Unknown virus/malware - black screen w/ cursor after startup

Solved
By KenBrown2
Nov 6, 2011
  1. Hello,

    I am having issues with my wife's laptop. The past couple of days she would get error messages that "rundll32.exe" has stopped working, and various other processes. I went into the task manager, and it seemed as if there were multiple of the same processes running. It was late, and I figured I would contact you guys today...however, when I tried to get onto the computer and run the usual items you guys ask to run before posting, I was unable to get into windows. Now, directly after the load screen (windows symbol, with boot options and bios), the screen is completely black with a cursor in the top left.

    Thank you so much for all you guys do! You have helped me in the past so much, and I know you will help again!!

    Ken
  2. Broni

    Broni Malware Annihilator Posts: 46,132   +251

  3. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Hi Broni,

    No, there was no reason for leaving that prematurely. I thought the process was over and, by mistake, I did not revisit the site after my last post. I apologize for ending that thread before everything had been solved. I assure you that I will make sure the issue is resolved when you say it is resolved, and not when I think it is!

    I'm not sure what you mean by: "Safe issue in Safe Mode." I press the power-on button, and I see the gateway symbol along with the options: F2-BIOs Settings F10-BOOT Menu. I am unable to enter safe mode, via pressing F8 repeatedly or pressing and holding F8....so I am at a loss.

    As stated previously, her machine has vista installed and unfortunately I do not have an install/boot/recovery disk for it.

    Thank you for your help in advance!

    Ken
  4. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    LOL...my bad typo.

    Let's see, if we can look at your computer booting from an external source.

    Please download OTLPE (filesize 120,9 MB)

    • When downloaded double click on OTLPENet.exe and make sure there is a blank CD in your CD drive. This will automatically create a bootable CD.
    • Reboot your system using the boot CD you just created.
      • Note : If you do not know how to set your computer to boot from CD follow the steps HERE
    • Your system should now display a REATOGO-X-PE desktop.
    • Depending on your type of internet connection, you should be able to get online as well so you can access this topic more easily.
    • Double-click on the OTLPE icon.
    • When asked Do you wish to load the remote registry, select Yes
    • When asked Do you wish to load remote user profile(s) for scanning, select Yes
    • Ensure the box Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start.
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\OTL.txt
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.
  5. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Broni,

    Below are the contents of the OTL.txt file. However, after the scan was done running, a message popped up with the .txt that stated this:

    Title: Untitiled - Notepad: notepad.exe - Bad Image

    Error: The application or DLL C:\Windows\system32\shell32.dll is not a valid Windows image. Please check this against your installation diskette.

    OTL.txt

    OTL logfile created on: 11/6/2011 9:07:16 PM - Run
    OTLPE by OldTimer - Version 3.1.43.0 Folder = X:\Programs\OTLPE
    64bit-Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free
    3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 144.04 Gb Total Space | 63.58 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
    Drive D: | 144.04 Gb Total Space | 143.74 Gb Free Space | 99.79% Space Free | Partition Type: NTFS
    Drive X: | 434.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

    Computer Name: REATOGO | User Name: SYSTEM
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
    Using ControlSet: ControlSet001

    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2011/02/22 08:53:27 | 001,149,440 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\FntCache.dll -- (FontCache)
    SRV:64bit: - [2009/04/11 02:11:13 | 000,053,760 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\bthserv.dll -- (BthServ)
    SRV:64bit: - [2008/06/11 13:18:30 | 000,024,576 | ---- | M] () [Disabled] -- C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe -- (ETService)
    SRV:64bit: - [2008/01/20 21:52:15 | 001,216,000 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
    SRV:64bit: - [2007/10/17 10:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Disabled] -- C:\Windows\System32\drivers\XAudio64.exe -- (XAudioService)
    SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/09/17 20:14:22 | 000,460,144 | ---- | M] () [Disabled] -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
    SRV - [2010/03/18 13:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
    SRV - [2010/03/18 13:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
    SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/30 00:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
    SRV - [2009/04/07 14:34:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
    SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/03/29 23:39:54 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
    SRV - [2009/03/06 11:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Disabled] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
    SRV - [2009/02/18 13:40:04 | 000,042,840 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
    SRV - [2009/02/18 13:39:11 | 000,857,432 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
    SRV - [2008/11/04 02:41:00 | 000,437,248 | ---- | M] (Conexant Systems, Inc.) [Auto] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
    SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
    SRV - [2008/07/20 19:45:06 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
    SRV - [2008/05/05 17:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [Disabled] -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2007/02/12 03:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Disabled] -- C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
    SRV - [2006/10/26 16:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwrchid.sys -- (btwrchid)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2010/10/25 23:28:39 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
    DRV:64bit: - [2010/10/18 04:15:18 | 007,959,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETwNv64.sys -- (NETwNv64) ___ Intel(R)
    DRV:64bit: - [2010/09/28 15:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb)
    DRV:64bit: - [2009/04/07 14:33:08 | 000,033,072 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\purendis.sys -- (purendis)
    DRV:64bit: - [2009/04/07 14:33:06 | 000,031,536 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\pnarp.sys -- (pnarp)
    DRV:64bit: - [2008/11/17 15:50:30 | 004,751,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw5v64.sys -- (NETw5v64) Intel(R)
    DRV:64bit: - [2008/11/04 02:40:46 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2008/10/15 07:57:50 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2008/10/15 07:53:44 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2008/10/15 07:52:24 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2008/07/28 22:44:20 | 000,314,880 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2008/07/20 19:44:54 | 000,402,456 | ---- | M] (Intel Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2008/07/15 03:39:24 | 000,062,296 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2mdx64.sys -- (O2MDRDR)
    DRV:64bit: - [2008/07/10 21:29:08 | 007,912,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2008/07/10 04:52:38 | 000,325,680 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2008/06/29 16:52:44 | 000,126,976 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
    DRV:64bit: - [2008/06/26 18:24:20 | 000,020,520 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
    DRV:64bit: - [2008/06/11 20:29:30 | 000,051,800 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2sdx64.sys -- (O2SDRDR)
    DRV:64bit: - [2008/04/29 03:00:00 | 000,392,192 | ---- | M] (Marvell) [Kernel | On_Demand] -- C:\Windows\System32\drivers\yk60x64.sys -- (yukonx64)
    DRV:64bit: - [2008/04/28 21:10:55 | 000,276,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthport.sys -- (BTHPORT)
    DRV:64bit: - [2008/04/28 21:10:51 | 000,034,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\BTHUSB.SYS -- (BTHUSB)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,185,912 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,168,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbvideo.sys -- (usbvideo)
    DRV:64bit: - [2008/01/20 21:47:26 | 000,078,392 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,149,048 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2008/01/20 21:47:03 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthenum.sys -- (BthEnum)
    DRV:64bit: - [2008/01/20 21:47:02 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthpan.sys -- (BthPan) Bluetooth Device (Personal Area Network)
    DRV:64bit: - [2008/01/20 21:47:01 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
    DRV:64bit: - [2008/01/20 21:47:00 | 000,091,192 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,397,368 | ---- | M] (Emulex) [Kernel | Disabled] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,290,872 | ---- | M] (Intel Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,047,672 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,035,896 | ---- | M] (LSI Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
    DRV:64bit: - [2008/01/20 21:46:57 | 000,286,720 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\VSTAZL6.SYS -- (HSFHWAZL)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,438,328 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,284,728 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,146,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\E1G6032E.sys -- (E1G60) Intel(R)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,105,016 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
    DRV:64bit: - [2008/01/20 21:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | Disabled] -- C:\Windows\System32\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,342,584 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,128,056 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,126,520 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
    DRV:64bit: - [2008/01/20 21:46:53 | 000,486,456 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
    DRV:64bit: - [2008/01/20 21:46:52 | 001,221,176 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,174,696 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,090,680 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arc.sys -- (arc)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rfcomm.sys -- (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,017,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CmBatt.sys -- (CmBatt)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,015,976 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
    DRV:64bit: - [2007/07/26 05:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- C:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2006/11/02 07:03:03 | 000,051,816 | ---- | M] (IBM Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
    DRV:64bit: - [2006/11/02 07:02:52 | 000,049,256 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
    DRV:64bit: - [2006/11/02 07:02:47 | 000,048,232 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
    DRV:64bit: - [2006/11/02 07:02:39 | 000,044,648 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
    DRV:64bit: - [2006/11/02 07:02:37 | 000,044,648 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
    DRV:64bit: - [2006/11/02 07:02:24 | 000,039,016 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
    DRV:64bit: - [2006/11/02 06:50:54 | 000,148,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
    DRV:64bit: - [2006/11/02 06:50:27 | 000,124,008 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
    DRV:64bit: - [2006/11/02 06:50:06 | 000,088,168 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
    DRV:64bit: - [2006/11/02 03:43:25 | 000,086,528 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
    DRV:64bit: - [2006/11/02 00:28:10 | 000,273,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService)
    DRV:64bit: - [2006/09/19 06:42:33 | 000,014,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
    DRV:64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,047,104 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,014,976 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,018,432 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,008,704 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
    DRV - [2008/06/11 13:13:24 | 000,017,952 | ---- | M] (Acer, Inc.) [Kernel | Auto] -- C:\Windows\SysWOW64\drivers\int15_64.sys -- (int15)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp64&d=1008&m=mc7801u


    IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livingston.org/
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.livingston.org/livingstonps/site/default.asp
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\Owner_ON_C\..\URLSearchHook: {37153479-1976-43c3-a1ee-557513977b64} - Reg Error: Key error. File not found
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56364



    [2011/05/13 20:07:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/10/24 18:42:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    [2011/07/01 22:02:49 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
    [2011/03/18 12:33:21 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2010/10/24 18:42:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    [2011/03/18 12:33:22 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

    O1 HOSTS File: ([2011/06/18 17:07:46 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
    O2 - BHO: (no name) - {01794EED-D333-4549-BCE6-1F2201793964} - C:\Users\Owner\AppData\Local\TCPIPSys32.dll (Windows (R) 2000 DDK provider)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
    O2 - BHO: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files (x86)\Coupons.com\prxtbCou2.dll (Conduit Ltd.)
    O2 - BHO: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files (x86)\Coupons.com\prxtbCou2.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3:64bit: - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Coupons.com Toolbar) - {37153479-1976-43C3-A1EE-557513977B64} - C:\Program Files (x86)\Coupons.com\prxtbCou2.dll (Conduit Ltd.)
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [0B8.exe] C:\Program Files (x86)\LP\3D92\0B8.exe ()
    O4 - HKLM..\Run: [Trigger New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\AppInRun.exe (Acer Inc.)
    O4 - HKU\Owner_ON_C..\Run: [GooglePolicyPolicy] C:\ProgramData\GooglePolicyPolicy.DLL (Microsoft Corporation)
    O4 - HKU\Owner_ON_C..\Run: [SmileboxTray] C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
    O4 - HKU\Owner_ON_C..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKU\Owner_ON_C..\Run: [WinRAR Update] C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.DLL (Windows (R) 2000 DDK provider)
    O4 - HKU\Owner_ON_C..\Run: [YahooPartnerToolbar Update] C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.DLL (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\LaunchAlaunchX.exe (Acer Inc.)
    O4 - Startup: Error locating startup folders.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.16.0.cab (SysInfo Class)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.130 167.206.245.129
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe) - C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe ()
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
    64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
    O36 - AppCertDlls: dvdppubw - (C:\Windows\system32\igxpgman64.dll) - C:\Windows\SysWow64\igxpgman64.dll File not found
    O36 - AppCertDlls: Fireeown - (C:\Windows\system32\igxpgman.dll) - C:\Windows\SysWOW64\igxpgman.dll ()
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/11/05 14:16:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\84716
    [2011/11/05 14:16:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\20D84
    [2011/11/04 02:29:19 | 001,126,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/03 19:13:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BF43E
    [2011/11/03 19:13:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
    [2011/11/03 19:13:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\532BF
    [2011/11/01 14:48:29 | 000,510,976 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:08:09 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\svchost.exe
    [2011/10/26 18:52:12 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/23 21:10:41 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\FlashDrive_Backup(10-23-11)
    [2011/10/15 08:58:13 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,563,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaut32.dll
    [2011/10/15 08:58:13 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
    [2011/10/15 08:58:13 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleacc.dll
    [2011/10/15 08:58:12 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaccrc.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
    [2011/10/15 08:58:00 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
    [2011/10/15 08:58:00 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
    [2011/10/15 08:58:00 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
    [2011/10/15 08:58:00 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
    [2011/10/15 08:58:00 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
    [2011/10/15 08:58:00 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax
    [1 C:\Users\Owner\Desktop\*.tmp files -> C:\Users\Owner\Desktop\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========


    Continued...
  6. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    ...Continued

    [2011/11/05 23:19:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/11/05 23:01:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 14:14:13 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/11/04 02:47:01 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
    [2011/11/04 02:37:05 | 000,000,975 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\SysWow64\icrav03.rat
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\SysWow64\ticrf.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
    [2011/11/04 02:29:19 | 001,126,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:16 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/04 02:29:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/03 20:08:22 | 000,644,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/11/03 20:08:22 | 000,117,992 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/11/03 19:57:51 | 000,002,651 | ---- | M] () -- C:\Users\Owner\Desktop\Word.lnk
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | M] () -- C:\Windows\System32\igxpgman64.dll
    [2011/11/02 19:50:24 | 000,053,248 | -H-- | M] () -- C:\Windows\SysWow64\igxpgman.dll
    [2011/11/01 14:48:29 | 000,510,976 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:04:34 | 000,038,400 | ---- | M] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/26 18:52:12 | 000,251,904 | ---- | M] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/22 12:39:36 | 000,029,184 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/22 11:11:34 | 000,033,739 | ---- | M] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/10/16 11:40:52 | 000,305,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [1 C:\Users\Owner\Desktop\*.tmp files -> C:\Users\Owner\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011/11/04 02:29:16 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:06 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | C] () -- C:\Windows\System32\igxpgman64.dll
    [2011/11/02 19:50:24 | 000,053,248 | -H-- | C] () -- C:\Windows\SysWow64\igxpgman.dll
    [2011/10/26 22:04:33 | 000,038,400 | ---- | C] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/18 21:50:34 | 000,033,739 | ---- | C] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/06/16 19:50:13 | 000,437,692 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistMSI1840.txt
    [2011/06/16 19:50:10 | 000,011,694 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistUI1840.txt
    [2010/10/11 23:21:08 | 000,000,680 | ---- | C] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
    [2010/10/11 22:19:22 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010/05/13 21:36:23 | 000,029,184 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/09/19 10:53:50 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
    [2009/09/19 10:52:13 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\Windows\SysWow64\OpenQuicktimeLib.dll
    [2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
    [2006/11/02 10:02:31 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll

    ========== LOP Check ==========

    [2011/11/05 20:05:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\20D84
    [2011/11/05 20:05:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\532BF
    [2011/05/15 22:46:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Catalina Marketing Corp
    [2010/10/25 23:33:39 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
    [2010/10/18 23:17:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ImgBurn
    [2011/04/25 21:40:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ooVoo Details
    [2011/04/09 21:22:14 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Red Kawa
    [2011/10/04 21:41:06 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Smilebox
    [2009/06/01 21:09:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\WildTangent
    [2011/11/04 02:47:01 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========


    < End of report >
  7. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Do this on the computer you are posting from:
    Copy the text in the codebox below:


    Code:
    :OTL
    IE - HKU\Owner_ON_C\..\URLSearchHook: {37153479-1976-43c3-a1ee-557513977b64} - Reg Error: Key error. File not found
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56364
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O4 - HKLM..\Run: [0B8.exe] C:\Program Files (x86)\LP\3D92\0B8.exe ()
    O4 - HKU\Owner_ON_C..\Run: [WinRAR Update] C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.DLL (Windows (R) 2000 DDK provider)
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe) - C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe ()
    O36 - AppCertDlls: dvdppubw - (C:\Windows\system32\igxpgman64.dll) - C:\Windows\SysWow64\igxpgman64.dll File not found
    O36 - AppCertDlls: Fireeown - (C:\Windows\system32\igxpgman.dll) - C:\Windows\SysWOW64\igxpgman.dll ()
    [2011/11/05 14:16:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\84716
    [2011/11/05 14:16:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\20D84
    [2011/11/03 19:13:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BF43E
    [2011/11/03 19:13:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
    [2011/11/03 19:13:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\532BF
    [1 C:\Users\Owner\Desktop\*.tmp files -> C:\Users\Owner\Desktop\*.tmp -> ]
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | M] () -- C:\Windows\System32\igxpgman64.dll
    [2011/11/02 19:50:24 | 000,053,248 | -H-- | M] () -- C:\Windows\SysWow64\igxpgman.dll
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    
    Open Notepad and paste it.
    Save the document as Fix.txt on to a USB flash drive


    On the infected computer the following...

    Run OTLPE

    • Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
      • (The content of Fix.txt should appear in the box)
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post the log produced (you'll need to transfer it with USB stick)
    • Attempt to reboot normally into Windows.
  8. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Broni,

    I did as directed. However after the fix completed, a dialog box popped up stating: "Click Ok to open the log file." But it never opened. I attempted to look for it, but I cannot find anything. So I decided to restart the machine....But it froze after I hit ok to restart....so I manually shut it down. I tried to run the fix again, and it still does not give me a log file. I searched the computer for a .txt, but nothing comes up since the last OTL.txt file I posted previously.

    Ken

    Also, the computer did not boot normally into windows...and i had to boot via the OTLPENET.exe disk.
  9. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Post new OTL log.
  10. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Newest OTL:

    OTL logfile created on: 11/6/2011 10:57:41 PM - Run
    OTLPE by OldTimer - Version 3.1.43.0 Folder = X:\Programs\OTLPE
    64bit-Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 90.00% Memory free
    3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 144.04 Gb Total Space | 63.58 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
    Drive D: | 1.87 Gb Total Space | 1.80 Gb Free Space | 96.66% Space Free | Partition Type: FAT
    Drive E: | 144.04 Gb Total Space | 143.74 Gb Free Space | 99.79% Space Free | Partition Type: NTFS
    Drive X: | 434.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

    Computer Name: REATOGO | User Name: SYSTEM
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
    Using ControlSet: ControlSet001

    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2011/02/22 08:53:27 | 001,149,440 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\FntCache.dll -- (FontCache)
    SRV:64bit: - [2009/04/11 02:11:13 | 000,053,760 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\bthserv.dll -- (BthServ)
    SRV:64bit: - [2008/06/11 13:18:30 | 000,024,576 | ---- | M] () [Disabled] -- C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe -- (ETService)
    SRV:64bit: - [2008/01/20 21:52:15 | 001,216,000 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
    SRV:64bit: - [2007/10/17 10:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Disabled] -- C:\Windows\System32\drivers\XAudio64.exe -- (XAudioService)
    SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/09/17 20:14:22 | 000,460,144 | ---- | M] () [Disabled] -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
    SRV - [2010/03/18 13:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
    SRV - [2010/03/18 13:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
    SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/30 00:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
    SRV - [2009/04/07 14:34:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
    SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/03/29 23:39:54 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
    SRV - [2009/03/06 11:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Disabled] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
    SRV - [2009/02/18 13:40:04 | 000,042,840 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
    SRV - [2009/02/18 13:39:11 | 000,857,432 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
    SRV - [2008/11/04 02:41:00 | 000,437,248 | ---- | M] (Conexant Systems, Inc.) [Auto] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
    SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
    SRV - [2008/07/20 19:45:06 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
    SRV - [2008/05/05 17:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [Disabled] -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2007/02/12 03:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Disabled] -- C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
    SRV - [2006/10/26 16:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwrchid.sys -- (btwrchid)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2010/10/25 23:28:39 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
    DRV:64bit: - [2010/10/18 04:15:18 | 007,959,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETwNv64.sys -- (NETwNv64) ___ Intel(R)
    DRV:64bit: - [2010/09/28 15:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb)
    DRV:64bit: - [2009/04/07 14:33:08 | 000,033,072 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\purendis.sys -- (purendis)
    DRV:64bit: - [2009/04/07 14:33:06 | 000,031,536 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\pnarp.sys -- (pnarp)
    DRV:64bit: - [2008/11/17 15:50:30 | 004,751,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw5v64.sys -- (NETw5v64) Intel(R)
    DRV:64bit: - [2008/11/04 02:40:46 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2008/10/15 07:57:50 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2008/10/15 07:53:44 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2008/10/15 07:52:24 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2008/07/28 22:44:20 | 000,314,880 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2008/07/20 19:44:54 | 000,402,456 | ---- | M] (Intel Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2008/07/15 03:39:24 | 000,062,296 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2mdx64.sys -- (O2MDRDR)
    DRV:64bit: - [2008/07/10 21:29:08 | 007,912,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2008/07/10 04:52:38 | 000,325,680 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2008/06/29 16:52:44 | 000,126,976 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
    DRV:64bit: - [2008/06/26 18:24:20 | 000,020,520 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
    DRV:64bit: - [2008/06/11 20:29:30 | 000,051,800 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2sdx64.sys -- (O2SDRDR)
    DRV:64bit: - [2008/04/29 03:00:00 | 000,392,192 | ---- | M] (Marvell) [Kernel | On_Demand] -- C:\Windows\System32\drivers\yk60x64.sys -- (yukonx64)
    DRV:64bit: - [2008/04/28 21:10:55 | 000,276,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthport.sys -- (BTHPORT)
    DRV:64bit: - [2008/04/28 21:10:51 | 000,034,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\BTHUSB.SYS -- (BTHUSB)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,185,912 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,168,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbvideo.sys -- (usbvideo)
    DRV:64bit: - [2008/01/20 21:47:26 | 000,078,392 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,149,048 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2008/01/20 21:47:03 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthenum.sys -- (BthEnum)
    DRV:64bit: - [2008/01/20 21:47:02 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthpan.sys -- (BthPan) Bluetooth Device (Personal Area Network)
    DRV:64bit: - [2008/01/20 21:47:01 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
    DRV:64bit: - [2008/01/20 21:47:00 | 000,091,192 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,397,368 | ---- | M] (Emulex) [Kernel | Disabled] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,290,872 | ---- | M] (Intel Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,047,672 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,035,896 | ---- | M] (LSI Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
    DRV:64bit: - [2008/01/20 21:46:57 | 000,286,720 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\VSTAZL6.SYS -- (HSFHWAZL)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,438,328 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,284,728 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,146,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\E1G6032E.sys -- (E1G60) Intel(R)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,105,016 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
    DRV:64bit: - [2008/01/20 21:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | Disabled] -- C:\Windows\System32\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,342,584 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,128,056 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,126,520 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
    DRV:64bit: - [2008/01/20 21:46:53 | 000,486,456 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
    DRV:64bit: - [2008/01/20 21:46:52 | 001,221,176 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,174,696 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,090,680 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arc.sys -- (arc)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rfcomm.sys -- (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,017,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CmBatt.sys -- (CmBatt)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,015,976 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
    DRV:64bit: - [2007/07/26 05:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- C:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2006/11/02 07:03:03 | 000,051,816 | ---- | M] (IBM Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
    DRV:64bit: - [2006/11/02 07:02:52 | 000,049,256 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
    DRV:64bit: - [2006/11/02 07:02:47 | 000,048,232 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
    DRV:64bit: - [2006/11/02 07:02:39 | 000,044,648 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
    DRV:64bit: - [2006/11/02 07:02:37 | 000,044,648 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
    DRV:64bit: - [2006/11/02 07:02:24 | 000,039,016 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
    DRV:64bit: - [2006/11/02 06:50:54 | 000,148,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
    DRV:64bit: - [2006/11/02 06:50:27 | 000,124,008 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
    DRV:64bit: - [2006/11/02 06:50:06 | 000,088,168 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
    DRV:64bit: - [2006/11/02 03:43:25 | 000,086,528 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
    DRV:64bit: - [2006/11/02 00:28:10 | 000,273,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService)
    DRV:64bit: - [2006/09/19 06:42:33 | 000,014,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
    DRV:64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,047,104 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,014,976 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,018,432 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,008,704 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
    DRV - [2008/06/11 13:13:24 | 000,017,952 | ---- | M] (Acer, Inc.) [Kernel | Auto] -- C:\Windows\SysWOW64\drivers\int15_64.sys -- (int15)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp64&d=1008&m=mc7801u


    IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livingston.org/
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.livingston.org/livingstonps/site/default.asp
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =



    [2011/05/13 20:07:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/10/24 18:42:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    [2011/07/01 22:02:49 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
    [2011/03/18 12:33:21 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2010/10/24 18:42:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    [2011/03/18 12:33:22 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

    O1 HOSTS File: ([2011/06/18 17:07:46 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
    O2 - BHO: (no name) - {01794EED-D333-4549-BCE6-1F2201793964} - C:\Users\Owner\AppData\Local\TCPIPSys32.dll (Windows (R) 2000 DDK provider)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
    O2 - BHO: (no name) - {37153479-1976-43c3-a1ee-557513977b64} - No CLSID value found.
    O2 - BHO: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (no name) - {37153479-1976-43c3-a1ee-557513977b64} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3:64bit: - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [Trigger New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\AppInRun.exe (Acer Inc.)
    O4 - HKU\Owner_ON_C..\Run: [GooglePolicyPolicy] C:\ProgramData\GooglePolicyPolicy.DLL (Microsoft Corporation)
    O4 - HKU\Owner_ON_C..\Run: [SmileboxTray] C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
    O4 - HKU\Owner_ON_C..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKU\Owner_ON_C..\Run: [WinRAR Update] C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.DLL File not found
    O4 - HKU\Owner_ON_C..\Run: [YahooPartnerToolbar Update] C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.DLL (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\LaunchAlaunchX.exe (Acer Inc.)
    O4 - Startup: Error locating startup folders.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.16.0.cab (SysInfo Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.130 167.206.245.129
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe) - C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe File not found
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
    64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/11/06 22:30:44 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2011/11/06 22:15:05 | 000,000,000 | ---D | C] -- C:\_OTL
    [2011/11/04 02:29:19 | 001,126,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/01 14:48:29 | 000,510,976 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:08:09 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\svchost.exe
    [2011/10/26 18:52:12 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/23 21:10:41 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\FlashDrive_Backup(10-23-11)
    [2011/10/15 08:58:13 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,563,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaut32.dll
    [2011/10/15 08:58:13 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
    [2011/10/15 08:58:13 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleacc.dll
    [2011/10/15 08:58:12 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaccrc.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
    [2011/10/15 08:58:00 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
    [2011/10/15 08:58:00 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
    [2011/10/15 08:58:00 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
    [2011/10/15 08:58:00 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
    [2011/10/15 08:58:00 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
    [2011/10/15 08:58:00 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax

    Continued...
  11. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    ...Continued


    ========== Files - Modified Within 30 Days ==========

    [2011/11/05 23:19:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/11/05 23:01:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 14:14:13 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/11/04 02:47:01 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
    [2011/11/04 02:37:05 | 000,000,975 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\SysWow64\icrav03.rat
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\SysWow64\ticrf.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
    [2011/11/04 02:29:19 | 001,126,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:16 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/04 02:29:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/03 20:08:22 | 000,644,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/11/03 20:08:22 | 000,117,992 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/11/03 19:57:51 | 000,002,651 | ---- | M] () -- C:\Users\Owner\Desktop\Word.lnk
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | M] () -- C:\Windows\System32\igxpgman64.dll
    [2011/11/01 14:48:29 | 000,510,976 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:04:34 | 000,038,400 | ---- | M] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/26 18:52:12 | 000,251,904 | ---- | M] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/22 12:39:36 | 000,029,184 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/22 11:11:34 | 000,033,739 | ---- | M] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/10/16 11:40:52 | 000,305,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT

    ========== Files Created - No Company Name ==========

    [2011/11/04 02:29:16 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:06 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | C] () -- C:\Windows\System32\igxpgman64.dll
    [2011/10/26 22:04:33 | 000,038,400 | ---- | C] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/18 21:50:34 | 000,033,739 | ---- | C] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/06/16 19:50:13 | 000,437,692 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistMSI1840.txt
    [2011/06/16 19:50:10 | 000,011,694 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistUI1840.txt
    [2010/10/11 23:21:08 | 000,000,680 | ---- | C] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
    [2010/10/11 22:19:22 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010/05/13 21:36:23 | 000,029,184 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/09/19 10:53:50 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
    [2009/09/19 10:52:13 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\Windows\SysWow64\OpenQuicktimeLib.dll
    [2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
    [2006/11/02 10:02:31 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll

    ========== LOP Check ==========

    [2011/05/15 22:46:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Catalina Marketing Corp
    [2010/10/25 23:33:39 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
    [2010/10/18 23:17:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ImgBurn
    [2011/04/25 21:40:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ooVoo Details
    [2011/04/09 21:22:14 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Red Kawa
    [2011/10/04 21:41:06 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Smilebox
    [2009/06/01 21:09:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\WildTangent
    [2011/11/04 02:47:01 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========


    < End of report >
     
  12. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Some entries have been successfully removed, but some are still there.

    Re-run OTL with this custom script:

    Code:
    :OTL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
    O4 - HKU\Owner_ON_C..\Run: [WinRAR Update] C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.DLL File not found
    O20 - HKU\Owner_ON_C Winlogon: Shell - (C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe) - C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe ()
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | M] () -- C:\Windows\System32\igxpgman64.dll
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    
  13. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Broni,

    Below is the new OTL scan log... not sure if it is relevant, but I have received the same error message every time I run the scan (as described in my first OTL log post)

    OTL


    OTL logfile created on: 11/7/2011 12:23:07 AM - Run
    OTLPE by OldTimer - Version 3.1.43.0 Folder = X:\Programs\OTLPE
    64bit-Windows Vista (TM) Home Premium Service Pack 2 (Version = 6.0.6002) - Type = System
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
    3.00 Gb Paging File | 3.00 Gb Available in Paging File | 97.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 144.04 Gb Total Space | 63.58 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
    Drive D: | 1.87 Gb Total Space | 1.80 Gb Free Space | 96.65% Space Free | Partition Type: FAT
    Drive E: | 144.04 Gb Total Space | 143.74 Gb Free Space | 99.79% Space Free | Partition Type: NTFS
    Drive X: | 434.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

    Computer Name: REATOGO | User Name: SYSTEM
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
    Using ControlSet: ControlSet001

    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2011/02/22 08:53:27 | 001,149,440 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\FntCache.dll -- (FontCache)
    SRV:64bit: - [2009/04/11 02:11:13 | 000,053,760 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\System32\bthserv.dll -- (BthServ)
    SRV:64bit: - [2008/06/11 13:18:30 | 000,024,576 | ---- | M] () [Disabled] -- C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe -- (ETService)
    SRV:64bit: - [2008/01/20 21:52:15 | 001,216,000 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
    SRV:64bit: - [2007/10/17 10:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Disabled] -- C:\Windows\System32\drivers\XAudio64.exe -- (XAudioService)
    SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/09/17 20:14:22 | 000,460,144 | ---- | M] () [Disabled] -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
    SRV - [2010/03/18 13:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
    SRV - [2010/03/18 13:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
    SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/30 00:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
    SRV - [2009/04/07 14:34:40 | 000,642,856 | ---- | M] (Cisco Systems, Inc.) [Disabled] -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
    SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/03/29 23:39:54 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
    SRV - [2009/03/06 11:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Disabled] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
    SRV - [2009/02/18 13:40:04 | 000,042,840 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
    SRV - [2009/02/18 13:39:11 | 000,857,432 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
    SRV - [2008/11/04 02:41:00 | 000,437,248 | ---- | M] (Conexant Systems, Inc.) [Auto] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
    SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
    SRV - [2008/07/20 19:45:06 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
    SRV - [2008/05/05 17:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [Disabled] -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2007/02/12 03:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Disabled] -- C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
    SRV - [2006/10/26 16:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwrchid.sys -- (btwrchid)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\DRIVERS\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - File not found [Kernel | On_Demand] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2010/10/25 23:28:39 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
    DRV:64bit: - [2010/10/18 04:15:18 | 007,959,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETwNv64.sys -- (NETwNv64) ___ Intel(R)
    DRV:64bit: - [2010/09/28 15:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb)
    DRV:64bit: - [2009/04/07 14:33:08 | 000,033,072 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\purendis.sys -- (purendis)
    DRV:64bit: - [2009/04/07 14:33:06 | 000,031,536 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\pnarp.sys -- (pnarp)
    DRV:64bit: - [2008/11/17 15:50:30 | 004,751,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw5v64.sys -- (NETw5v64) Intel(R)
    DRV:64bit: - [2008/11/04 02:40:46 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio64.sys -- (XAudio)
    DRV:64bit: - [2008/10/15 07:57:50 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_DPV.sys -- (HSF_DPV)
    DRV:64bit: - [2008/10/15 07:53:44 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAXHWAZL.sys -- (CAXHWAZL)
    DRV:64bit: - [2008/10/15 07:52:24 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CAX_CNXT.sys -- (winachsf)
    DRV:64bit: - [2008/07/28 22:44:20 | 000,314,880 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CHDRT64.sys -- (CnxtHdAudService)
    DRV:64bit: - [2008/07/20 19:44:54 | 000,402,456 | ---- | M] (Intel Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2008/07/15 03:39:24 | 000,062,296 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2mdx64.sys -- (O2MDRDR)
    DRV:64bit: - [2008/07/10 21:29:08 | 007,912,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2008/07/10 04:52:38 | 000,325,680 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2008/06/29 16:52:44 | 000,126,976 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
    DRV:64bit: - [2008/06/26 18:24:20 | 000,020,520 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
    DRV:64bit: - [2008/06/11 20:29:30 | 000,051,800 | ---- | M] (O2Micro ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\o2sdx64.sys -- (O2SDRDR)
    DRV:64bit: - [2008/04/29 03:00:00 | 000,392,192 | ---- | M] (Marvell) [Kernel | On_Demand] -- C:\Windows\System32\drivers\yk60x64.sys -- (yukonx64)
    DRV:64bit: - [2008/04/28 21:10:55 | 000,276,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthport.sys -- (BTHPORT)
    DRV:64bit: - [2008/04/28 21:10:51 | 000,034,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\BTHUSB.SYS -- (BTHUSB)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,185,912 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
    DRV:64bit: - [2008/01/20 21:47:27 | 000,168,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbvideo.sys -- (usbvideo)
    DRV:64bit: - [2008/01/20 21:47:26 | 000,078,392 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,149,048 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
    DRV:64bit: - [2008/01/20 21:47:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2008/01/20 21:47:03 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthenum.sys -- (BthEnum)
    DRV:64bit: - [2008/01/20 21:47:02 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\bthpan.sys -- (BthPan) Bluetooth Device (Personal Area Network)
    DRV:64bit: - [2008/01/20 21:47:01 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
    DRV:64bit: - [2008/01/20 21:47:00 | 000,091,192 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,397,368 | ---- | M] (Emulex) [Kernel | Disabled] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,290,872 | ---- | M] (Intel Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,047,672 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
    DRV:64bit: - [2008/01/20 21:46:59 | 000,035,896 | ---- | M] (LSI Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
    DRV:64bit: - [2008/01/20 21:46:57 | 000,286,720 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\VSTAZL6.SYS -- (HSFHWAZL)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,438,328 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,284,728 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,146,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\E1G6032E.sys -- (E1G60) Intel(R)
    DRV:64bit: - [2008/01/20 21:46:56 | 000,105,016 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
    DRV:64bit: - [2008/01/20 21:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | Disabled] -- C:\Windows\System32\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,342,584 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,128,056 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,126,520 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
    DRV:64bit: - [2008/01/20 21:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
    DRV:64bit: - [2008/01/20 21:46:53 | 000,486,456 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
    DRV:64bit: - [2008/01/20 21:46:52 | 001,221,176 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,174,696 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,090,680 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\arc.sys -- (arc)
    DRV:64bit: - [2008/01/20 21:46:52 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rfcomm.sys -- (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,113,720 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
    DRV:64bit: - [2008/01/20 21:46:51 | 000,017,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\CmBatt.sys -- (CmBatt)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,018,024 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
    DRV:64bit: - [2008/01/20 21:46:50 | 000,015,976 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
    DRV:64bit: - [2007/07/26 05:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- C:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2006/11/02 07:03:03 | 000,051,816 | ---- | M] (IBM Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
    DRV:64bit: - [2006/11/02 07:02:52 | 000,049,256 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
    DRV:64bit: - [2006/11/02 07:02:47 | 000,048,232 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
    DRV:64bit: - [2006/11/02 07:02:39 | 000,044,648 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
    DRV:64bit: - [2006/11/02 07:02:37 | 000,044,648 | ---- | M] (LSI Logic) [Kernel | Disabled] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
    DRV:64bit: - [2006/11/02 07:02:24 | 000,039,016 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
    DRV:64bit: - [2006/11/02 07:02:09 | 000,037,480 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
    DRV:64bit: - [2006/11/02 06:50:54 | 000,148,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
    DRV:64bit: - [2006/11/02 06:50:27 | 000,124,008 | ---- | M] (QLogic Corporation) [Kernel | Disabled] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
    DRV:64bit: - [2006/11/02 06:50:06 | 000,088,168 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
    DRV:64bit: - [2006/11/02 03:43:25 | 000,086,528 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
    DRV:64bit: - [2006/11/02 00:28:10 | 000,273,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\HdAudio.sys -- (HdAudAddService)
    DRV:64bit: - [2006/09/19 06:42:33 | 000,014,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
    DRV:64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,047,104 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
    DRV:64bit: - [2006/09/18 16:30:18 | 000,014,976 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,018,432 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
    DRV:64bit: - [2006/09/18 16:30:15 | 000,008,704 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
    DRV - [2008/06/11 13:13:24 | 000,017,952 | ---- | M] (Acer, Inc.) [Kernel | Auto] -- C:\Windows\SysWOW64\drivers\int15_64.sys -- (int15)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp64&d=1008&m=mc7801u


    IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]

    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livingston.org/
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.livingston.org/livingstonps/site/default.asp
    IE - HKU\Owner_ON_C\Software\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = ED 4E 79 01 33 D3 49 45 BC E6 1F 22 01 79 39 64 [binary data]
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKU\Owner_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =



    [2011/05/13 20:07:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/10/24 18:42:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    [2011/07/01 22:02:49 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
    [2011/03/18 12:33:21 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2010/10/24 18:42:12 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    [2011/03/18 12:33:22 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

    O1 HOSTS File: ([2011/06/18 17:07:46 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
    O2 - BHO: (no name) - {01794EED-D333-4549-BCE6-1F2201793964} - C:\Users\Owner\AppData\Local\TCPIPSys32.dll (Windows (R) 2000 DDK provider)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
    O2 - BHO: (no name) - {37153479-1976-43c3-a1ee-557513977b64} - No CLSID value found.
    O2 - BHO: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
    O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (no name) - {37153479-1976-43c3-a1ee-557513977b64} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll ()
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
    O3:64bit: - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKU\Owner_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [Trigger New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\AppInRun.exe (Acer Inc.)
    O4 - HKU\Owner_ON_C..\Run: [GooglePolicyPolicy] C:\ProgramData\GooglePolicyPolicy.DLL (Microsoft Corporation)
    O4 - HKU\Owner_ON_C..\Run: [SmileboxTray] C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
    O4 - HKU\Owner_ON_C..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - HKU\Owner_ON_C..\Run: [WinRAR Update] C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.DLL File not found
    O4 - HKU\Owner_ON_C..\Run: [YahooPartnerToolbar Update] C:\Users\Owner\AppData\Local\Apple\AppleUpdate\Appleupdt32.DLL (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [New Acer AlaunchX] C:\ACER\Preload\Command\AlaunchX\LaunchAlaunchX.exe (Acer Inc.)
    O4 - Startup: Error locating startup folders.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\Owner_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.16.0.cab (SysInfo Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.130 167.206.245.129
    O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
    O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
    O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKU\Owner_ON_C Winlogon: Shell - (C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe) - C:\Users\Owner\AppData\Roaming\20D84\FD93D.exe File not found
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
    64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    Continued...
  14. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    ...Continued


    ========== Files/Folders - Created Within 30 Days ==========

    [2011/11/06 22:30:44 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2011/11/06 22:15:05 | 000,000,000 | ---D | C] -- C:\_OTL
    [2011/11/04 02:29:19 | 001,126,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/01 14:48:29 | 000,510,976 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:08:09 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\svchost.exe
    [2011/10/26 18:52:12 | 000,251,904 | ---- | C] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/23 21:10:41 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\FlashDrive_Backup(10-23-11)
    [2011/10/15 08:58:13 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,563,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaut32.dll
    [2011/10/15 08:58:13 | 000,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
    [2011/10/15 08:58:13 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
    [2011/10/15 08:58:13 | 000,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleacc.dll
    [2011/10/15 08:58:12 | 000,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaccrc.dll
    [2011/10/15 08:58:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaccrc.dll
    [2011/10/15 08:58:00 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
    [2011/10/15 08:58:00 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
    [2011/10/15 08:58:00 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
    [2011/10/15 08:58:00 | 000,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
    [2011/10/15 08:58:00 | 000,100,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
    [2011/10/15 08:58:00 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mpeg2Data.ax
    [2011/10/15 08:58:00 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSDvbNP.ax

    ========== Files - Modified Within 30 Days ==========

    [2011/11/05 23:19:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/11/05 23:01:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 22:14:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/11/05 14:14:13 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/11/04 02:47:01 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
    [2011/11/04 02:37:05 | 000,000,975 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\SysWow64\icrav03.rat
    [2011/11/04 02:30:03 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\SysWow64\ticrf.rat
    [2011/11/04 02:30:03 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
    [2011/11/04 02:29:19 | 001,126,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
    [2011/11/04 02:29:19 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
    [2011/11/04 02:29:19 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
    [2011/11/04 02:29:18 | 001,791,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
    [2011/11/04 02:29:18 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2011/11/04 02:29:18 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2011/11/04 02:29:18 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2011/11/04 02:29:18 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2011/11/04 02:29:18 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2011/11/04 02:29:18 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2011/11/04 02:29:17 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2011/11/04 02:29:17 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2011/11/04 02:29:17 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2011/11/04 02:29:17 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
    [2011/11/04 02:29:17 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
    [2011/11/04 02:29:17 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2011/11/04 02:29:16 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2011/11/04 02:29:16 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
    [2011/11/04 02:29:16 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
    [2011/11/04 02:29:16 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2011/11/04 02:29:16 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2011/11/04 02:29:16 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2011/11/04 02:29:16 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2011/11/04 02:29:16 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2011/11/04 02:29:16 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
    [2011/11/04 02:29:16 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:16 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2011/11/04 02:29:16 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2011/11/04 02:29:16 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2011/11/04 02:29:16 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2011/11/04 02:29:15 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
    [2011/11/04 02:29:14 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.tlb
    [2011/11/04 02:29:14 | 001,798,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
    [2011/11/04 02:29:14 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2011/11/04 02:29:14 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2011/11/04 02:29:14 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2011/11/04 02:29:14 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
    [2011/11/04 02:29:14 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2011/11/04 02:29:13 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
    [2011/11/04 02:29:13 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
    [2011/11/04 02:29:13 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
    [2011/11/04 02:29:13 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2011/11/04 02:29:13 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
    [2011/11/04 02:29:13 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2011/11/04 02:29:13 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
    [2011/11/04 02:29:13 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
    [2011/11/04 02:29:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2011/11/04 02:29:10 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
    [2011/11/04 02:29:09 | 002,143,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
    [2011/11/04 02:29:09 | 001,389,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
    [2011/11/04 02:29:09 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
    [2011/11/04 02:29:09 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
    [2011/11/04 02:29:09 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
    [2011/11/04 02:29:09 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
    [2011/11/04 02:29:09 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
    [2011/11/04 02:29:09 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
    [2011/11/04 02:29:09 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
    [2011/11/04 02:29:08 | 002,309,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
    [2011/11/04 02:29:08 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
    [2011/11/04 02:29:08 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
    [2011/11/04 02:29:08 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
    [2011/11/04 02:29:08 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
    [2011/11/04 02:29:08 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advpack.dll
    [2011/11/04 02:29:08 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
    [2011/11/04 02:29:08 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
    [2011/11/04 02:29:08 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
    [2011/11/04 02:29:08 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
    [2011/11/04 02:29:08 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
    [2011/11/04 02:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
    [2011/11/04 02:29:08 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
    [2011/11/04 02:29:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tdc.ocx
    [2011/11/04 02:29:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
    [2011/11/04 02:29:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
    [2011/11/04 02:29:06 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
    [2011/11/04 02:29:06 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
    [2011/11/04 02:29:06 | 000,403,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
    [2011/11/04 02:29:06 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
    [2011/11/04 02:29:06 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
    [2011/11/04 02:29:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
    [2011/11/04 02:29:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
    [2011/11/04 02:29:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\icardie.dll
    [2011/11/04 02:29:06 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/04 02:29:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
    [2011/11/04 02:29:05 | 001,492,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
    [2011/11/04 02:29:05 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
    [2011/11/04 02:29:05 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
    [2011/11/04 02:29:05 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
    [2011/11/04 02:29:05 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
    [2011/11/04 02:29:05 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
    [2011/11/04 02:29:05 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
    [2011/11/04 02:29:05 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
    [2011/11/04 02:29:03 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
    [2011/11/04 02:29:03 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
    [2011/11/04 02:29:03 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
    [2011/11/03 20:08:22 | 000,644,118 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/11/03 20:08:22 | 000,117,992 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/11/03 19:57:51 | 000,002,651 | ---- | M] () -- C:\Users\Owner\Desktop\Word.lnk
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | M] () -- C:\Windows\System32\igxpgman64.dll
    [2011/11/01 14:48:29 | 000,510,976 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Users\Owner\AppData\Local\TCPIPSys32.dll
    [2011/10/26 22:04:34 | 000,038,400 | ---- | M] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/26 18:52:12 | 000,251,904 | ---- | M] (Microsoft Corporation) -- C:\Users\Owner\AppData\Local\SystemWMP.dll
    [2011/10/22 12:39:36 | 000,029,184 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/10/22 11:11:34 | 000,033,739 | ---- | M] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/10/16 11:40:52 | 000,305,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT

    ========== Files Created - No Company Name ==========

    [2011/11/04 02:29:16 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
    [2011/11/04 02:29:06 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
    [2011/11/02 19:50:24 | 000,060,416 | -H-- | C] () -- C:\Windows\System32\igxpgman64.dll
    [2011/10/26 22:04:33 | 000,038,400 | ---- | C] () -- C:\Users\Owner\Documents\MKTG 342 Questionnaires.doc
    [2011/10/18 21:50:34 | 000,033,739 | ---- | C] () -- C:\Users\Owner\Desktop\Halloween Party.docx
    [2011/06/16 19:50:13 | 000,437,692 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistMSI1840.txt
    [2011/06/16 19:50:10 | 000,011,694 | ---- | C] () -- C:\Users\Owner\AppData\Local\dd_vcredistUI1840.txt
    [2010/10/11 23:21:08 | 000,000,680 | ---- | C] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
    [2010/10/11 22:19:22 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2010/05/13 21:36:23 | 000,029,184 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/09/19 10:53:50 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
    [2009/09/19 10:52:13 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\Windows\SysWow64\OpenQuicktimeLib.dll
    [2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
    [2006/11/02 10:02:31 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll

    ========== LOP Check ==========

    [2011/05/15 22:46:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Catalina Marketing Corp
    [2010/10/25 23:33:39 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
    [2010/10/18 23:17:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ImgBurn
    [2011/04/25 21:40:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ooVoo Details
    [2011/04/09 21:22:14 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Red Kawa
    [2011/10/04 21:41:06 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Smilebox
    [2009/06/01 21:09:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\WildTangent
    [2011/11/04 02:47:01 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========


    < End of report >
  15. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Did you actually run the fix?
  16. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Yes. I ran the fix and found no log....so I ran a scan again and posted it. Then I rebooted the computer (no luck starting into windows). so I booted with the disk again... Do I need to reboot before looking for the log file? (or running the scan again?)
  17. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    If you have Vista/7 DVD...

    start with step 2

    If you don't have Vista/7 DVD...

    1. Create Vista/7 Recovery Disc.

    Option 1 :
    Vista: http://www.vistax64.com/tutorials/141820-create-recovery-disc.html (Option Two)
    Windows 7: http://www.guidingtech.com/3816/system-repair-recovery-disc-windows-7/

    Option 2:
    Download Vista Recovery Disc iso image: http://digiex.net/downloads/downloa...6-windows-vista-32-bit-x86-recovery-disc.html
    Download Windows 7 Recovery Disc iso image: http://digiex.net/downloads/downloa.../2659-windows-7-32-bit-x86-recovery-disc.html
    Burn it to DVD: http://neosmart.net/wiki/display/G/Burning ISO Images to a CD or DVD

    2. Boot from created disk. You may need to set the CD-Rom as first boot device if it isn't already (if you don't know how to do it, see HERE)

    Vista users. At first screen click on Repair your computer:
    [​IMG]

    Windows 7 users. At first screen click on Install now:
    [​IMG]
    Select your language and click next:
    [​IMG]
    Click the button for "Use recovery tools":
    [​IMG]

    The following applies to both, Vista and Windows 7 users.

    This will bring you to a new screen where the repair process will look for all Windows Vista/7 installations on your computer. When done you will be presented with the System Recovery Options dialog box:
    [​IMG]
    After this, it will present you with a list of options including startup repair, system restore and command prompt:
    [​IMG]
    Select Command Prompt

    Type in:
    bootrec /fixmbr (<--- there is a "space" after "bootrec")
    and then press Enter

    Once completed then type Exit, press Enter and restart computer.

    See if you can boot normally now.
  18. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Yes! I am able to get into windows normally. Although an error came up when my desktop came up

    Title: "RunDLL"
    Message: "Error Loading C:\Users\Owner\AppData\Local\Conduit\ConduitUpdate\Conduitup.dll

    The specified module could not be found."

    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    Update 1:
    Also, I went away from my computer for about 50 minutes and I came back and a File Download had popped up. It states:

    "Name: weirdvideos-173268-08-16-2009.mp4
    Type: MPEG-4 Movie
    From: media.podshow.com"

    My options are to open, save, or cancel.
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    Finally, there is a pop-up at the bottom of my screen stating this:

    "Check you computer security
    There are multiple security problems with your computer"

    This hasn't popped up in the past, but we hadn't changed any security settings to cause it to pop up. Not sure if this is a real warning or a fake one.


    Thanks again for all of your help. I will wait until you give direction before I do anything.

    Ken
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    Update 2:

    Now the first message has disappeared, but I have two different messages.

    1 - Windows host process (Rundll32) has stopped working
    2 - What appears to be an email to craigslist.org about a single family house in bridgewater, nj

    -Ken
     
  19. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    The most important thing is you can boot.
    Now we'll try to sort things out....

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.
  20. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    Malwarebytes


    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8111

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421

    11/7/2011 10:43:35 PM
    mbam-log-2011-11-07 (22-43-35).txt

    Scan type: Quick scan
    Objects scanned: 187260
    Time elapsed: 8 minute(s), 21 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 4
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 6

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GooglePolicyPolicy (Trojan.SHarpro.PGen) -> Value: GooglePolicyPolicy -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YahooPartnerToolbar Update (Trojan.SHarpro.PGen) -> Value: YahooPartnerToolbar Update -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WinRAR Update (Trojan.SHarpro.PGen) -> Value: WinRAR Update -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\Users\Owner\AppData\Local\temp\thpm2538701745674011528.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
    c:\Users\Owner\AppData\Local\temp\thpm2833137803045707695.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
    c:\Users\Owner\AppData\Local\temp\thpm3698677889801561757.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
    c:\Users\Owner\AppData\Local\temp\thpm3778840307662886181.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
    c:\Users\Owner\AppData\Local\temp\thpm6598688767644920225.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.



    GMER



    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-11-07 23:50:30
    Windows 6.0.6002 Service Pack 2
    Running: x16w8n6q.exe


    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe2f66c76
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1F 0x91 0x01 0xD2 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x79 0x58 0xD9 0xA8 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x31 0x1F 0x15 ...
    Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001fe2f66c76 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1F 0x91 0x01 0xD2 ...
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x79 0x58 0xD9 0xA8 ...
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x31 0x1F 0x15 ...

    ---- EOF - GMER 1.0.15 ----



    DDS


    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
    Run by Owner at 23:50:42 on 2011-11-07
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3960.2644 [GMT -5:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Acer\Preload\Command\AlaunchX\AlaunchX.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehtray.exe
    C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Windows\system32\svchost.exe -k HsfXAudioService
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\DllHost.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.livingston.org/
    mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=2&o=vp64&d=1008&m=mc7801u
    uInternet Settings,ProxyOverride = *.local
    mURLSearchHooks: H - No File
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: {37153479-1976-43c3-a1ee-557513977b64} - No File
    BHO: ooVoo Toolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB: ooVoo Toolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll
    TB: {37153479-1976-43c3-a1ee-557513977b64} - No File
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    {7febefe3-6b19-4349-98d2-ffb09d4b49ca}
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    uRun: [SmileboxTray] "C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe"
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [Trigger New Acer AlaunchX] c:\Acer\Preload\Command\AlaunchX\AppInRun.exe
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
    mRunOnce: [New Acer AlaunchX] c:\Acer\Preload\Command\AlaunchX\LaunchAlaunchX.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.16.0.cab
    TCP: DhcpNameServer = 167.206.245.130 167.206.245.129
    TCP: Interfaces\{7C7D86A6-5962-483F-89BB-ED5F19941C31} : DhcpNameServer = 167.206.245.130 167.206.245.129
    TCP: Interfaces\{9AC1704F-5238-42FA-AC76-6A1EF6B6BD72} : DhcpNameServer = 167.206.245.130 167.206.245.129
    Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
    BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO-X64: 0x1 - No File
    BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO-X64: HP Print Enhancer - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: {37153479-1976-43c3-a1ee-557513977b64} - No File
    BHO-X64: Coupons.com - No File
    BHO-X64: ooVoo Toolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll
    BHO-X64: ooVoo Toolbar - No File
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    BHO-X64: HP Smart BHO Class - No File
    TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB-X64: ooVoo Toolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - C:\Program Files (x86)\oovootoolbar\oovootoolbarX.dll
    TB-X64: {37153479-1976-43c3-a1ee-557513977b64} - No File
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
    EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [Trigger New Acer AlaunchX] c:\Acer\Preload\Command\AlaunchX\AppInRun.exe
    mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
    mRunOnce-x64: [New Acer AlaunchX] c:\Acer\Preload\Command\AlaunchX\LaunchAlaunchX.exe
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\
    FF - prefs.js: browser.search.selectedEngine - Bing
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - prefs.js: keyword.URL - hxxp://www.oovoostart.com/s/?src=FF-Address&site=Bing&cfg=2-201-0-0&engine_id=1&provider_id=1&product_id=201&country=US&q=
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 56364
    FF - prefs.js: network.proxy.type - 1
    FF - component: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{59c6f12b-f004-43e5-9997-08f2123119b6}\components\dtTransparency.dll
    FF - component: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{59c6f12b-f004-43e5-9997-08f2123119b6}\components\dtTransparency3.5.dll
    FF - component: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{59c6f12b-f004-43e5-9997-08f2123119b6}\components\dtTransparency3.6.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol500.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    FF - Ext: ooVooToolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - %profile%\extensions\{59c6f12b-f004-43e5-9997-08f2123119b6}
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
    R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
    R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-11-7 44768]
    R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 HsfXAudioService;HsfXAudioService;C:\Windows\system32\svchost.exe -k HsfXAudioService [2008-1-20 21504]
    R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?]
    R3 NETwNv64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETwNv64.sys --> C:\Windows\system32\DRIVERS\NETwNv64.sys [?]
    R3 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2mdx64.sys --> C:\Windows\system32\DRIVERS\o2mdx64.sys [?]
    R3 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sdx64.sys --> C:\Windows\system32\DRIVERS\o2sdx64.sys [?]
    R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x64.sys --> C:\Windows\system32\DRIVERS\yk60x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-4 135664]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-4 135664]
    S3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 atashost;WebEx Service Host for Support Center;C:\Windows\SysWOW64\atashost.exe [2010-7-29 20376]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-19 89920]
    S4 ETService;Empowering Technology Service;C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-10-4 24576]
    .
    =============== File Associations ===============
    .
    JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    2011-11-08 01:11:46 601944 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2011-11-08 01:07:02 65368 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
    2011-11-08 01:06:44 41184 ----a-w- C:\Windows\avastSS.scr
    2011-11-07 03:15:05 -------- d-----w- C:\_OTL
    2011-11-01 14:11:58 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B7788402-BA3B-41B8-958A-358F0A2B4869}\mpengine.dll
    2011-10-26 01:59:57 6144 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
    2011-10-26 01:59:57 6144 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
    .
    ==================== Find3M ====================
    .
    2011-09-06 13:56:50 2764288 ----a-w- C:\Windows\System32\win32k.sys
    2011-08-31 22:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-08-25 16:20:38 735744 ----a-w- C:\Windows\System32\UIAutomationCore.dll
    2011-08-25 16:19:32 847360 ----a-w- C:\Windows\System32\oleaut32.dll
    2011-08-25 16:19:32 332288 ----a-w- C:\Windows\System32\oleacc.dll
    2011-08-25 16:15:04 555520 ----a-w- C:\Windows\SysWow64\UIAutomationCore.dll
    2011-08-25 16:14:01 563712 ----a-w- C:\Windows\SysWow64\oleaut32.dll
    2011-08-25 16:14:01 238080 ----a-w- C:\Windows\SysWow64\oleacc.dll
    2011-08-25 13:54:14 4096 ----a-w- C:\Windows\System32\oleaccrc.dll
    2011-08-25 13:31:01 4096 ----a-w- C:\Windows\SysWow64\oleaccrc.dll
    .
    ============= FINISH: 23:51:59.70 ===============



    Attach


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 10/4/2008 4:20:18 AM
    System Uptime: 11/7/2011 10:45:35 PM (1 hours ago)
    .
    Motherboard: Gateway | |
    Processor: Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz | uFCPGA2 | 800/800mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 144 GiB total, 63.11 GiB free.
    D: is FIXED (NTFS) - 144 GiB total, 143.735 GiB free.
    E: is CDROM (UDF)
    F: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
    Description: HP Photosmart C6300
    Device ID: ROOT\IMAGE\0000
    Manufacturer: Hewlett-Packard
    Name: HP Photosmart C6300
    PNP Device ID: ROOT\IMAGE\0000
    Service: StillCam
    .
    Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
    Description: Deskjet F4500 series
    Device ID: ROOT\IMAGE\0001
    Manufacturer: HP
    Name: Deskjet F4500 series
    PNP Device ID: ROOT\IMAGE\0001
    Service: StillCam
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Photosmart C6300 series
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Photosmart C6300 series
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Deskjet F4500 series
    Device ID: ROOT\MULTIFUNCTION\0001
    Manufacturer: HP
    Name: Deskjet F4500 series
    PNP Device ID: ROOT\MULTIFUNCTION\0001
    Service:
    .
    ==== System Restore Points ===================
    .
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    3ivx MPEG-4 5.0.3 (remove only)
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.6
    Apple Application Support
    Apple Software Update
    avast! Free Antivirus
    AviSynth 2.5
    BufferChm
    C6300
    C6300_Help
    Camera Assistant Software for Gateway
    Cards_Calendar_OrderGift_DoMorePlugout
    Cisco Network Magic
    Compatibility Pack for the 2007 Office system
    Copy
    Coupon Printer for Windows
    Coupons.com Toolbar
    CustomerResearchQFolder
    CyberLink LabelPrint
    CyberLink Power2Go
    Destinations
    DeviceDiscovery
    DeviceManagementQFolder
    DJ_AIO_06_F4500_SW_MIN
    DocProc
    DocProcQFolder
    DriverBoost
    ESET Online Scanner v3
    eSupportQFolder
    F4500
    FlipShare
    Free Convert to DIVX AVI WMV MP4 MPEG Converter 5.8
    Gateway Games
    Gateway Recovery Management
    GearDrvs
    Google Toolbar for Internet Explorer
    Google Update Helper
    GPBaseService
    GPBaseService2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Photo Creations
    HP Photosmart Essential 2.5
    HP Update
    HPPhotoGadget
    HPPhotoSmartPhotobookWebPack1
    HPProductAssistant
    HPSSupply
    ImgBurn
    Java Auto Updater
    Java(TM) 6 Update 22
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    K-Lite Codec Pack 6.4.0 (Basic)
    Malwarebytes' Anti-Malware version 1.51.2.1300
    MarketResearch
    Marvell Miniport Driver
    Microsoft Money Essentials
    Microsoft Money Shared Libraries
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office File Validation Add-In
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    Mozilla Firefox (3.6.8)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Napster
    Napster Burn Engine
    Network Magic
    ooVoo
    ooVoo Toolbar
    PanoStandAlone
    PS_AIO_04_C6300_ProductContext
    PS_AIO_04_C6300_Software
    PS_AIO_04_C6300_Software_Min
    PSSWCORE
    Pure Networks Platform
    QuickTime
    Scan
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB2553074)
    Security Update for 2007 Microsoft Office System (KB2553089)
    Security Update for 2007 Microsoft Office System (KB2553090)
    Security Update for 2007 Microsoft Office System (KB2584063)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft Office Excel 2007 (KB2553073)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
    Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    SmartWebPrinting
    Smilebox
    SolutionCenter
    Status
    System Requirements Lab for Intel
    Toolbox
    TrayApp
    UnloadSupport
    Update for 2007 Microsoft Office System (KB2284654)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 System (KB2539530)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    VideoToolkit01
    VLC media player 0.9.2
    WebEx Support Manager for Internet Explorer
    WebReg
    Wii Video 9 6
    Windows Live Messenger
    WinRAR archiver
    WinZip 14.5
    Yahoo! Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    11/7/2011 2:17:17 AM, Error: EventLog [6008] - The previous system shutdown at 12:19:30 AM on 11/6/2011 was unexpected.
    11/7/2011 10:47:23 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep
    11/5/2011 3:20:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
    11/5/2011 3:20:29 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    11/5/2011 3:20:29 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    11/4/2011 2:01:20 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
    11/4/2011 2:01:20 AM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    11/4/2011 2:01:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
    11/3/2011 8:14:11 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.108 for the Network Card with network address 00215D40C41C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    11/3/2011 12:03:24 AM, Error: Service Control Manager [7034] - The HP Network Devices Support service terminated unexpectedly. It has done this 1 time(s).
    11/2/2011 12:54:42 PM, Error: EventLog [6008] - The previous system shutdown at 12:48:22 PM on 11/2/2011 was unexpected.
    11/2/2011 10:36:53 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer KEN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{9AC1704F-5238-42FA-AC76-6A1EF6B6BD72}. The master browser is stopping or an election is being forced.
    11/2/2011 10:36:50 PM, Error: netbt [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state.
    11/1/2011 8:01:47 PM, Error: EventLog [6008] - The previous system shutdown at 3:50:28 PM on 11/1/2011 was unexpected.
    11/1/2011 10:03:37 AM, Error: EventLog [6008] - The previous system shutdown at 6:57:02 AM on 10/27/2011 was unexpected.
    .
    ==== End Of File ===========================
  21. Broni

    Broni Malware Annihilator Posts: 46,132   +251

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan:
    [​IMG]

    On completion of the scan click "Save log", save it to your desktop and post in your next reply:
    [​IMG]

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

    =================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
  22. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    aswMBR

    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-11-08 18:15:46
    -----------------------------
    18:15:46.758 OS Version: Windows x64 6.0.6002 Service Pack 2
    18:15:46.758 Number of processors: 2 586 0xF0D
    18:15:46.758 ComputerName: OWNER-PC UserName: Owner
    18:15:47.398 Initialize success
    18:15:47.850 AVAST engine defs: 11110800
    18:15:56.430 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    18:15:56.446 Disk 0 Vendor: Hitachi_ FB4O Size: 305245MB BusType: 3
    18:15:56.446 Disk 0 MBR read error 0
    18:15:56.446 Disk 0 MBR scan
    18:15:56.851 Disk 0 unknown MBR code
    18:15:56.851 MBR BIOS signature not found 0
    18:15:56.867 Service scanning
    18:16:01.890 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
    18:16:03.107 Modules scanning
    18:16:03.107 Disk 0 trace - called modules:
    18:16:03.122 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys spmk.sys hal.dll
    18:16:03.138 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004fb9790]
    18:16:03.138 3 CLASSPNP.SYS[fffffa6000dcfc33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004cc2050]
    18:16:07.631 AVAST engine scan C:\Windows
    18:21:00.958 AVAST engine scan C:\Windows\system32
    18:22:59.970 AVAST engine scan C:\Windows\system32\drivers
    18:23:12.200 AVAST engine scan C:\Users\Owner
    18:41:59.332 AVAST engine scan C:\ProgramData
    18:45:12.896 Scan finished successfully
    21:44:48.694 Disk 0 MBR has been saved successfully to "F:\6 November 2011\Logs\MBR.dat"
    21:44:48.725 The log file has been saved successfully to "F:\6 November 2011\Logs\aswMBR.txt"



    ComboFix

    ComboFix 11-11-08.02 - Owner 11/08/2011 21:53:42.3.2 - x64
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3960.2343 [GMT -5:00]
    Running from: c:\users\Owner\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{edbd594b-e8db-4633-b448-d1d0641c5173}
    c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{edbd594b-e8db-4633-b448-d1d0641c5173}\chrome.manifest
    c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{edbd594b-e8db-4633-b448-d1d0641c5173}\chrome\xulcache.jar
    c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{edbd594b-e8db-4633-b448-d1d0641c5173}\defaults\preferences\xulcache.js
    c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\c8nzy25t.default\extensions\{edbd594b-e8db-4633-b448-d1d0641c5173}\install.rdf
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-10-09 to 2011-11-09 )))))))))))))))))))))))))))))))
    .
    .
    2011-11-09 03:07 . 2011-11-09 03:07 -------- d-----w- c:\users\Public\AppData\Local\temp
    2011-11-09 03:07 . 2011-11-09 03:07 -------- d-----w- c:\users\Owner\AppData\Local\temp
    2011-11-09 03:07 . 2011-11-09 03:07 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-11-08 01:11 . 2011-09-06 21:45 254400 ----a-w- c:\windows\system32\aswBoot.exe
    2011-11-08 01:11 . 2011-09-06 21:38 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-11-08 01:07 . 2011-09-06 21:38 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2011-11-08 01:07 . 2011-09-06 21:36 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2011-11-08 01:07 . 2011-09-06 21:36 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2011-11-08 01:07 . 2011-09-06 21:36 58200 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2011-11-08 01:07 . 2011-09-06 21:36 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2011-11-08 01:06 . 2011-09-06 21:45 41184 ----a-w- c:\windows\avastSS.scr
    2011-11-08 01:06 . 2011-09-06 21:45 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2011-11-07 03:15 . 2011-11-07 03:15 -------- d-----w- C:\_OTL
    2011-11-01 14:11 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B7788402-BA3B-41B8-958A-358F0A2B4869}\mpengine.dll
    2011-10-26 01:59 . 2011-08-13 05:11 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
    2011-10-26 01:59 . 2011-08-13 04:43 6144 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-08-31 22:00 . 2011-06-17 02:20 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-06-18_18.26.11 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-04 08:14 . 2008-08-12 03:25 97304 c:\windows\SysWOW64\x64\Difx64.exe
    + 2011-02-24 13:49 . 2009-10-09 21:56 24064 c:\windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll
    + 2011-02-24 13:49 . 2009-10-09 21:56 20480 c:\windows\SysWOW64\WindowsPowerShell\v1.0\PSEvents.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 61952 c:\windows\SysWOW64\wbem\xml\wmi2xml.dll
    + 2009-09-19 15:50 . 2009-04-11 06:28 83968 c:\windows\SysWOW64\wbem\wmiutils.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 47104 c:\windows\SysWOW64\wbem\WmiPerfInst.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 91136 c:\windows\SysWOW64\wbem\WmiPerfClass.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 74752 c:\windows\SysWOW64\wbem\WMICOOKR.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 90112 c:\windows\SysWOW64\wbem\WmiApRpl.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 77824 c:\windows\SysWOW64\wbem\WinMgmt.exe
    + 2009-09-19 15:51 . 2009-04-11 06:28 49152 c:\windows\SysWOW64\wbem\wbemsvc.dll
    + 2009-09-19 15:50 . 2009-04-11 06:28 30208 c:\windows\SysWOW64\wbem\wbemprox.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 98304 c:\windows\SysWOW64\wbem\stdprov.dll
    + 2008-01-21 02:48 . 2008-01-21 02:48 19968 c:\windows\SysWOW64\wbem\mofcomp.exe
    + 2008-01-21 02:50 . 2008-01-21 02:50 94720 c:\windows\SysWOW64\sysprep\sysprep.exe
    + 2006-11-02 15:01 . 2006-11-02 15:01 16384 c:\windows\SysWOW64\Speech\SpeechUX\SpeechUXPS.DLL
    + 2008-01-21 02:47 . 2008-01-21 02:47 99328 c:\windows\SysWOW64\Speech\Engines\SR\spsrx.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 66048 c:\windows\SysWOW64\setup\tssysprep.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 59904 c:\windows\SysWOW64\setup\msdtcstp.dll
    + 2008-01-21 02:49 . 2008-01-21 02:49 56320 c:\windows\SysWOW64\setup\cmmigr.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 76800 c:\windows\SysWOW64\SetIEInstalledDate.exe
    + 2007-11-15 21:58 . 2007-11-15 21:58 73728 c:\windows\SysWOW64\SDA\SDPA7120.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 74752 c:\windows\SysWOW64\RegisterIEPKEYs.exe
    + 2006-11-02 15:13 . 2006-11-02 15:13 51462 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prnqctl.vbs
    + 2006-11-02 15:13 . 2006-11-02 15:13 56756 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prnport.vbs
    + 2006-11-02 15:13 . 2006-11-02 15:13 81048 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prnmngr.vbs
    + 2006-11-02 15:13 . 2006-11-02 15:13 69882 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prnjobs.vbs
    + 2006-11-02 15:13 . 2006-11-02 15:13 51312 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prndrvr.vbs
    + 2011-11-04 07:29 . 2011-11-04 07:29 54272 c:\windows\SysWOW64\pngfilt.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 62976 c:\windows\SysWOW64\oobe\windeploy.exe
    + 2008-01-21 02:50 . 2008-01-21 02:50 47616 c:\windows\SysWOW64\oobe\wdsutil.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 54272 c:\windows\SysWOW64\oobe\spprgrss.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 42496 c:\windows\SysWOW64\oobe\oobeldr.exe
    + 2008-01-21 02:50 . 2008-01-21 02:50 31232 c:\windows\SysWOW64\oobe\diagER.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 52736 c:\windows\SysWOW64\oobe\audit.exe
    + 2010-06-24 19:24 . 2009-11-08 14:55 11600 c:\windows\SysWOW64\MUI\0409\mscorees.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 48640 c:\windows\SysWOW64\mshtmler.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 72704 c:\windows\SysWOW64\mshtmled.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 11776 c:\windows\SysWOW64\mshta.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 10752 c:\windows\SysWOW64\msfeedssync.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 41472 c:\windows\SysWOW64\msfeedsbs.dll
    + 2006-11-02 12:14 . 2006-09-18 21:27 19429 c:\windows\SysWOW64\Msdtc\Trace\msdtcvtr.bat
    + 2008-01-21 02:47 . 2008-01-21 02:47 54272 c:\windows\SysWOW64\migwiz\usmt2xtr.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 87552 c:\windows\SysWOW64\migwiz\MXEAgent.dll
    + 2006-11-02 15:02 . 2006-11-02 15:02 82944 c:\windows\SysWOW64\migwiz\MIGUIRes.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 87552 c:\windows\SysWOW64\migwiz\dlmanifests\Networking-MPSSVC-Svc\icfupgd.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 31232 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\TableTextServiceMig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 22528 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\imtcmig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 31744 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\imscmig.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 38912 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\imkrmig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 35328 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\imjpmig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 98304 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TapiSetup\TapiMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 72704 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-Sxs\SxsMigPlugin.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 79872 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-shmig-DL\shmig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 56320 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-RasConnectionManager\cmmigr.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 87552 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-OfflineFiles-DL\CscMig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 61952 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-NetworkBridge\bridgemigplugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 89088 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-International-Core-DL\nlscoremig.dll
    + 2009-09-19 15:52 . 2009-04-11 06:28 44544 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-IE-ESC\EscMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 89088 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-DirectoryServices-ADAM-DL\adammigrate.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 59904 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-COM-DTC-Setup-DL\msdtcstp.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 55808 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-COM-ComPlus-Setup-DL\commig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 73216 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-Bluetooth-Config\BthMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 60928 c:\windows\SysWOW64\migwiz\dlmanifests\BITSExtensions-Server\bitsmig.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 23552 c:\windows\SysWOW64\licmgr10.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 65024 c:\windows\SysWOW64\jsproxy.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 78848 c:\windows\SysWOW64\inseng.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 35840 c:\windows\SysWOW64\imgutil.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 86528 c:\windows\SysWOW64\iesysprep.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 74752 c:\windows\SysWOW64\iesetup.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 31744 c:\windows\SysWOW64\iernonce.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 74240 c:\windows\SysWOW64\ie4uinit.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 66048 c:\windows\SysWOW64\icardie.dll
    - 2008-01-21 03:20 . 2011-06-17 00:53 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-01-21 03:20 . 2011-11-08 03:48 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2011-07-23 11:41 . 2011-11-08 03:48 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-01-21 03:20 . 2011-06-17 00:53 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-01-21 03:20 . 2011-11-08 03:48 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-01-21 02:23 . 2011-11-08 03:48 60938 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-11-30 14:00 . 2011-11-08 23:20 14894 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1361230698-3698658676-2926581387-1000_UserData.bin
    + 2011-11-04 07:29 . 2011-11-04 07:29 91648 c:\windows\system32\SetIEInstalledDate.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 89088 c:\windows\system32\RegisterIEPKEYs.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 65024 c:\windows\system32\pngfilt.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 48640 c:\windows\system32\mshtmler.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 96256 c:\windows\system32\mshtmled.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 12288 c:\windows\system32\mshta.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 10752 c:\windows\system32\msfeedssync.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 55296 c:\windows\system32\msfeedsbs.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 86528 c:\windows\system32\migration\WininetPlugin.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 30720 c:\windows\system32\licmgr10.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 85504 c:\windows\system32\jsproxy.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 49664 c:\windows\system32\imgutil.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 85504 c:\windows\system32\iesetup.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 39936 c:\windows\system32\iernonce.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 89088 c:\windows\system32\ie4uinit.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 82432 c:\windows\system32\icardie.dll
    + 2011-07-12 17:41 . 2009-06-17 10:37 35328 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\BTHUSB.SYS
    + 2009-09-19 15:52 . 2009-04-11 05:39 26112 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\bthenum.sys
    - 2008-01-21 02:49 . 2008-01-21 02:49 85504 c:\windows\system32\csrsrv.dll
    + 2011-07-12 17:41 . 2011-04-20 15:58 85504 c:\windows\system32\csrsrv.dll
    - 2008-11-30 13:46 . 2011-06-18 00:11 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-11-30 13:46 . 2011-11-05 19:22 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-11-30 13:46 . 2011-06-18 00:11 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2011-06-21 00:47 . 2011-11-05 19:22 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-11-30 13:46 . 2011-06-18 00:11 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-11-30 13:46 . 2011-11-05 19:22 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-30 00:16 . 2011-11-04 01:06 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-30 00:16 . 2011-06-11 02:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-30 00:16 . 2011-06-11 02:38 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-11-30 00:16 . 2011-11-04 01:06 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-11-30 00:16 . 2011-06-11 02:38 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-30 00:16 . 2011-11-04 01:06 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-30 00:16 . 2011-06-18 14:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-30 00:16 . 2011-11-04 00:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-11-30 00:16 . 2011-11-04 00:44 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-11-30 00:16 . 2011-06-18 14:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2011-04-06 20:48 . 2011-04-06 20:48 11120 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
    - 2011-04-13 02:16 . 2011-04-13 02:16 67920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 67920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll
    + 2011-05-17 14:08 . 2011-05-17 14:08 53072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Culture.dll
    - 2010-03-18 18:27 . 2010-03-18 18:27 53072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Culture.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 11120 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 56656 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
    - 2011-04-12 19:11 . 2011-04-12 19:11 56656 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
    + 2011-05-17 13:27 . 2011-05-17 13:27 44368 c:\windows\Microsoft.NET\Framework\v4.0.30319\Culture.dll
    - 2010-03-18 17:16 . 2010-03-18 17:16 44368 c:\windows\Microsoft.NET\Framework\v4.0.30319\Culture.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-10-22 16:56 . 2011-10-22 16:56 22016 c:\windows\Installer\2af992.msi
    + 2011-11-04 07:30 . 2011-11-04 07:30 19968 c:\windows\Installer\174b3ef.msi
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut9.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut9.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut8.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut8.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut7.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut7.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut6.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut6.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut5.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut5.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut28.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut28.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut27.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut27.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut26.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut26.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut25.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut25.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut24.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut24.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut23.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut23.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut22.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut22.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut21.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut21.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut20.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut20.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut2_1.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut2_1.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut19.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut19.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut18.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut18.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut17.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut17.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut16.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut16.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut15.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut15.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut14.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut14.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut13.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut13.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut12.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut12.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut11.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut11.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut10.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut10.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
    - 2009-05-13 00:34 . 2010-11-29 04:48 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\ARPPRODUCTICON.exe
    + 2009-05-13 00:34 . 2011-06-18 22:09 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\ARPPRODUCTICON.exe
    - 2011-06-16 23:08 . 2011-06-16 23:08 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    + 2011-09-16 10:41 . 2011-09-16 10:41 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2011-09-16 10:41 . 2011-09-16 10:41 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2011-06-16 23:08 . 2011-06-16 23:08 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    + 2010-09-23 08:47 . 2010-09-23 08:47 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\reader_sl.exe
    + 2010-09-23 07:03 . 2010-09-23 07:03 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\eula.exe
    + 2010-09-21 03:07 . 2010-09-21 03:07 70584 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\adobeextractfiles.dll
    + 2010-09-23 06:52 . 2010-09-23 06:52 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\acrotextextractor.exe
    + 2010-09-22 22:12 . 2010-09-22 22:12 15800 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\AcroRd32Info.exe
    - 2006-11-02 12:40 . 2011-06-11 02:50 86016 c:\windows\inf\infstor.dat
    + 2006-11-02 12:40 . 2011-07-15 02:07 86016 c:\windows\inf\infstor.dat
    + 2006-11-02 12:40 . 2011-07-15 02:07 51200 c:\windows\inf\infpub.dat
    - 2006-11-02 12:40 . 2011-06-16 23:42 51200 c:\windows\inf\infpub.dat
    + 2011-10-16 15:52 . 2011-10-16 15:52 10240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\59e70022e798ce28f9f5b8870c5c8bf2\System.Xml.Serialization.ni.dll
    + 2011-10-16 15:52 . 2011-10-16 15:52 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\d32e9d2d879649adb929915723e1eecb\System.Windows.Presentation.ni.dll
    + 2011-10-16 15:52 . 2011-10-16 15:52 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\f36d1265de7263ea199fa7058bf40477\System.Web.ApplicationServices.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\09132e10556be9ab331f43b2a8c52235\System.AddIn.Contract.ni.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\49a7edb0d7f35bebc304b303b0700ddc\Microsoft.VisualC.ni.dll
    + 2011-10-16 15:29 . 2011-10-16 15:29 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5b39108886107f654624373c54000e3c\dfsvc.ni.exe
    + 2011-10-16 15:29 . 2011-10-16 15:29 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\41d4534c5a98fd1bc7edc2f73cd41a0a\Accessibility.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\1c177e9aa7a1661ddec16c2f9f30947c\UIAutomationProvider.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\e4f0e0d45a1739bad6cc96377c9dd7f2\System.Windows.Presentation.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\385b56be2d617548e4b731dd050a1f32\System.Web.ApplicationServices.ni.dll
    + 2011-10-16 16:01 . 2011-10-16 16:01 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\e08ecf530f270cd45c72318b67826cb1\System.ServiceModel.Channels.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\117b65133fc00228bc249d1c61c387ea\System.AddIn.Contract.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\432eb09604ab71ee1aa4622bfbc4afee\Microsoft.VisualC.ni.dll
    + 2011-10-16 15:55 . 2011-10-16 15:55 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\06ac8d640d2dfa7d4bb23c03584304ef\Accessibility.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\00db78298fe5452c0f0841e3688193df\System.Windows.Presentation.ni.dll
    + 2011-09-26 01:10 . 2011-09-26 01:10 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\00539d6e9bd5e7456bdbc98a47ab995c\System.Windows.Presentation.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\77e310c7ad8dd72ffc2bb041cb8b2844\System.Web.DynamicData.Design.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\1f136447130a4f69df3c6560ea58abb3\System.Web.DynamicData.Design.ni.dll
    - 2011-06-18 15:32 . 2011-06-18 15:32 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\5038a4070cfc72e23a191ab4ba38c477\stdole.ni.dll
    + 2011-09-21 03:37 . 2011-09-21 03:37 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\5038a4070cfc72e23a191ab4ba38c477\stdole.ni.dll
    + 2011-10-16 17:02 . 2011-10-16 17:02 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\3dc984b6976f8bc8e7d2e9c2129e5ade\stdole.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\175efd925a4d4e7deccc7855d6dcb3c9\PresentationFontCache.ni.exe
    + 2011-09-26 01:06 . 2011-09-26 01:06 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\151ac6b026e8ca585e0dfd1ce33e8ecb\PresentationFontCache.ni.exe
    + 2011-10-16 17:08 . 2011-10-16 17:08 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\fa0c632bdf12e9d70405212bbcb255ee\PresentationCFFRasterizer.ni.dll
    + 2011-09-26 01:04 . 2011-09-26 01:04 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\b81308b591d239f587cc0e113d43fa35\PresentationCFFRasterizer.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\ec097538108aed5ed52aace1e4579f91\Microsoft.WSMan.Runtime.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\a4a66a531fcba4ae3db28c68033787a4\Microsoft.WSMan.Runtime.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\28baaf9cc7640ebf81cc317dbd5119d6\Microsoft.VisualC.ni.dll
    - 2011-06-18 15:27 . 2011-06-18 15:27 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\09f46722269da16f1a6d1abbb580d7ed\Microsoft.VisualC.ni.dll
    + 2011-09-21 02:19 . 2011-09-21 02:19 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\09f46722269da16f1a6d1abbb580d7ed\Microsoft.VisualC.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 62464 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtCOM\d44223fe604b9811a3a57cbf71c3f1f9\ehiExtCOM.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 62464 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtCOM\8856fca280c8ecf7d1f798ed5a66dff1\ehiExtCOM.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 62464 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtCOM\8856fca280c8ecf7d1f798ed5a66dff1\ehiExtCOM.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 62976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtCOM\2c497fedb47981d3f9cd789d3966ccf4\ehExtCOM.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 62976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtCOM\071f35122c0c83d4791f7d7a5f2ae4a1\ehExtCOM.ni.dll
    + 2011-09-21 03:37 . 2011-09-21 03:37 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\be7de592b7f3c30299328ddff449db59\dfsvc.ni.exe
    - 2011-06-18 15:32 . 2011-06-18 15:32 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\be7de592b7f3c30299328ddff449db59\dfsvc.ni.exe
    + 2011-10-16 17:02 . 2011-10-16 17:02 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\42bec19a6f2ecc6f45c4d07b4e2d6083\dfsvc.ni.exe
    + 2011-09-21 02:23 . 2011-09-21 02:23 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\957ce139305f26be16614e23afa899a7\Accessibility.ni.dll
    - 2011-06-18 15:27 . 2011-06-18 15:27 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\957ce139305f26be16614e23afa899a7\Accessibility.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\006ccb4b89e6670929d149ff641369ef\Accessibility.ni.dll
    - 2011-06-18 15:15 . 2011-06-18 15:15 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a6485a160959fbed092dc2ddbed3509e\UIAutomationProvider.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a6485a160959fbed092dc2ddbed3509e\UIAutomationProvider.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5aab9bc687029a908fc01473f8e5f77b\UIAutomationProvider.ni.dll
    + 2011-10-16 17:23 . 2011-10-16 17:23 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\5a612d5f8aa2cd185d458018f1c516c8\System.Windows.Presentation.ni.dll
    + 2011-09-26 00:45 . 2011-09-26 00:45 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\3b0d2893e72d3baf1e67bcdb0b8737cf\System.Windows.Presentation.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\f02fc02350dad1da369a9c200b8ef277\System.Web.DynamicData.Design.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\46f477a132ae1e94e07d3873867cde2b\System.Web.DynamicData.Design.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\37cff04b1ba772743292372b797c28f6\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-16 17:20 . 2011-10-16 17:20 94208


    Continued...
  23. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\04ca8580a54386eb58d4a8815126f51b\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-16 17:20 . 2011-10-16 17:20 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\fa4e1998745ba5cfd3751d17172a50c1\System.AddIn.Contract.ni.dll
    - 2011-06-18 15:16 . 2011-06-18 15:16 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\971463f91825692f7cd123b2a3af721b\System.AddIn.Contract.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\971463f91825692f7cd123b2a3af721b\System.AddIn.Contract.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\b350a5cb539f16b07028cfa6483ee886\PresentationFontCache.ni.exe
    + 2011-10-16 17:19 . 2011-10-16 17:19 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\83be7d564785d94bf06b26fd10c8c981\PresentationFontCache.ni.exe
    + 2011-09-26 00:41 . 2011-09-26 00:41 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\4a2a3e502cc441c97350acf5c3dacc4e\PresentationCFFRasterizer.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0e7ac2a3a8e276173911d35d51bfc0c8\PresentationCFFRasterizer.ni.dll
    - 2011-06-18 15:15 . 2011-06-18 15:15 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\78704655584ce2fd27a6c39573f6f36a\napcrypt.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\78704655584ce2fd27a6c39573f6f36a\napcrypt.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\67e74beedea6b1c61609c3199a41c112\napcrypt.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\bcdf31c5057d7222e2472d105e3ea5a7\Microsoft.WSMan.Runtime.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\018450526569962d4bb24564143c50f6\Microsoft.WSMan.Runtime.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\748a5063c67235044f516d4c2c5f090a\Microsoft.Vsa.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\41c8887d9cdeba5c067d34e2303a4a87\Microsoft.Vsa.ni.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\81bc126ce60194c5af7e6d4b1b03f6c1\Microsoft.VisualC.ni.dll
    - 2011-06-18 15:11 . 2011-06-18 15:11 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\81bc126ce60194c5af7e6d4b1b03f6c1\Microsoft.VisualC.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\0be0eb42238f115408fd2fab2b9a387f\Microsoft.VisualC.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e51e9b0e132d5639a9d24d2fc93d84e2\Microsoft.Build.Framework.ni.dll
    - 2011-06-18 15:12 . 2011-06-18 15:12 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\9c6b098a9a7ee64cc4ff276a7babb0da\Microsoft.Build.Framework.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\9c6b098a9a7ee64cc4ff276a7babb0da\Microsoft.Build.Framework.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\4bcbda8a78ed8746b758f2c961df98f9\Microsoft.Build.Framework.ni.dll
    - 2011-06-18 15:14 . 2011-06-18 15:14 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\09f4fc8e36b2012a5f3cb0a9d23b9e20\Microsoft.Build.Framework.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\09f4fc8e36b2012a5f3cb0a9d23b9e20\Microsoft.Build.Framework.ni.dll
    - 2011-06-18 15:13 . 2011-06-18 15:13 57856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\b7dc08f390f95b199da497bba999b5dc\ehiUserXp.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 57856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\b7dc08f390f95b199da497bba999b5dc\ehiUserXp.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 57856 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\188cef9a56634d7e4b9239c388576d94\ehiUserXp.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\e6cbea88a9a9df05833dbd941a21528b\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 73728 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\33cd844d8168c4fa50bbd03dda2a83a1\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\e4c8338d98d38340bd2e9eb91eb4ad78\dfsvc.ni.exe
    + 2011-09-25 15:10 . 2011-09-25 15:10 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\710e9691861b597505a63f2b29e4d7d2\dfsvc.ni.exe
    - 2011-06-18 15:13 . 2011-06-18 15:13 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\710e9691861b597505a63f2b29e4d7d2\dfsvc.ni.exe
    - 2011-06-18 15:11 . 2011-06-18 15:11 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c8750ecd71abac98fb26b2f4bf3a031a\Accessibility.ni.dll
    + 2011-09-22 00:05 . 2011-09-22 00:05 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c8750ecd71abac98fb26b2f4bf3a031a\Accessibility.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll
    + 2011-02-24 13:49 . 2009-10-09 21:56 2048 c:\windows\SysWOW64\WindowsPowerShell\v1.0\pwrshmsg.dll
    + 2011-02-24 13:49 . 2009-10-12 21:59 4096 c:\windows\SysWOW64\WindowsPowerShell\v1.0\en-US\powershell_ise.resources.dll
    + 2011-08-25 02:45 . 2011-07-11 13:25 2048 c:\windows\SysWOW64\tzres.dll
    - 2010-12-21 00:56 . 2010-10-28 13:20 2048 c:\windows\SysWOW64\tzres.dll
    + 2006-11-02 15:13 . 2006-11-02 15:13 7418 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\pubprn.vbs
    + 2011-10-15 13:58 . 2011-08-25 13:31 4096 c:\windows\SysWOW64\oleaccrc.dll
    - 2010-04-19 00:32 . 2009-10-08 21:07 4096 c:\windows\SysWOW64\oleaccrc.dll
    + 2006-11-02 12:19 . 2006-09-19 11:41 9560
    c:\windows\SysWOW64\networklist\icons\StockIcons\office_48.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 4280 c:\windows\SysWOW64\networklist\icons\StockIcons\office_32.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 2456 c:\windows\SysWOW64\networklist\icons\StockIcons\office_24.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 9560 c:\windows\SysWOW64\networklist\icons\StockIcons\house_48.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 4280 c:\windows\SysWOW64\networklist\icons\StockIcons\house_32.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 2456 c:\windows\SysWOW64\networklist\icons\StockIcons\house_24.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 9560 c:\windows\SysWOW64\networklist\icons\StockIcons\bench_48.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 4280 c:\windows\SysWOW64\networklist\icons\StockIcons\bench_32.bin
    + 2006-11-02 12:19 . 2006-09-19 11:41 2456 c:\windows\SysWOW64\networklist\icons\StockIcons\bench_24.bin
    + 2008-11-30 15:44 . 2011-11-08 03:45 1772 c:\windows\system32\WDI\ERCQueuedResolutions.dat
    - 2010-12-21 00:56 . 2010-10-28 13:56 2048 c:\windows\system32\tzres.dll
    + 2011-08-25 02:45 . 2011-07-11 13:45 2048 c:\windows\system32\tzres.dll
    + 2011-10-15 13:58 . 2011-08-25 13:54 4096 c:\windows\system32\oleaccrc.dll
    - 2010-04-19 00:32 . 2009-10-08 21:07 4096 c:\windows\system32\oleaccrc.dll
    + 2011-06-21 02:04 . 2011-06-21 02:04 9560 c:\windows\system32\networklist\icons\{CED50A58-9E1F-4B6D-8430-E5A692CF2425}_48.bin
    + 2011-06-21 02:04 . 2011-06-21 02:04 4280 c:\windows\system32\networklist\icons\{CED50A58-9E1F-4B6D-8430-E5A692CF2425}_32.bin
    + 2011-06-21 02:04 . 2011-06-21 02:04 2456 c:\windows\system32\networklist\icons\{CED50A58-9E1F-4B6D-8430-E5A692CF2425}_24.bin
    + 2011-07-30 22:18 . 2011-07-30 22:18 9560 c:\windows\system32\networklist\icons\{95043D38-2BED-49A6-A5F1-567CF577E295}_48.bin
    + 2011-07-30 22:18 . 2011-07-30 22:18 4280 c:\windows\system32\networklist\icons\{95043D38-2BED-49A6-A5F1-567CF577E295}_32.bin
    + 2011-07-30 22:18 . 2011-07-30 22:18 2456 c:\windows\system32\networklist\icons\{95043D38-2BED-49A6-A5F1-567CF577E295}_24.bin
    + 2011-11-08 03:46 . 2011-11-08 23:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-06-18 18:25 . 2011-06-18 18:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-06-18 18:25 . 2011-06-18 18:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-11-08 03:46 . 2011-11-08 23:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-10-16 16:02 . 2011-10-16 16:02 9216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\3a2ab56bb224b871516526753985ff69\System.Xml.Serialization.ni.dll
    + 2011-10-16 15:55 . 2011-10-16 15:55 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\5cc246adea1b07b9c2a76bbe86fbfe2e\dfsvc.ni.exe
    + 2009-09-19 15:53 . 2009-02-18 18:39 299368 c:\windows\SysWOW64\XPSViewer\XPSViewer.exe
    + 2011-08-10 14:50 . 2011-06-15 16:12 182784 c:\windows\SysWOW64\xmllite.dll
    + 2008-10-04 08:14 . 2006-11-10 01:25 525792 c:\windows\SysWOW64\x64\difxapi.dll
    + 2011-02-24 13:49 . 2009-10-09 21:57 154112 c:\windows\SysWOW64\WindowsPowerShell\v1.0\pspluginwkr.dll
    + 2011-02-24 13:49 . 2009-10-09 21:57 204800 c:\windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe
    + 2011-02-24 13:49 . 2009-10-09 21:56 448000 c:\windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
    + 2011-02-24 13:49 . 2009-10-09 21:57 112640 c:\windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitsTransfer\Microsoft.BackgroundIntelligentTransfer.Management.Interop.dll
    + 2011-02-24 13:49 . 2009-07-16 17:22 126976 c:\windows\SysWOW64\WindowsPowerShell\v1.0\CompiledComposition.Microsoft.PowerShell.GPowerShell.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 152064 c:\windows\SysWOW64\wextract.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 203776 c:\windows\SysWOW64\webcheck.dll
    + 2009-09-19 15:52 . 2009-04-11 06:28 247296 c:\windows\SysWOW64\wbem\WmiPrvSE.exe
    + 2009-09-19 15:52 . 2009-04-11 06:28 129024 c:\windows\SysWOW64\wbem\WmiDcPrv.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 625664 c:\windows\SysWOW64\wbem\WMIC.exe
    + 2009-09-19 15:51 . 2009-04-11 06:28 117248 c:\windows\SysWOW64\wbem\WMIADAP.exe
    + 2008-01-21 02:50 . 2008-01-21 02:50 143360 c:\windows\SysWOW64\wbem\Win32_Tpm.dll
    + 2008-01-21 02:51 . 2008-01-21 02:51 188928 c:\windows\SysWOW64\wbem\wbemdisp.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 250368 c:\windows\SysWOW64\wbem\wbemcntl.dll
    + 2008-01-21 02:48 . 2008-01-21 02:48 135168 c:\windows\SysWOW64\wbem\vsswmi.dll
    + 2008-01-21 02:49 . 2008-01-21 02:49 135168 c:\windows\SysWOW64\wbem\viewprov.dll
    + 2008-01-21 02:48 . 2008-01-21 02:48 160768 c:\windows\SysWOW64\wbem\vdswmi.dll
    + 2009-09-19 15:50 . 2009-04-11 06:28 189440 c:\windows\SysWOW64\wbem\mofd.dll
    + 2009-09-19 15:50 . 2009-04-11 06:28 614912 c:\windows\SysWOW64\wbem\fastprox.dll
    + 2009-09-19 15:50 . 2009-04-11 06:28 265728 c:\windows\SysWOW64\wbem\esscli.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 420864 c:\windows\SysWOW64\vbscript.dll
    - 2011-04-17 16:06 . 2011-02-17 06:23 420864 c:\windows\SysWOW64\vbscript.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 231936 c:\windows\SysWOW64\url.dll
    + 2011-10-15 13:58 . 2011-08-25 16:15 555520 c:\windows\SysWOW64\UIAutomationCore.dll
    - 2010-04-19 00:32 . 2009-10-08 21:08 555520 c:\windows\SysWOW64\UIAutomationCore.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 402432 c:\windows\SysWOW64\Speech\Engines\SR\srloc.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 851456 c:\windows\SysWOW64\Speech\Engines\SR\spsreng.dll
    + 2008-01-21 02:49 . 2008-01-21 02:49 115200 c:\windows\SysWOW64\setup\RasMigPlugin.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 125440 c:\windows\SysWOW64\setup\pbkmigr.dll
    + 2008-01-21 02:51 . 2008-01-21 02:51 246272 c:\windows\SysWOW64\setup\comsetup.dll
    + 2011-06-29 21:11 . 2011-04-29 15:59 276992 c:\windows\SysWOW64\schannel.dll
    - 2009-09-19 15:51 . 2009-04-11 06:28 293376 c:\windows\SysWOW64\psisdecd.dll
    + 2011-10-15 13:58 . 2011-07-29 16:01 293376 c:\windows\SysWOW64\psisdecd.dll
    + 2006-11-02 15:13 . 2006-11-02 15:13 105940 c:\windows\SysWOW64\Printing_Admin_Scripts\en-US\prncnfg.vbs
    + 2008-01-21 02:50 . 2008-01-21 02:50 416768 c:\windows\SysWOW64\oobe\win32ui.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 266752 c:\windows\SysWOW64\oobe\W32UIRes.dll
    + 2008-01-21 02:50 . 2008-01-21 02:50 195640 c:\windows\SysWOW64\oobe\Setup.exe
    + 2008-01-21 02:50 . 2008-01-21 02:50 121856 c:\windows\SysWOW64\oobe\diagnostic.dll
    - 2011-06-16 11:10 . 2010-12-20 16:35 563712 c:\windows\SysWOW64\oleaut32.dll
    + 2011-10-15 13:58 . 2011-08-25 16:14 563712 c:\windows\SysWOW64\oleaut32.dll
    + 2011-10-15 13:58 . 2011-08-25 16:14 238080 c:\windows\SysWOW64\oleacc.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 123392 c:\windows\SysWOW64\occache.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 162304 c:\windows\SysWOW64\msrating.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 161792 c:\windows\SysWOW64\msls31.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 580608 c:\windows\SysWOW64\msfeeds.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 634268 c:\windows\SysWOW64\migwiz\SFLIST2K.dat
    + 2008-01-21 02:47 . 2008-01-21 02:47 155704 c:\windows\SysWOW64\migwiz\migwiz.exe
    + 2008-01-21 02:47 . 2008-01-21 02:47 372224 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-WMI-Core\WMIMigrationPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 143872 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-Unimodem-Config\ModemMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 153600 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-TextServicesFramework-Migration-DL\msctfmig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 201216 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-StorageMigration\StorMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 115200 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-RasServer-MigPlugin\RasMigPlugin.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 125440 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-RasApi\pbkmigr.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 120832 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-PerformanceCounterInfrastructure-DL\CntrtextMig.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 135680 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-NetworkLoadBalancing-Core\NlbMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 129024 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-NDIS\ndismigplugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 122880 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-msmq-messagingcoreservice\mqmigplugin.dll
    + 2009-09-19 15:52 . 2009-04-11 06:28 539136 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-MediaPlayer\MediaPlayer-DLMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 284672 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-MediaPlayer-DRM-DL\drmmgrtn.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 209408 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-IIS-DL\iismig.dll
    + 2009-09-19 15:53 . 2009-04-11 06:28 454144 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-IasServer-MigPlugin\IasMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 122880 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-DHCPServerMigPlugin-DL\DhcpSrvMigPlugin.dll
    + 2008-01-21 02:47 . 2008-01-21 02:47 150016 c:\windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-ADFS-DL\adfsmig.dll
    + 2011-06-21 00:06 . 2011-06-21 00:06 240288 c:\windows\SysWOW64\Macromed\Flash\FlashUtil10t_ActiveX.exe
    + 2011-06-21 00:06 . 2011-06-21 00:06 321184 c:\windows\SysWOW64\Macromed\Flash\FlashUtil10t_ActiveX.dll
    + 2011-07-12 17:41 . 2011-04-12 16:11 859648 c:\windows\SysWOW64\kernel32.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 716800 c:\windows\SysWOW64\jscript.dll
    - 2009-09-19 15:53 . 2009-04-11 06:28 327680 c:\windows\SysWOW64\IME\IMEJP10\IMJPAPI.DLL
    + 2011-09-16 01:20 . 2011-07-26 16:04 327680 c:\windows\SysWOW64\IME\IMEJP10\IMJPAPI.DLL
    + 2011-11-04 07:29 . 2011-11-04 07:29 150528 c:\windows\SysWOW64\iexpress.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 142848 c:\windows\SysWOW64\ieUnatt.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 176640 c:\windows\SysWOW64\ieui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 118784 c:\windows\SysWOW64\iepeers.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 353584 c:\windows\SysWOW64\iedkcs32.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 434176 c:\windows\SysWOW64\ieapfltr.dll
    - 2010-04-17 15:41 . 2009-03-08 11:32 163840 c:\windows\SysWOW64\ieakui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 163840 c:\windows\SysWOW64\ieakui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 227840 c:\windows\SysWOW64\ieaksie.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 130560 c:\windows\SysWOW64\ieakeng.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 110592 c:\windows\SysWOW64\IEAdvpack.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 223232 c:\windows\SysWOW64\dxtrans.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 353792 c:\windows\SysWOW64\dxtmsft.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 114176 c:\windows\SysWOW64\advpack.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 101888 c:\windows\SysWOW64\admparse.dll
    + 2011-08-10 14:50 . 2011-06-15 16:16 180736 c:\windows\system32\xmllite.dll
    + 2011-08-10 14:50 . 2011-06-17 16:16 451072 c:\windows\system32\winsrv.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 160256 c:\windows\system32\wextract.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 249344 c:\windows\system32\webcheck.dll
    + 2009-05-14 00:47 . 2011-11-09 02:44 327172 c:\windows\system32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2006-11-02 15:45 . 2011-11-08 23:20 102128 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2011-11-04 07:29 . 2011-11-04 07:29 603648 c:\windows\system32\vbscript.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 237056 c:\windows\system32\url.dll
    + 2011-10-15 13:58 . 2011-08-25 16:20 735744 c:\windows\system32\UIAutomationCore.dll
    + 2011-06-29 21:11 . 2011-04-29 16:15 344576 c:\windows\system32\schannel.dll
    + 2008-01-21 02:47 . 2007-09-18 00:05 216064 c:\windows\system32\recdisc.exe
    - 2009-09-19 15:52 . 2009-04-11 07:11 375808 c:\windows\system32\psisdecd.dll
    + 2011-10-15 13:58 . 2011-07-29 16:08 375808 c:\windows\system32\psisdecd.dll
    + 2006-11-02 12:46 . 2011-11-09 02:45 644118 c:\windows\system32\perfh009.dat
    + 2006-11-02 12:46 . 2011-11-09 02:45 117992 c:\windows\system32\perfc009.dat
    + 2011-10-15 13:58 . 2011-08-25 16:19 847360 c:\windows\system32\oleaut32.dll
    - 2011-06-16 11:10 . 2010-12-20 16:59 847360 c:\windows\system32\oleaut32.dll
    + 2011-10-15 13:58 . 2011-08-25 16:19 332288 c:\windows\system32\oleacc.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 149504 c:\windows\system32\occache.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 197120 c:\windows\system32\msrating.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 222208 c:\windows\system32\msls31.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 697344 c:\windows\system32\msfeeds.dll
    + 2010-04-17 23:29 . 2011-05-24 23:14 270720 c:\windows\system32\MpSigStub.exe
    - 2010-04-17 23:29 . 2011-02-02 22:11 270720 c:\windows\system32\MpSigStub.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 818176 c:\windows\system32\jscript.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 103936 c:\windows\system32\inseng.dll
    + 2011-09-16 01:20 . 2011-07-26 16:28 507904 c:\windows\system32\IME\IMEJP10\IMJPAPI.DLL
    - 2009-09-19 15:53 . 2009-04-11 07:11 507904 c:\windows\system32\IME\IMEJP10\IMJPAPI.DLL
    + 2011-11-04 07:29 . 2011-11-04 07:29 165888 c:\windows\system32\iexpress.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 173056 c:\windows\system32\ieUnatt.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 248320 c:\windows\system32\ieui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 111616 c:\windows\system32\iesysprep.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 145920 c:\windows\system32\iepeers.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 403248 c:\windows\system32\iedkcs32.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 534528 c:\windows\system32\ieapfltr.dll
    - 2010-04-17 15:41 . 2009-03-08 11:39 163840 c:\windows\system32\ieakui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 163840 c:\windows\system32\ieakui.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 267776 c:\windows\system32\ieaksie.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 160256 c:\windows\system32\ieakeng.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 135168 c:\windows\system32\IEAdvpack.dll
    - 2006-11-02 15:21 . 2011-06-16 23:17 305984 c:\windows\system32\FNTCACHE.DAT
    + 2006-11-02 15:21 . 2011-10-16 16:40 305984 c:\windows\system32\FNTCACHE.DAT
    + 2011-11-04 07:29 . 2011-11-04 07:29 282112 c:\windows\system32\dxtrans.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 452608 c:\windows\system32\dxtmsft.dll
    + 2009-09-19 15:53 . 2009-04-11 07:10 204288 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\fsquirt.exe
    + 2011-07-12 17:41 . 2011-04-21 14:17 695296 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\bthport.sys
    - 2011-06-16 11:10 . 2011-04-29 13:39 275456 c:\windows\system32\drivers\mrxsmb10.sys
    + 2011-08-10 14:50 . 2011-07-06 15:49 275456 c:\windows\system32\drivers\mrxsmb10.sys
    - 2010-04-17 15:54 . 2011-06-12 23:55 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2010-04-17 15:54 . 2011-11-05 19:22 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2011-11-04 07:29 . 2011-11-04 07:29 136192 c:\windows\system32\advpack.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 114176 c:\windows\system32\admparse.dll
    + 2011-02-14 03:14 . 2011-11-08 03:45 289040 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2011-04-06 20:48 . 2011-04-06 20:48 236880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Net.dll
    - 2011-04-13 02:16 . 2011-04-13 02:16 597832 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 597832 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll
    + 2011-04-06 21:45 . 2011-04-06 21:45 260448 c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
    + 2011-05-17 14:08 . 2011-05-17 14:08 578896 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
    - 2010-03-18 18:27 . 2010-03-18 18:27 578896 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
    + 2011-10-15 13:58 . 2011-07-08 11:52 485192 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 485192 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 916312 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpftxt_v0400.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 236880 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Net.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 517448 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
    - 2011-04-12 19:11 . 2011-04-12 19:11 517448 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 191840 c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
    + 2011-05-17 13:27 . 2011-05-17 13:27 413520 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 956240 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll
    - 2011-04-12 19:11 . 2011-04-12 19:11 385864 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
    + 2011-05-17 13:27 . 2011-05-17 13:27 385864 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
    - 2011-06-18 00:19 . 2011-03-29 10:53 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2011-10-15 13:58 . 2011-07-08 11:53 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2011-10-15 13:58 . 2011-07-08 11:53 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 607064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 149848 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2008-09-03 18:10 . 2011-09-16 10:41 888080


    Continued
  24. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    - 2008-09-03 18:10 . 2011-06-16 23:09 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    + 2010-03-18 17:16 . 2010-03-18 17:16 915800 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\wpftxt_x86.dll
    + 2010-09-21 03:07 . 2010-09-21 03:07 338856 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\readerupdater.exe
    + 2010-09-22 22:10 . 2010-09-22 22:10 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\nppdf32.dll
    + 2010-09-10 22:17 . 2010-09-10 22:17 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\JP2KLib.dll
    + 2010-09-23 00:41 . 2010-09-23 00:41 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\AdobeCollabSync.exe
    + 2010-09-21 03:07 . 2010-09-21 03:07 932288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\adobearm.exe
    + 2010-09-23 08:47 . 2010-09-23 08:47 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\AcroRd32.exe
    + 2010-09-22 22:04 . 2010-09-22 22:04 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\AcroPDF.dll
    + 2010-09-22 23:39 . 2010-09-22 23:39 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\acrobroker.exe
    + 2010-09-21 03:07 . 2010-09-21 03:07 338856 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\acrobatupdater.exe
    + 2010-09-22 22:50 . 2010-09-22 22:50 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\a3dutility.exe
    + 2011-01-14 11:10 . 2011-01-14 11:10 155520 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKWORD6.DLL
    + 2011-01-14 11:10 . 2011-01-14 11:10 140160 c:\windows\Installer\$PatchCache$\Managed\00004109500200000000000000F01FEC\14.0.5130\GKEXCEL2.DLL
    - 2006-11-02 12:40 . 2011-06-16 23:42 143360 c:\windows\inf\infstrng.dat
    + 2006-11-02 12:40 . 2011-07-15 02:07 143360 c:\windows\inf\infstrng.dat
    - 2006-11-02 12:40 . 2010-04-19 02:40 665600 c:\windows\inf\drvindex.dat
    + 2006-11-02 12:40 . 2011-07-15 02:07 665600 c:\windows\inf\drvindex.dat
    + 2011-10-16 15:53 . 2011-10-16 15:53 336896 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\7bd6a3a7ccecff64ae970ef25b5fedb0\WindowsFormsIntegration.ni.dll
    + 2011-10-16 15:44 . 2011-10-16 15:44 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\a5daacd5d0f46d77f10814f975152b34\UIAutomationTypes.ni.dll
    + 2011-10-16 15:44 . 2011-10-16 15:44 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\86dd26195072a7ba1241c316a90d76c0\UIAutomationProvider.ni.dll
    + 2011-10-16 15:52 . 2011-10-16 15:52 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\9b9b20440b1acb0bcbbb2f66aa421f0e\UIAutomationClient.ni.dll
    + 2011-10-16 15:42 . 2011-10-16 15:42 528896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\d26a80d8e9ee010d3d1bc8c8c19f2d4d\System.Xml.Linq.ni.dll
    + 2011-10-16 15:44 . 2011-10-16 15:44 256000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\2f4927e3f120092b6d65371d502d6e73\System.Windows.Input.Manipulations.ni.dll
    + 2011-10-16 15:43 . 2011-10-16 15:43 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\578f67c81f61729a88f5de3b46f73c29\System.Transactions.ni.dll
    + 2011-10-16 15:52 . 2011-10-16 15:52 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\127b422c3177e9f042ee3390dc53abff\System.ServiceProcess.ni.dll
    + 2011-10-16 15:51 . 2011-10-16 15:51 108032 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\b93d584ea973a95d5e2632445fe47d30\System.ServiceModel.Channels.ni.dll
    + 2011-10-16 15:52 . 2011-10-16 15:52 517120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\acd98781c9317af9edaf3da46ce1befc\System.ServiceModel.Routing.ni.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 946688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\b94e86c584564773de3fe2b4b3b8ecbb\System.Security.ni.dll
    + 2011-10-16 15:43 . 2011-10-16 15:43 376832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\6cd778cd2c8c61130ff71ee7a685222b\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-10-16 15:43 . 2011-10-16 15:43 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\8eaff8b779c73cbd317c1431a51ed5fa\System.Runtime.Remoting.ni.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\55ac95edd96a5e6b675bb9b42d460b0b\System.Numerics.ni.dll
    + 2011-10-16 15:50 . 2011-10-16 15:50 933376 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\5d1aa20dae99fcc9bd68410eb81eb9c0\System.Net.ni.dll
    + 2011-10-16 15:50 . 2011-10-16 15:50 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\75f4107c91447218fac9cc052c77d89d\System.Messaging.ni.dll
    + 2011-10-16 15:49 . 2011-10-16 15:49 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\1e191470099054203157049f808f6629\System.Management.Instrumentation.ni.dll
    + 2011-10-16 15:49 . 2011-10-16 15:49 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\e5f5a73a8fb1040b1f30a14a2adf9d5d\System.IO.Log.ni.dll
    + 2011-10-16 15:49 . 2011-10-16 15:49 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\d23c19bfe0f8a508f143c5bf5d0d732f\System.IdentityModel.Selectors.ni.dll
    + 2011-10-16 15:43 . 2011-10-16 15:43 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\5a86b6067f001cef079bde90f001d54d\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 512000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\86913afe1c8f5138c9ba36fdf6603bf8\System.Dynamic.ni.dll
    + 2011-10-16 15:49 . 2011-10-16 15:49 632832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\cc9c9cebee876445d2b6439b15ffef94\System.DirectoryServices.Protocols.ni.dll
    + 2011-10-16 15:49 . 2011-10-16 15:49 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\8465ce07d4753d5891458d09ee0b1fe7\System.Device.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\bc62508161a5a687274ef5cb39a09da3\System.Data.DataSetExtensions.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c9db420a1795c4347f93f2f089a8b49f\System.Configuration.Install.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\deff07dc250a4de404090ed98736b690\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 865792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\89a509497e04317189aa568e44d7a1e5\System.AddIn.ni.dll
    + 2011-10-16 15:46 . 2011-10-16 15:46 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\04abc0f1feffd7a15c4815c15738324b\System.Activities.DurableInstancing.ni.dll
    + 2011-10-16 15:29 . 2011-10-16 15:29 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\bf456f7f6470250f58b92158aefdc008\SMSvcHost.ni.exe
    + 2011-10-16 15:43 . 2011-10-16 15:43 185344 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\2d3c35ffc646287827a79c31eb91c21d\SMDiagnostics.ni.dll
    + 2011-10-16 15:42 . 2011-10-16 15:42 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\bafbbd94a2c60bdf546669699b05a7fe\PresentationFramework.Classic.ni.dll
    + 2011-10-16 15:42 . 2011-10-16 15:42 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a60a1e1a47525ec0b227d3d612d65c60\PresentationFramework.Royale.ni.dll
    + 2011-10-16 15:42 . 2011-10-16 15:42 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\900cacd34dc5bd770289d04b0b6face1\PresentationFramework.Aero.ni.dll
    + 2011-10-16 15:42 . 2011-10-16 15:42 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\39a8890967e22ae6bd24a2ebf7ee694e\PresentationFramework.Luna.ni.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 422400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\19221010dfff8328105a4706e4a31f7a\Microsoft.VisualBasic.Compatibility.Data.ni.dll
    + 2011-10-16 15:38 . 2011-10-16 15:38 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\694c3f74f790e2c327f114dfbe4983c2\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-16 15:29 . 2011-10-16 15:29 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\39973e3573bd27e6897e631ac1570c85\CustomMarshalers.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\962b04386ebf18f5871d5ceefa83ba4b\WindowsFormsIntegration.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\5b96ee4992d9559ba5483c769bc5c889\UIAutomationTypes.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\1c29539a07226b411e0a1a47aed57183\UIAutomationClient.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 393216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\bd729791a7504ef9ecb4ad6ebfd94935\System.Xml.Linq.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 189440 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\dcad72e49476386b76a81d2df187c32c\System.Windows.Input.Manipulations.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 649728 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\caf1d94cb89859c72d6c8cd8774068d3\System.Transactions.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\aab1c287bc73a03c51b55fb3f102c27e\System.ServiceProcess.ni.dll
    + 2011-10-16 16:02 . 2011-10-16 16:02 369664
    c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\bd104bb2f798661c5a972249582b5441\System.ServiceModel.Routing.ni.dll
    + 2011-10-16 13:46 . 2011-10-16 13:46 736768 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\aecd169d75edbcbe626d2a222a02e9f3\System.Security.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\bed774dde4b62ed1d2d55c2d1769d600\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 762880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\44d18693baaee5ee0e6f6fd4910e8f81\System.Runtime.Remoting.ni.dll
    + 2011-10-16 13:44 . 2011-10-16 13:44 145408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\97126244f88693adb36f94116d8d0dda\System.Numerics.ni.dll
    + 2011-10-16 16:01 . 2011-10-16 16:01 657408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\56fe9070b1d56613fd5cf7c73ec3b26f\System.Net.ni.dll
    + 2011-10-16 16:01 . 2011-10-16 16:01 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\420c9d9b271bc26d1b6f437f1f4913a9\System.Messaging.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\b71ea67c5bfa5b660efc12eb1c6ea4af\System.Management.Instrumentation.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\267d7dbdbe126590fba4a11c1ab12926\System.IO.Log.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 229888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\4ca1f130cbacf72beedf13da42b93e75\System.IdentityModel.Selectors.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\fd4f85af43b2c177c8d085a8ba3f4993\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 787456 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\fd4f85af43b2c177c8d085a8ba3f4993\System.EnterpriseServices.ni.dll
    + 2011-10-16 13:46 . 2011-10-16 13:46 377856 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\b806ef4a19c8157e7858e0a15f9cf48d\System.Dynamic.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 470528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\4178d8536c67896ab77af36a48ee7ec4\System.DirectoryServices.Protocols.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\324617c0a492d6acc64325c836553f2c\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-10-16 16:00 . 2011-10-16 16:00 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\ca25f888c067fa170d8bba824efa2ca8\System.Device.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\282487a15f595c199b6cc640ea8995e8\System.Data.DataSetExtensions.ni.dll
    + 2011-10-16 13:46 . 2011-10-16 13:46 982528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\4844dd28e0611d1ebd1e449fe822c2a5\System.Configuration.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\06f71e66b9913a24c22f85a0caef3ae4\System.Configuration.Install.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\fa608e0882b98981cb6fd6e0754bdff8\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-16 13:45 . 2011-10-16 13:45 693760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\a91d48ec926171da7de01cf2a10b1dfc\System.ComponentModel.Composition.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 617984 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\f407937d4694c46537c470007a1df957\System.AddIn.ni.dll
    + 2011-10-16 15:57 . 2011-10-16 15:57 411136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\80347a66af30b5c14c0114baee4c64f8\System.Activities.DurableInstancing.ni.dll
    + 2011-10-16 15:55 . 2011-10-16 15:55 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\fcbb4a33ebdc8562603bc7f725a088ce\SMSvcHost.ni.exe
    + 2011-10-16 15:56 . 2011-10-16 15:56 143360 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\398a52caf1e9fd1a6ea9dd589b0f6e68\SMDiagnostics.ni.dll
    + 2011-10-16 13:45 . 2011-10-16 13:45 387072 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d2d4bdbd9e2196e04dcdd68994a1f952\PresentationFramework.Royale.ni.dll
    + 2011-10-16 13:45 . 2011-10-16 13:45 595968 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\9211f2faac02f0082b201a95731736c4\PresentationFramework.Aero.ni.dll
    + 2011-10-16 13:45 . 2011-10-16 13:45 755712 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\6e48fb2ce01b4758a68f61651d6461d8\PresentationFramework.Luna.ni.dll
    + 2011-10-16 13:45 . 2011-10-16 13:45 309760 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\351819dc653a07a310cf1387b3266936\PresentationFramework.Classic.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\99cd15931eb2db4711057dce2af7d93a\Microsoft.VisualBasic.Compatibility.Data.ni.dll
    + 2011-10-16 15:56 . 2011-10-16 15:56 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\f4ab32c177d931f26072a14c27efc3b5\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-16 15:55 . 2011-10-16 15:55 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\48ad8351ab66166c853d410d3282a408\CustomMarshalers.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\d3b8ba89ad6b7e3dd72e903eba259c9a\WsatConfig.ni.exe
    + 2011-09-26 01:11 . 2011-09-26 01:11 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\5f6a5d0fd18e43b62272d501e4cecc4b\WsatConfig.ni.exe
    + 2011-09-26 01:11 . 2011-09-26 01:11 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\f055886146673a35518ee749c53f0417\WindowsFormsIntegration.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\ea6d8df86fc35898ec0ed1931286079d\WindowsFormsIntegration.ni.dll
    + 2011-10-16 17:08 . 2011-10-16 17:08 257024 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\fcc1bb8b7816577d8ace229d8b10efc1\UIAutomationTypes.ni.dll
    - 2011-06-18 15:37 . 2011-06-18 15:37 257024 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\4587969f21341220dc17747f280477b2\UIAutomationTypes.ni.dll
    + 2011-09-26 01:04 . 2011-09-26 01:04 257024 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\4587969f21341220dc17747f280477b2\UIAutomationTypes.ni.dll
    + 2011-09-26 01:04 . 2011-09-26 01:04 120320 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\ff10a07c2b72a66edbe6f45f91d17769\UIAutomationProvider.ni.dll
    - 2011-06-18 15:37 . 2011-06-18 15:37 120320 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\ff10a07c2b72a66edbe6f45f91d17769\UIAutomationProvider.ni.dll
    + 2011-10-16 17:08 . 2011-10-16 17:08 120320 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\caf208f16abe2d305effc78e1f81e9b5\UIAutomationProvider.ni.dll
    + 2011-10-16 17:08 . 2011-10-16 17:08 648704 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\ff7ff4d1cef4eb69de7a031b48398987\UIAutomationClient.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 648704 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\9ec639af32b36d056d5044de48a51fbf\UIAutomationClient.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 290304 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\a386c1261e6fa238c30d1ac51f56ef5b\TaskScheduler.ni.dll
    + 2011-09-26 01:11 . 2011-09-26 01:11 290304 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\0ee32f3917dd39d4a7f4e52314b9157e\TaskScheduler.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\e961e5d1c86bf0c2b52249c3eb1d476c\System.Xml.Linq.ni.dll
    + 2011-09-26 01:11 . 2011-09-26 01:11 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\483ebadfe1f658e95b87a934cdd6cf8e\System.Xml.Linq.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\d9d826b4fd018549cd3a168f1f6d5b2a\System.Web.Routing.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\484c3ca1119870f02609a03d3a94be43\System.Web.Routing.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\f2602c5bcb6c2065db8329f1f7f32ae1\System.Web.RegularExpressions.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\b7e323c4caccb48a6c7cd45c5c8b16f7\System.Web.RegularExpressions.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 449536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\ee1384ab27cb5fc1885d21a390aa8ea8\System.Web.Entity.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 449536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\514928967cafc8e4a7671f68ce4eb43a\System.Web.Entity.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\b27836d6560a49750d21920693d19627\System.Web.Entity.Design.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\6614eb0a91d0de4f50300769e4f2b562\System.Web.Entity.Design.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 754176 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\e5ebefe6b81d9c789c8749521676f29a\System.Web.DynamicData.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 754176 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\d7e9403b32a63c9e61ac7ba90c37b757\System.Web.DynamicData.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\22e583697dbb5510101fab4aa5d18254\System.Web.Abstractions.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\0788917377526dad632f69a0c29a17f2\System.Web.Abstractions.ni.dll
    + 2011-09-21 02:20 . 2011-09-21 02:20 921088 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b433e4de6804ce087c2c5827efc8feff\System.Transactions.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 921088 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\26713be7f0119f1ccd5cb301b4088616\System.Transactions.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\fd5a2f4321cd339b0d7dfcd46aac578c\System.ServiceProcess.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\fb509de55bc82e23c862dcd0a8823eb8\System.ServiceProcess.ni.dll
    + 2011-09-21 02:19 . 2011-09-21 02:19 929280 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\9191aa60b79eda0c7df35784e1986195\System.Security.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 929280 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\6ec0affc7f8a6ef94bb7457353bed773\System.Security.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\d526d3a3a6657c8cd4508ebe888d50ad\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\0d1187c395060f06d84e4c398e7729e2\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-10-16 17:12 . 2011-10-16 17:12 911872 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\691b5229cb26bbb7fdb9ae20c289ad7f\System.Net.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 911872 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\2505633b5679bba3e3da53db79616c62\System.Net.ni.dll
    + 2011-10-16 17:02 . 2011-10-16 17:02 782848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\43950691e68fa889d8276281c843c90a\System.Messaging.ni.dll
    + 2011-09-21 02:25 . 2011-09-21 02:25 782848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\32d484a0a6db3c92f0e593a958dc265a\System.Messaging.ni.dll
    + 2011-10-16 17:12 . 2011-10-16 17:12 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\bb552a747610ce1e38ca20f767a905b3\System.Management.Instrumentation.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\a445650911635ffcedceaa5759e96c83\System.Management.Instrumentation.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 568832 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\b4d997aeba03b77e5d09f9eabd3e7ffb\System.IO.Log.ni.dll
    + 2011-10-16 17:12 . 2011-10-16 17:12 568832 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\1b7cfed2b4bac8be0d75b2e5840e1648\System.IO.Log.ni.dll
    + 2011-09-21 02:25 . 2011-09-21 02:25 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\e327689326341f4d7656ff743c939838\System.IdentityModel.Selectors.ni.dll
    + 2011-10-16 17:02 . 2011-10-16 17:02 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\b936404b70f3d96230370185221d2988\System.IdentityModel.Selectors.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\caab7166e3bd29ad25ddab20072bfa47\System.EnterpriseServices.Wrapper.dll
    + 2011-09-21 02:20 . 2011-09-21 02:20 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\60d0a368a83327d788a62b762a670cce\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 16:50 . 2011-10-16 16:50 289280 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\23ae39416a886e06e99e5f1a362a0ca2\System.Drawing.Design.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 289280 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\1049a906d8aeb09b7cf608ed4670b48a\System.Drawing.Design.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 650240 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d3b45c9a426e4247060210a4442e57c1\System.DirectoryServices.Protocols.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 650240 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\495ff50306c8f7ca33e6407b4660ade5\System.DirectoryServices.Protocols.ni.dll
    + 2011-09-26 01:08 . 2011-09-26 01:08 489472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\b68168596944761a8a1613929f26ecd8\System.Data.Services.Design.ni.dll
    + 2011-10-16 17:12 . 2011-10-16 17:12 489472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\8ae8c8c594d7ad7f6430b65d72d0cb58\System.Data.Services.Design.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\5e7784d0562f54ba2bac4fab3f3c7da6\System.Data.DataSetExtensions.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\376e4579a8a9a6075b329e4414db7e30\System.Data.DataSetExtensions.ni.dll
    + 2011-10-16 17:00 . 2011-10-16 17:00 191488 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\a00d13945ba2ae72e0f81a330405ef94\System.Configuration.Install.ni.dll
    + 2011-09-21 02:23 . 2011-09-21 02:23 191488 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\41852b2f76b9a3883be55cd39268339b\System.Configuration.Install.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\e0828964993d832dabb31b17c6d82a02\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\3684f5079f82b87759efed87ecb52c11\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 889856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\892fa605806b4152e60a5b80d01d646a\System.AddIn.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 889856 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\4e4ecc6b61f0e2a39ddfdae3ada992b0\System.AddIn.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\fab800c985d2637100bb4a74ee70c5c1\System.AddIn.Contract.ni.dll
    - 2011-06-18 15:39 . 2011-06-18 15:39 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\eebfb193348c4ee09fde0f55897153ef\System.AddIn.Contract.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\eebfb193348c4ee09fde0f55897153ef\System.AddIn.Contract.ni.dll
    + 2011-09-26 01:09 . 2011-09-26 01:09 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\88aeb9f3b7d6a8124f470a41a904d42a\sysglobl.ni.dll
    - 2011-06-18 15:42 . 2011-06-18 15:42 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\88aeb9f3b7d6a8124f470a41a904d42a\sysglobl.ni.dll
    + 2011-10-16 17:13 . 2011-10-16 17:13 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\091348740bb38b85dece99d1deb33d06\sysglobl.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\e50076b441b0a3744dfb857e8c10c7a3\SMSvcHost.ni.exe
    + 2011-09-26 01:06 . 2011-09-26 01:06 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\c2ae3ebf99c837d022aaafafc6cd04fd\SMSvcHost.ni.exe
    + 2011-10-16 17:02 . 2011-10-16 17:02 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\fa7982dd82101344f9a0ec5a7df12d13\SMDiagnostics.ni.dll
    + 2011-09-21 02:25 . 2011-09-21 02:25 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\37cadb80dab6954ac815ad5530032508\SMDiagnostics.ni.dll
    + 2011-10-16 17:10 . 2011-10-16 17:10 438784 c:\windows\assembly\NativeImages_v2.0.50727_64\ServiceModelReg\6048f8ab1d025e6654e291bf4f1d630d\ServiceModelReg.ni.exe
    + 2011-09-26 01:06 . 2011-09-26 01:06 438784 c:\windows\assembly\NativeImages_v2.0.50727_64\ServiceModelReg\383e793a6af09df130b14f96138aaa54\ServiceModelReg.ni.exe
    + 2011-09-26 01:06 . 2011-09-26 01:06 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\c2b971104c296416bb15eb458ec5f7c9\PresentationFramework.Aero.ni.dll
    + 2011-10-16 16:47 . 2011-10-16 16:47 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\b1a7be598a0c377152ef1f42e7c1eac3\PresentationFramework.Royale.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 279040 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\a9367ed6263e99440976427a650a86bc\PresentationFramework.Classic.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\a46418abae39bda36af970a351a8cd23\PresentationFramework.Luna.ni.dll
    + 2011-10-16 16:47 . 2011-10-16 16:47 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\939a859ef807fb6511db2a22ede35d29\PresentationFramework.Luna.ni.dll
    + 2011-10-16 16:47 . 2011-10-16 16:47 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\574c8f267bed7da9a80d9f3a428099bd\PresentationFramework.Aero.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\5571660610f416a16f101e9dc615328d\PresentationFramework.Royale.ni.dll
    + 2011-10-16 16:47 . 2011-10-16 16:47 279040 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\3f65d45a3ff81a26fc82e5c6fcc10370\PresentationFramework.Classic.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 852992 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\64af7da17fc9439d2c8f23d34feb260b\napsnap.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 852992 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\155c6b2c094e804bc48f3c697c8b5875\napsnap.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 154112 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\8ba28cd475eddd59aa72048078b9d38d\napinit.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 154112 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\336c6eca608a2bd0f07760aa73fc1dca\napinit.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 177152 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\e1b9bb0c83dd8cac30d87fdfd7166756\naphlpr.ni.dll
    - 2011-06-18 15:39 . 2011-06-18 15:39 177152 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\e1b9bb0c83dd8cac30d87fdfd7166756\naphlpr.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 177152 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\c1aca362549bc87db4cd9b39e915fc34\naphlpr.ni.dll
    + 2011-09-26 01:06 . 2011-09-26 01:06 126464 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\fa472bf1f8f24c6ed281ed4dcd9d6571\napcrypt.ni.dll
    - 2011-06-18 15:39 . 2011-06-18 15:39 126464 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\fa472bf1f8f24c6ed281ed4dcd9d6571\napcrypt.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 126464 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\db12e1be90224e573376cc86b197d869\napcrypt.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\eb2563ff14d1cea338648ac1feeafc1f\MSBuild.ni.exe
    + 2011-09-21 02:19 . 2011-09-21 02:19 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\3fed3dfbbe1d477a86b5c5685e98bee1\MSBuild.ni.exe
    + 2011-10-16 17:05 . 2011-10-16 17:05 414720 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\f5e34def2ddaf9fbab2225e5a302d33f\MMCFxCommon.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 414720 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\407d27837b8ecea3b66bdbd280586e5d\MMCFxCommon.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 657920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\a340bab4c167d4ed8abeee6ce5685772\Microsoft.WSMan.Management.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 657920 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\94f66b0665ea9b4b709b570e7c814fed\Microsoft.WSMan.Management.ni.dll
    + 2011-09-25 14:43 . 2011-09-25 14:43 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\8378df092aebbb9e875f3daeb073b345\Microsoft.Vsa.ni.dll
    + 2011-10-16 17:07 . 2011-10-16 17:07 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\0e11d1b7322a3ccdcf4f62122608d657\Microsoft.Vsa.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\fed874427d329b3843becb214c2cbb24\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\39be58c468f0bf887a7548a6388cf419\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-16 17:06 . 2011-10-16 17:06 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\ec5a27a580cc2bf11095f4734768280c\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2011-09-22 01:48 . 2011-09-22 01:48 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\df75eeffbe8172f901c0f995f9d86205\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 224768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\d1d9afd53ef03252bb4407613ab11a1d\Microsoft.PowerShell.Security.ni.dll
    + 2011-10-16 17:09 . 2011-10-16 17:09 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\bf181ea99e6aa101d6d6fcb21fb851ed\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b0be0bdc2b41922fc436aaf40fbcc943\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2011-10-16 17:07 . 2011-10-16 17:07 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\a097fc0285187f39c11115f78eef26af\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2011-09-26 01:05 . 2011-09-26 01:05 224768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\626377739fe928133c5759b150ff933b\Microsoft.PowerShell.Security.ni.dll
    + 2011-09-25 14:44 . 2011-09-25 14:44 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\201551dfa891ef2533b4f6961f158b53\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 324608 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e4b446852f196438818c0ce9e68605e8\Microsoft.MediaCenter.Shell.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 933376 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c981dc80ad13bec94aa54b8fb28b9b86\Microsoft.MediaCenter.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 946688 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\9cd63300be3a34c0f37e141403dd4d02\Microsoft.MediaCenter.Sports.ni.dll
    + 2011-09-22 01:46 . 2011-09-22 01:46 324608 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\848c9da3e69048629734e47234788a7d\Microsoft.MediaCenter.Shell.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 933376 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\643b81852e3d9761f609db2d2d149e6f\Microsoft.MediaCenter.ni.dll
    + 2011-09-22 01:46 . 2011-09-22 01:46 946688 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\3009e8d27d0662799fcde4a99cfaa62c\Microsoft.MediaCenter.Sports.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 794624 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\7bccb8455ab63acd2fd36dbb6348b77a\Microsoft.ManagementConsole.ni.dll
    + 2011-10-16 17:05 . 2011-10-16 17:05 794624 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\3de8add426da03a3b88c5a35d9d60855\Microsoft.ManagementConsole.ni.dll
    + 2011-09-22 01:48 . 2011-09-22 01:48 228864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\f62d326919623ec6e0ab3f835aedb3f5\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-10-16 17:06 . 2011-10-16 17:06 228864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\b23eceb3a5e8db89f107bdc02ab6cda9\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-09-22 01:48 . 2011-09-22 01:48 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\9f583d5c7de9d6469697e822dbabe645\Microsoft.Build.Utilities.ni.dll
    + 2011-10-16 17:06 . 2011-10-16 17:06 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\1a43bbc417d8f56c5fd3d828bdca0c75\Microsoft.Build.Utilities.ni.dll
    + 2011-10-16 17:06 . 2011-10-16 17:06 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\96c6b81949f7e09457d21c1591996471\Microsoft.Build.Framework.ni.dll
    - 2011-06-18 15:28 . 2011-06-18 15:28 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\5cca853a01d7873f5d763de8677b8482\Microsoft.Build.Framework.ni.dll
    + 2011-09-21 02:19 . 2011-09-21 02:19 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\5cca853a01d7873f5d763de8677b8482\Microsoft.Build.Framework.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\592acc376f9c89d56f0c781289b42805\Microsoft.Build.Framework.ni.dll
    - 2011-06-18 15:35 . 2011-06-18 15:35 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\14790d6818b2c3722b3877caf007a418\Microsoft.Build.Framework.ni.dll
    + 2011-09-22 01:48 . 2011-09-22 01:48 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\14790d6818b2c3722b3877caf007a418\Microsoft.Build.Framework.ni.dll
    + 2011-10-16 17:05 . 2011-10-16 17:05 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\d4aed105d188ae1bfd6ed294f7c0eef6\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\a65a7ff52cef80cd25d5f7a08be30bde\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-10-16 17:05 . 2011-10-16 17:05 372224 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\8724bb8184276f3d4fe41218ebf5f91a\Mcx2Dvcs.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 372224 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\656fee71cea5bce92f762df631ecebeb\Mcx2Dvcs.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 372224 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\46247732b2fdb4edb0f30f8c25dd14a4\mcupdate.ni.exe
    + 2011-10-16 17:05 . 2011-10-16 17:05 372224 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\1c4decc241e2a8c8ee713733948d8086\mcupdate.ni.exe
    + 2011-09-22 01:46 . 2011-09-22 01:46 337920 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\933b32ca7ef1bab5c3c846d1e8498b52\mcstoredb.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 337920 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\29eb48280c132b50756e460f2d5b9811\mcstoredb.ni.dll
    + 2011-09-22 01:46 . 2011-09-22 01:46 893952 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\f542b6731c25678aa81fafe1e59292e4\mcstore.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 893952 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\2a18d543282212deac79ff3c4f47ec43\mcstore.ni.dll
    + 2011-09-22 01:47 . 2011-09-22 01:47 108032 c:\windows\assembly\NativeImages_v2.0.50727_64\loadmxf\a4a6d5566946a8bf38b3b17446cf1f58\loadmxf.ni.exe
    + 2011-10-16 17:05 . 2011-10-16 17:05 108032 c:\windows\assembly\NativeImages_v2.0.50727_64\loadmxf\23bb4c93c638296182a538f3461c455b\loadmxf.ni.exe
    + 2011-09-22 01:47 . 2011-09-22 01:47 645120 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\a85ee567ab2608b4a0e926600b56b0ab\EventViewer.ni.dll
    + 2011-10-16 17:05 . 2011-10-16 17:05 645120 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\1fbfd420e2a2d97c24c80ac7cc8392c6\EventViewer.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\eacfe9b74df294dc175cb2c85aece537\ehiWUapi.ni.dll
    + 2011-09-22 01:46 . 2011-09-22 01:46 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\2fcc1a9e9d1562a68bc676f4a9821f38\ehiWUapi.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\2fcc1a9e9d1562a68bc676f4a9821f38\ehiWUapi.ni.dll
    + 2011-10-16 17:04 . 2011-10-16 17:04 927232 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\29283480f471139af1c4a6fd3b59b205\ehiwmp.ni.dll

    Continued...
  25. KenBrown2

    KenBrown2 Newcomer, in training Topic Starter Posts: 59

    + 2011-09-22 01:46 . 2011-09-22 01:46 927232 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\14701ef3387cf0a95c98bb1e4ceae0da\ehiwmp.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 927232 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\14701ef3387cf0a95c98bb1e4ceae0da\ehiwmp.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 138752 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\16440d92821e195feb65203904210d75\ehiUserXp.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 138752 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\00922b3ff2116a38b97469cc4b405573\ehiUserXp.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 138752 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\00922b3ff2116a38b97469cc4b405573\ehiUserXp.ni.dll
    + 2011-09-22 01:46 . 2011-09-22 01:46 151040 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiReplay\ec0aa4c11ed3aefcae02eb38f86231cd\ehiReplay.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 151040 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiReplay\ec0aa4c11ed3aefcae02eb38f86231cd\ehiReplay.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 151040 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiReplay\2e9bb1ae3de00a2678978386f6f73de9\ehiReplay.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\aecbd2f45aa74ee3f57dc277e9d8343f\ehiExtens.ni.dll
    - 2011-06-18 15:33 . 2011-06-18 15:33 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\aecbd2f45aa74ee3f57dc277e9d8343f\ehiExtens.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\638557ed53ca8211c123007bdc3dc548\ehiExtens.ni.dll
    + 2011-09-22 01:45 . 2011-09-22 01:45 368640 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\7f3e720ebf0164673c94202b8e51c119\ehExtHost.ni.exe
    + 2011-10-16 17:03 . 2011-10-16 17:03 368640 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\0bc1a19c1cb03723ef685b5917e74903\ehExtHost.ni.exe
    + 2011-09-22 01:45 . 2011-09-22 01:45 409600 c:\windows\assembly\NativeImages_v2.0.50727_64\ehepgdat\d9c6f79562e7618065e4e22446500a02\ehepgdat.ni.dll
    + 2011-10-16 17:03 . 2011-10-16 17:03 409600 c:\windows\assembly\NativeImages_v2.0.50727_64\ehepgdat\9fba8fc4c06bfe3d9a87d2035fa7b156\ehepgdat.ni.dll
    + 2011-10-16 17:02 . 2011-10-16 17:02 311296 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\5d69d006137ed7704b7b7aa2d54f296e\ehCIR.ni.dll
    + 2011-09-21 03:37 . 2011-09-21 03:37 311296 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\3261cad9c1981ebf952370ebb267f46f\ehCIR.ni.dll
    - 2011-06-18 15:32 . 2011-06-18 15:32 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\44e83cf4ba00700dec4e6d9364daa7b1\CustomMarshalers.ni.dll
    + 2011-09-21 03:37 . 2011-09-21 03:37 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\44e83cf4ba00700dec4e6d9364daa7b1\CustomMarshalers.ni.dll
    + 2011-10-16 17:02 . 2011-10-16 17:02 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\3af5fbffd80931f39a49cb1dc5737e5e\CustomMarshalers.ni.dll
    + 2011-09-21 02:20 . 2011-09-21 02:20 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\c392ae5019176660dd3e81503ede7bb4\ComSvcConfig.ni.exe
    + 2011-10-16 16:58 . 2011-10-16 16:58 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\3f5faea5c8517449702312f28aa6a7bb\ComSvcConfig.ni.exe
    + 2011-09-21 02:19 . 2011-09-21 02:19 568320 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\b8a793412f4ae385b0e6bc97f2afc1ff\BDATunePIA.ni.dll
    + 2011-10-16 16:58 . 2011-10-16 16:58 568320 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\1049e555d490785eeb1e572a8c2c2637\BDATunePIA.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\ba7aa58f0f726349207df53769dff760\XPBurnComponent.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\2b12278a0d6a52787de80bf6263b53f3\XPBurnComponent.ni.dll
    + 2011-10-16 17:23 . 2011-10-16 17:23 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\9857dc9eb534d32e93a93d5064bcd182\WsatConfig.ni.exe
    + 2011-09-26 00:55 . 2011-09-26 00:55 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4393f39e7dcd910521a93a5a588fa1c5\WsatConfig.ni.exe
    + 2011-09-26 00:55 . 2011-09-26 00:55 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\64e6bc21d6554252e53e87c04a70a04d\WindowsFormsIntegration.ni.dll
    + 2011-10-16 17:23 . 2011-10-16 17:23 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\22e853d2fe1435baa459685dee7ce7b7\WindowsFormsIntegration.ni.dll
    - 2011-06-18 15:15 . 2011-06-18 15:15 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\96031e87be161842765531e37a996df6\UIAutomationTypes.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\96031e87be161842765531e37a996df6\UIAutomationTypes.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\8056d047225d4a9c2e4c6b096563d93d\UIAutomationTypes.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ec050b2f1ddc5f3023e9bc7375f90a1d\UIAutomationClient.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3f30a98854189ad67ff97a1ed4e53917\UIAutomationClient.ni.dll
    + 2011-09-26 00:55 . 2011-09-26 00:55 235520 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\8db6e879e71858d2995390526368262e\TaskScheduler.ni.dll
    + 2011-10-16 17:23 . 2011-10-16 17:23 235520 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\5debac527eb5d431bbc033e36c80826a\TaskScheduler.ni.dll
    + 2011-09-26 00:55 . 2011-09-26 00:55 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\d3e1b40454b27a1f8d6a32654b7e57db\System.Xml.Linq.ni.dll
    + 2011-10-16 17:23 . 2011-10-16 17:23 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\2bd29c61fe6cc3ef769932a89a865acf\System.Xml.Linq.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\f62903d939777c65873c6f5760c8143a\System.Web.Routing.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\ebe085fa59b43b6c179dcf159348a2c4\System.Web.Routing.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\9a2b4bc9b326f62233a76100535ce039\System.Web.RegularExpressions.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\3ea90d05680ed6259ccb21f12cce70fb\System.Web.RegularExpressions.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\670c9d1c106d5707db388246a03455ab\System.Web.Extensions.Design.ni.dll
    + 2011-09-26 00:45 . 2011-09-26 00:45 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\1abc99e2fa94ca63c9b44ebcb074b031\System.Web.Extensions.Design.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\464aac8b3b4a36ee4a850f7c2e4366f5\System.Web.Entity.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\2f8678a10880144ac78440ab4e6a97d4\System.Web.Entity.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\855b737109e459f307c741bde4ffdc7f\System.Web.Entity.Design.ni.dll
    + 2011-09-26 00:45 . 2011-09-26 00:45 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\7727fb0db7028e636f30f7ff9f908113\System.Web.Entity.Design.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\eb60d9a30d018828f5dbe7f39e047030\System.Web.DynamicData.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\73a65d633f6e7795bfc4362b4e15d4c9\System.Web.DynamicData.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\6932e2b0f41ee5cf6059633712b25fe7\System.Web.Abstractions.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\12da8d5708a0cf1c5c5ae02d1394880a\System.Web.Abstractions.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8f3b3ab45e3e5fa61aa6cbfe2a8b61af\System.Transactions.ni.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\5e58f10757c91da0ac05161ca8e11e8b\System.Transactions.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\1cc11918d8dd561391bba05c61de7573\System.ServiceProcess.ni.dll
    + 2011-09-22 00:05 . 2011-09-22 00:05 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\ccd064df52eb5479bf745ec2a7b74952\System.Security.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\cbfa4bf002c1abaf94ba8634139727eb\System.Security.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f97b31da89858b85c70b4eb45bc91ace\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-09-22 00:06 . 2011-09-22 00:06 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\4a62d68943088191659432dbe33669f2\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a6d889aa69fd51c100352f23c7cebd22\System.Runtime.Remoting.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\87ea73f8c8843eb7b022af4152bd21be\System.Net.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\7754d47296d9201c1856c41637b8a911\System.Net.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\6db17e040b1104fa9a9760c88c67b862\System.Messaging.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\6811eaa8b0f958064288a31d8e481326\System.Messaging.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\4117485024b0f652b9fbb66ff5025896\System.Management.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\c652c85e33a636d688b848cd5b39d7c4\System.Management.Instrumentation.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\47a7a4b08c2a08203849d20dd6ac3a4d\System.Management.Instrumentation.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\80bbf13d4e56a02266c87bc4710e0c66\System.IO.Log.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\06bcbb2f0b2de5bc7ebc92f7c2028181\System.IO.Log.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\2ba816b41a3f13685fd28d2ad50970ec\System.IdentityModel.Selectors.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\09d9d35b68b4fe07c1d2f25e2533f21e\System.IdentityModel.Selectors.ni.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2d2ebc3015150594787564a55d5abe9\System.EnterpriseServices.Wrapper.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2d2ebc3015150594787564a55d5abe9\System.EnterpriseServices.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\02768700bc8f762ccfe37785ba8eb498\System.EnterpriseServices.Wrapper.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\02768700bc8f762ccfe37785ba8eb498\System.EnterpriseServices.ni.dll
    + 2011-10-16 16:56 . 2011-10-16 16:56 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\a830aaff38f89b91fa5b5e36e7f5151d\System.Drawing.Design.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\29cbe2999c5c4d9b16ce0942323075fc\System.Drawing.Design.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\fc86e413df3f0d5f534d9075b59721b0\System.DirectoryServices.Protocols.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4220d664c6e2df524893d5ff00090cf4\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1ed84c038dbce9cab34496f5dbd10b12\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-09-22 00:07 . 2011-09-22 00:07 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\10dea0183eb6ff30200d910dc34b872b\System.DirectoryServices.Protocols.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\bea25c80a05c3ec58f4cfa4f5047dfc3\System.Data.Services.Client.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ac6798f7b52c9ae389574ac01caa520f\System.Data.Services.Design.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\938ebecb514d07fd01d8ca66fd4571b8\System.Data.Services.Client.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\6046ede88b4cd96a42c29dc2671c99e2\System.Data.Services.Design.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\315d103465e4f181b6a1a81edfdd8b70\System.Data.Entity.Design.ni.dll
    + 2011-10-16 17:21 . 2011-10-16 17:21 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\1df0e488d8bb7111ec751ecdc9990781\System.Data.Entity.Design.ni.dll
    + 2011-10-16 17:20 . 2011-10-16 17:20 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\d032d9cae8a95ef817ba81ee12e9ccc1\System.Data.DataSetExtensions.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\429c6372db169d1867f5892d351a4a14\System.Data.DataSetExtensions.ni.dll
    + 2011-10-16 17:14 . 2011-10-16 17:14 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
    + 2011-09-22 00:05 . 2011-09-22 00:05 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\29c6ef7f07d89496c72a1bbf718aed5d\System.Configuration.ni.dll
    + 2011-09-22 00:06 . 2011-09-22 00:06 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\c3cfe8388734152100ff476350fb3ddb\System.Configuration.Install.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\7f3c596d0a5463520a5f8052c0f298f6\System.Configuration.Install.ni.dll
    + 2011-10-16 17:20 . 2011-10-16 17:20 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\d7a8e2b8395718b508c677b102504a1f\System.AddIn.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\0d00826b5faadbfc192c3679e5ab30cf\System.AddIn.ni.dll
    - 2011-06-18 15:18 . 2011-06-18 15:18 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\7879c86ded9fabda3e3285420ab3a406\sysglobl.ni.dll
    + 2011-09-26 00:44 . 2011-09-26 00:44 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\7879c86ded9fabda3e3285420ab3a406\sysglobl.ni.dll
    + 2011-10-16 17:22 . 2011-10-16 17:22 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\289d4e6d05fe5ca5f43330483fb0e549\sysglobl.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\878ab210235309095edcd2565987503e\SMSvcHost.ni.exe
    + 2011-10-16 17:20 . 2011-10-16 17:20 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\1e92b23704410d1c43c4c7e9a7439d0c\SMSvcHost.ni.exe
    + 2011-09-25 15:09 . 2011-09-25 15:09 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\ca54e016986a14796591228eaa80cce1\SMDiagnostics.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\a800035f1686fdb0b7a019b954a37cfe\SMDiagnostics.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\c0e48084525f817b13d79d7d2dec52cc\ServiceModelReg.ni.exe
    + 2011-10-16 17:20 . 2011-10-16 17:20 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a191710dc9ec0488fb2eafd7b7dc3ac8\ServiceModelReg.ni.exe
    + 2011-10-16 16:55 . 2011-10-16 16:55 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bd47a61dc232cd6a0feea1b30ffa2499\PresentationFramework.Luna.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a51a17cc3195c47d97be3f387f86c462\PresentationFramework.Luna.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6a38f370d4e68b65106d1065d0b77067\PresentationFramework.Aero.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4aa958d331158aa1c46b80468c842a34\PresentationFramework.Classic.ni.dll
    + 2011-10-16 16:55 . 2011-10-16 16:55 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2c472b6ac873a7ff2ebc5bb9eb0f9ce0\PresentationFramework.Classic.ni.dll
    + 2011-10-16 16:55 . 2011-10-16 16:55 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2500ab0516144f848294d6a3ad20692e\PresentationFramework.Royale.ni.dll
    + 2011-10-16 16:55 . 2011-10-16 16:55 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\231b0b42eff55de5c7d7debe555c16b7\PresentationFramework.Aero.ni.dll
    + 2011-09-26 00:42 . 2011-09-26 00:42 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0159274c97a3fa4d942e6b4e321b6a54\PresentationFramework.Royale.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 724992 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\6849e7e884c97c0b8c9601539c0e093f\napsnap.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 724992 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\09588b506c3536beb6d684eb74dd085e\napsnap.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 110080 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\abace0d3ea5d15d57cac11c1bbcd0952\napinit.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 110080 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\a1aef4dc8e6bbef74ff53dfed28a0f4d\napinit.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 115712 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\86024627ce245ddb4d6df1acad88b4c6\naphlpr.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 115712 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\4dad5608f35eaa140c6eae43f1f2ea6c\naphlpr.ni.dll
    - 2011-06-18 15:15 . 2011-06-18 15:15 115712 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\4dad5608f35eaa140c6eae43f1f2ea6c\naphlpr.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\f1f2f55a0427a355d4bfde947a4a1546\MSBuild.ni.exe
    + 2011-10-16 17:16 . 2011-10-16 17:16 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\3c0c85efc63007f776f492e08fb32cdb\MSBuild.ni.exe
    + 2011-10-16 17:17 . 2011-10-16 17:17 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\daadd85d23b93f162d03a05c4cb0f2c3\MMCFxCommon.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 285184 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\2c18cdf3808acb8ecb484b9f2940f0b3\MMCFxCommon.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 508928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\c3b4602f861bbf8a77d16be1a16017b7\Microsoft.WSMan.Management.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 508928 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\4708bff160c4d942b1f02dd5a7b05be6\Microsoft.WSMan.Management.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\cf693d9799ee92ab0dc4ad51719842f9\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c5f23819070d044fbefb785b5ed9e7a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\e3867f57cf5555c7dc127a85c6536ad9\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\c2b70981f17c645a6da93adae7c2aa4d\Microsoft.Practices.ObjectBuilder.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\a12cdae7008a9049243d4fdc2033a6e3\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\9717a238c6c200f93561ecbfba2319a0\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\683b49de1588ec1bedbd9d4c86bbda6b\Microsoft.Practices.ObjectBuilder.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\4cba203a22ae3a031c8e2612c2f5790c\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ca43c0a5db3c716335b4d7c074b0cedd\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ac3ad80c24977b3bbee2b4f9be782c04\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2011-09-25 15:12 . 2011-09-25 15:12 737792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\a7de5db00e81689537057130e3fa9d5b\Microsoft.PowerShell.Commands.Management.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 729600 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9cf468a79e3c6ef33976415b4854ecc2\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2011-09-25 15:13 . 2011-09-25 15:13 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\83306689d48575a50d4d84b27a63146b\Microsoft.PowerShell.ConsoleHost.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 729600 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7d3830e31972116c36547ee39c4e8749\Microsoft.PowerShell.GraphicalHost.ni.dll
    + 2011-10-16 17:19 . 2011-10-16 17:19 156160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7d12fa40f29bad911feaca0b3a70885c\Microsoft.PowerShell.Security.ni.dll
    + 2011-09-25 15:12 . 2011-09-25 15:12 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7c32a2335dc8481175cbef33ee90c8dd\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
    + 2011-09-26 00:41 . 2011-09-26 00:41 156160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\767b4b96bb9ae9630bcb460fab12d2b0\Microsoft.PowerShell.Security.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 737792 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\38f0b7ef64ff3079061ace44b2451980\Microsoft.PowerShell.Commands.Management.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\bb189e9d53d02b3d63c3828c0463cc12\Microsoft.MediaCenter.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\a7d3927c679ca47b3d79f725ef37ebaf\Microsoft.MediaCenter.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 558592 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\dbc1816a7bd59302368ec20a8b1cdfb5\Microsoft.ManagementConsole.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 558592 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\6ef5be72dab25ea6491e4a6891aa1457\Microsoft.ManagementConsole.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ec6572eaa39404db6eb5146b4a10cf3b\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\e9e6ed1e90de7f57500f137fcf429f0b\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\b316d7ba730f523a2ec12d9c5f4b73b6\Microsoft.Build.Utilities.ni.dll
    + 2011-10-16 17:18 . 2011-10-16 17:18 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\41e4b2b0cf0b89613845e766cd85d047\Microsoft.Build.Utilities.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e9af947dc6d2428c521ac653b21b8668\Microsoft.Build.Engine.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 888320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8531b16a502ccd0f53af70ca00411fd2\Microsoft.Build.Engine.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\ea3acb2fc7a8433efd09d63f6ff5bb5b\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\05adc31c04e41f58825cc4b26e0245e6\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 230912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\631bd5ed7a121ba609770290d506e8c6\Microsoft.ApplicationBlocks.Updater.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 230912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\1f0b7a83f63f620d8758a5ae55367a03\Microsoft.ApplicationBlocks.Updater.ni.dll
    + 2011-09-25 15:11 . 2011-09-25 15:11 543744 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\ce072aeecd1c5d0ae54fd0fce46f52e0\EventViewer.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 543744 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\988d71b788a69c083b6dd6993b37269d\EventViewer.ni.dll
    - 2011-06-18 15:13 . 2011-06-18 15:13 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\9e98d7dcfeb34bbf6d2ea0e711b3ae4f\ehiExtens.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\9e98d7dcfeb34bbf6d2ea0e711b3ae4f\ehiExtens.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 160768 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\6c0adc1b359993851c9af87074f237d5\ehiExtens.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 243200 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\b54654928cb5eabb468d19a32ae75d32\ehExtHost32.ni.exe
    + 2011-10-16 17:17 . 2011-10-16 17:17 243200 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\a49ee57ba76b53113b41af3fdb9eebd1\ehExtHost32.ni.exe
    + 2011-10-16 17:15 . 2011-10-16 17:15 364544 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\dfbca18139363c84e950c1a23af042f1\DriversHQ.DriverDetective.Client.Communication.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 315904 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\bdecc49e1f46e188d16a5ea46ebaf129\DriversHQ.DriverDetective.Common.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 315904 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\624983bb8a395535e62dd7b1767369b4\DriversHQ.DriverDetective.Common.ni.dll
    + 2011-09-22 00:06 . 2011-09-22 00:06 364544 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\09b30324fb783efe7b4ad6caa10874df\DriversHQ.DriverDetective.Client.Communication.ni.dll
    + 2011-09-22 00:24 . 2011-09-22 00:24 602112 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\bdf5516e95a5c4078e09b4bf66fb65a6\DriversHQ.Common.ni.dll
    + 2011-10-16 17:15 . 2011-10-16 17:15 602112 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\3e0d2f86feda9de5de2ccc8359a697ca\DriversHQ.Common.ni.dll
    + 2011-10-16 17:17 . 2011-10-16 17:17 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\d72212e0e98b6ea4339d453bf540b5a6\CustomMarshalers.ni.dll
    - 2011-06-18 15:13 . 2011-06-18 15:13 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\798dad8e1b1dae489aa30b4341bcdba7\CustomMarshalers.ni.dll
    + 2011-09-25 15:10 . 2011-09-25 15:10 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\798dad8e1b1dae489aa30b4341bcdba7\CustomMarshalers.ni.dll
    + 2011-10-16 17:16 . 2011-10-16 17:16 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\ad9bd4a8856b4c61f798da4dc31f5ef0\ComSvcConfig.ni.exe
    + 2011-09-22 00:24 . 2011-09-22 00:24 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\147a04caf482e4d4082582a7698883e4\ComSvcConfig.ni.exe
    + 2011-11-04 07:29 . 2011-11-04 07:29 1126912 c:\windows\SysWOW64\wininet.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 1102848 c:\windows\SysWOW64\urlmon.dll
    + 2009-09-19 15:51 . 2009-04-11 06:28 1154048 c:\windows\SysWOW64\Speech\Common\sapi.dll
    + 2009-09-19 15:52 . 2009-04-11 06:28 1469952 c:\windows\SysWOW64\oobe\winsetup.dll
    + 2006-11-02 12:21 . 2006-11-02 09:43 2928640 c:\windows\SysWOW64\oobe\W32UIImg.dll
    + 2006-11-02 12:20 . 2006-11-02 07:26 2105856 c:\windows\SysWOW64\oobe\OOBEResources.dll
    + 2009-09-19 15:52 . 2009-04-11 06:27 1315840 c:\windows\SysWOW64\oobe\msoobe.exe
    + 2008-01-21 02:47 . 2008-01-21 02:47 1427046 c:\windows\SysWOW64\migwiz\SFLISTXP.dat
    + 2008-01-21 02:47 . 2008-01-21 02:47 2462746 c:\windows\SysWOW64\migwiz\SFLISTLH.dat
    + 2011-11-04 07:29 . 2011-11-04 07:29 1798144 c:\windows\SysWOW64\jscript9.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 1791488 c:\windows\SysWOW64\iertutil.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 9704960 c:\windows\SysWOW64\ieframe.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 3695416 c:\windows\SysWOW64\ieapfltr.dat
    + 2011-11-04 07:29 . 2011-11-04 07:29 1389056 c:\windows\system32\wininet.dll
    + 2011-10-15 13:58 . 2011-09-06 13:56 2764288 c:\windows\system32\win32k.sys
    + 2011-11-04 07:29 . 2011-11-04 07:29 1344512 c:\windows\system32\urlmon.dll
    + 2011-08-10 14:50 . 2011-06-20 08:45 4699536 c:\windows\system32\ntoskrnl.exe
    + 2011-07-12 17:41 . 2011-04-12 16:15 1210880 c:\windows\system32\kernel32.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 2309120 c:\windows\system32\jscript9.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 2143744 c:\windows\system32\iertutil.dll
    + 2011-11-04 07:29 . 2011-11-04 07:29 3695416 c:\windows\system32\ieapfltr.dat
    + 2011-08-10 14:50 . 2011-06-17 20:14 1427344 c:\windows\system32\drivers\tcpip.sys
    + 2011-11-04 07:47 . 2011-11-08 01:13 2773972 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1361230698-3698658676-2926581387-1000-12288.dat
    - 2010-03-18 18:27 . 2010-03-18 18:27 1221464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpftxt_v0400.dll
    + 2011-04-06 21:45 . 2011-04-06 21:45 1221464 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpftxt_v0400.dll
    - 2010-03-18 18:27 . 2010-03-18 18:27 2153816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll
    + 2011-04-06 21:45 . 2011-04-06 21:45 2153816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 1368920 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 6428520 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll
    + 2011-04-06 21:45 . 2011-04-06 21:45 3824480 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll
    + 2011-04-06 21:45 . 2011-04-06 21:45 3235656 c:\windows\Microsoft.NET\Framework64\v4.0.30319\vbc.exe
    - 2010-03-18 17:16 . 2010-03-18 17:16 2207568 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.XML.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 2207568 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.XML.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 6097256 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.dll
    + 2011-04-28 12:48 . 2011-04-28 12:48 3510600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
    - 2011-03-23 02:01 . 2011-03-23 02:01 3510600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll
    + 2011-05-17 14:08 . 2011-05-17 14:08 3116376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 1354584 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Core.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 4967248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
    - 2011-04-13 02:16 . 2011-04-13 02:16 4967248 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 1454416 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 1514840 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll
    + 2011-05-17 14:08 . 2011-05-17 14:08 1511240 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
    + 2011-07-09 14:05 . 2011-07-09 14:05 9790792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
    + 2011-08-10 14:50 . 2011-05-04 11:53 3182592 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
    - 2011-06-18 00:19 . 2011-01-20 11:09 3182592 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    + 2011-10-15 13:58 . 2011-07-08 11:52 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll
    + 2011-10-15 13:58 . 2011-07-08 11:52 1764696 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 1764696 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll
    - 2010-03-18 17:16 . 2010-03-18 17:16 1663320 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 1663320 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 1368920 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 6428520 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 3788128 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 2261832 c:\windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
    + 2011-04-06 20:48 . 2011-04-06 20:48 2207568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.XML.dll
    - 2010-03-18 17:16 . 2010-03-18 17:16 2207568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.XML.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 6097256 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.dll
    + 2011-04-28 12:48 . 2011-04-28 12:48 3510600 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
    - 2011-03-23 02:01 . 2011-03-23 02:01 3510600 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
    + 2011-05-17 13:27 . 2011-05-17 13:27 2975064 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.dll
    + 2011-04-06 20:48 . 2011-04-06 20:48 1354584 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
    - 2011-04-12 19:11 . 2011-04-12 19:11 5197648 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 5197648 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 1142616 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
    + 2011-07-09 13:30 . 2011-07-09 13:30 6724424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
    - 2011-06-18 00:19 . 2011-01-20 11:09 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2011-08-10 14:50 . 2011-05-04 11:53 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2011-10-15 13:58 . 2011-07-08 11:53 5911888 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 5911888 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    + 2011-10-15 13:58 . 2011-07-08 11:53 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    - 2011-06-18 00:19 . 2011-03-29 10:52 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1368920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 3510600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 3510600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 5028200 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 6428520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 3824480 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 4967248 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 4967248 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-18 14:50 . 2011-06-18 14:50 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-10-16 13:41 . 2011-10-16 13:41 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 3788128 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 5197648 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2011-06-18 14:49 . 2011-06-18 14:49 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-10-16 13:40 . 2011-10-16 13:40 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
    + 2011-08-10 21:43 . 2011-08-10 21:43 3795968 c:\windows\Installer\82fc4.msp
    + 2011-09-07 01:46 . 2011-09-07 01:46 9006080 c:\windows\Installer\82fbb.msp
    + 2011-08-10 21:42 . 2011-08-10 21:42 7070208 c:\windows\Installer\82f99.msp
    + 2011-09-07 01:48 . 2011-09-07 01:48 8181248 c:\windows\Installer\82f80.msp
    + 2011-07-27 11:39 . 2011-07-27 11:39 9892352 c:\windows\Installer\82f60.msp
    + 2011-09-07 23:36 . 2011-09-07 23:36 6069248 c:\windows\Installer\657a7.msp
    + 2011-07-21 17:34 . 2011-07-21 17:34 3456000 c:\windows\Installer\56cff.msp
    + 2011-04-28 13:57 . 2011-04-28 13:57 2721280 c:\windows\Installer\4fd7c.msp
    + 2011-07-17 23:17 . 2011-07-17 23:17 3940864 c:\windows\Installer\18ba9.msi
    - 2008-09-03 18:10 . 2011-06-16 23:09 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    + 2008-09-03 18:10 . 2011-09-16 10:41 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    + 2010-03-18 18:27 . 2010-03-18 18:27 1221464 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\wpftxt_amd64.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 1663320 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\wpfgfx_x86.dll
    + 2010-03-18 18:27 . 2010-03-18 18:27 2153816 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\wpfgfx_amd64.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 1303896 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\WindowsBase_x86.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 1303896 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\WindowsBase_amd64.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 6346600 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationFramework_x86.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 6346600 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationFramework_amd64.dll
    + 2010-03-18 17:16 . 2010-03-18 17:16 3545952


    Continued...


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.