8f807ab\Microsoft.WSMan.Runtime.ni.dll
    + 2012-02-28 01:06:07 . 2012-02-28 01:06:07 19968 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ef668f1802501935d634458ef637f5e7\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
    + 2011-10-19 00:11:52 . 2011-10-19 00:11:52 32256
     
  22. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    Combo fix 2:
    ..............................................................................................
    C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ed12245481e36d8cc238876bd79b1e6c\Microsoft.Windows.Diagnosis.SDHost.ni.dll
    + 2012-02-28 01:06:09 . 2012-02-28 01:06:09 86528 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\a66c7d26f61bb8e12960441a77159102\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
    + 2011-10-19 00:11:59 . 2011-10-19 00:11:59 21504 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\62e68252fc137a55d2d39fe0d5093599\Microsoft.Windows.Diagnosis.SDEngine.ni.dll
    + 2012-02-28 01:06:06 . 2012-02-28 01:06:06 23040 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\61a8d567fe6450b5b77584b0044a6979\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
    + 2012-02-28 01:06:06 . 2012-02-28 01:06:06 25088 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\52785c0dca46f1e08b5cf9299fba9ae0\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
    + 2012-02-28 01:06:07 . 2012-02-28 01:06:07 27136 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\183073b14873e3b18951879ae4a8b425\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
    + 2012-02-28 01:05:43 . 2012-02-28 01:05:43 55296 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\824d2cc6a8193a2458ce90e579c8b8f5\Microsoft.Vsa.ni.dll
    + 2011-10-16 02:23:12 . 2011-10-16 02:23:12 15872 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\3cb6023aa6ab962babcee9c0ec8991de\Microsoft.VisualC.ni.dll
    + 2011-10-19 00:10:29 . 2011-10-19 00:10:29 74752 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aac5bc888c15c2630ea22e517e4e19f8\Microsoft.Build.Framework.ni.dll
    + 2011-10-19 00:10:32 . 2011-10-19 00:10:32 65024 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4ee55572f0f54a71e24fe3fec094968b\Microsoft.Build.Framework.ni.dll
    + 2011-10-19 00:10:04 . 2011-10-19 00:10:04 60416 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\e6e4bd9a47848b93cd2dd8a688968741\ehiUserXp.ni.dll
    + 2011-10-19 00:09:53 . 2011-10-19 00:09:53 14336 C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\94a173b39fa90956937b41c775ac66d7\dfsvc.ni.exe
    + 2011-10-16 02:23:44 . 2011-10-16 02:23:44 25600 C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\31fce331fded94dd06627603f6fe4562\Accessibility.ni.dll
    + 2012-03-24 19:43:48 . 2012-03-24 19:43:48 11144 C:\Windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
    + 2012-03-24 19:43:19 . 2012-03-24 19:43:19 63336 C:\Windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    - 2011-09-13 08:05:07 . 2011-09-13 08:05:07 63336 C:\Windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    + 2012-03-24 19:43:46 . 2012-03-24 19:43:46 34696 C:\Windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    - 2011-08-24 02:23:10 . 2011-07-09 04:29:46 2048 C:\Windows\SysWOW64\tzres.dll
    + 2011-12-16 01:11:43 . 2011-11-05 04:26:03 2048 C:\Windows\SysWOW64\tzres.dll
    + 2011-02-24 22:28:10 . 2011-11-26 01:21:01 3872 C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-661016940-2190693489-1753151072-1005_UserData.bin
    + 2011-12-16 01:11:45 . 2011-11-05 05:32:50 2048 C:\Windows\system32\tzres.dll
    - 2011-08-24 02:23:10 . 2011-07-09 05:26:20 2048 C:\Windows\system32\tzres.dll
    + 2011-11-21 19:07:52 . 2011-11-21 19:07:52 9560 C:\Windows\system32\NetworkList\Icons\{CDD246AA-546B-4783-86D7-4F6CB105E748}_48.bin
    + 2011-11-21 19:07:52 . 2011-11-21 19:07:52 4280 C:\Windows\system32\NetworkList\Icons\{CDD246AA-546B-4783-86D7-4F6CB105E748}_32.bin
    + 2011-11-21 19:07:52 . 2011-11-21 19:07:52 2456 C:\Windows\system32\NetworkList\Icons\{CDD246AA-546B-4783-86D7-4F6CB105E748}_24.bin
    + 2011-11-28 17:56:48 . 2011-11-28 17:56:48 9560 C:\Windows\system32\NetworkList\Icons\{B2946FE2-94B8-4BF2-9ADD-DBA2038E55E4}_48.bin
    + 2011-11-28 17:56:48 . 2011-11-28 17:56:48 4280 C:\Windows\system32\NetworkList\Icons\{B2946FE2-94B8-4BF2-9ADD-DBA2038E55E4}_32.bin
    + 2011-11-28 17:56:48 . 2011-11-28 17:56:48 2456 C:\Windows\system32\NetworkList\Icons\{B2946FE2-94B8-4BF2-9ADD-DBA2038E55E4}_24.bin
    + 2012-03-19 04:01:07 . 2012-03-19 04:01:14 1728 C:\Windows\SoftwareDistribution\EventCache\{ECF86E00-9723-4DA4-9AB3-DAFA720A45E1}.bin
    + 2012-03-18 03:44:29 . 2012-03-18 03:44:32 1728 C:\Windows\SoftwareDistribution\EventCache\{77AB9029-26DB-4AB3-B00A-8D5E51B08E57}.bin
    + 2012-03-27 03:25:10 . 2012-03-27 03:25:10 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-10-09 01:50:15 . 2011-10-09 01:50:15 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2012-03-27 03:25:09 . 2012-03-27 03:25:09 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2011-10-09 01:50:15 . 2011-10-09 01:50:15 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2012-03-25 22:05:17 . 2012-03-25 22:05:17 9216 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\6bafe185b3d23de57ec689035642fe43\System.Xml.Serialization.ni.dll
    + 2012-03-25 21:43:26 . 2012-03-25 21:43:26 9728 C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc\592252ee904bd41f99cd1d19909b548c\dfsvc.ni.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 152064 C:\Windows\SysWOW64\wextract.exe
    + 2012-01-18 17:32:37 . 2011-11-17 05:35:02 314880 C:\Windows\SysWOW64\webio.dll
    - 2011-06-11 00:34:32 . 2010-11-20 12:21:35 314880 C:\Windows\SysWOW64\webio.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 203776 C:\Windows\SysWOW64\webcheck.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 420864 C:\Windows\SysWOW64\vbscript.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 231936 C:\Windows\SysWOW64\url.dll
    + 2012-01-18 17:32:39 . 2011-11-17 05:34:52 224768 C:\Windows\SysWOW64\schannel.dll
    + 2012-01-11 14:12:13 . 2011-10-26 04:32:11 514560 C:\Windows\SysWOW64\qdvd.dll
    - 2011-06-11 00:33:38 . 2010-11-20 12:20:57 514560 C:\Windows\SysWOW64\qdvd.dll
    - 2009-07-14 00:05:43 . 2009-07-14 01:16:12 465408 C:\Windows\SysWOW64\psisdecd.dll
    + 2011-10-13 21:05:25 . 2011-08-17 04:24:12 465408 C:\Windows\SysWOW64\psisdecd.dll
    + 2011-10-13 21:03:18 . 2011-08-27 04:26:27 571904 C:\Windows\SysWOW64\oleaut32.dll
    - 2011-06-17 22:29:10 . 2011-02-25 05:34:36 571904 C:\Windows\SysWOW64\oleaut32.dll
    + 2011-10-13 21:03:18 . 2011-08-27 04:26:27 233472 C:\Windows\SysWOW64\oleacc.dll
    - 2009-07-13 23:26:29 . 2009-07-14 01:16:12 233472 C:\Windows\SysWOW64\oleacc.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 123392 C:\Windows\SysWOW64\occache.dll
    - 2009-07-13 23:12:58 . 2009-07-14 01:15:50 690688 C:\Windows\SysWOW64\msvcrt.dll
    + 2012-02-14 18:54:03 . 2011-12-16 07:52:58 690688 C:\Windows\SysWOW64\msvcrt.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 162304 C:\Windows\SysWOW64\msrating.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 161792 C:\Windows\SysWOW64\msls31.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 580608 C:\Windows\SysWOW64\msfeeds.dll
    + 2011-11-25 23:53:01 . 2011-11-25 23:53:01 247968 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe
    + 2011-11-25 23:53:01 . 2011-11-25 23:53:01 335520 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.dll
    - 2011-04-16 02:44:03 . 2011-02-18 05:41:57 716800 C:\Windows\SysWOW64\jscript.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 716800 C:\Windows\SysWOW64\jscript.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 150528 C:\Windows\SysWOW64\iexpress.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 142848 C:\Windows\SysWOW64\ieUnatt.exe
    - 2011-08-11 00:47:47 . 2011-06-21 05:26:00 176640 C:\Windows\SysWOW64\ieui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 176640 C:\Windows\SysWOW64\ieui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 118784 C:\Windows\SysWOW64\iepeers.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 353584 C:\Windows\SysWOW64\iedkcs32.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 434176 C:\Windows\SysWOW64\ieapfltr.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 163840 C:\Windows\SysWOW64\ieakui.dll
    - 2009-07-13 23:42:51 . 2009-07-14 01:05:47 163840 C:\Windows\SysWOW64\ieakui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 227840 C:\Windows\SysWOW64\ieaksie.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 130560 C:\Windows\SysWOW64\ieakeng.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 110592 C:\Windows\SysWOW64\IEAdvpack.dll
    + 2011-12-16 01:17:48 . 2011-10-15 05:38:59 534528 C:\Windows\SysWOW64\EncDec.dll
    - 2011-03-09 23:11:07 . 2010-12-23 05:54:17 534528 C:\Windows\SysWOW64\EncDec.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 223232 C:\Windows\SysWOW64\dxtrans.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 353792 C:\Windows\SysWOW64\dxtmsft.dll
    - 2010-01-30 09:19:05 . 2011-10-01 02:30:58 262144 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2010-01-30 09:19:05 . 2012-03-26 23:34:28 262144 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2009-07-14 04:54:17 . 2012-03-26 23:34:28 278528 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2012-03-20 21:11:55 . 2012-03-20 21:11:55 327680 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Microsoft\zchvwceaw.dll
    + 2012-03-20 21:11:55 . 2012-03-20 21:11:55 327680 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Microsoft\ruamntmv.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 101888 C:\Windows\SysWOW64\admparse.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 160256 C:\Windows\system32\wextract.exe
    + 2012-01-18 17:32:37 . 2011-11-17 06:35:28 395776 C:\Windows\system32\webio.dll
    - 2011-06-11 00:34:40 . 2010-11-20 13:27:28 395776 C:\Windows\system32\webio.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 249344 C:\Windows\system32\webcheck.dll
    + 2010-02-02 00:44:57 . 2012-03-15 22:13:08 281748 C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
    + 2010-01-28 21:21:09 . 2012-03-27 02:56:43 322834 C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 603648 C:\Windows\system32\vbscript.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 237056 C:\Windows\system32\url.dll
    + 2012-01-18 17:32:37 . 2011-11-17 06:35:26 136192 C:\Windows\system32\sspicli.dll
    - 2011-06-11 00:34:10 . 2010-11-20 13:27:26 136192 C:\Windows\system32\sspicli.dll
    + 2010-01-29 01:16:27 . 2009-02-27 08:42:02 863128 C:\Windows\system32\spool\drivers\x64\msonpdrv.dll
    - 2011-06-11 00:34:48 . 2010-11-20 13:27:25 340992 C:\Windows\system32\schannel.dll
    + 2012-01-18 17:32:39 . 2011-11-17 06:35:25 340992 C:\Windows\system32\schannel.dll
    + 2012-01-11 14:12:13 . 2011-10-26 05:25:15 366592 C:\Windows\system32\qdvd.dll
    - 2011-06-11 00:33:40 . 2010-11-20 13:27:23 366592 C:\Windows\system32\qdvd.dll
    - 2009-07-14 00:20:32 . 2009-07-14 01:41:53 613888 C:\Windows\system32\psisdecd.dll
    + 2011-10-13 21:05:26 . 2011-08-17 05:26:46 613888 C:\Windows\system32\psisdecd.dll
    + 2009-07-14 02:36:59 . 2012-03-27 04:18:10 636084 C:\Windows\system32\perfh009.dat
    - 2009-07-14 02:36:59 . 2011-10-09 01:27:31 636084 C:\Windows\system32\perfh009.dat
    + 2009-07-14 02:36:59 . 2012-03-27 04:18:10 111626 C:\Windows\system32\perfc009.dat
    - 2009-07-14 02:36:59 . 2011-10-09 01:27:31 111626 C:\Windows\system32\perfc009.dat
    - 2011-06-17 22:29:11 . 2011-02-25 06:22:22 861696 C:\Windows\system32\oleaut32.dll
    + 2011-10-13 21:03:18 . 2011-08-27 05:37:49 861696 C:\Windows\system32\oleaut32.dll
    + 2011-10-13 21:03:19 . 2011-08-27 05:37:48 331776 C:\Windows\system32\oleacc.dll
    - 2009-07-13 23:39:13 . 2009-07-14 01:41:53 331776 C:\Windows\system32\oleacc.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 149504 C:\Windows\system32\occache.dll
    - 2009-07-13 23:19:29 . 2009-07-14 01:41:32 634880 C:\Windows\system32\msvcrt.dll
    + 2012-02-14 18:54:03 . 2011-12-16 08:46:06 634880 C:\Windows\system32\msvcrt.dll
    + 2012-03-18 03:38:46 . 2012-03-18 03:38:46 197120 C:\Windows\system32\msrating.dll
    - 2009-07-13 23:39:06 . 2009-07-14 01:41:29 222208 C:\Windows\system32\msls31.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 222208 C:\Windows\system32\msls31.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 697344 C:\Windows\system32\msfeeds.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 818688 C:\Windows\system32\jscript.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 103936 C:\Windows\system32\inseng.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 165888 C:\Windows\system32\iexpress.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 173056 C:\Windows\system32\ieUnatt.exe
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 248320 C:\Windows\system32\ieui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 111616 C:\Windows\system32\iesysprep.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 145920 C:\Windows\system32\iepeers.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 403248 C:\Windows\system32\iedkcs32.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 534528 C:\Windows\system32\ieapfltr.dll
    - 2009-07-13 23:58:32 . 2009-07-14 01:27:58 163840 C:\Windows\system32\ieakui.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 163840 C:\Windows\system32\ieakui.dll
    - 2009-07-13 23:58:38 . 2009-07-14 01:41:05 267776 C:\Windows\system32\ieaksie.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 267776 C:\Windows\system32\ieaksie.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 160256 C:\Windows\system32\ieakeng.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 135168 C:\Windows\system32\IEAdvpack.dll
    + 2009-07-14 04:45:34 . 2012-03-14 20:11:08 426344 C:\Windows\system32\FNTCACHE.DAT
    + 2011-12-16 01:17:49 . 2011-10-15 06:31:56 723456 C:\Windows\system32\EncDec.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 282112 C:\Windows\system32\dxtrans.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 452608 C:\Windows\system32\dxtmsft.dll
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 284648 C:\Windows\system32\drivers\mfewfpk.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 100912 C:\Windows\system32\drivers\mferkdet.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 647080 C:\Windows\system32\drivers\mfehidk.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 481768 C:\Windows\system32\drivers\mfefirek.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 229528 C:\Windows\system32\drivers\mfeavfk.sys
    + 2010-08-15 04:48:00 . 2011-10-15 19:16:16 160280 C:\Windows\system32\drivers\mfeapfk.sys
    + 2012-01-18 17:32:39 . 2011-11-17 06:49:14 152432 C:\Windows\system32\drivers\ksecpkg.sys
    + 2012-01-18 17:32:38 . 2011-11-17 06:44:43 459232 C:\Windows\system32\drivers\cng.sys
    + 2012-02-14 18:54:13 . 2011-12-28 03:59:24 498688 C:\Windows\system32\drivers\afd.sys
    - 2009-07-14 05:38:14 . 2010-01-21 22:57:44 262144 C:\Windows\system32\config\systemprofile\ntuser.dat
    + 2009-07-14 05:38:14 . 2012-03-24 09:12:50 262144 C:\Windows\system32\config\systemprofile\ntuser.dat
    - 2009-07-14 05:12:52 . 2011-08-27 01:57:02 262144 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2009-07-14 05:12:52 . 2012-03-27 02:08:34 262144 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 114176 C:\Windows\system32\admparse.dll
    - 2010-01-28 19:12:32 . 2011-04-16 08:34:06 262144 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2010-01-28 19:12:32 . 2012-02-17 14:34:29 262144 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2012-02-21 16:58:18 . 2012-02-21 16:58:15 262144 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2009-07-14 05:01:48 . 2012-03-27 03:24:20 399660 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2012-03-23 01:17:18 . 2012-03-27 03:24:22 560092 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-661016940-2190693489-1753151072-1001-8192.dat
    + 2012-03-23 01:17:18 . 2012-03-26 05:34:57 526144 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 598784 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
    + 2011-12-26 11:47:52 . 2011-12-26 11:47:52 261912 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
    + 2011-12-31 02:15:55 . 2011-12-25 20:40:48 746256 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\webengine.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:32:11 485192 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
    + 2011-10-13 21:05:17 . 2011-07-08 22:31:17 485192 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 518400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
    + 2011-12-26 10:39:12 . 2011-12-26 10:39:12 192792 C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 957200 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
    + 2011-12-31 02:15:55 . 2011-12-25 20:42:15 437520 C:\Windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:33:52 388936 C:\Windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2011-10-13 21:05:16 . 2011-07-08 22:33:46 388936 C:\Windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:33:48 995672 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-10-13 21:05:16 . 2011-07-08 22:33:42 995672 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    - 2011-09-18 05:09:36 . 2011-09-18 05:09:36 350592 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    + 2012-03-24 19:31:53 . 2012-03-24 19:31:53 350592 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    + 2012-03-24 19:31:53 . 2012-03-24 19:31:53 163168 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    - 2011-09-18 05:09:36 . 2011-09-18 05:09:36 163168 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 138592 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2012-03-24 19:31:39 . 2012-03-24 19:31:39 138592 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2012-03-24 19:31:48 . 2012-03-24 19:31:48 699224 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    - 2011-09-18 05:09:33 . 2011-09-18 05:09:34 699224 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    + 2012-03-24 19:31:47 . 2012-03-24 19:31:47 857960 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2011-09-18 05:09:33 . 2011-09-18 05:09:33 857960 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2011-09-18 05:09:34 . 2011-09-18 05:09:34 675672 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    + 2012-03-24 19:31:48 . 2012-03-24 19:31:48 675672 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    + 2012-03-24 19:31:33 . 2012-03-24 19:31:33 113512 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2011-09-18 05:09:23 . 2011-09-18 05:09:23 113512 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2011-09-18 05:09:32 . 2011-09-18 05:09:32 129912 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 129912 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    - 2011-09-18 05:09:32 . 2011-09-18 05:09:32 390008 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 390008 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 505208 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    - 2011-09-18 05:09:32 . 2011-09-18 05:09:32 505208 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    - 2011-09-18 05:09:23 . 2011-09-18 05:09:23 261472 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2012-03-24 19:31:33 . 2012-03-24 19:31:33 261472 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2011-09-18 05:09:33 . 2011-09-18 05:09:33 122264 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 122264 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2012-03-24 19:31:46 . 2012-03-24 19:31:46 291184 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2011-09-18 05:09:33 . 2011-09-18 05:09:33 291184 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2012-03-24 19:31:44 . 2012-03-24 19:31:44 349568 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    - 2011-09-18 05:09:31 . 2011-09-18 05:09:31 349568 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 236880 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
    + 2012-03-24 19:31:37 . 2012-03-24 19:31:37 236880 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
    - 2011-09-18 05:09:32 . 2011-09-18 05:09:32 253280 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2012-03-24 19:31:45 . 2012-03-24 19:31:45 253280 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2012-03-24 19:31:32 . 2012-03-24 19:31:32 378720 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2011-09-18 05:09:23 . 2011-09-18 05:09:23 378720 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2012-03-24 19:31:37 . 2012-03-24 19:31:37 134528 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    - 2011-09-18 05:09:27 . 2011-09-18 05:09:27 134528 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    - 2011-09-18 05:09:31 . 2011-09-18 05:09:31 123736 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    + 2012-03-24 19:31:43 . 2012-03-24 19:31:43 123736 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    - 2011-09-18 05:09:30 . 2011-09-18 05:09:30 392552 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    + 2012-03-24 19:31:43 . 2012-03-24 19:31:43 392552 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    - 2011-09-18 05:09:30 . 2011-09-18 05:09:31 125816 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    + 2012-03-24 19:31:43 . 2012-03-24 19:31:43 125816 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    - 2011-09-18 05:09:19 . 2011-09-18 05:09:19 120152 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    + 2012-03-24 19:31:27 . 2012-03-24 19:31:27 120152 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    - 2011-09-18 05:09:23 . 2011-09-18 05:09:23 607064 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2012-03-24 19:31:32 . 2012-03-24 19:31:32 607064 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2011-09-18 05:09:22 . 2011-09-18 05:09:22 395120 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2012-03-24 19:31:31 . 2012-03-24 19:31:31 395120 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-09-18 05:09:22 . 2011-09-18 05:09:22 182144 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2012-03-24 19:31:31 . 2012-03-24 19:31:31 182144 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2011-09-18 05:09:22 . 2011-09-18 05:09:22 285072 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    + 2012-03-24 19:31:31 . 2012-03-24 19:31:31 285072 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    - 2011-09-18 05:09:22 . 2011-09-18 05:09:22 829280 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2012-03-24 19:31:30 . 2012-03-24 19:31:30 829280 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2011-09-18 05:09:21 . 2011-09-18 05:09:21 747360 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2012-03-24 19:31:30 . 2012-03-24 19:31:30 747360 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2012-03-24 19:31:37 . 2012-03-24 19:31:37 436600 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-09-18 05:09:26 . 2011-09-18 05:09:26 436600 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-09-18 05:09:26 . 2011-09-18 05:09:26 683872 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2012-03-24 19:31:36 . 2012-03-24 19:31:36 683872 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    - 2011-09-18 05:09:21 . 2011-09-18 05:09:21 409448 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2012-03-24 19:31:29 . 2012-03-24 19:31:29 409448 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2011-09-18 05:09:25 . 2011-09-18 05:09:25 210816 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    + 2012-03-24 19:31:35 . 2012-03-24 19:31:35 210816 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    + 2012-03-24 19:31:35 . 2012-03-24 19:31:35 149848 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    - 2011-09-18 05:09:25 . 2011-09-18 05:09:25 149848 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    + 2012-03-24 19:31:43 . 2012-03-24 19:31:43 122248 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    - 2011-09-18 05:09:30 . 2011-09-18 05:09:30 122248 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    + 2012-03-24 19:31:42 . 2012-03-24 19:31:42 525704 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    - 2011-09-18 05:09:29 . 2011-09-18 05:09:29 525704 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    - 2011-09-18 05:09:21 . 2011-09-18 05:09:21 112976 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2012-03-24 19:31:28 . 2012-03-24 19:31:28 112976 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2011-09-18 05:09:37 . 2011-09-18 05:09:37 581464 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2012-03-24 19:31:54 . 2012-03-24 19:31:54 581464 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2012-03-24 19:31:53 . 2012-03-24 19:31:53 832856 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    - 2011-09-18 05:09:36 . 2011-09-18 05:09:36 832856 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    - 2011-09-18 05:09:36 . 2011-09-18 05:09:36 194424 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    + 2012-03-24 19:31:52 . 2012-03-24 19:31:52 194424 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    - 2011-09-18 05:09:35 . 2011-09-18 05:09:35 478576 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    + 2012-03-24 19:31:52 . 2012-03-24 19:31:52 478576 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    + 2012-03-24 19:31:51 . 2012-03-24 19:31:51 167288 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    - 2011-09-18 05:09:35 . 2011-09-18 05:09:35 167288 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    - 2011-09-18 05:09:35 . 2011-09-18 05:09:35 232304 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    + 2012-03-24 19:31:51 . 2012-03-24 19:31:51 232304 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    - 2011-09-18 05:09:20 . 2011-09-18 05:09:20 661352 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2012-03-24 19:31:28 . 2012-03-24 19:31:28 661352 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2011-09-18 05:09:28 . 2011-09-18 05:09:28 349576 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2012-03-24 19:31:39 . 2012-03-24 19:31:39 349576 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2011-09-18 05:09:28 . 2011-09-18 05:09:28 387960 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2012-03-24 19:31:40 . 2012-03-24 19:31:40 387960 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2012-03-24 19:31:28 . 2012-03-24 19:31:28 746336 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2011-09-18 05:09:20 . 2011-09-18 05:09:20 746336 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2012-03-24 19:31:26 . 2012-03-24 19:31:26 505184 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    - 2011-09-18 05:09:19 . 2011-09-18 05:09:19 505184 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    + 2012-03-24 19:31:46 . 2012-03-24 19:31:46 288616 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-09-18 05:09:33 . 2011-09-18 05:09:33 288616 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-09-18 05:09:34 . 2011-09-18 05:09:34 335712 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2012-03-24 19:31:48 . 2012-03-24 19:31:48 335712 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-09-18 05:09:19 . 2011-09-18 05:09:19 125440 C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2012-03-24 19:31:26 . 2012-03-24 19:31:26 125440 C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2012-03-24 19:31:26 . 2012-03-24 19:31:26 237424 C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2011-09-18 05:09:18 . 2011-09-18 05:09:18 237424 C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-03-24 19:31:40 . 2012-03-24 19:31:40 187776 C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-09-18 05:09:28 . 2011-09-18 05:09:28 187776 C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-09-18 05:09:13 . 2011-09-18 05:09:13 269672 C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2012-03-24 19:31:11 . 2012-03-24 19:31:11 269672 C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2012-03-24 19:31:14 . 2012-03-24 19:31:14 334688
     
  23. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    #3 ............................................................................................
    C:\Windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-09-18 05:09:14 . 2011-09-18 05:09:14 334688 C:\Windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2012-03-24 19:30:29 . 2012-03-24 19:30:29 109568 C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-09-18 05:08:52 . 2011-09-18 05:08:52 109568 C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2011-09-18 05:08:52 . 2011-09-18 05:08:52 246128 C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-03-24 19:30:29 . 2012-03-24 19:30:29 246128 C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2012-03-24 19:30:58 . 2012-03-24 19:30:58 170368 C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-09-18 05:09:07 . 2011-09-18 05:09:07 170368 C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-10-17 18:31:18 . 2011-10-17 18:31:18 926208 C:\Windows\Installer\908910e0.msi
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 888080 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 888080 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 922384 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 922384 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 217864 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 217864 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 184080 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:32 184080 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    - 2011-09-13 08:02:42 . 2011-09-13 08:02:42 217864 C:\Windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
    + 2012-03-24 19:38:01 . 2012-03-24 19:38:01 217864 C:\Windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 888080 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 888080 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 272648 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 272648 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 922384 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 922384 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
    + 2010-05-19 17:20:33 . 2012-03-24 19:45:57 845584 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
    - 2010-05-19 17:20:33 . 2011-09-17 08:11:46 845584 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
    - 2010-05-19 17:20:34 . 2011-09-17 08:11:46 217864 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
    + 2010-05-19 17:20:34 . 2012-03-24 19:45:57 217864 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
    + 2010-05-19 17:20:33 . 2012-03-24 19:45:56 184080 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
    - 2010-05-19 17:20:33 . 2011-09-17 08:11:46 184080 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
    + 2010-05-19 17:20:33 . 2012-03-24 19:45:56 159504 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
    - 2010-05-19 17:20:33 . 2011-09-17 08:11:46 159504 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
    + 2009-02-26 03:05:52 . 2009-02-26 03:05:52 531840 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XPAGE3C.DLL
    + 2009-02-26 22:45:08 . 2009-02-26 22:45:08 509256 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CVR.DLL
    + 2011-09-16 01:41:56 . 2011-09-16 01:41:56 408936 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WINWORD.EXE
    + 2009-02-26 03:05:46 . 2009-02-26 03:05:46 126328 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\TWCUTCHR.DLL
    + 2011-07-27 09:58:56 . 2011-07-27 09:58:56 439160 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\SETUP.EXE
    + 2011-07-27 09:54:00 . 2011-07-27 09:54:00 503184 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\SELFCERT.EXE
    + 2011-05-27 02:13:38 . 2011-05-27 02:13:38 368520 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PPSLAX.DLL
    + 2011-07-27 09:36:06 . 2011-07-27 09:36:06 481640 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PORTCONN.DLL
    + 2007-06-08 00:51:00 . 2007-06-08 00:51:00 465800 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
    + 2011-07-27 11:00:46 . 2011-07-27 11:00:46 783296 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONSYNCPC.DLL
    + 2011-07-27 11:25:44 . 2011-07-27 11:25:44 664968 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONBTTNOL.DLL
    + 2011-07-27 11:25:44 . 2011-07-27 11:25:44 603552 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONBTTNIE.DLL
    + 2011-07-27 10:17:00 . 2011-07-27 10:17:00 284560 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OISGRAPH.DLL
    + 2011-07-27 10:16:58 . 2011-07-27 10:16:58 997768 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OISAPP.DLL
    + 2011-07-27 10:16:56 . 2011-07-27 10:16:56 273792 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OIS.EXE
    + 2008-03-19 11:27:28 . 2008-03-19 11:27:28 661536 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
    + 2009-02-26 20:24:30 . 2009-02-26 20:24:30 231864 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ODEPLOY.EXE
    + 2011-07-20 10:22:32 . 2011-07-20 10:22:32 538968 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSTORES.DLL
    + 2011-07-20 10:22:32 . 2011-07-20 10:22:32 144728 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSTORE.EXE
    + 2011-07-20 10:22:30 . 2011-07-20 10:22:30 832360 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSTORDB.EXE
    + 2006-07-24 15:50:38 . 2006-07-24 15:50:38 125744 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
    + 2009-02-26 03:02:38 . 2009-02-26 03:02:38 504176 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSSOAP30.DLL
    + 2011-07-27 11:10:58 . 2011-07-27 11:10:58 670560 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSQRY32.EXE
    + 2011-05-31 22:19:30 . 2011-05-31 22:19:30 732000 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSPROOF6.DLL
    + 2009-02-26 02:46:02 . 2009-02-26 02:46:02 435568 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSORUN.DLL
    + 2009-02-27 08:42:02 . 2009-02-27 08:42:02 863128 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSONPDRV.DLL
    + 2011-07-27 09:53:58 . 2011-07-27 09:53:58 427856 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSODCW.DLL
    + 2011-07-27 09:34:32 . 2011-07-27 09:34:32 160632 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSOCF.DLL
    + 2011-06-23 14:54:18 . 2011-06-23 14:54:18 119160 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSCONV97.DLL
    + 2011-07-20 10:22:28 . 2011-07-20 10:22:28 828264 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MEDCAT.DLL
    + 2011-07-27 22:49:22 . 2011-07-27 22:49:22 177536 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IETAG.DLL
    + 2008-10-25 11:18:50 . 2008-10-25 11:18:50 172880 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
    + 2009-02-26 20:24:20 . 2009-02-26 20:24:20 970128 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\FPWEC.DLL
    + 2011-07-27 10:13:08 . 2011-07-27 10:13:08 434080 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\DWTRIG20.EXE
    + 2011-07-27 09:53:56 . 2011-07-27 09:53:56 105872 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\DSSM.EXE
    + 2011-07-27 09:53:56 . 2011-07-27 09:53:56 188800 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\CONTACTPICKER.DLL
    + 2011-07-27 11:13:32 . 2011-07-27 11:13:32 204664 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\CLVIEW.EXE
    + 2011-07-27 11:20:44 . 2011-07-27 11:20:44 400216 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\CDLMSO.DLL
    + 2011-07-27 09:41:30 . 2011-07-27 09:41:30 370608 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEXBE.DLL
    + 2011-07-27 09:41:30 . 2011-07-27 09:41:30 223152 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACETXT.DLL
    + 2011-07-27 09:41:28 . 2011-07-27 09:41:28 550840 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEREP.DLL
    + 2011-07-27 09:41:28 . 2011-07-27 09:41:28 288688 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACER3X.DLL
    + 2011-07-27 09:41:26 . 2011-07-27 09:41:26 255920 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACER2X.DLL
    + 2011-07-27 09:41:26 . 2011-07-27 09:41:26 391096 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEPDE.DLL
    + 2011-07-27 09:41:26 . 2011-07-27 09:41:26 378808 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEOLEDB.DLL
    + 2011-07-27 09:41:24 . 2011-07-27 09:41:24 278912 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEODBC.DLL
    + 2011-07-27 09:41:24 . 2011-07-27 09:41:24 206776 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACELTS.DLL
    + 2011-07-27 09:41:24 . 2011-07-27 09:41:24 632752 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEEXCL.DLL
    + 2011-07-27 09:41:22 . 2011-07-27 09:41:22 337848 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEEXCH.DLL
    + 2011-07-27 09:41:22 . 2011-07-27 09:41:22 186304 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEES.DLL
    + 2011-07-27 09:41:22 . 2011-07-27 09:41:22 571320 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACEDAO.DLL
    + 2011-07-27 09:41:18 . 2011-07-27 09:41:18 763848 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACECNF.DLL
    + 2006-10-27 01:13:44 . 2006-10-27 01:13:44 764800 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ACECNF.DLL
    + 2007-06-08 00:51:00 . 2007-06-08 00:51:00 125320 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SSGEN.DLL
    + 2007-06-08 00:51:00 . 2007-06-08 00:51:00 465800 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
    + 2008-03-19 11:27:28 . 2008-03-19 11:27:28 661536 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
    + 2006-07-24 15:50:38 . 2006-07-24 15:50:38 125744 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
    + 2008-10-25 11:18:50 . 2008-10-25 11:18:50 172880 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
    + 2006-10-27 20:35:18 . 2006-10-27 20:35:18 436512 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL
    + 2006-10-27 01:13:44 . 2006-10-27 01:13:44 764800 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNF.DLL
    + 2009-02-26 22:45:08 . 2009-02-26 22:45:08 509256 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\WRD12CVR.DLL
    + 2008-10-25 05:51:08 . 2008-10-25 05:51:08 844696 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\OICE.EXE
    - 2011-06-11 00:34:11 . 2010-11-20 13:27:09 465920 C:\Windows\ehome\mstvcapn.dll
    + 2012-01-11 14:12:14 . 2011-10-29 05:23:20 465920 C:\Windows\ehome\mstvcapn.dll
    + 2011-10-13 21:05:24 . 2011-08-17 05:28:23 315392 C:\Windows\ehome\Microsoft.MediaCenter.Interop.dll
    - 2011-06-11 00:33:48 . 2010-11-20 13:44:11 315392 C:\Windows\ehome\Microsoft.MediaCenter.Interop.dll
    + 2012-03-25 22:26:57 . 2012-03-25 22:26:57 336896 C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\d05858dd730eef93a5e4a3cc88dd4ec3\WindowsFormsIntegration.ni.dll
    + 2012-03-25 22:11:34 . 2012-03-25 22:11:34 231424 C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\b2a2a1fb4e1313088250b334b3af2a15\UIAutomationTypes.ni.dll
    + 2012-03-25 22:11:33 . 2012-03-25 22:11:33 122368 C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\89414bab411eb27c7c181df81b4d36a5\UIAutomationProvider.ni.dll
    + 2012-03-25 22:26:37 . 2012-03-25 22:26:37 645120 C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\cd55f47d44c3695862bc047b8e86fcd3\UIAutomationClient.ni.dll
    + 2012-03-25 22:10:18 . 2012-03-25 22:10:18 528896 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\910d557d55f4fc7bb51ace0546bd3c50\System.Xml.Linq.ni.dll
    + 2012-03-25 22:11:37 . 2012-03-25 22:11:37 256000 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\dcb9e1eaa1491094f79c3288b8c78830\System.Windows.Input.Manipulations.ni.dll
    + 2012-03-25 22:10:41 . 2012-03-25 22:10:41 903168 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\922f3f17f5112441e77f9d3d56d5b753\System.Transactions.ni.dll
    + 2012-03-25 22:25:07 . 2012-03-25 22:25:07 281088 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\73874670b92afbde73b23e8a1200eede\System.ServiceProcess.ni.dll
    + 2012-03-25 22:25:05 . 2012-03-25 22:25:05 517120 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\909c8d76773648809478644ac50a21eb\System.ServiceModel.Routing.ni.dll
    + 2012-03-25 22:24:48 . 2012-03-25 22:24:48 108032 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\26db69101f5bcf148fd962f00c0e78dd\System.ServiceModel.Channels.ni.dll
    + 2012-03-25 21:32:08 . 2012-03-25 21:32:08 946688 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Security\878946615037b9d5f09916c598420dc1\System.Security.ni.dll
    + 2012-03-25 22:11:04 . 2012-03-25 22:11:04 376832 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\73cc698ccc98e37f53cdbff3687a921c\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2012-03-25 22:11:01 . 2012-03-25 22:11:01 987648 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\b73b4f0282ef46505b3e59702ded433b\System.Runtime.Remoting.ni.dll
    + 2012-03-25 21:32:09 . 2012-03-25 21:32:09 176640 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\8064e773b9addf027658899e27e94c7b\System.Numerics.ni.dll
    + 2012-03-25 22:22:22 . 2012-03-25 22:22:22 933376 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net\a46d5472536da900435885b28a19eda8\System.Net.ni.dll
    + 2012-03-25 22:22:18 . 2012-03-25 22:22:18 781824 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\ae0089b9135614de304ebe288fa6fca8\System.Messaging.ni.dll
    + 2012-03-25 22:16:25 . 2012-03-25 22:16:25 521728 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\3ad050d3f47352421e05b7707ddd3524\System.Management.Instrumentation.ni.dll
    + 2012-03-25 22:16:21 . 2012-03-25 22:16:21 531456 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\87efa405cd384d2c47380467fcd7ea86\System.IO.Log.ni.dll
    + 2012-03-25 22:16:18 . 2012-03-25 22:16:18 290816 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\50ccc897ad714e66f750ca1e51e0ffde\System.IdentityModel.Selectors.ni.dll
    + 2012-03-25 22:10:47 . 2012-03-25 22:10:47 348672 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\7b06b84cb3b99a3ab22adb2a3f6376e6\System.EnterpriseServices.Wrapper.dll
    + 2012-03-25 21:32:11 . 2012-03-25 21:32:11 512000 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\cbc3e5d028dd347a294096f068a053d4\System.Dynamic.ni.dll
    + 2012-03-25 22:16:06 . 2012-03-25 22:16:06 632832 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\1ae0a8a9eb92ccaf900f5911740b2c3c\System.DirectoryServices.Protocols.ni.dll
    + 2012-03-25 22:15:59 . 2012-03-25 22:15:59 141824 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Device\9edded64312f5cbae54a093eca246aaa\System.Device.ni.dll
    + 2012-03-25 22:14:10 . 2012-03-25 22:14:10 176128 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\db296a100034c7dee5f80219f0542df7\System.Data.DataSetExtensions.ni.dll
    + 2012-03-25 22:14:08 . 2012-03-25 22:14:08 181760 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\0f771cbf8b32ae1618f4cd4266337b3c\System.Configuration.Install.ni.dll
    + 2012-03-25 22:14:05 . 2012-03-25 22:14:05 255488 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\501ad39b1ef6f43e8dc92a4efa7c35ea\System.ComponentModel.DataAnnotations.ni.dll
    + 2012-03-25 22:13:56 . 2012-03-25 22:13:56 865792 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\f8c6e4854178bb4d928c8aec1c04648d\System.AddIn.ni.dll
    + 2012-03-25 22:13:31 . 2012-03-25 22:13:31 560640 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\3503e3c2a87db97b720c0ed8a5d59f61\System.Activities.DurableInstancing.ni.dll
    + 2012-03-25 21:31:09 . 2012-03-25 21:31:09 432128 C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\30cf4fc2c247cf490879f5436c63017c\SMSvcHost.ni.exe
    + 2012-03-25 22:10:31 . 2012-03-25 22:10:31 185344 C:\Windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\b4f75962376771b6b6d39279d780abba\SMDiagnostics.ni.dll
    + 2012-03-25 22:09:51 . 2012-03-25 22:09:51 428032 C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\eaca48940ac6976d39d5de4d5b42fed6\PresentationFramework.Royale.ni.dll
    + 2012-03-25 22:09:46 . 2012-03-25 22:09:46 802304 C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\bdb41ce9ab6d561ddb8107255daaee30\PresentationFramework.Luna.ni.dll
    + 2012-03-25 22:09:40 . 2012-03-25 22:09:40 622592 C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\78310f7eef84b5f9ca4bf32798bd77f9\PresentationFramework.Aero.ni.dll
    + 2012-03-25 22:09:42 . 2012-03-25 22:09:42 349184 C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\64b86aebea22fd357f22384757caed3f\PresentationFramework.Classic.ni.dll
    + 2012-03-25 22:06:35 . 2012-03-25 22:06:35 422400 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\480ae0610a44148c6532d3d134f9956f\Microsoft.VisualBasic.Compatibility.Data.ni.dll
    + 2012-03-25 21:32:18 . 2012-03-25 21:32:18 600064 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\16bf3be602620d349b25e6c2d08199a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2012-03-25 21:31:10 . 2012-03-25 21:31:10 279552 C:\Windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\f6b9abf9cd43524102ad9be82b7136d0\CustomMarshalers.ni.dll
    + 2012-03-25 22:05:36 . 2012-03-25 22:05:36 253952 C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\d5a18f2355101b19f23ff2f31d1d1e17\WindowsFormsIntegration.ni.dll
    + 2012-03-25 21:44:35 . 2012-03-25 21:44:35 196096 C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\9562374f940f41cdc64d88268d543f0b\UIAutomationTypes.ni.dll
    + 2012-03-25 22:05:22 . 2012-03-25 22:05:22 484352 C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\641eec5b274fe3972d02892607f9b650\UIAutomationClient.ni.dll
    + 2012-03-25 21:44:15 . 2012-03-25 21:44:15 393216 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\295b3156b838ca161a64a5456522438b\System.Xml.Linq.ni.dll
    + 2012-03-25 21:44:37 . 2012-03-25 21:44:37 189440
     
  24. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    #4 .................................................................................................................
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\0b68854406b775365c6d91e87813c2dc\System.Windows.Input.Manipulations.ni.dll
    + 2012-03-25 21:44:25 . 2012-03-25 21:44:25 649728 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\5e3cf00b80c0aecd8392f1702d2d0f28\System.Transactions.ni.dll
    + 2012-03-25 21:49:06 . 2012-03-25 21:49:06 221696 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\bf0b3689dd5e261097f2feb2ed0103e8\System.ServiceProcess.ni.dll
    + 2012-03-25 21:49:04 . 2012-03-25 21:49:04 369664 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d3d9c582c7cd77f17fd93167dc462242\System.ServiceModel.Routing.ni.dll
    + 2012-03-24 19:34:40 . 2012-03-24 19:34:40 736768 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\c1127f26363bea39c40707b9ddb6bbb9\System.Security.ni.dll
    + 2012-03-25 21:44:33 . 2012-03-25 21:44:33 311296 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\7b17528dffe47d9b17be6086a575a516\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2012-03-25 21:44:32 . 2012-03-25 21:44:32 762880 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\533deafc53346179cd118acc874752a3\System.Runtime.Remoting.ni.dll
    + 2012-03-24 19:34:19 . 2012-03-24 19:34:19 145408 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\3ce3d5b8126cda36b3dbd3535f249890\System.Numerics.ni.dll
    + 2012-03-25 21:48:16 . 2012-03-25 21:48:16 657408 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net\965e2749489298cc85387f44f76a40f2\System.Net.ni.dll
    + 2012-03-25 21:48:13 . 2012-03-25 21:48:13 626176 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\f5333e6e06a2d476f93b0880c5e7fd14\System.Messaging.ni.dll
    + 2012-03-25 21:48:05 . 2012-03-25 21:48:05 395264 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\1bff2d3e952c2160ba0c790d2342a601\System.Management.Instrumentation.ni.dll
    + 2012-03-25 21:48:02 . 2012-03-25 21:48:02 413696 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\e6cb98078120266f5310adf0f45aa7df\System.IO.Log.ni.dll
    + 2012-03-25 21:48:00 . 2012-03-25 21:48:00 229888 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\22dadf930ad449894633480562d6c913\System.IdentityModel.Selectors.ni.dll
    + 2012-03-25 21:44:26 . 2012-03-25 21:44:26 236032 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d0d8c27be9116224e42260292e21cad5\System.EnterpriseServices.Wrapper.dll
    + 2012-03-25 21:44:26 . 2012-03-25 21:44:26 787456 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d0d8c27be9116224e42260292e21cad5\System.EnterpriseServices.ni.dll
    + 2012-03-24 19:34:41 . 2012-03-24 19:34:41 377856 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\cbb6e9a9b075d9f6fa303e3eef4c0ffd\System.Dynamic.ni.dll
    + 2012-03-25 21:47:53 . 2012-03-25 21:47:53 913920 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\e25cc7918b583b3beffcad52920eae29\System.DirectoryServices.AccountManagement.ni.dll
    + 2012-03-25 21:47:55 . 2012-03-25 21:47:55 470528 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\a3be39ae9813098aa81430dd507d22ca\System.DirectoryServices.Protocols.ni.dll
    + 2012-03-25 21:47:50 . 2012-03-25 21:47:50 112640 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Device\4975f93d2055b33bd7a91d6f05628e2a\System.Device.ni.dll
    + 2012-03-25 21:45:39 . 2012-03-25 21:45:39 134656 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\42d3d301d2adef24edeb3b775fbe3a4b\System.Data.DataSetExtensions.ni.dll
    + 2012-03-24 19:34:38 . 2012-03-24 19:34:38 982528 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bab886a18699bab842769c5ce486c332\System.Configuration.ni.dll
    + 2012-03-25 21:45:36 . 2012-03-25 21:45:37 148480 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\e844f0d4cf703c2e97515ed020331b76\System.Configuration.Install.ni.dll
    + 2012-03-24 19:34:48 . 2012-03-24 19:34:48 693760 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\a92c1bd4d32fbbc54134fc40d2f97389\System.ComponentModel.Composition.ni.dll
    + 2012-03-25 21:45:34 . 2012-03-25 21:45:34 194048 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\9b418b211d6207feafcdc27027d26036\System.ComponentModel.DataAnnotations.ni.dll
    + 2012-03-25 21:45:30 . 2012-03-25 21:45:30 617984 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\a4cfba8e3500f8387fe5924b940983be\System.AddIn.ni.dll
    + 2012-03-25 21:45:13 . 2012-03-25 21:45:13 411136 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\520d0ed9f48c121fbe79bda6fc176b74\System.Activities.DurableInstancing.ni.dll
    + 2012-03-25 21:43:29 . 2012-03-25 21:43:29 317952 C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\98ec8a39382e6eee39845bd4759ecf04\SMSvcHost.ni.exe
    + 2012-03-25 21:44:21 . 2012-03-25 21:44:21 143360 C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\3b905cdec5960d51e5bdc7030b005c09\SMDiagnostics.ni.dll
    + 2012-03-24 19:35:04 . 2012-03-24 19:35:04 309760 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\94d89db071d382d9ba0bc6381669b85f\PresentationFramework.Classic.ni.dll
    + 2012-03-24 19:34:54 . 2012-03-24 19:34:54 595968 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\8b8a5c194aacfb2102d4e26b75a84e03\PresentationFramework.Aero.ni.dll
    + 2012-03-24 19:34:49 . 2012-03-24 19:34:49 387072 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\443c3fae1f6f0588a542ddc1c02c1be1\PresentationFramework.Royale.ni.dll
    + 2012-03-24 19:35:08 . 2012-03-24 19:35:08 755712 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\273034086c19b92034c9f2896724ac33\PresentationFramework.Luna.ni.dll
    + 2012-03-25 21:43:54 . 2012-03-25 21:43:54 303104 C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\cdd04b14b9dd6ced2e2572a044c3c57e\Microsoft.VisualBasic.Compatibility.Data.ni.dll
    + 2012-03-25 21:43:39 . 2012-03-25 21:43:39 418816 C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\5958d9610eb58adb2b62153492a7c27e\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2012-03-25 21:43:31 . 2012-03-25 21:43:31 194048 C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\e3e1fd8ccf76e9eb0147484fb8dd773a\CustomMarshalers.ni.dll
    + 2012-02-27 23:33:39 . 2012-02-27 23:33:39 468992 C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\600f8ca5fcc54f10623903952fcc10ac\WsatConfig.ni.exe
    + 2012-02-27 23:33:38 . 2012-02-27 23:33:38 329216 C:\Windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\ddb96c334583dc79463edcb14ae16c99\WindowsFormsIntegration.ni.dll
    + 2012-02-27 23:27:05 . 2012-02-27 23:27:05 472576 C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\afc5368f90ec60a06936dc00bf6c18e9\VistaBridgeLibrary.ni.dll
    + 2012-02-27 23:27:06 . 2012-02-27 23:27:06 736768 C:\Windows\assembly\NativeImages_v2.0.50727_64\VDialog\48eb0fa4373a42c2da93f56c580f869e\VDialog.ni.dll
    + 2011-10-16 02:20:29 . 2011-10-16 02:20:29 253952 C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\344ac206baaadddc6f7c5fb8ae189b1a\UIAutomationTypes.ni.dll
    + 2011-10-16 02:20:28 . 2011-10-16 02:20:28 120832 C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\7a61dc7e8c606d1ed2c703cbeae2f8ef\UIAutomationProvider.ni.dll
    + 2012-02-27 23:31:09 . 2012-02-27 23:31:09 653312 C:\Windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\152b577b846875cb3ac5e2097451daf0\UIAutomationClient.ni.dll
    + 2012-02-27 23:33:34 . 2012-02-27 23:33:34 304128 C:\Windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\fb5fce5cf09733b71a796d1da399f07a\TaskScheduler.ni.dll
    + 2012-02-27 23:32:32 . 2012-02-27 23:32:32 529920 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\bc3bbe78635aeacaeea3b310ea5ff002\System.Xml.Linq.ni.dll
    + 2012-02-27 23:33:12 . 2012-02-27 23:33:12 187392 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\894b696a87ad47b5e18ac89954813a94\System.Web.Routing.ni.dll
    + 2012-02-17 14:37:49 . 2012-02-17 14:37:49 261120 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\ed681c0aefa909f528d50d0d7f87b799\System.Web.RegularExpressions.ni.dll
    + 2012-02-27 23:33:17 . 2012-02-27 23:33:17 449024 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\a6885ee42ea49eb80f1bd18a5252684d\System.Web.Entity.ni.dll
    + 2012-02-27 23:33:19 . 2012-02-27 23:33:19 398848 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\88ffeea88ac9ce23de0c5a27a95e773a\System.Web.Entity.Design.ni.dll
    + 2012-02-27 23:33:14 . 2012-02-27 23:33:14 753664 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\7a311c3305dbbd5cfa2613997608a4ae\System.Web.DynamicData.ni.dll
    + 2012-02-27 23:32:45 . 2012-02-27 23:32:45 204800 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\e5069f3c90b4413dd2f3dc226c80bc68\System.Web.Abstractions.ni.dll
    + 2012-02-17 14:36:46 . 2012-02-17 14:36:46 921600 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\caa6d0e3ec056ab964616da777c2fcb1\System.Transactions.ni.dll
    + 2012-02-17 14:37:50 . 2012-02-17 14:37:50 295424 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\872d9ab7e9259b407668c38b6112499e\System.ServiceProcess.ni.dll
    + 2012-02-17 14:33:28 . 2012-02-17 14:33:28 928768 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Security\ffc67ee81b75ac04dfc1fee6a7fef8c5\System.Security.ni.dll
    + 2012-02-17 14:34:59 . 2012-02-17 14:34:59 396288 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\bc8c5bdae37a113b2274279ceb94d6d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2012-02-27 23:33:04 . 2012-02-27 23:33:04 916480 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Net\e238ca4ca02f9309283c98e1a4235bbd\System.Net.ni.dll
    + 2012-02-27 23:28:22 . 2012-02-27 23:28:22 783360 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\9880905a6fde778e564adf54b2afbaa5\System.Messaging.ni.dll
    + 2012-02-27 23:33:02 . 2012-02-27 23:33:02 534016 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\c340633057ed6b9ffcf2214cb348a1fa\System.Management.Instrumentation.ni.dll
    + 2012-02-27 23:33:00 . 2012-02-27 23:33:00 569856 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\c24a84d54ad05618cf6cab545c31b06b\System.IO.Log.ni.dll
    + 2012-02-27 23:28:23 . 2012-02-27 23:28:23 294400 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\2ba95581264a766410a6dbbe767c5ed8\System.IdentityModel.Selectors.ni.dll
    + 2012-02-17 14:36:48 . 2012-02-17 14:36:48 446464 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\dbd535c6b73a9d9ffab8b91124ea7dda\System.EnterpriseServices.Wrapper.dll
    + 2012-02-17 14:37:45 . 2012-02-17 14:37:45 288768 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\f1fd4593259aaf5fd2b2e9a7aed2d8cb\System.Drawing.Design.ni.dll
    + 2012-02-17 14:37:50 . 2012-02-17 14:37:50 649728 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\3c2c8f083f34a3c75e0aa17ef9ac4127\System.DirectoryServices.Protocols.ni.dll
    + 2012-02-27 23:32:55 . 2012-02-27 23:32:55 629760 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\be6635364f1af379afff83dd877a4e03\System.Data.Services.Design.ni.dll
    + 2012-02-27 23:31:44 . 2012-02-27 23:31:44 194560 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\027959159200e828ccfddaef5f01b3a9\System.Data.DataSetExtensions.ni.dll
    + 2012-02-17 14:37:51 . 2012-02-17 14:37:51 192000 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\e71e38d2ca2cd291467d890336f45931\System.Configuration.Install.ni.dll
    + 2012-02-27 23:31:43 . 2012-02-27 23:31:43 132096 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\8c954be3f8d070b1364844741ff4b4b1\System.ComponentModel.DataAnnotations.ni.dll
    + 2012-02-27 23:31:42 . 2012-02-27 23:31:42 889344 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\bd9159951d0caa9bf5c90c44fc96661b\System.AddIn.ni.dll
    + 2011-11-28 04:21:06 . 2011-11-28 04:21:06 156672 C:\Windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\edf038eef2dc9f21b13da8bdc046a834\System.AddIn.Contract.ni.dll
    + 2011-11-28 04:22:23 . 2011-11-28 04:22:23 297984 C:\Windows\assembly\NativeImages_v2.0.50727_64\sysglobl\0ba53d547dabd039b0cfc9ce52fa6c57\sysglobl.ni.dll
    + 2012-02-27 23:31:40 . 2012-02-27 23:31:40 525824 C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\8bfc7a328911ae69686576bd24f4f771\SMSvcHost.ni.exe
    + 2012-02-27 23:28:13 . 2012-02-27 23:28:13 349184 C:\Windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\823bd996cb5aefd6c2b2fa7e19e0ef40\SMDiagnostics.ni.dll
    + 2012-02-17 14:37:57 . 2012-02-17 14:37:57 317440 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\cc864feeea3e918e3d9790b301bb2004\PresentationFramework.Royale.ni.dll
    + 2012-02-17 14:37:57 . 2012-02-17 14:37:57 620544 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\ab440c134c4d619f82ba6eab569c8fed\PresentationFramework.Luna.ni.dll
    + 2012-02-17 14:37:53 . 2012-02-17 14:37:53 463360 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\0e79d12dc8bede29dc337dba8d803bfa\PresentationFramework.Aero.ni.dll
    + 2012-02-17 14:37:55 . 2012-02-17 14:37:55 282624 C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\0e6121dbd31ce6b51354b38075dc9007\PresentationFramework.Classic.ni.dll
    + 2012-02-27 23:31:29 . 2012-02-27 23:31:29 855040 C:\Windows\assembly\NativeImages_v2.0.50727_64\napsnap\9c808282a0cfdc5bafcb43e1778d97d6\napsnap.ni.dll
    + 2012-02-27 23:31:28 . 2012-02-27 23:31:28 162816 C:\Windows\assembly\NativeImages_v2.0.50727_64\napinit\616ce317134d4225fc7eec80f9351855\napinit.ni.dll
    + 2011-11-28 04:20:51 . 2011-11-28 04:20:51 175104 C:\Windows\assembly\NativeImages_v2.0.50727_64\naphlpr\fd2464358cddfa04f46d55b9153249e3\naphlpr.ni.dll
    + 2011-11-28 04:20:51 . 2011-11-28 04:20:51 127488 C:\Windows\assembly\NativeImages_v2.0.50727_64\napcrypt\717cc07bafa8f50a6f87be383fa9018b\napcrypt.ni.dll
    + 2012-02-27 23:26:52 . 2012-02-27 23:26:52 407552 C:\Windows\assembly\NativeImages_v2.0.50727_64\MyDock.Util\1544eaee85f685abaa4a4dab79e71891\MyDock.Util.ni.dll
    + 2012-02-27 23:31:27 . 2012-02-27 23:31:27 184320 C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild\a4b5d98bf175a3f10c47f223195c34b0\MSBuild.ni.exe
    + 2012-02-27 23:29:49 . 2012-02-27 23:29:49 417792 C:\Windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\b94e1c9115d8e37e734b27b48f54d236\MMCFxCommon.ni.dll
    + 2012-02-27 23:31:22 . 2012-02-27 23:31:22 681984 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\04532b2b5174ca249e01a8b21d0ba6fd\Microsoft.WSMan.Management.ni.dll
    + 2012-02-27 23:31:20 . 2012-02-27 23:31:20 122368 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\5cd854d075caf8b50de3c803b4303e03\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll
    + 2012-02-27 23:27:04 . 2012-02-27 23:27:04 105984 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\cb1c199305d00b2424e707311eb9dcfd\Microsoft.Vsa.ni.dll
    + 2012-02-27 23:31:16 . 2012-02-27 23:31:16 584192 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\b2438f632ab1dcbb1cb91c5a1226aaf1\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2012-02-27 23:31:14 . 2012-02-27 23:31:14 999936 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d7f5b39fba028d2f9e2b3a772845a2a6\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2012-02-27 23:30:53 . 2012-02-27 23:30:53 416768 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\99bb7896ddbe74236efaa97733c63cbc\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2012-02-27 23:31:00 . 2012-02-27 23:31:00 713216 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\71542ecf96342dc1464fe471852be89a\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2012-02-27 23:31:15 . 2012-02-27 23:31:15 237056 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\0bafa5e2dc431bb12108395cf2e18773\Microsoft.PowerShell.Security.ni.dll
    + 2012-02-27 23:29:04 . 2012-02-27 23:29:04 522240 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\ddd2f252bea1cce14bb498257992635a\Microsoft.MediaCenter.Interop.ni.dll
    + 2012-02-27 23:30:28 . 2012-02-27 23:30:28 164864 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\cf9be66d53dddbf49b75cead76ef3cea\Microsoft.MediaCenter.Mheg.ni.dll
    + 2011-11-26 01:56:30 . 2011-11-26 01:56:30 152576 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\a743124afb874ab00d713ab50a7d850d\Microsoft.MediaCenter.ITVVM.ni.dll
    + 2011-11-28 04:18:54 . 2011-11-28 04:18:54 219648 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\7de5318ee2be8e2b8fcffde83c79ab7c\Microsoft.MediaCenter.iTv.Media.ni.dll
    + 2012-02-27 23:29:04 . 2012-02-27 23:29:04 370176 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\55172dec8f1353d1a8d9cdc4c0b9fac0\Microsoft.MediaCenter.Playback.ni.dll
    + 2012-02-27 23:29:08 . 2012-02-27 23:29:08 965632 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5495e7eca3dac7eee473e30a3611f178\Microsoft.MediaCenter.Sports.ni.dll
    + 2012-02-27 23:29:45 . 2012-02-27 23:29:45 312320 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\35ce662c1368782ede0852134106ea43\Microsoft.MediaCenter.iTv.ni.dll
    + 2012-02-27 23:29:48 . 2012-02-27 23:29:48 798720 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\505549b05e5c3ceccd26ad9c398381e8\Microsoft.ManagementConsole.ni.dll
    + 2012-02-27 23:30:18 . 2012-02-27 23:30:18 244736 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\f356844d3667b88d03bde2ae524659b6\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2012-02-27 23:30:19 . 2012-02-27 23:30:19 198656 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\86f7fa65013864ae7da2fba058199dae\Microsoft.Build.Utilities.ni.dll
    + 2011-11-28 04:19:23 . 2011-11-28 04:19:23 142336 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\9f5bcff6a0b169efa6b607efd8789ea9\Microsoft.Build.Framework.ni.dll
    + 2011-11-28 04:19:26 . 2011-11-28 04:19:26 121344 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\0ef8fa5e835e9ae9fd9a20e5d5058460\Microsoft.Build.Framework.ni.dll
    + 2012-02-27 23:30:05 . 2012-02-27 23:30:05 294912 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\c467a4d9eeda620e3e7602a9ecf9ae76\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-11-28 04:19:19 . 2011-11-28 04:19:19 107520 C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\348c58da6c217fb9a1a6f33b19bc1501\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll
    + 2012-02-27 23:29:45 . 2012-02-27 23:29:45 380928 C:\Windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\304068df803748d7743a6a4dc344915f\Mcx2Dvcs.ni.dll
    + 2012-02-27 23:30:03 . 2012-02-27 23:30:03 547328 C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate\fb79aad0c745ff7b45151bc58b4dc8e9\mcupdate.ni.exe
    + 2012-02-27 23:28:55 . 2012-02-27 23:28:55 533504 C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\4a29229fecf805779bee25b756d78a0d\mcstoredb.ni.dll
    + 2012-02-27 23:30:02 . 2012-02-27 23:30:02 549376 C:\Windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\8affc4346a86b80727282966ce58662b\mcplayerinterop.ni.dll
    + 2012-02-27 23:30:00 . 2012-02-27 23:30:00 696320 C:\Windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\756a74d6b322877662a0f6da4bc7d8e6\mcGlidHostObj.ni.dll
    + 2012-02-27 23:29:58 . 2012-02-27 23:29:58 156672 C:\Windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\2ce02776e0f2f1770f4bb77e1f6d7472\MCESidebarCtrl.ni.dll
    + 2012-02-27 23:29:47 . 2012-02-27 23:29:47 659456 C:\Windows\assembly\NativeImages_v2.0.50727_64\EventViewer\956ca0e08e881df7f16f7d6d1381f71d\EventViewer.ni.dll
    + 2012-02-27 23:28:45 . 2012-02-27 23:28:45 969216 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\307ca4b67db79b05b4781634ea8ec0d7\ehRecObj.ni.dll
    + 2011-11-26 01:56:27 . 2011-11-26 01:56:27 661504 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\87f11d95ab10469f888fd76c45f9fceb\ehiWUapi.ni.dll
    + 2011-11-26 01:56:26 . 2011-11-26 01:56:26 933888 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\a24c79d19a6d2a3e8ca587ecddd3e735\ehiwmp.ni.dll
    + 2011-10-16 02:12:39 . 2011-10-16 02:12:39 145408 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0de7a02857c6041bc2c86c1db3ca8c23\ehiUserXp.ni.dll
    + 2011-11-26 01:56:23 . 2011-11-26 01:56:23 196096 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\421eb174f94249cf6a3b9e517baa82f8\ehiiTv.ni.dll
    + 2011-11-26 01:56:22 . 2011-11-26 01:56:22 397824 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\d5bf6f8e9e3d08d407ed68b714c268ae\ehiExtens.ni.dll
    + 2011-11-26 01:56:22 . 2011-11-26 01:56:22 110080 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\b55c3bb24dda0acda2bc332cc3016f75\ehiBmlDataCarousel.ni.dll
    + 2011-11-26 01:56:22 . 2011-11-26 01:56:22 126976 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\cbebce3e616f8fa475427e94a5f607de\ehiActivScp.ni.dll
    + 2012-02-27 23:28:29 . 2012-02-27 23:28:29 389120 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\5f53457f49927ecf00156d20466cc5a6\ehExtHost.ni.exe
    + 2012-02-27 23:28:26 . 2012-02-27 23:28:26 313856 C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR\b49168b11f5f60ddafed2ab1fdd4540f\ehCIR.ni.dll
    + 2011-11-26 01:56:00 . 2011-11-26 01:56:00 348672 C:\Windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\1e040217cf674c6cf528fbfe18c4c2f8\CustomMarshalers.ni.dll
    + 2012-02-27 23:27:34 . 2012-02-27 23:27:34 640000 C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\f2808fb3389d3e28e2b0223dcd654e02\ComSvcConfig.ni.exe
    + 2012-02-27 23:26:22 . 2012-02-27 23:26:22 971264 C:\Windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\45af2aab82a69a1a6fe0f7cef4024673\BDATunePIA.ni.dll
    + 2012-03-01 22:46:54 . 2012-03-01 22:46:54 321024 C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\105e77fbca8c5bb29988f3847b0d599f\WsatConfig.ni.exe
    + 2012-02-28 01:04:33 . 2012-02-28 01:04:33 633856 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\89b33061218d345ed0b937b7fe785df9\WindowsLiveLocal.WriterPlugin.ni.dll
    + 2012-02-28 01:04:31 . 2012-02-28 01:04:31 119296 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dd50adf5a3ac7dadf33131f4eb595a57\WindowsLive.Writer.FileDestinations.ni.dll
    + 2012-02-28 01:04:25 . 2012-02-28 01:04:25 108544 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b8347c45498583e893bf6d2f32b3557c\WindowsLive.Writer.Passport.ni.dll
    + 2011-10-19 00:08:57 . 2011-10-19 00:08:57 334848 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a2fb4df08101d5b1ae54f23d8b450e77\WindowsLive.Writer.Interop.Mshtml.ni.dll
    + 2012-02-28 01:04:24 . 2012-02-28 01:04:24 152064 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8b0678e775e389f71cfa327fa7d9517d\WindowsLive.Writer.HtmlParser.ni.dll
    + 2012-02-28 01:04:27 . 2012-02-28 01:04:27 118784 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\83710dc46973b5d931177e243fe32f83\WindowsLive.Writer.Extensibility.ni.dll
    + 2012-02-28 01:04:23 . 2012-02-28 01:04:23 319488 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7fce28738c3284334511cc990338c2c8\WindowsLive.Writer.Interop.ni.dll
    + 2012-02-28 01:04:30 . 2012-02-28 01:04:30 594944 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7a491a59942aabc7006dfa22ecf97d83\WindowsLive.Writer.HtmlEditor.ni.dll
    + 2012-02-28 01:04:29 . 2012-02-28 01:04:29 851968 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\799eebb88b45f4bb1d319354fb9c4ab1\WindowsLive.Writer.BlogClient.ni.dll
    + 2012-02-28 01:04:23 . 2012-02-28 01:04:23 174080 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7638e949e82bcb69be73a5d980b15849\WindowsLive.Writer.BrowserControl.ni.dll
    + 2012-02-28 01:04:31 . 2012-02-28 01:04:31 321536 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6bc2037a1ce1c95b8ef186df80cc245e\WindowsLive.Writer.SpellChecker.ni.dll
    + 2012-02-28 01:04:21 . 2012-02-28 01:04:21 843776 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5de26322b6768d6ca30c7916372b8d79\WindowsLive.Writer.Controls.ni.dll
    + 2012-02-28 01:04:32 . 2012-02-28 01:04:32 117760 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4603800223476adaa15d9ddcddad4517\WindowsLive.Writer.Instrumentation.ni.dll
    + 2012-02-28 01:04:25 . 2012-02-28 01:04:25 258560 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3763ca29387f486abc63a7d4cbfb2417\WindowsLive.Writer.Mshtml.ni.dll
    + 2012-02-28 01:04:24 . 2012-02-28 01:04:24 428032 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\34be42e5977a1297ddb2037a48c02c30\WindowsLive.Writer.Localization.ni.dll
    + 2011-10-19 00:08:57 . 2011-10-19 00:08:57 313856 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\337a858556e37fa49fd8673a7c1c79c1\WindowsLive.Writer.Interop.SHDocVw.ni.dll
    + 2012-02-28 01:04:29 . 2012-02-28 01:04:29 145920 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\d037382638d933e81479a0099d33663d\WindowsLive.Client.ni.dll
    + 2012-03-01 22:46:48 . 2012-03-01 22:46:48 240128 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\af6e0dd358a5edc094dca9e7957f1038\WindowsFormsIntegration.ni.dll
    + 2011-10-16 02:23:44 . 2011-10-16 02:23:44 185344 C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\93df5ea9646ad11a21517e4ab1d803d9\UIAutomationTypes.ni.dll
    + 2012-02-28 01:05:58 . 2012-02-28 01:05:58 452096 C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\d0972fea9e965a565c3cff76982709db\UIAutomationClient.ni.dll
    + 2012-02-28 01:07:42 . 2012-02-28 01:07:42 245248
     
  25. Mominator

    Mominator TS Rookie Topic Starter Posts: 29

    #5 ......................................................................................................
    C:\Windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\ff345d3a2aaafb8a960c3d400e3c11a9\TaskScheduler.ni.dll
    + 2012-02-28 01:07:03 . 2012-02-28 01:07:03 401408 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\fa1161af51ab42a61bfac9d02d469a06\System.Xml.Linq.ni.dll
    + 2012-02-28 01:07:25 . 2012-02-28 01:07:25 129536 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\43e0731fbb58632563909f1fa5dfe063\System.Web.Routing.ni.dll
    + 2012-02-17 14:40:25 . 2012-02-17 14:40:25 202240 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\84ee5a23a20b65773686657254ea9831\System.Web.RegularExpressions.ni.dll
    + 2012-02-28 01:07:31 . 2012-02-28 01:07:31 860160 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\95f94674ddc4b1224df94bd7ae19c9ef\System.Web.Extensions.Design.ni.dll
    + 2012-02-28 01:07:28 . 2012-02-28 01:07:28 328192 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\4c569a365154300e49ab3450f74c2618\System.Web.Entity.ni.dll
    + 2012-02-28 01:07:29 . 2012-02-28 01:07:29 301568 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\fb21c5770bc64fc4105787238842f70d\System.Web.Entity.Design.ni.dll
    + 2012-02-28 01:07:26 . 2012-02-28 01:07:26 547328 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\785e2ad4125cef423bc367b37fabb71c\System.Web.DynamicData.ni.dll
    + 2012-02-28 01:07:09 . 2012-02-28 01:07:09 141312 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\685fb72f0189330eda1d62176fb38996\System.Web.Abstractions.ni.dll
    + 2012-02-17 14:40:05 . 2012-02-17 14:40:05 627200 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9e8dfbd1334d30a08ce1f2df29ca9aff\System.Transactions.ni.dll
    + 2012-02-17 14:40:26 . 2012-02-17 14:40:26 212992 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\075d9c27aa02085fef8983b5f5f85834\System.ServiceProcess.ni.dll
    + 2012-02-17 14:39:12 . 2012-02-17 14:39:12 680448 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\dc4a4350f8c0c0919b5fb78f0c44291b\System.Security.ni.dll
    + 2012-02-17 14:39:37 . 2012-02-17 14:39:37 310784 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\adb2fc93e7a4462eb399442c678be681\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2012-02-17 14:40:06 . 2012-02-17 14:40:06 771584 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll
    + 2012-02-28 01:07:20 . 2012-02-28 01:07:20 624128 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Net\2273d6ab12c9ae0d52842a84d586b8df\System.Net.ni.dll
    + 2012-02-28 01:05:00 . 2012-02-28 01:05:00 593408 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\a717cdb44ec0d3238c621efa420a9956\System.Messaging.ni.dll
    + 2012-02-28 01:07:19 . 2012-02-28 01:07:19 330240 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\b5930434d0d624701114e014513c9041\System.Management.Instrumentation.ni.dll
    + 2012-02-28 01:07:18 . 2012-02-28 01:07:18 381440 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\7651951311f9d134e6bc08be7dc9ddc7\System.IO.Log.ni.dll
    + 2012-02-28 01:05:00 . 2012-02-28 01:05:00 212992 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\8b0dc9405f292a93ddd52eb76bb88169\System.IdentityModel.Selectors.ni.dll
    + 2012-02-17 14:40:05 . 2012-02-17 14:40:05 280064 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.Wrapper.dll
    + 2012-02-17 14:40:05 . 2012-02-17 14:40:05 628224 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\3fccda0d4dd150a217c2798e39e97a48\System.EnterpriseServices.ni.dll
    + 2012-02-17 14:40:23 . 2012-02-17 14:40:23 208384 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\a09d397c3a4eb60b04a0628cc187ce34\System.Drawing.Design.ni.dll
    + 2012-02-17 14:40:25 . 2012-02-17 14:40:25 455680 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\eebb837dbb8e5781e448c72eeda27983\System.DirectoryServices.Protocols.ni.dll
    + 2012-02-28 01:07:16 . 2012-02-28 01:07:16 888320 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\344d3289061b28a0f7fb19229f45bb9c\System.DirectoryServices.AccountManagement.ni.dll
    + 2012-02-28 01:07:14 . 2012-02-28 01:07:14 462336 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\6a6642467bcccf0345c5e9139e7fd9ae\System.Data.Services.Design.ni.dll
    + 2012-02-28 01:06:57 . 2012-02-28 01:06:57 763392 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\c1cf8e31da405f07780fa7b0f28cc650\System.Data.Entity.Design.ni.dll
    + 2012-02-28 01:06:24 . 2012-02-28 01:06:24 135680 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\71400a36c8621388031e00075f2fc8e9\System.Data.DataSetExtensions.ni.dll
    + 2012-02-17 14:38:53 . 2012-02-17 14:38:53 971264 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
    + 2012-02-17 14:40:26 . 2012-02-17 14:40:26 141312 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\47e25ae9163f4624a66f99ede0ea98fe\System.Configuration.Install.ni.dll
    + 2012-02-28 01:06:23 . 2012-02-28 01:06:23 633344 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\05c4011ad0068d0af722b4b52677d915\System.AddIn.ni.dll
    + 2011-10-19 00:14:09 . 2011-10-19 00:14:09 232448 C:\Windows\assembly\NativeImages_v2.0.50727_32\sysglobl\571bcd3c57411a09469a58c7462a4c8b\sysglobl.ni.dll
    + 2012-02-28 01:06:22 . 2012-02-28 01:06:22 366080 C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\17b78ffee2144cf38f024e73b131158d\SMSvcHost.ni.exe
    + 2012-02-28 01:04:55 . 2012-02-28 01:04:55 256000 C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\281b67b96a2dd473dad4d222da0ca514\SMDiagnostics.ni.dll
    + 2012-02-17 14:40:29 . 2012-02-17 14:40:29 539648 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fbcb09488417e40b6f7f7737f737bbfd\PresentationFramework.Luna.ni.dll
    + 2012-02-17 14:40:28 . 2012-02-17 14:40:28 226816 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\dbd1929fa377b354903e37469838d9a1\PresentationFramework.Classic.ni.dll
    + 2012-02-17 14:40:27 . 2012-02-17 14:40:27 368128 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\74fcc0f56435d0396f9524cd4293d3e5\PresentationFramework.Aero.ni.dll
    + 2012-02-17 14:40:29 . 2012-02-17 14:40:29 258048 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4ff6c887092d4db687441d71e2c812ff\PresentationFramework.Royale.ni.dll
    + 2012-02-28 01:06:15 . 2012-02-28 01:06:15 723456 C:\Windows\assembly\NativeImages_v2.0.50727_32\napsnap\62531ec9534c96e83de2bbd4edfd07e8\napsnap.ni.dll
    + 2012-02-28 01:06:14 . 2012-02-28 01:06:14 117760 C:\Windows\assembly\NativeImages_v2.0.50727_32\napinit\bb49eea48fd5f546afc6d5be634d3cb9\napinit.ni.dll
    + 2011-10-19 00:12:14 . 2011-10-19 00:12:14 114176 C:\Windows\assembly\NativeImages_v2.0.50727_32\naphlpr\6c31aace1d7b39145fe0ef94f1530e8a\naphlpr.ni.dll
    + 2012-02-28 01:06:13 . 2012-02-28 01:06:13 133632 C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild\4ac4095081957a001a6174c0b9f7f195\MSBuild.ni.exe
    + 2012-02-28 01:05:19 . 2012-02-28 01:05:19 287232 C:\Windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\bd5a72adac7a95585984d5bcce994b71\MMCFxCommon.ni.dll
    + 2012-02-28 01:06:10 . 2012-02-28 01:06:10 531968 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\928fb6b2401fffd8cc993578c3a04acd\Microsoft.WSMan.Management.ni.dll
    + 2012-02-28 01:06:03 . 2012-02-28 01:06:03 386560 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\481b6ebea3e357f29a4ec0e8193d36d3\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2012-02-28 01:05:51 . 2012-02-28 01:05:51 515584 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\eda566c4dc6595779c3c9dfc359575ed\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2012-02-28 01:06:02 . 2012-02-28 01:06:02 167424 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\df4f6b6f33d84b7f438c3f3b66f0336d\Microsoft.PowerShell.Security.ni.dll
    + 2012-02-28 01:06:01 . 2012-02-28 01:06:01 729088 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\951235283ff1d4a91ffaa92ea8693249\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2012-02-28 01:05:47 . 2012-02-28 01:05:47 786432 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\5f7928a2ffe462f16e25f03be01966e9\Microsoft.PowerShell.Commands.Management.ni.dll
    + 2012-02-28 01:05:46 . 2012-02-28 01:05:46 291328 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\2015eca4346e34310e958089b22a9c62\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2012-02-28 01:05:18 . 2012-02-28 01:05:18 561664 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\6386ef67ed70f53fe6424246d256190d\Microsoft.ManagementConsole.ni.dll
    + 2012-02-28 01:05:30 . 2012-02-28 01:05:30 175104 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\c8e128b5e6ceee852cb1f8c165c2177e\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2012-02-28 01:05:30 . 2012-02-28 01:05:30 144384 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\9795da40a8ee0bc54e91792de7422152\Microsoft.Build.Utilities.ni.dll
    + 2012-02-28 01:05:26 . 2012-02-28 01:05:26 839680 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\be7ad749a064283deab76fad38bf2930\Microsoft.Build.Engine.ni.dll
    + 2012-02-28 01:05:23 . 2012-02-28 01:05:23 222720 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\f42105699650a206e2ae439ac54ad40a\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2012-02-28 01:05:16 . 2012-02-28 01:05:16 364032 C:\Windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\886a8c3d4f00567df779318fea56f28a\mcstoredb.ni.dll
    + 2012-02-28 01:05:17 . 2012-02-28 01:05:17 553472 C:\Windows\assembly\NativeImages_v2.0.50727_32\EventViewer\58ea1059f397ccd13d6a8d94d7be7830\EventViewer.ni.dll
    + 2012-02-28 01:05:10 . 2012-02-28 01:05:10 693248 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\9d5219961228fb5236c843ea75c69d39\ehRecObj.ni.dll
    + 2011-10-19 00:10:13 . 2011-10-19 00:10:13 875520 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\fbec5a519a2c5005d43b04b6386406b2\ehiVidCtl.ni.dll
    + 2011-10-19 00:10:05 . 2011-10-19 00:10:05 442880 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\832b98f0578e73e8693fea7067c3d2ab\ehiProxy.ni.dll
    + 2011-10-19 00:10:13 . 2011-10-19 00:10:13 161280 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\fa383760dc46e586ae40374129164b4e\ehiExtens.ni.dll
    + 2012-02-28 01:05:04 . 2012-02-28 01:05:04 254464 C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\6a07aa6df4d45d1485b6a2749647a3aa\ehExtHost32.ni.exe
    + 2011-10-19 00:09:52 . 2011-10-19 00:09:52 220672 C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\2c2215e99c21daeec6bf697cf7bcf103\CustomMarshalers.ni.dll
    + 2012-02-28 01:04:35 . 2012-02-28 01:04:35 410112 C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\39ab6b73bdbaac85b90cc561761916f7\ComSvcConfig.ni.exe
    + 2012-02-28 01:03:58 . 2012-02-28 01:03:58 621568 C:\Windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\d89086a63a9d85aa9d719d7088e5ae69\BDATunePIA.ni.dll
    + 2012-03-24 19:43:58 . 2012-03-24 19:43:58 608136 C:\Windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
    + 2011-10-13 21:05:24 . 2011-08-17 05:28:23 315392 C:\Windows\assembly\GAC_64\Microsoft.MediaCenter.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Interop.dll
    - 2011-06-11 00:33:48 . 2010-11-20 13:44:11 315392 C:\Windows\assembly\GAC_64\Microsoft.MediaCenter.Interop\6.1.0.0__31bf3856ad364e35\Microsoft.MediaCenter.Interop.dll
    + 2012-03-24 19:43:58 . 2012-03-24 19:43:58 117160 C:\Windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
    - 2011-09-13 08:05:42 . 2011-09-13 08:05:42 870256 C:\Windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2012-03-24 19:43:53 . 2012-03-24 19:43:53 870256 C:\Windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2011-12-22 18:08:16 . 2011-12-22 18:08:16 350080 C:\Windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2012-03-24 19:43:16 . 2012-03-24 19:43:16 149368 C:\Windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1127424 C:\Windows\SysWOW64\wininet.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1103360 C:\Windows\SysWOW64\urlmon.dll
    + 2012-01-11 14:12:14 . 2011-10-26 04:32:11 1328128 C:\Windows\SysWOW64\quartz.dll
    - 2011-06-11 00:34:38 . 2010-11-20 12:20:59 1328128 C:\Windows\SysWOW64\quartz.dll
    + 2012-01-11 14:12:20 . 2011-11-17 05:38:39 1292080 C:\Windows\SysWOW64\ntdll.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1798656 C:\Windows\SysWOW64\jscript9.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1792000 C:\Windows\SysWOW64\iertutil.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 9705472 C:\Windows\SysWOW64\ieframe.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 3695416 C:\Windows\SysWOW64\ieapfltr.dat
    + 2011-07-07 07:28:22 . 2011-07-07 07:28:22 1193320 C:\Windows\SysWOW64\FM20.DLL
    + 2009-07-14 04:54:17 . 2012-03-26 23:34:28 3489792 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-14 04:54:17 . 2012-03-26 23:34:28 4702208 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1390080 C:\Windows\system32\wininet.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 1345536 C:\Windows\system32\urlmon.dll
    + 2012-01-11 14:12:14 . 2011-10-26 05:25:16 1572864 C:\Windows\system32\quartz.dll
    + 2012-01-11 14:12:20 . 2011-11-17 06:41:18 1731920 C:\Windows\system32\ntdll.dll
    - 2011-06-11 00:34:47 . 2010-11-20 13:26:47 1447936 C:\Windows\system32\lsasrv.dll
    + 2012-01-18 17:32:39 . 2011-11-17 06:35:19 1447936 C:\Windows\system32\lsasrv.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 2308096 C:\Windows\system32\jscript9.dll
    + 2012-03-24 19:54:21 . 2012-03-24 19:54:21 2144256 C:\Windows\system32\iertutil.dll
    + 2012-03-24 19:54:20 . 2012-03-24 19:54:20 3695416 C:\Windows\system32\ieapfltr.dat
    + 2011-11-14 22:34:02 . 2011-09-29 16:29:28 1923952 C:\Windows\system32\drivers\tcpip.sys
    + 2009-07-14 04:45:55 . 2012-03-25 20:11:58 7114300 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    - 2009-07-14 04:45:55 . 2011-10-08 02:37:24 7114300 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2010-02-07 09:09:41 . 2012-03-27 02:02:31 1964760 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 3512072 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 4970768 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 1455376 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 1515792 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
    + 2011-11-22 04:57:40 . 2011-11-22 04:57:40 9793280 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
    + 2011-12-31 02:15:57 . 2011-12-25 20:40:47 5263360 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
    - 2011-08-11 00:48:47 . 2011-05-04 22:31:13 3190784 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
    + 2012-02-14 18:54:09 . 2011-10-31 23:15:44 3190784 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
    + 2011-10-13 21:05:19 . 2011-07-08 22:31:15 9990992 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
    + 2011-10-13 21:05:16 . 2011-07-08 22:31:14 4567040 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:32:08 4567040 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:32:07 1755480 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
    + 2011-10-13 21:05:17 . 2011-07-08 22:31:14 1755480 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 3512072 C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 5201168 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 1143568 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
    + 2011-11-22 03:31:18 . 2011-11-22 03:31:18 6727424 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
    + 2011-12-31 02:15:57 . 2011-12-25 20:42:15 5255168 C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    - 2011-08-11 00:48:47 . 2011-05-04 22:32:40 3190784 C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2012-02-14 18:54:10 . 2011-10-31 23:16:22 3190784 C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:33:49 5924176 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    + 2011-10-13 21:05:18 . 2011-07-08 22:33:43 5924176 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2011-07-13 08:35:11 . 2011-03-29 22:33:48 4550656 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-10-13 21:05:16 . 2011-07-08 22:33:43 4550656 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2012-03-24 19:31:53 . 2012-03-24 19:31:53 1368920 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    - 2011-09-18 05:09:36 . 2011-09-18 05:09:36 1368920 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    + 2012-03-24 19:31:32 . 2012-03-24 19:31:32 3512072 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    - 2011-09-18 05:09:25 . 2011-09-18 05:09:25 2207568 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    + 2012-03-24 19:31:34 . 2012-03-24 19:31:34 2207568 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    + 2012-03-24 19:31:33 . 2012-03-24 19:31:33 5028200 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2011-09-18 05:09:24 . 2011-09-18 05:09:24 5028200 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2012-03-24 19:31:33 . 2012-03-24 19:31:33 1711496 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    - 2011-09-18 05:09:24 . 2011-09-18 05:09:24 1711496 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    + 2012-03-24 19:31:44 . 2012-03-24 19:31:44 6097256 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    - 2011-09-18 05:09:31 . 2011-09-18 05:09:31 6097256 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    + 2012-03-24 19:31:44 . 2012-03-24 19:31:44 1026936 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-09-18 05:09:31 . 2011-09-18 05:09:31 1026936 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    - 2011-09-18 05:09:26 . 2011-09-18 05:09:26 4464480 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2012-03-24 19:31:36 . 2012-03-24 19:31:36 4464480 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2012-03-24 19:31:36 . 2012-03-24 19:31:36 1354584 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    - 2011-09-18 05:09:26 . 2011-09-18 05:09:26 1354584 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    + 2012-03-24 19:31:43 . 2012-03-24 19:31:43 1199968 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    - 2011-09-18 05:09:30 . 2011-09-18 05:09:30 1199968 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    - 2011-09-18 05:09:30 . 2011-09-18 05:09:30 1462648 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    + 2012-03-24 19:31:42 . 2012-03-24 19:31:42 1462648 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    + 2012-03-24 19:31:50 . 2012-03-24 19:31:50 6428520 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    - 2011-09-18 05:09:35 . 2011-09-18 05:09:35 6428520 C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    - 2011-09-18 05:09:21 . 2011-09-18 05:09:21 3116376 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2012-03-24 19:31:29 . 2012-03-24 19:31:29 3116376 C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-09-18 05:09:34 . 2011-09-18 05:09:34 3824480 C:\Windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-03-24 19:31:49 . 2012-03-24 19:31:49 3824480 C:\Windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-03-24 19:31:25 . 2012-03-24 19:31:25 4970768 C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2012-03-24 19:31:41 . 2012-03-24 19:31:41 3563408 C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    - 2011-09-18 05:09:29 . 2011-09-18 05:09:29 3563408 C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2012-03-24 19:30:34 . 2012-03-24 19:30:34 2975064 C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-09-18 05:08:56 . 2011-09-18 05:08:56 2975064 C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    - 2011-09-18 05:09:14 . 2011-09-18 05:09:14 3788128 C:\Windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-03-24 19:31:14 . 2012-03-24 19:31:14 3788128 C:\Windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2012-03-24 19:30:19 . 2012-03-24 19:30:19 5201168 C:\Windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-09-18 05:09:07 . 2011-09-18 05:09:07 2989456 C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2012-03-24 19:30:58 . 2012-03-24 19:30:58 2989456 C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-10-26 22:36:14 . 2011-10-26 22:36:14 2829312 C:\Windows\Installer\c7cda.msp
    + 2012-02-03 21:13:48 . 2012-02-03 21:13:48 4988928 C:\Windows\Installer\c7cd1.msp
    + 2011-12-26 12:24:12 . 2011-12-26 12:24:12 8835072 C:\Windows\Installer\ba0fa59.msp
    + 2011-11-01 19:34:30 . 2011-11-01 19:34:30 1552384 C:\Windows\Installer\7d9c9.msp
    + 2011-11-01 19:34:56 . 2011-11-01 19:34:56 4250112 C:\Windows\Installer\7d9a3.msp
    + 2011-11-01 19:34:28 . 2011-11-01 19:34:28 2247168 C:\Windows\Installer\7d967.msp
    + 2011-11-11 22:14:40 . 2011-11-11 22:14:40 9096192 C:\Windows\Installer\7d942.msp
    + 2011-11-01 19:34:58 . 2011-11-01 19:34:58 4225536 C:\Windows\Installer\7d92c.msp
    + 2011-11-01 19:34:30 . 2011-11-01 19:34:30 2531840 C:\Windows\Installer\7d8e8.msp
    + 2011-11-11 22:15:00 . 2011-11-11 22:15:00 1795584 C:\Windows\Installer\7d8d1.msp
    + 2011-11-11 22:16:20 . 2011-11-11 22:16:20 8458240 C:\Windows\Installer\7d898.msp
    + 2011-12-09 01:24:04 . 2011-12-09 01:24:04 4989952 C:\Windows\Installer\63112.msp
    + 2011-09-15 23:40:36 . 2011-09-15 23:40:36 7959552 C:\Windows\Installer\4e58d.msp
    + 2011-09-15 23:34:14 . 2011-09-15 23:34:14 8499712 C:\Windows\Installer\4e56f.msp
    + 2011-09-15 23:35:54 . 2011-09-15 23:35:54 1411072 C:\Windows\Installer\4e215.msp
    + 2012-03-01 04:45:14 . 2012-03-01 04:45:14 4989440 C:\Windows\Installer\2baefdc.msp
    + 2012-02-07 23:12:24 . 2012-02-07 23:12:24 2924544 C:\Windows\Installer\156261f8.msi
    + 2011-09-21 21:18:24 . 2011-09-21 21:18:24 4985856 C:\Windows\Installer\14bd59.msp
    + 2010-01-29 01:16:29 . 2012-03-24 19:50:31 1172240 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-01-29 01:16:29 . 2011-09-17 08:11:34 1172240 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-05-19 17:20:33 . 2011-09-17 08:11:46 1172240 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    + 2010-05-19 17:20:33 . 2012-03-24 19:45:56 1172240 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
    - 2010-05-19 17:20:33 . 2011-09-17 08:11:46 1165584 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    + 2010-05-19 17:20:33 . 2012-03-24 19:45:56 1165584 C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
    + 2009-02-26 03:05:52 . 2009-02-26 03:05:52 1195912 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\XIMAGE3B.DLL
    + 2011-08-17 14:49:46 . 2011-08-17 14:49:46 4683624 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2011-07-20 13:12:12 . 2011-07-20 13:12:12 3750776 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VVIEWER.DLL
    + 2011-06-29 12:02:04 . 2011-06-29 12:02:04 1846656 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VVIEWDWG.DLL
    + 2009-10-10 04:10:46 . 2009-10-10 04:10:46 2594632 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-07-27 23:15:10 . 2011-07-27 23:15:10 2335648 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\STSLIST.DLL
    + 2011-06-10 04:51:02 . 2011-06-10 04:51:02 2171736 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\PSRCHFEA.DLL
    + 2011-07-27 09:59:00 . 2011-07-27 09:59:00 6540136 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OSETUP.DLL
    + 2011-07-27 10:47:50 . 2011-07-27 10:47:50 6598008 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONMAIN.DLL
    + 2011-06-10 04:50:56 . 2011-06-10 04:50:56 1165176 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONLIBS.DLL
    + 2011-07-27 10:47:48 . 2011-07-27 10:47:48 1019760 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ONENOTE.EXE
    + 2011-07-07 07:58:32 . 2011-07-07 07:58:32 1616240 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-07-27 10:51:48 . 2011-07-27 10:51:48 7040896 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OFFOWC.DLL
    + 2011-08-03 05:14:00 . 2011-08-03 05:14:00 8579448 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2011-07-20 10:31:36 . 2011-07-20 10:31:36 1523632 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\NLSD0000.DLL
    + 2011-05-27 00:28:06 . 2011-05-27 00:28:06 6637952 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSORES.DLL
    + 2011-07-27 10:09:28 . 2011-07-27 10:09:28 5310848 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
    + 2011-06-22 13:16:34 . 2011-06-22 13:16:34 1681784 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\FPSRVUTL.DLL
    + 2011-07-07 07:28:22 . 2011-07-07 07:28:22 1193320 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\FM20.DLL
    + 2011-08-03 23:27:26 . 2011-08-03 23:27:26 1415072 C:\Windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\ACECORE.DLL
    + 2009-10-10 04:10:46 . 2009-10-10 04:10:46 2594632 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL
    + 2011-07-07 07:58:32 . 2011-07-07 07:58:32 1616240 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-08-03 05:14:00 . 2011-08-03 05:14:00 8579448 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2006-10-27 01:25:00 . 2006-10-27 01:25:00 2172688 C:\Windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
    + 2011-08-17 14:49:46 . 2011-08-17 14:49:46 4683624 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\WRD12CNV.DLL
    + 2011-07-07 07:58:32 . 2011-07-07 07:58:32 1616240 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\OGL.DLL
    + 2011-08-03 05:14:00 . 2011-08-03 05:14:00 8579448 C:\Windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6612\OARTCONV.DLL
    + 2012-03-25 22:06:57 . 2012-03-25 22:06:57 5237248 C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\02198c29552545c7d7e7a95ab39488e5\WindowsBase.ni.dll
    + 2012-03-25 22:26:48 . 2012-03-25 22:26:48 1430016 C:\Windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\d1d48cd30cd275b06fad70778798cae7\UIAutomationClientsideProviders.ni.dll
    + 2012-02-28 00:52:20 . 2012-02-28 00:52:20 4232704 C:\Windows\assembly\NativeImages_v4.0.30319_64\Temp\1f64-0\ReachFramework.dll
    + 2012-03-25 21:31:58 . 2012-03-25 21:31:58 7037952 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\ecdcf3d1d7bc90546464d70a4bee843d\System.Xml.ni.dll
    + 2012-03-25 22:10:08 . 2012-03-25 22:10:08 2449408 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\3a9670f473f8f9291ca256d9a15fc281\System.Xaml.ni.dll
    + 2012-03-25 22:26:11 . 2012-03-25 22:26:11 5627904 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\455d5edfdc989057a8fea7bc88a02ef6\System.Windows.Forms.DataVisualization.ni.dll
    + 2012-03-25 22:25:36 . 2012-03-25 22:25:38 2236416 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bd044dc068adc34e430faa820e5c5e44\System.Web.Services.ni.dll
    + 2012-03-25 22:25:16 . 2012-03-25 22:25:16 2735616 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Speech\561e5a115d6d7ade93236df74d61af84\System.Speech.ni.dll
    + 2012-03-25 22:24:42 . 2012-03-25 22:24:42 1918976 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\4606cac0ba2d406b4ddefca21a3db1eb\System.ServiceModel.Activities.ni.dll
    + 2012-03-25 22:24:59 . 2012-03-25 22:24:59 1579008 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\28b5d075cf252a24a6b007ff5941dce1\System.ServiceModel.Discovery.ni.dll
    + 2012-03-25 22:10:29 . 2012-03-25 22:10:29 3412992 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\1a361129f93a8190d8797b7c680baecc\System.Runtime.Serialization.ni.dll
    + 2012-03-25 22:10:37 . 2012-03-25 22:10:37 1348096 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\2c57eff357f1bc56d0367f04adcf6d76\System.Runtime.DurableInstancing.ni.dll
    + 2012-03-25 22:12:30 . 2012-03-25 22:12:30 1467392 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Printing\7668fa73a73410f2e00d341a8684e28a\System.Printing.ni.dll
    + 2012-03-25 22:21:58 . 2012-03-25 22:21:58 1470464 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\2280764a011295483642b17fe5d2b1f7\System.Management.ni.dll
    + 2012-03-25 22:16:15 . 2012-03-25 22:16:15 1416192 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\a77730a57cc54142f1ecbb1e85060e5f\System.IdentityModel.ni.dll
    + 2012-03-25 22:10:47 . 2012-03-25 22:10:47 1098752 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\7b06b84cb3b99a3ab22adb2a3f6376e6\System.EnterpriseServices.ni.dll
    + 2012-03-25 22:10:15 . 2012-03-25 22:10:15 2290176 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\5b5fe518d1a632afaae9f24dd18cee2f\System.Drawing.ni.dll
    + 2012-03-25 22:16:05 . 2012-03-25 22:16:05 1217024 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\60390cb3abc6f1d85a572c156d39fc02\System.DirectoryServices.AccountManagement.ni.dll
    + 2012-03-25 22:10:55 . 2012-03-25 22:10:55 1622528 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\5eaf17b571cf9fb6f159a0c92d6244ab\System.DirectoryServices.ni.dll
    + 2012-03-25 22:11:43 . 2012-03-25 22:11:43 2402816 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\0ce1b3a9a0192c2cdb16d848e78e6688\System.Deployment.ni.dll
    + 2012-03-25 22:11:31 . 2012-03-25 22:11:31 8601600 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data\ca4a0bde02b2eb73d2e9f22925719ecf\System.Data.ni.dll
    + 2012-03-25 21:32:05 . 2012-03-25 21:32:05 3390976 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\657b967b5fd7819f273f5704197ce97e\System.Data.SqlXml.ni.dll
    + 2012-03-25 22:15:57 . 2012-03-25 22:15:57 1799168 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\930a4b48234d358f2758f075be0684c5\System.Data.Services.Client.ni.dll
    + 2012-03-25 22:15:50 . 2012-03-25 22:15:50 3386880 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\0ba3ab7e136a52fcba260ad7893ede32\System.Data.Linq.ni.dll
    + 2012-03-25 21:31:43 . 2012-03-25 21:31:43 1257472 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\c24ce44b45c0e0c0961a9755f192eb3a\System.Configuration.ni.dll
    + 2012-03-25 22:14:02 . 2012-03-25 22:14:02 1007616 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\5a66bc1859e864d87b81e31438a5f07d\System.ComponentModel.Composition.ni.dll
    + 2012-03-25 22:13:09 . 2012-03-25 22:13:09 5695488 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities\f25d1dde40ef0128d9e5163d142bd2e2\System.Activities.ni.dll
    + 2012-03-25 22:13:50 . 2012-03-25 22:13:50 5048832 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\26671ab09e54e0ecfd23012e32cb6383\System.Activities.Presentation.ni.dll
    + 2012-03-25 22:13:25 . 2012-03-25 22:13:25 2064896 C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\e9f6686e336507594e33cad6ed7814cd\System.Activities.Core.Presentation.ni.dll
    + 2012-03-25 22:12:45 . 2012-03-25 22:12:45 4233216 C:\Windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\9c49a7b6fb133a307e3804ca7ba35d16\ReachFramework.ni.dll
    + 2012-03-25 22:10:01 . 2012-03-25 22:10:01 2056192 C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\68d02e44d8b1f23c21a116119fbb65d0\PresentationUI.ni.dll
    + 2012-03-25 21:32:26 . 2012-03-25 21:32:26 2317312 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\1903f5de0c7c33993c55319d4fc3062e\Microsoft.VisualBasic.ni.dll
    + 2012-03-25 22:06:18 . 2012-03-25 22:06:19 1623040 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\15b88fefd6d638f01856a68c14e2ab9b\Microsoft.VisualBasic.Activities.Compiler.ni.dll
    + 2012-03-25 22:06:31 . 2012-03-25 22:06:31 1843200 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\10bfd23b78a3492727e8b11e2fcbb990\Microsoft.VisualBasic.Compatibility.ni.dll
    + 2012-03-25 21:32:16 . 2012-03-25 21:32:16 1526784 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\2d92f0cffe052f601c1bca1f52425fef\Microsoft.Transactions.Bridge.ni.dll
    + 2012-03-25 22:22:10 . 2012-03-25 22:22:10 3313664 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\0fbfc1087f7622c5b6b06f88fce1a45e\Microsoft.JScript.ni.dll
    + 2012-03-25 21:31:40 . 2012-03-25 21:31:40 2009600 C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\83f53b455553f5ad67e756f6762dc3b4\Microsoft.CSharp.ni.dll
    + 2012-03-24 19:34:45 . 2012-03-24 19:34:45 3858432 C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\ef8c44c3c8766f219f576faab54c8dc7\WindowsBase.ni.dll
    + 2012-03-25 22:05:28 . 2012-03-25 22:05:29 1063424 C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\0f5df23e9f268e9ff4c8033f9865a12a\UIAutomationClientsideProviders.ni.dll
    + 2012-03-25 21:49:10 . 2012-03-25 21:49:11 2012160 C:\Windows\assembly\NativeImages_v4.0.30319_32\Temp\1468-0\System.Speech.dll
    + 2012-03-24 19:34:25 . 2012-03-24 19:34:25 9091584 C:\Windows\assembly\NativeImages_v4.0.30319_32\System\2c59490afc22def906d3ca96e1207ff9\System.ni.dll
    + 2012-03-24 19:34:44 . 2012-03-24 19:34:44 5617664 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\19e79fc0f95c93b0244c7b287e254871\System.Xml.ni.dll
    + 2012-03-25 21:44:14 . 2012-03-25 21:44:14 1782272 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\ae31d46211440b11a9e66c3ba1a4e7ff\System.Xaml.ni.dll
    + 2012-03-25 22:05:05 . 2012-03-25 22:05:06 4545024 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\d6c84e888c7f465844a8ae0e6470e05c\System.Windows.Forms.DataVisualization.ni.dll
    + 2012-03-25 22:04:48 . 2012-03-25 22:04:48 1885696 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\b60e888b3b9e41d46dcbd34d9fae80d6\System.Web.Services.ni.dll
    + 2012-03-25 22:04:38 . 2012-03-25 22:04:38 2012160 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Speech\90de8ba8101001c8845439cd5f9a76eb\System.Speech.ni.dll
    + 2012-03-25 21:48:54 . 2012-03-25 21:48:54 1393152 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\8c12f469cbd6b8d9718c64a4b2c96d47\System.ServiceModel.Activities.ni.dll
    + 2012-03-25 21:49:01 . 2012-03-25 21:49:01 1140736 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\746651ce870c2f9cd43bc7246154f81a\System.ServiceModel.Discovery.ni.dll
    + 2012-03-25 21:44:20 . 2012-03-25 21:44:20 2647040 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a14816d568ee8c7cc9f9923d979d682d\System.Runtime.Serialization.ni.dll
    + 2012-03-25 21:44:23 . 2012-03-25 21:44:23 1021952 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\d6b9e13a40ed53cfc10e04c023c62a49\System.Runtime.DurableInstancing.ni.dll
    + 2012-03-25 21:44:43 . 2012-03-25 21:44:43 1060864 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Printing\1141220aff69c63f638ab64e5b0186bc\System.Printing.ni.dll
    + 2012-03-25 21:48:07 . 2012-03-25 21:48:07 1218560 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\dfd9cbfccfadcf84406398a9d83ab4f4\System.Management.ni.dll
    + 2012-03-25 21:47:58 . 2012-03-25 21:47:58 1072640 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\2a4589aeec877df58cbbcd633bc18fb6\System.IdentityModel.ni.dll
    + 2012-03-24 19:34:27 . 2012-03-24 19:34:27 1653248 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\aa90407cafb9b4a0dc5e3fdff170fee9\System.Drawing.ni.dll
    + 2012-03-25 21:44:29 . 2012-03-25 21:44:29 1172992 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\6bd4a77663c0e708e0827be849906fdc\System.DirectoryServices.ni.dll
    + 2012-03-25 21:44:39 . 2012-03-25 21:44:39 1879040 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\84d9ec8b14f9731797c51d31cae12d87\System.Deployment.ni.dll
    + 2012-03-24 19:35:01 . 2012-03-24 19:35:01 6815232
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.