Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: jefraz on December 26, 2011, 01:09:48 PM

Title: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 26, 2011, 01:09:48 PM
AVG Resident Shield Alert keeps coming up saying C:\WINDOWS\SYSTEM32\DRIVERS\volsnap.sys

Trojan horse Rootkit-Pakes.BI

Is there any way to fix this?

- SuperAntispyware
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/25/2011 at 05:56 PM

Application Version : 5.0.1142

Core Rules Database Version : 8087
Trace Rules Database Version: 5899

Scan type       : Complete Scan
Total Scan Time : 04:50:37

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned      : 510
Memory threats detected   : 0
Registry items scanned    : 40295
Registry threats detected : 0
File items scanned        : 53436
File threats detected     : 389

Adware.IEPlugin
   C:\WINDOWS\isp.ico

Adware.ClearSearch
   C:\Program Files\ClearSearch

Adware.BargainBuddy/NaviSearch
   C:\Program Files\BullsEye Network

Adware.Tracking Cookie
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@atdmt[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@apmebf[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@media6degrees[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tradedoubler[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@bluestreak[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/hotbartenders/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adsonar[2].txt [ Cookie:[email protected]/adserving ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@valueclick[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@sexxyeyes[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@ru4[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/pagead/conversion/1068214132/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adbrite[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@webpower[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@specificclick[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@kanoodle[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@revsci[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@2o7[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tribalfusion[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@chitika[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@lucidmedia[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/pagead/conversion/1033212164/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@internetfuel[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adecn[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@advertise[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@nextag[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@interclick[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@insightexpress[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@revenue[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ftvi/france2/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@doubleclick[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@pointroll[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@questionmarket[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@trafficmp[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@serving-sys[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@fastclick[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@advertising[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@mediaplex[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adknowledge[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][3].txt [ Cookie:[email protected]/ak/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@zedo[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@toplist[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@targetnet[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@yieldmanager[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/html ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@247realmedia[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tacoda[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][3].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@insightexpressai[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@pathfinder[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@smartadserver[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@realmedia[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@edgeadx[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[2].txt [ Cookie:[email protected]/hc/76226072 ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@eyewonder[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@weborama[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/NeROITrack/908 ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@collective-media[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[4].txt [ Cookie:[email protected]/hc/37457093 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@mediaplex[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@atwola[3].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@tmpad[1].txt [ Cookie:daniel [email protected]/tmpad ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@doubleclick[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@questionmarket[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ix ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcsew60m1oifwznbkznc6j9ix_5x7j[1].txt [ Cookie:daniel [email protected]/dcsew60m1oifwznbkznc6j9ix_5x7j ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultadworld[2].txt [ Cookie:daniel@*adult URL*/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@burstnet[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@hitbox[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@2o7[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adult-traf[2].txt [ Cookie:daniel@*adult URL*/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsx8czs1erp17368wkcsn8pc_9z2q[1].txt [ Cookie:[email protected]/dcsx8czs1erp17368wkcsn8pc_9z2q ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/cgi-bin ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcsxx9nthdrp17fja823qwk9f_9k9t[2].txt [ Cookie:daniel [email protected]/dcsxx9nthdrp17fja823qwk9f_9k9t ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@cgi-bin[3].txt [ Cookie:daniel [email protected]/cgi-bin ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@2o7[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@maxserving[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@bizrate[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@webpower[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@spylog[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/cgi-bin ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@webpower[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@trafficmp[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@insightexpress[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@estat[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@qksrv[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@focalex[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@findwhat[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@bluestreak[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcskqeg2voifwznnd6alhtnei_8f3u[1].txt [ Cookie:daniel [email protected]/dcskqeg2voifwznnd6alhtnei_8f3u ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@fastclick[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@atdmt[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@advertising[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsuuftkberp17368wkcsn8pc_5z5u[2].txt [ Cookie:[email protected]/dcsuuftkberp17368wkcsn8pc_5z5u ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S005-01-3-24-203189-62747[1].txt [ Cookie:[email protected]/S005-01-3-24-203189-62747 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@overture[2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@cgi-bin[2].txt [ Cookie:daniel [email protected]/cgi-bin ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@revenue[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@boeingmedia[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@exitexchange[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@maxserving[1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@S150235[2].txt [ Cookie:daniel [email protected]/S150235 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indiads[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@gieat[2].txt [ Cookie:[email protected]/gieat/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultactioncam[1].txt [ Cookie:daniel@*adult URL*/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcs9rrxib6twkffavyfc6qjmn_1l5y[1].txt [ Cookie:[email protected]/dcs9rrxib6twkffavyfc6qjmn_1l5y ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultcheck[1].txt [ Cookie:daniel@*adult URL*/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@commission-junction[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S145588[2].txt [ Cookie:[email protected]/S145588 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@partypoker[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findwhat[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xxxtoolbar[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@partner2profit[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pornochicks[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@specificpop[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@clickability[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S005-01-5-9-246403-73932[1].txt [ Cookie:[email protected]/S005-01-5-9-246403-73932 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@yourmedia[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@roiservice[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@bravenet[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@gieat[1].txt [ Cookie:[email protected]/gieat/gieat/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@perfettomedia[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@rgsex[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@rightmedia[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findtherightschool[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@metareward[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsklxjd7oifwzramfu7ehxd9_2j2f[1].txt [ Cookie:[email protected]/dcsklxjd7oifwzramfu7ehxd9_2j2f ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adknowledge[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@insightexpress[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[7].txt [ Cookie:[email protected]/cgi-bin/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@emarketmakers[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xiti[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsqp2wy611e5hibqykurvsnu_2p1b[1].txt [ Cookie:[email protected]/dcsqp2wy611e5hibqykurvsnu_2p1b ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[3].txt [ Cookie:[email protected]/cgi-bin ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:daniel@www.*adult URL*/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@qnsr[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@local[1].txt [ Cookie:[email protected]/touchplc/local/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@revsci[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/adserver ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexsearchcom[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexlist[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@insightexpresserdd[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@homesexnetwork[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xxx_rated[1].txt [ Cookie:[email protected]/ecards/adults/xxx_rated/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@paycounter[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@keywordmax[2].txt [ Cookie:[email protected]/tracking/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@toplist[4].txt [ Cookie:[email protected]/cgi-bin/toplist/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indextools[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S150235[1].txt [ Cookie:[email protected]/S150235 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adprofile[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@bizrate[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[8].txt [ Cookie:[email protected]/cgi-bin/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@superstats[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@86793153[1].txt [ Cookie:[email protected]/hc/86793153 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@teacherscount[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@keywordmax[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@spamblockerutility[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@s[1].txt [ Cookie:[email protected]/s/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@onlinerewardcenter[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@home_porn_052[1].txt [ Cookie:[email protected]/homemadevids/home_porn_052/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@europcar[1].txt [ Cookie:[email protected]/europcar/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@resaweb[1].txt [ Cookie:[email protected]/europcar/resaweb/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pathfinder[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][5].txt [ Cookie:[email protected]/hc/33069911 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@vipsexcams[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@winfixer[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@entrepreneur[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@weborama[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/hc/LPneimanmarcus ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findarticles[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@incentaclick[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/pagead/conversion/1072669019/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@ad[1].txt [ Cookie:[email protected]//ad/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@wTracker[2].txt [ Cookie:[email protected]/wTracker/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcs7z2vq0wo4xny3pd9f1blk5_3m5k[1].txt [ Cookie:[email protected]/dcs7z2vq0wo4xny3pd9f1blk5_3m5k ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indexstats[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@clickbank[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/pagead/conversion/1072499559/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@kmpads[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexinfo101[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@thesexydump[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@petfinder[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@chokertraffic[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@hornymatches[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pornhub[1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@azoogleads[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/hc/28856772 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@tripod[2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/adserver ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
   ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   s0.2mdn.net [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   2mdn.net [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   adknowledge.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   b.ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   doubleclick.net [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   ds.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   host-d.oddcast.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   macromedia.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   orders.webpower.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\DANIEL@ATWOLA[1].TXT [ /ATWOLA ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\DANIEL@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
   C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\[email protected][1].TXT [ /SERVEDBY.ADVERTISING ]
   ads1.msn.com [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   msnbcmedia.msn.com [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   s0.2mdn.net [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
   C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\COOKIES\[email protected][1].TXT [ /Z1.ADSERVER ]
   C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\COOKIES\ADMINISTRATOR@ZEDO[1].TXT [ /ZEDO ]
- Malwarebytes' Anti-Malware
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 911122603

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/26/2011 1:47:01 PM
mbam-log-2011-12-26 (13-47-01).txt

Scan type: Quick scan
Objects scanned: 205876
Time elapsed: 9 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

- DDS logs (DDS.txt & Attach.txt)
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Joe Frazier at 13:48:52 on 2011-12-26
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1354 [GMT -6:00]
.
AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Enabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\AVG\AVG2012\avgfws.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\ihrcovpn\IHRCO VPN Client\cvpnd.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://webaccess3.columbiasussex.com/gw/webacc
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Google Update] "c:\documents and settings\daniel clark\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - hxxp://10.73.30.30:8080/emc/setup.exe
DPF: {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_01-win.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.73.10.5
TCP: Interfaces\{1B565AA0-3397-4046-A063-455480BF973B} : DhcpNameServer = 10.73.10.5
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 avgfws;AVG Firewall;c:\program files\avg\avg2012\avgfws.exe [2011-11-23 2391832]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-9-26 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-9-16 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-11-20 47640]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-1-11 366152]
R2 MSSQL$CSS;MSSQL$CSS;c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlservr.exe -scss --> c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlservr.exe -sCSS [?]
R2 MSSQL$CSS2;SQL Server (CSS2);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2010-12-10 29293408]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-11 22216]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-12 136176]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-12 136176]
S3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2004-1-12 36013]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 SQLAgent$CSS;SQLAgent$CSS;c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlagent.exe -i css --> c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlagent.EXE -i CSS [?]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2004-3-19 189792]
S3 w89c940;Winbond W89C940 PCI Ethernet Adapter Driver;c:\windows\system32\drivers\w940nd.sys [2004-1-13 16925]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S4 LMIRfsClientNP;LMIRfsClientNP;
.
=============== Created Last 30 ================
.
2011-12-26 15:32:45   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-12-25 18:58:52   --------   d-----w-   c:\documents and settings\daniel clark\application data\SUPERAntiSpyware.com
2011-12-25 18:57:30   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-12-25 18:57:30   --------   d-----w-   c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-12-25 18:40:38   --------   d-----w-   c:\program files\CCleaner
2011-12-21 01:21:06   --------   d-----w-   c:\windows\system32\wbem\repository\FS
2011-12-21 01:21:06   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-12-04 11:29:56   --------   d-----w-   c:\windows\system32\Robert Shindler
2011-12-02 07:25:10   --------   d-----w-   c:\documents and settings\daniel clark\local settings\application data\RcIncidents
.
==================== Find3M  ====================
.
2011-12-26 15:31:50   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-11-20 19:37:44   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 11:23:48   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21:42   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
2010-01-07 22:07:10   1394000   ----a-w-   c:\program files\mbam.exe
2004-05-31 16:55:55   5245352   ----a-w-   c:\program files\SetupDl.EXE
2004-05-05 20:59:20   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
2004-04-23 16:38:25   10135688   ----a-w-   c:\program files\MPSetupXP.exe
2004-02-23 19:52:57   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
2004-02-23 19:50:49   6262872   ----a-w-   c:\program files\psa2se_us.exe
2004-02-06 13:39:26   3401360   ----a-w-   c:\program files\Install_AIM.exe
2003-11-09 01:26:08   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
.
============= FINISH: 13:50:48.12 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 11/8/2003 5:05:29 PM
System Uptime: 12/26/2011 1:19:03 PM (0 hours ago)
.
Motherboard: Dell Computer Corp. |  | 0G1548
Processor:               Intel(R) Pentium(R) 4 CPU 2.20GHz | Microprocessor | 2192/400mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 49.837 GiB free.
D: is CDROM ()
E: is FIXED (FAT) - 0 GiB total, 0.024 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Winbond W89C940-Based Ethernet Adapter (Generic)
Device ID: PCI\VEN_8E2E&DEV_3000&SUBSYS_00000000&REV_00\4&3B1CAF2B&0&20F0
Manufacturer: Winbond Electronics Corporation
Name: Winbond W89C940-Based Ethernet Adapter (Generic)
PNP Device ID: PCI\VEN_8E2E&DEV_3000&SUBSYS_00000000&REV_00\4&3B1CAF2B&0&20F0
Service: w89c940
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Packet Scheduler Miniport
Device ID: ROOT\MS_PSCHEDMP\0004
Manufacturer: Microsoft
Name: Packet Scheduler Miniport #5
PNP Device ID: ROOT\MS_PSCHEDMP\0004
Service: PSched
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
==== System Restore Points ===================
.
RP2764: 10/20/2011 2:16:28 PM - Restore Operation
RP2765: 10/20/2011 2:42:20 PM - Restore Operation
RP2766: 10/21/2011 11:04:09 AM - Installed TuneUp Utilities 2011
RP2767: 10/21/2011 5:54:19 PM - Software Distribution Service 3.0
RP2768: 10/22/2011 7:05:11 PM - System Checkpoint
RP2769: 10/23/2011 7:34:33 PM - System Chec
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: SuperDave on December 26, 2011, 06:12:42 PM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1 (http://screen317.spywareinfoforum.org/SecurityCheck.exe)
Link 2 (http://screen317.changelog.fr/SecurityCheck.exe)

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
*****************************************************
Please download ComboFix (http://img7.imageshack.us/img7/4930/combofix.gif) from BleepingComputer.com (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

Alternate link: GeeksToGo.com (http://subs.geekstogo.com/ComboFix.exe)

and save it to your Desktop.
It would be easiest to download using Internet Explorer.
If you want to use Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here (http://www.bleepingcomputer.com/forums/topic114351.html)
Double click ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
(http://i424.photobucket.com/albums/pp322/digistar/Query_RC.gif)
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
(http://i424.photobucket.com/albums/pp322/digistar/RC_successful.gif)

Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

If you have problems with ComboFix usage, see  How to use ComboFix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 27, 2011, 09:40:12 AM
Thanks Dave!  Here is the requested information:
Results of screen317's Security Check version 0.99.30 
 Windows XP Service Pack 3 x86   
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Disabled! 
 AVG 2012     
 Antivirus up to date! 
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 HijackThis 2.0.2   
 CCleaner     
 Java Web Start   
 Java 2 Runtime Environment Standard Edition v1.3.1_01
 Java(TM) 6 Update 30 
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Malwarebytes' Anti-Malware mbamservice.exe 
 Malwarebytes' Anti-Malware mbamgui.exe 
 AVG avgwdsvc.exe
 AVG avgtray.exe
 AVG avgrsx.exe
 AVG avgnsx.exe
 AVG avgemc.exe
``````````End of Log````````````


ComboFix 11-12-27.01 - Joe Frazier 12/27/2011   9:36.4.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1629 [GMT -6:00]
Running from: c:\documents and settings\Daniel Clark\Desktop\Computer Cleanup\ComboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Start Menu\Programs\NaviSearch
c:\windows\system32\SET727.tmp
c:\windows\system32\SET72B.tmp
c:\windows\system32\SET733.tmp
c:\windows\system32\SET73C.tmp
c:\windows\system32\SET73D.tmp
c:\windows\system32\SET73E.tmp
c:\windows\system32\SET741.tmp
.
 
 
.
.
(((((((((((((((((((((((((   Files Created from 2011-11-27 to 2011-12-27  )))))))))))))))))))))))))))))))
.
.
2011-12-26 15:32 . 2011-12-26 15:31   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-12-25 18:58 . 2011-12-25 18:58   --------   d-----w-   c:\documents and settings\Daniel Clark\Application Data\SUPERAntiSpyware.com
2011-12-25 18:57 . 2011-12-25 18:58   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-12-25 18:57 . 2011-12-25 18:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-12-25 18:40 . 2011-12-25 18:40   --------   d-----w-   c:\program files\CCleaner
2011-12-21 01:21 . 2011-12-21 01:21   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-12-04 11:29 . 2011-12-08 13:58   --------   d-----w-   c:\windows\system32\Robert Shindler
2011-12-02 07:25 . 2011-12-02 07:25   --------   d-----w-   c:\documents and settings\Daniel Clark\Local Settings\Application Data\RcIncidents
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-26 15:31 . 2009-01-23 16:18   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-11-20 19:37 . 2011-11-20 19:37   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 11:23 . 2011-07-11 06:13   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21 . 2011-07-11 06:14   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
2010-01-07 22:07 . 2010-01-11 18:41   1394000   ----a-w-   c:\program files\mbam.exe
2004-05-31 16:55 . 2004-03-18 19:32   5245352   ----a-w-   c:\program files\SetupDl.EXE
2004-05-05 20:59 . 2004-05-05 20:59   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
2004-04-23 16:38 . 2004-04-23 16:38   10135688   ----a-w-   c:\program files\MPSetupXP.exe
2004-02-23 19:52 . 2004-02-23 19:51   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
2004-02-23 19:50 . 2004-02-23 19:50   6262872   ----a-w-   c:\program files\psa2se_us.exe
2004-02-06 13:39 . 2003-12-19 14:15   3401360   ----a-w-   c:\program files\Install_AIM.exe
2003-11-09 01:26 . 2003-11-09 01:25   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
.
.
(((((((((((((((((((((((((((((   SnapShot_2011-05-08_18.06.00   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 05:02 . 2009-07-12 05:02   51008              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61760              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   53568              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   63296              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   35648              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_a4.dat
+ 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_47c.dat
+ 2011-06-22 17:47 . 2011-10-17 18:11   25307              c:\windows\SYSTEM32\winhstp.dat
+ 2007-01-29 08:58 . 2011-07-08 13:49   46080              c:\windows\SYSTEM32\tzchange.exe
- 2007-01-29 08:58 . 2010-11-03 13:12   46080              c:\windows\SYSTEM32\tzchange.exe
+ 2011-11-20 17:54 . 2011-09-27 00:16   52096              c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\LMIproc.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterui.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterdat.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinter.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterui.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterdat.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinter.dll
+ 2003-09-10 20:15 . 2011-11-14 19:26   94634              c:\windows\SYSTEM32\PERFC009.DAT
+ 2002-08-29 10:00 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\oleaccrc.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\mshtmled.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\mshtmled.dll
+ 2006-11-08 03:03 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\msfeedsbs.dll
- 2006-11-08 03:03 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\msfeedsbs.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   83360              c:\windows\SYSTEM32\LMIRfsClientNP.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   30592              c:\windows\SYSTEM32\LMIport.dll
+ 2011-09-16 21:10 . 2011-09-16 21:10   11552              c:\windows\SYSTEM32\lmimirr2.dll
+ 2011-09-16 21:10 . 2011-09-16 21:10   25248              c:\windows\SYSTEM32\lmimirr.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   87424              c:\windows\SYSTEM32\LMIinit.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\licmgr10.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\licmgr10.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\jsproxy.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\jsproxy.dll
+ 2008-05-06 21:06 . 2008-05-06 21:06   11520              c:\windows\SYSTEM32\DRIVERS\wdcsam.sys
+ 2002-08-29 10:00 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DRIVERS\ndistapi.sys
+ 2010-01-11 18:39 . 2011-08-31 22:00   22216              c:\windows\SYSTEM32\DRIVERS\mbam.sys
+ 2011-11-20 17:54 . 2011-09-16 21:10   47640              c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys
+ 2011-09-16 21:10 . 2011-09-16 21:10   10144              c:\windows\SYSTEM32\DRIVERS\lmimirr.sys
+ 2011-09-13 11:30 . 2011-09-13 11:30   32592              c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
+ 2011-08-08 11:08 . 2011-08-08 11:08   40016              c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   24272              c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   23120              c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys
+ 2011-05-23 06:03 . 2011-05-23 06:03   30944              c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys
- 2005-06-13 14:27 . 2008-04-14 00:11   45568              c:\windows\SYSTEM32\dnsrslvr.dll
+ 2005-06-13 14:27 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\dnsrslvr.dll
- 2009-06-10 13:02 . 2010-12-20 23:59   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
+ 2009-06-10 13:02 . 2011-08-22 23:48   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
+ 2011-09-26 16:41 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\DLLCACHE\oleaccrc.dll
+ 2011-10-16 22:13 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DLLCACHE\ndistapi.sys
- 2006-05-10 05:23 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2006-05-10 05:23 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2007-05-09 16:55 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
- 2007-05-09 16:55 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
+ 2006-10-17 18:05 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
- 2006-10-17 18:05 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
- 2006-05-10 05:22 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2006-05-10 05:22 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2009-04-20 17:17 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\DLLCACHE\dnsrslvr.dll
- 2010-12-09 14:30 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
+ 2010-12-09 14:30 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
+ 2005-06-13 14:25 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\csrsrv.dll
- 2005-06-13 14:25 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\csrsrv.dll
+ 2011-05-23 06:03 . 2011-05-23 06:03   61280              c:\windows\SYSTEM32\avgfwdx.dll
+ 2011-07-08 19:00 . 2011-07-08 19:00   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-09-23 21:55 . 2010-09-23 21:55   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 17:03 . 2011-07-07 17:03   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 09:17 . 2010-09-23 09:17   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 09:17 . 2010-09-23 09:17   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-10-20 01:51 . 2011-10-20 01:51   22016              c:\windows\Installer\36534e.msi
+ 2011-05-12 13:17 . 2011-05-12 13:17   24064              c:\windows\Installer\12b8f5e1.msi
- 2005-05-25 21:25 . 2011-03-12 00:08   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2011-03-12 00:22 . 2011-03-12 00:22   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2011-10-21 23:36 . 2011-10-21 23:36   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2011-03-11 23:41 . 2011-03-11 23:41   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-03-11 23:41 . 2011-10-21 23:42   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   12800              c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   66560              c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   55296              c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   43520              c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   25600              c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-07-07 15:42 . 2011-07-07 15:47   20137              c:\windows\hpqins11.dat
+ 2011-10-21 22:57 . 2011-10-21 22:57   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_64433b8a\System.Drawing.Design.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_a1f745d8\CustomMarshalers.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-10-22 00:22 . 2011-10-22 00:22   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-22 00:22 . 2011-10-22 00:22   82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-10-22 00:03 . 2011-10-22 00:03   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-10-22 00:01 . 2011-10-22 00:01   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-10-22 00:19 . 2011-10-22 00:19   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ba5f039c6cee5268d549382692b6e365\Microsoft.SqlServer.CustomControls.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-10-22 00:13 . 2011-10-22 00:13   14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-10-22 00:11 . 2011-10-22 00:11   25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-03-11 23:07 . 2011-03-11 23:07   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-21 22:56 . 2011-10-21 22:56   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-22 00:00 . 2010-11-03 13:12   46080              c:\windows\$NtUninstallKB2570791$\tzchange.exe
+ 2011-10-22 00:00 . 2011-07-09 00:32   16896              c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
+ 2011-10-21 23:00 . 2008-04-13 18:57   10112              c:\windows\$NtUninstallKB2566454$\ndistapi.sys
+ 2011-10-21 23:38 . 2002-08-29 10:00   16896              c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
+ 2011-10-21 23:02 . 2008-04-14 00:11   45568              c:\windows\$NtUninstallKB2509553$\dnsrslvr.dll
+ 2011-10-21 23:24 . 2010-12-09 14:30   33280              c:\windows\$NtUninstallKB2507938$\csrsrv.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2616676-v2\update\spcustom.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2616676-v2\spmsg.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2592799\spmsg.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   12800              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   66560              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   55296              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   43520              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   25600              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570947\spmsg.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570222\spmsg.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567680\spmsg.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567053\spmsg.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2566454\spmsg.dll
+ 2011-10-16 22:13 . 2011-07-08 13:51   10496              c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
+ 2011-10-21 22:59 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
+ 2011-10-21 22:59 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2562937\spmsg.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544893\update\spcustom.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544893\spmsg.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544521-IE8\update\spcustom.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544521-IE8\spmsg.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2541763\update\spcustom.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2541763\spmsg.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2535512\update\spcustom.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2535512\spmsg.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2510531-IE8\update\spcustom.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2510531-IE8\spmsg.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2509553\update\spcustom.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2509553\spmsg.dll
+ 2009-04-20 17:06 . 2009-04-20 17:06   45568              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsrslvr.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508429\update\spcustom.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508429\spmsg.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508272\update\spcustom.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508272\spmsg.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507938\spmsg.dll
+ 2011-04-26 11:02 . 2011-04-26 11:02   33280              c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507618\update\spcustom.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507618\spmsg.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2506212\update\spcustom.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2506212\spmsg.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2485663\update\spcustom.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2485663\spmsg.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2476490\update\spcustom.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2476490\spmsg.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-04-15 12:50 . 2011-02-17 12:32   5120              c:\windows\SYSTEM32\xpsp4res.dll
- 2009-04-15 12:50 . 2010-08-26 12:52   5120              c:\windows\SYSTEM32\xpsp4res.dll
- 2005-05-25 21:25 . 2011-03-12 00:08   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2011-03-11 23:55 . 2011-03-11 23:55   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-10-21 23:07 . 2010-08-26 12:52   5120              c:\windows\$NtUninstallKB2508429$\xpsp4res.dll
+ 2011-02-17 12:32 . 2011-02-17 12:32   5120              c:\windows\$hf_mig$\KB2508429\SP3QFE\xpsp4res.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
- 2005-06-13 14:25 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\winsrv.dll
+ 2005-06-13 14:25 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\winsrv.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\wininet.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\wininet.dll
+ 2005-06-13 14:25 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\vbscript.dll
- 2005-06-13 14:25 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\url.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\url.dll
+ 2008-07-30 00:59 . 2011-09-26 16:41   611328              c:\windows\SYSTEM32\uiautomationcore.dll
+ 2005-06-13 14:25 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\schannel.dll
+ 2011-06-22 17:47 . 2011-10-17 18:11   152788              c:\windows\SYSTEM32\rhttpmah.dat
+ 2010-12-24 14:18 . 2011-12-21 01:23   229224              c:\windows\SYSTEM32\Restore\rstrlog.dat
+ 2011-06-22 17:47 . 2011-10-17 18:11   320053              c:\windows\SYSTEM32\prinauiv.dat
+ 2003-09-10 20:15 . 2011-11-14 19:26   500748              c:\windows\SYSTEM32\PERFH009.DAT
- 2005-06-13 14:25 . 2008-04-14 00:12   551936              c:\windows\SYSTEM32\oleaut32.dll
+ 2005-06-13 14:25 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\oleaut32.dll
+ 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\oleacc.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\occache.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\occache.dll
- 2005-06-13 14:26 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\mswsock.dll
+ 2005-06-13 14:26 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\mswsock.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\mstime.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\mstime.dll
- 2006-11-08 03:03 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\msfeeds.dll
+ 2006-11-08 03:03 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\msfeeds.dll
- 2005-06-13 14:26 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\mfc42u.dll
+ 2005-06-13 14:26 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\mfc42u.dll
+ 2005-06-13 14:26 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\mfc42.dll
+ 2011-11-20 19:37 . 2011-11-20 19:37   247968              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.exe
+ 2011-11-20 19:37 . 2011-11-20 19:37   335520              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.dll
+ 2005-06-13 14:26 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\jscript.dll
- 2005-06-13 14:26 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\jscript.dll
+ 2011-12-26 15:32 . 2011-12-26 15:31   157472              c:\windows\SYSTEM32\javaws.exe
+ 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\javaw.exe
+ 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\java.exe
+ 2005-06-13 14:26 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\inetcomm.dll
- 2005-06-13 14:26 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\inetcomm.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\iepeers.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\iepeers.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\iedkcs32.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\iedkcs32.dll
+ 2005-06-13 14:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\ie4uinit.exe
+ 2002-09-03 18:42 . 2011-10-22 06:19   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
- 2002-09-03 18:42 . 2011-03-12 01:05   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2011-04-12 19:55 . 2011-10-17 18:48   825939              c:\windows\SYSTEM32\dskquouh.dat
+ 2005-06-13 14:25 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DRIVERS\srv.sys
- 2005-06-13 14:25 . 2008-04-14 00:13   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
+ 2005-06-13 14:25 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
+ 2005-06-13 14:25 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DRIVERS\mup.sys
+ 2005-06-13 14:25 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   295248              c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   134608              c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys
+ 2005-06-13 14:25 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
- 2005-06-13 14:25 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
+ 2005-06-13 14:27 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\dnsapi.dll
- 2010-06-18 17:45 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2010-06-18 17:45 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
+ 2006-09-18 14:15 . 2011-04-30 03:01   758784              c:\windows\SYSTEM32\DLLCACHE\vgx.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\DLLCACHE\vbscript.dll
- 2006-10-17 18:05 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2006-10-17 18:05 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2008-10-15 03:09 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DLLCACHE\srv.sys
+ 2008-12-05 06:54 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\DLLCACHE\schannel.dll
+ 2011-10-16 22:20 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DLLCACHE\rdpwd.sys
+ 2010-12-20 17:32 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\DLLCACHE\oleaut32.dll
+ 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\DLLCACHE\oleacc.dll
- 2006-10-17 18:04 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2006-10-17 18:04 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2011-10-16 22:18 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DLLCACHE\mup.sys
+ 2008-06-20 17:46 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
- 2008-06-20 17:46 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
+ 2006-05-10 05:23 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2006-05-10 05:23 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2007-05-09 16:55 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2007-05-09 16:55 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
+ 2006-10-14 08:13 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
- 2006-10-14 08:13 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
+ 2011-03-11 13:42 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\DLLCACHE\mfc42.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
- 2008-05-09 10:53 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
- 2008-08-12 18:56 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2008-08-12 18:56 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2009-06-10 13:02 . 2011-08-22 23:48   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
- 2009-06-10 13:02 . 2010-12-20 23:59   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2011-03-11 13:36 . 2010-12-20 23:59   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
+ 2011-03-11 13:36 . 2011-08-22 23:48   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
+ 2006-11-07 09:27 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
- 2006-11-07 09:27 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
+ 2006-11-07 09:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
+ 2008-06-20 17:46 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\DLLCACHE\dnsapi.dll
+ 2005-06-13 14:27 . 2008-04-14 00:11   640000              c:\windows\SYSTEM32\DLLCACHE\dbghelp.dll
+ 2011-09-09 09:12 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\DLLCACHE\crypt32.dll
+ 2011-01-07 14:09 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\DLLCACHE\atmfd.dll
+ 2008-06-20 11:40 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
+ 2005-06-13 14:27 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\crypt32.dll
- 2005-06-13 14:27 . 2008-04-14 00:11   599040              c:\windows\SYSTEM32\crypt32.dll
+ 2005-06-13 14:27 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\atmfd.dll
- 2010-05-11 12:40 . 2010-05-11 12:40   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 11:15 . 2011-03-25 11:15   363856              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-05-11 12:40 . 2010-05-11 12:40   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 08:25 . 2010-09-23 08:25   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 17:01 . 2011-07-07 17:01   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 09:17 . 2010-09-23 09:17   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-05-10 12:37 . 2011-05-10 12:37   689152              c:\windows\Installer\844cd51.msi
+ 2011-12-26 15:31 . 2011-12-26 15:31   901120              c:\windows\Installer\4975043.msi
+ 2011-10-17 18:27 . 2011-10-17 18:27   219648              c:\windows\Installer\3d86bf5d.msi
+ 2011-07-07 15:44 . 2011-07-07 15:44   344576              c:\windows\Installer\1da16103.msi
- 2005-05-25 21:25 . 2011-03-12 00:08   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2011-05-10 12:35 . 2011-05-10 12:35   371272              c:\windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
+ 2011-10-21 23:10 . 2010-12-20 23:59   916480              c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-21 23:10 . 2009-03-08 09:34   105984              c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:10 . 2010-12-20 23:59   206848              c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   611840              c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   602112              c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   247808              c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   184320              c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   743424              c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   387584              c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-21 23:11 . 2010-12-20 12:55   173568              c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-10-21 23:00 . 2009-03-08 09:33   759296              c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:02 . 2010-03-10 06:15   420352              c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:02 . 2009-12-09 05:53   726528              c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2009-08-15 20:11 . 2011-07-07 15:51   116264              c:\windows\hpoins33.dat
+ 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\Driver Cache\I386\mrxsmb.sys
+ 2011-10-21 22:58 . 2011-10-21 22:58   835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b7a8f596\System.Drawing.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fd54f924\System.Drawing.Design.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_c86fa1ef\CustomMarshalers.dll
+ 2011-10-22 00:16 . 2011-10-22 00:16   321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-10-22 00:09 . 2011-10-22 00:09   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   187904              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-10-22 00:29 . 2011-10-22 00:29   400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-10
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: SuperDave on December 27, 2011, 11:39:36 AM
That is not the complete ComboFix log. You should be able to find it on your C: drive in the ComboFix folder. If you can't find it, please run it again and post the complete log.
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 27, 2011, 03:32:14 PM
ComboFix 11-12-27.01 - Joe Frazier 12/27/2011   9:36.4.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1629 [GMT -6:00]
Running from: c:\documents and settings\Daniel Clark\Desktop\Computer Cleanup\ComboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Start Menu\Programs\NaviSearch
c:\windows\system32\SET727.tmp
c:\windows\system32\SET72B.tmp
c:\windows\system32\SET733.tmp
c:\windows\system32\SET73C.tmp
c:\windows\system32\SET73D.tmp
c:\windows\system32\SET73E.tmp
c:\windows\system32\SET741.tmp
.
 
 
.
.
(((((((((((((((((((((((((   Files Created from 2011-11-27 to 2011-12-27  )))))))))))))))))))))))))))))))
.
.
2011-12-26 15:32 . 2011-12-26 15:31   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-12-25 18:58 . 2011-12-25 18:58   --------   d-----w-   c:\documents and settings\Daniel Clark\Application Data\SUPERAntiSpyware.com
2011-12-25 18:57 . 2011-12-25 18:58   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-12-25 18:57 . 2011-12-25 18:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-12-25 18:40 . 2011-12-25 18:40   --------   d-----w-   c:\program files\CCleaner
2011-12-21 01:21 . 2011-12-21 01:21   --------   d-----w-   c:\windows\system32\wbem\Repository
2011-12-04 11:29 . 2011-12-08 13:58   --------   d-----w-   c:\windows\system32\Robert Shindler
2011-12-02 07:25 . 2011-12-02 07:25   --------   d-----w-   c:\documents and settings\Daniel Clark\Local Settings\Application Data\RcIncidents
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-26 15:31 . 2009-01-23 16:18   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2011-11-20 19:37 . 2011-11-20 19:37   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 11:23 . 2011-07-11 06:13   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21 . 2011-07-11 06:14   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
2010-01-07 22:07 . 2010-01-11 18:41   1394000   ----a-w-   c:\program files\mbam.exe
2004-05-31 16:55 . 2004-03-18 19:32   5245352   ----a-w-   c:\program files\SetupDl.EXE
2004-05-05 20:59 . 2004-05-05 20:59   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
2004-04-23 16:38 . 2004-04-23 16:38   10135688   ----a-w-   c:\program files\MPSetupXP.exe
2004-02-23 19:52 . 2004-02-23 19:51   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
2004-02-23 19:50 . 2004-02-23 19:50   6262872   ----a-w-   c:\program files\psa2se_us.exe
2004-02-06 13:39 . 2003-12-19 14:15   3401360   ----a-w-   c:\program files\Install_AIM.exe
2003-11-09 01:26 . 2003-11-09 01:25   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
.
.
(((((((((((((((((((((((((((((   SnapShot_2011-05-08_18.06.00   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 05:02 . 2009-07-12 05:02   51008              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61760              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   53568              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   63296              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   35648              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_a4.dat
+ 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_47c.dat
+ 2011-06-22 17:47 . 2011-10-17 18:11   25307              c:\windows\SYSTEM32\winhstp.dat
+ 2007-01-29 08:58 . 2011-07-08 13:49   46080              c:\windows\SYSTEM32\tzchange.exe
- 2007-01-29 08:58 . 2010-11-03 13:12   46080              c:\windows\SYSTEM32\tzchange.exe
+ 2011-11-20 17:54 . 2011-09-27 00:16   52096              c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\LMIproc.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterui.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterdat.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinter.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterui.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterdat.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinter.dll
+ 2003-09-10 20:15 . 2011-11-14 19:26   94634              c:\windows\SYSTEM32\PERFC009.DAT
+ 2002-08-29 10:00 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\oleaccrc.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\mshtmled.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\mshtmled.dll
+ 2006-11-08 03:03 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\msfeedsbs.dll
- 2006-11-08 03:03 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\msfeedsbs.dll
+ 2011-11-20 17:54 . 2011-09-27 00:16   83360              c:\windows\SYSTEM32\LMIRfsClientNP.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   30592              c:\windows\SYSTEM32\LMIport.dll
+ 2011-09-16 21:10 . 2011-09-16 21:10   11552              c:\windows\SYSTEM32\lmimirr2.dll
+ 2011-09-16 21:10 . 2011-09-16 21:10   25248              c:\windows\SYSTEM32\lmimirr.dll
+ 2011-11-20 17:54 . 2011-09-27 00:15   87424              c:\windows\SYSTEM32\LMIinit.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\licmgr10.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\licmgr10.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\jsproxy.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\jsproxy.dll
+ 2008-05-06 21:06 . 2008-05-06 21:06   11520              c:\windows\SYSTEM32\DRIVERS\wdcsam.sys
+ 2002-08-29 10:00 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DRIVERS\ndistapi.sys
+ 2010-01-11 18:39 . 2011-08-31 22:00   22216              c:\windows\SYSTEM32\DRIVERS\mbam.sys
+ 2011-11-20 17:54 . 2011-09-16 21:10   47640              c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys
+ 2011-09-16 21:10 . 2011-09-16 21:10   10144              c:\windows\SYSTEM32\DRIVERS\lmimirr.sys
+ 2011-09-13 11:30 . 2011-09-13 11:30   32592              c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
+ 2011-08-08 11:08 . 2011-08-08 11:08   40016              c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   24272              c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   23120              c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys
+ 2011-05-23 06:03 . 2011-05-23 06:03   30944              c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys
- 2005-06-13 14:27 . 2008-04-14 00:11   45568              c:\windows\SYSTEM32\dnsrslvr.dll
+ 2005-06-13 14:27 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\dnsrslvr.dll
- 2009-06-10 13:02 . 2010-12-20 23:59   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
+ 2009-06-10 13:02 . 2011-08-22 23:48   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
+ 2011-09-26 16:41 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\DLLCACHE\oleaccrc.dll
+ 2011-10-16 22:13 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DLLCACHE\ndistapi.sys
- 2006-05-10 05:23 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2006-05-10 05:23 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2007-05-09 16:55 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
- 2007-05-09 16:55 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
+ 2006-10-17 18:05 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
- 2006-10-17 18:05 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
- 2006-05-10 05:22 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2006-05-10 05:22 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2009-04-20 17:17 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\DLLCACHE\dnsrslvr.dll
- 2010-12-09 14:30 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
+ 2010-12-09 14:30 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
+ 2005-06-13 14:25 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\csrsrv.dll
- 2005-06-13 14:25 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\csrsrv.dll
+ 2011-05-23 06:03 . 2011-05-23 06:03   61280              c:\windows\SYSTEM32\avgfwdx.dll
+ 2011-07-08 19:00 . 2011-07-08 19:00   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-09-23 21:55 . 2010-09-23 21:55   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 17:03 . 2011-07-07 17:03   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 09:17 . 2010-09-23 09:17   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 09:17 . 2010-09-23 09:17   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-10-20 01:51 . 2011-10-20 01:51   22016              c:\windows\Installer\36534e.msi
+ 2011-05-12 13:17 . 2011-05-12 13:17   24064              c:\windows\Installer\12b8f5e1.msi
- 2005-05-25 21:25 . 2011-03-12 00:08   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2011-03-12 00:22 . 2011-03-12 00:22   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2011-10-21 23:36 . 2011-10-21 23:36   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2011-03-11 23:41 . 2011-03-11 23:41   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-03-11 23:41 . 2011-10-21 23:42   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   12800              c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   66560              c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   55296              c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   43520              c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   25600              c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-07-07 15:42 . 2011-07-07 15:47   20137              c:\windows\hpqins11.dat
+ 2011-10-21 22:57 . 2011-10-21 22:57   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_64433b8a\System.Drawing.Design.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_a1f745d8\CustomMarshalers.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-10-22 00:22 . 2011-10-22 00:22   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-22 00:22 . 2011-10-22 00:22   82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-10-22 00:03 . 2011-10-22 00:03   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-10-22 00:01 . 2011-10-22 00:01   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-10-22 00:19 . 2011-10-22 00:19   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ba5f039c6cee5268d549382692b6e365\Microsoft.SqlServer.CustomControls.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-10-22 00:13 . 2011-10-22 00:13   14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-10-22 00:11 . 2011-10-22 00:11   25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-03-11 23:07 . 2011-03-11 23:07   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-21 22:56 . 2011-10-21 22:56   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-22 00:00 . 2010-11-03 13:12   46080              c:\windows\$NtUninstallKB2570791$\tzchange.exe
+ 2011-10-22 00:00 . 2011-07-09 00:32   16896              c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
+ 2011-10-21 23:00 . 2008-04-13 18:57   10112              c:\windows\$NtUninstallKB2566454$\ndistapi.sys
+ 2011-10-21 23:38 . 2002-08-29 10:00   16896              c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
+ 2011-10-21 23:02 . 2008-04-14 00:11   45568              c:\windows\$NtUninstallKB2509553$\dnsrslvr.dll
+ 2011-10-21 23:24 . 2010-12-09 14:30   33280              c:\windows\$NtUninstallKB2507938$\csrsrv.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2616676-v2\update\spcustom.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2616676-v2\spmsg.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2592799\spmsg.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   12800              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   66560              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   55296              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   43520              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   25600              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570947\spmsg.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570222\spmsg.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567680\spmsg.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567053\spmsg.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2566454\spmsg.dll
+ 2011-10-16 22:13 . 2011-07-08 13:51   10496              c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
+ 2011-10-21 22:59 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
+ 2011-10-21 22:59 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2562937\spmsg.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544893\update\spcustom.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544893\spmsg.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544521-IE8\update\spcustom.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544521-IE8\spmsg.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2541763\update\spcustom.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2541763\spmsg.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2535512\update\spcustom.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2535512\spmsg.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2510531-IE8\update\spcustom.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2510531-IE8\spmsg.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2509553\update\spcustom.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2509553\spmsg.dll
+ 2009-04-20 17:06 . 2009-04-20 17:06   45568              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsrslvr.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508429\update\spcustom.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508429\spmsg.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508272\update\spcustom.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508272\spmsg.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507938\spmsg.dll
+ 2011-04-26 11:02 . 2011-04-26 11:02   33280              c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507618\update\spcustom.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507618\spmsg.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2506212\update\spcustom.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2506212\spmsg.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2485663\update\spcustom.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2485663\spmsg.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2476490\update\spcustom.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2476490\spmsg.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-04-15 12:50 . 2011-02-17 12:32   5120              c:\windows\SYSTEM32\xpsp4res.dll
- 2009-04-15 12:50 . 2010-08-26 12:52   5120              c:\windows\SYSTEM32\xpsp4res.dll
- 2005-05-25 21:25 . 2011-03-12 00:08   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2011-03-11 23:55 . 2011-03-11 23:55   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-10-21 23:07 . 2010-08-26 12:52   5120              c:\windows\$NtUninstallKB2508429$\xpsp4res.dll
+ 2011-02-17 12:32 . 2011-02-17 12:32   5120              c:\windows\$hf_mig$\KB2508429\SP3QFE\xpsp4res.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
- 2005-06-13 14:25 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\winsrv.dll
+ 2005-06-13 14:25 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\winsrv.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\wininet.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\wininet.dll
+ 2005-06-13 14:25 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\vbscript.dll
- 2005-06-13 14:25 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\url.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\url.dll
+ 2008-07-30 00:59 . 2011-09-26 16:41   611328              c:\windows\SYSTEM32\uiautomationcore.dll
+ 2005-06-13 14:25 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\schannel.dll
+ 2011-06-22 17:47 . 2011-10-17 18:11   152788              c:\windows\SYSTEM32\rhttpmah.dat
+ 2010-12-24 14:18 . 2011-12-21 01:23   229224              c:\windows\SYSTEM32\Restore\rstrlog.dat
+ 2011-06-22 17:47 . 2011-10-17 18:11   320053              c:\windows\SYSTEM32\prinauiv.dat
+ 2003-09-10 20:15 . 2011-11-14 19:26   500748              c:\windows\SYSTEM32\PERFH009.DAT
- 2005-06-13 14:25 . 2008-04-14 00:12   551936              c:\windows\SYSTEM32\oleaut32.dll
+ 2005-06-13 14:25 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\oleaut32.dll
+ 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\oleacc.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\occache.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\occache.dll
- 2005-06-13 14:26 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\mswsock.dll
+ 2005-06-13 14:26 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\mswsock.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\mstime.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\mstime.dll
- 2006-11-08 03:03 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\msfeeds.dll
+ 2006-11-08 03:03 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\msfeeds.dll
- 2005-06-13 14:26 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\mfc42u.dll
+ 2005-06-13 14:26 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\mfc42u.dll
+ 2005-06-13 14:26 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\mfc42.dll
+ 2011-11-20 19:37 . 2011-11-20 19:37   247968              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.exe
+ 2011-11-20 19:37 . 2011-11-20 19:37   335520              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.dll
+ 2005-06-13 14:26 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\jscript.dll
- 2005-06-13 14:26 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\jscript.dll
+ 2011-12-26 15:32 . 2011-12-26 15:31   157472              c:\windows\SYSTEM32\javaws.exe
+ 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\javaw.exe
+ 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\java.exe
+ 2005-06-13 14:26 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\inetcomm.dll
- 2005-06-13 14:26 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\inetcomm.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\iepeers.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\iepeers.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\iedkcs32.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\iedkcs32.dll
+ 2005-06-13 14:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\ie4uinit.exe
+ 2002-09-03 18:42 . 2011-10-22 06:19   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
- 2002-09-03 18:42 . 2011-03-12 01:05   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2011-04-12 19:55 . 2011-10-17 18:48   825939              c:\windows\SYSTEM32\dskquouh.dat
+ 2005-06-13 14:25 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DRIVERS\srv.sys
- 2005-06-13 14:25 . 2008-04-14 00:13   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
+ 2005-06-13 14:25 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
+ 2005-06-13 14:25 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DRIVERS\mup.sys
+ 2005-06-13 14:25 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   295248              c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
+ 2011-07-11 06:14 . 2011-07-11 06:14   134608              c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys
+ 2005-06-13 14:25 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
- 2005-06-13 14:25 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
+ 2005-06-13 14:27 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\dnsapi.dll
- 2010-06-18 17:45 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2010-06-18 17:45 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
+ 2006-09-18 14:15 . 2011-04-30 03:01   758784              c:\windows\SYSTEM32\DLLCACHE\vgx.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\DLLCACHE\vbscript.dll
- 2006-10-17 18:05 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2006-10-17 18:05 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2008-10-15 03:09 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DLLCACHE\srv.sys
+ 2008-12-05 06:54 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\DLLCACHE\schannel.dll
+ 2011-10-16 22:20 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DLLCACHE\rdpwd.sys
+ 2010-12-20 17:32 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\DLLCACHE\oleaut32.dll
+ 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\DLLCACHE\oleacc.dll
- 2006-10-17 18:04 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2006-10-17 18:04 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2011-10-16 22:18 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DLLCACHE\mup.sys
+ 2008-06-20 17:46 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
- 2008-06-20 17:46 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
+ 2006-05-10 05:23 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2006-05-10 05:23 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
- 2007-05-09 16:55 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2007-05-09 16:55 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
+ 2006-10-14 08:13 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
- 2006-10-14 08:13 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
+ 2011-03-11 13:42 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\DLLCACHE\mfc42.dll
+ 2008-05-09 10:53 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
- 2008-05-09 10:53 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
- 2008-08-12 18:56 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2008-08-12 18:56 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
+ 2009-06-10 13:02 . 2011-08-22 23:48   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
- 2009-06-10 13:02 . 2010-12-20 23:59   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
+ 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
- 2011-03-11 13:36 . 2010-12-20 23:59   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
+ 2011-03-11 13:36 . 2011-08-22 23:48   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
+ 2006-11-07 09:27 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
- 2006-11-07 09:27 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
+ 2006-11-07 09:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
+ 2008-06-20 17:46 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\DLLCACHE\dnsapi.dll
+ 2005-06-13 14:27 . 2008-04-14 00:11   640000              c:\windows\SYSTEM32\DLLCACHE\dbghelp.dll
+ 2011-09-09 09:12 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\DLLCACHE\crypt32.dll
+ 2011-01-07 14:09 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\DLLCACHE\atmfd.dll
+ 2008-06-20 11:40 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
+ 2005-06-13 14:27 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\crypt32.dll
- 2005-06-13 14:27 . 2008-04-14 00:11   599040              c:\windows\SYSTEM32\crypt32.dll
+ 2005-06-13 14:27 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\atmfd.dll
- 2010-05-11 12:40 . 2010-05-11 12:40   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-03-25 11:15 . 2011-03-25 11:15   363856              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-05-11 12:40 . 2010-05-11 12:40   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 17:04 . 2011-07-07 17:04   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 08:25 . 2010-09-23 08:25   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 17:01 . 2011-07-07 17:01   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 09:17 . 2010-09-23 09:17   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 18:09 . 2011-07-07 18:09   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-05-10 12:37 . 2011-05-10 12:37   689152              c:\windows\Installer\844cd51.msi
+ 2011-12-26 15:31 . 2011-12-26 15:31   901120              c:\windows\Installer\4975043.msi
+ 2011-10-17 18:27 . 2011-10-17 18:27   219648              c:\windows\Installer\3d86bf5d.msi
+ 2011-07-07 15:44 . 2011-07-07 15:44   344576              c:\windows\Installer\1da16103.msi
- 2005-05-25 21:25 . 2011-03-12 00:08   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2005-05-25 21:25 . 2011-10-21 23:38   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2005-05-25 21:25 . 2011-03-12 00:08   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2005-05-25 21:25 . 2011-10-21 23:37   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2011-05-10 12:35 . 2011-05-10 12:35   371272              c:\windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
+ 2011-10-21 23:10 . 2010-12-20 23:59   916480              c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-21 23:10 . 2009-03-08 09:34   105984              c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:10 . 2010-12-20 23:59   206848              c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   611840              c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   602112              c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   247808              c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   184320              c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   743424              c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-21 23:11 . 2010-12-20 23:59   387584              c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-21 23:11 . 2010-12-20 12:55   173568              c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-10-21 23:00 . 2009-03-08 09:33   759296              c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:02 . 2010-03-10 06:15   420352              c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-10-21 23:02 . 2009-12-09 05:53   726528              c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2009-08-15 20:11 . 2011-07-07 15:51   116264              c:\windows\hpoins33.dat
+ 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\Driver Cache\I386\mrxsmb.sys
+ 2011-10-21 22:58 . 2011-10-21 22:58   835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b7a8f596\System.Drawing.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fd54f924\System.Drawing.Design.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_c86fa1ef\CustomMarshalers.dll
+ 2011-10-22 00:16 . 2011-10-22 00:16   321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-10-22 00:09 . 2011-10-22 00:09   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   187904              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-10-22 00:29 . 2011-10-22 00:29   400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   859648              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   328704              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   301056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
+ 2011-10-22 00:26 . 2011-10-22 00:26   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dl
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 27, 2011, 03:37:16 PM
+ 2011-10-22 00:26 . 2011-10-22 00:26   627200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-10-22 00:26 . 2011-10-22 00:26   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   679936              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   311296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   621056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   998400              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   330752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-10-22 00:11 . 2011-10-22 00:11   381440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-10-22 00:11 . 2011-10-22 00:11   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   280064              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   627712              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-10-22 00:06 . 2011-10-22 00:06   208384              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   455680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   881152              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   939008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   354816              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   756736              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
+ 2011-10-22 00:22 . 2011-10-22 00:22   135680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   971264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-10-22 00:21 . 2011-10-22 00:21   633856              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-10-22 00:15 . 2011-10-22 00:15   366080              c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-10-22 00:15 . 2011-10-22 00:15   256000              c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2011-10-22 00:15 . 2011-10-22 00:15   320512              c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
+ 2011-10-22 00:04 . 2011-10-22 00:04   539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-10-22 00:04 . 2011-10-22 00:04   368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-10-22 00:04 . 2011-10-22 00:04   224768              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-10-22 00:04 . 2011-10-22 00:04   258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   133632              c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-10-22 00:14 . 2011-10-22 00:14   386560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-10-22 00:21 . 2011-10-22 00:21   989184              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\bae550eab1420c5c5281e115e0ecd6cb\Microsoft.SqlServer.WizardFrameworkLite.ni.dll
+ 2011-10-22 00:19 . 2011-10-22 00:19   530432              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\b43153b1799dfe26e130630eb467aefd\Microsoft.SqlServer.GridControl.ni.dll
+ 2011-10-22 00:21 . 2011-10-22 00:21   355840              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\1eeab1daf96463188df131a0822ece69\Microsoft.SqlServer.Setup.ni.dll
+ 2011-10-22 00:18 . 2011-10-22 00:18   231936              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\e9b9b40429d65e4c254a7caa8a957c4b\Microsoft.NetEnterpriseServers.ExceptionMessageBox.ni.dll
+ 2011-10-22 00:18 . 2011-10-22 00:18   144384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-10-22 00:18 . 2011-10-22 00:18   175104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   839680              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   222720              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   220672              c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-10-22 00:13 . 2011-10-22 00:13   410112              c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2011-10-22 00:11 . 2011-10-22 00:11   842240              c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-03-11 23:54 . 2011-03-11 23:54   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2616676-v2$\spuninst\updspapi.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2616676-v2$\spuninst\spuninst.exe
+ 2011-10-21 23:23 . 2008-04-14 00:11   599040              c:\windows\$NtUninstallKB2616676-v2$\crypt32.dll
+ 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2592799$\spuninst\updspapi.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2592799$\spuninst\spuninst.exe
+ 2011-10-21 23:14 . 2008-10-16 14:43   138496              c:\windows\$NtUninstallKB2592799$\afd.sys
+ 2011-10-21 23:09 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570947$\spuninst\updspapi.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570947$\spuninst\spuninst.exe
+ 2011-10-22 00:00 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
+ 2011-10-22 00:00 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
+ 2011-10-21 23:13 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570222$\spuninst\updspapi.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570222$\spuninst\spuninst.exe
+ 2011-10-21 23:13 . 2008-04-14 00:13   139656              c:\windows\$NtUninstallKB2570222$\rdpwd.sys
+ 2011-10-21 23:40 . 2011-04-26 11:07   293376              c:\windows\$NtUninstallKB2567680$\winsrv.dll
+ 2011-10-21 23:40 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2567680$\spuninst\updspapi.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2567680$\spuninst\spuninst.exe
+ 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2567053$\spuninst\updspapi.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2567053$\spuninst\spuninst.exe
+ 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2566454$\spuninst\updspapi.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2566454$\spuninst\spuninst.exe
+ 2011-10-21 23:38 . 2008-07-30 00:59   161296              c:\windows\$NtUninstallKB2564958$\uiautomationcore.dll
+ 2011-10-21 23:38 . 2011-08-12 18:51   382840              c:\windows\$NtUninstallKB2564958$\spuninst\updspapi.dll
+ 2011-10-21 23:38 . 2011-08-12 18:51   231288              c:\windows\$NtUninstallKB2564958$\spuninst\spuninst.exe
+ 2011-10-21 23:38 . 2002-08-29 10:00   163328              c:\windows\$NtUninstallKB2564958$\oleacc.dll
+ 2011-10-21 22:59 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2562937$\spuninst\updspapi.dll
+ 2011-10-21 22:59 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2562937$\spuninst\spuninst.exe
+ 2011-10-21 23:03 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2544893$\spuninst\updspapi.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2544893$\spuninst\spuninst.exe
+ 2011-10-21 23:03 . 2010-06-09 07:43   692736              c:\windows\$NtUninstallKB2544893$\inetcomm.dll
+ 2011-10-21 23:01 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2541763$\spuninst\updspapi.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2541763$\spuninst\spuninst.exe
+ 2011-10-21 23:01 . 2010-06-30 12:31   149504              c:\windows\$NtUninstallKB2541763$\schannel.dll
+ 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2536276-v2$\spuninst\updspapi.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe
+ 2011-10-21 23:25 . 2010-02-24 13:11   455680              c:\windows\$NtUninstallKB2536276-v2$\mrxsmb.sys
+ 2011-10-21 23:10 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2535512$\spuninst\updspapi.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2535512$\spuninst\spuninst.exe
+ 2011-10-21 23:10 . 2008-04-13 19:17   105344              c:\windows\$NtUninstallKB2535512$\mup.sys
+ 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2509553$\spuninst\updspapi.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2509553$\spuninst\spuninst.exe
+ 2011-10-21 23:02 . 2008-06-20 17:46   245248              c:\windows\$NtUninstallKB2509553$\mswsock.dll
+ 2011-10-21 23:02 . 2008-06-20 17:46   147968              c:\windows\$NtUninstallKB2509553$\dnsapi.dll
+ 2011-10-21 23:02 . 2008-08-14 10:04   138496              c:\windows\$NtUninstallKB2509553$\afd.sys
+ 2011-10-21 23:07 . 2010-08-26 13:39   357248              c:\windows\$NtUninstallKB2508429$\srv.sys
+ 2011-10-21 23:07 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2508429$\spuninst\updspapi.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2508429$\spuninst\spuninst.exe
+ 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2508272$\spuninst\updspapi.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2508272$\spuninst\spuninst.exe
+ 2011-10-21 23:24 . 2010-06-18 17:45   293376              c:\windows\$NtUninstallKB2507938$\winsrv.dll
+ 2011-10-21 23:24 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2507938$\spuninst\updspapi.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2507938$\spuninst\spuninst.exe
+ 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2507618$\spuninst\updspapi.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2507618$\spuninst\spuninst.exe
+ 2011-10-21 23:08 . 2011-01-07 14:09   290048              c:\windows\$NtUninstallKB2507618$\atmfd.dll
+ 2011-10-21 23:06 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2506212$\spuninst\updspapi.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2506212$\spuninst\spuninst.exe
+ 2011-10-21 23:06 . 2010-09-18 18:23   974848              c:\windows\$NtUninstallKB2506212$\mfc42u.dll
+ 2011-10-21 23:06 . 2010-09-18 06:53   974848              c:\windows\$NtUninstallKB2506212$\mfc42.dll
+ 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2485663$\spuninst\updspapi.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2485663$\spuninst\spuninst.exe
+ 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2476490$\spuninst\updspapi.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2476490$\spuninst\spuninst.exe
+ 2011-10-21 23:23 . 2008-04-14 00:12   551936              c:\windows\$NtUninstallKB2476490$\oleaut32.dll
+ 2011-10-21 23:09 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB2412687$\spuninst\updspapi.dll
+ 2011-10-21 23:09 . 2009-05-26 11:40   231288              c:\windows\$NtUninstallKB2412687$\spuninst\spuninst.exe
+ 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2616676-v2\update\updspapi.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2616676-v2\update\update.exe
+ 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2616676-v2\spuninst.exe
+ 2011-09-09 09:11 . 2011-09-09 09:11   599552              c:\windows\$hf_mig$\KB2616676-v2\SP3QFE\crypt32.dll
+ 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2592799\update\updspapi.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2592799\update\update.exe
+ 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2592799\spuninst.exe
+ 2011-10-16 22:20 . 2011-08-17 13:41   138496              c:\windows\$hf_mig$\KB2592799\SP3QFE\afd.sys
+ 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2586448-IE8\update\updspapi.dll
+ 2011-10-21 23:11 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2586448-IE8\update\update.exe
+ 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2586448-IE8\spuninst.exe
+ 2011-10-16 22:20 . 2011-08-22 23:47   919552              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   105984              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\url.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   206848              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\occache.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   611840              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mstime.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   602112              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeeds.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   247808              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieproxy.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   184320              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iepeers.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   743424              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedvtool.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   387584              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedkcs32.dll
+ 2011-10-16 22:20 . 2011-08-22 11:52   174080              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ie4uinit.exe
+ 2011-10-21 23:09 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2570947\update\updspapi.dll
+ 2011-10-21 23:09 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2570947\update\update.exe
+ 2011-10-21 23:09 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2570947\spuninst.exe
+ 2011-10-21 23:13 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2570222\update\updspapi.dll
+ 2011-10-21 23:13 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2570222\update\update.exe
+ 2011-10-21 23:13 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2570222\spuninst.exe
+ 2011-10-16 22:20 . 2011-06-24 14:09   139656              c:\windows\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys
+ 2011-10-21 23:40 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2567680\update\updspapi.dll
+ 2011-10-21 23:40 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2567680\update\update.exe
+ 2011-10-21 23:40 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2567680\spuninst.exe
+ 2011-06-20 17:43 . 2011-06-20 17:43   293376              c:\windows\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
+ 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2567053\update\updspapi.dll
+ 2011-10-21 23:14 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2567053\update\update.exe
+ 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2567053\spuninst.exe
+ 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2566454\update\updspapi.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2566454\update\update.exe
+ 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2566454\spuninst.exe
+ 2011-10-21 22:59 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2562937\update\updspapi.dll
+ 2011-10-21 22:59 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2562937\update\update.exe
+ 2011-10-21 22:59 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2562937\spuninst.exe
+ 2011-10-21 23:03 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2544893\update\updspapi.dll
+ 2011-10-21 23:03 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2544893\update\update.exe
+ 2011-10-21 23:03 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2544893\spuninst.exe
+ 2011-10-16 22:15 . 2011-05-02 15:30   692736              c:\windows\$hf_mig$\KB2544893\SP3QFE\inetcomm.dll
+ 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2544521-IE8\update\updspapi.dll
+ 2011-10-21 23:00 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2544521-IE8\update\update.exe
+ 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2544521-IE8\spuninst.exe
+ 2011-10-16 22:13 . 2011-04-30 02:59   758784              c:\windows\$hf_mig$\KB2544521-IE8\SP3QFE\vgx.dll
+ 2011-10-21 23:01 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2541763\update\updspapi.dll
+ 2011-10-21 23:01 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2541763\update\update.exe
+ 2011-10-21 23:01 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2541763\spuninst.exe
+ 2011-04-29 17:23 . 2011-04-29 17:23   151552              c:\windows\$hf_mig$\KB2541763\SP3QFE\schannel.dll
+ 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2536276-v2\update\updspapi.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2536276-v2\update\update.exe
+ 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2536276-v2\spuninst.exe
+ 2011-10-16 22:22 . 2011-07-15 13:29   457856              c:\windows\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys
+ 2011-10-21 23:10 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2535512\update\updspapi.dll
+ 2011-10-21 23:10 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2535512\update\update.exe
+ 2011-10-21 23:10 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2535512\spuninst.exe
+ 2011-10-16 22:18 . 2011-04-21 13:52   105472              c:\windows\$hf_mig$\KB2535512\SP3QFE\mup.sys
+ 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2510531-IE8\update\updspapi.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2510531-IE8\update\update.exe
+ 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2510531-IE8\spuninst.exe
+ 2011-10-16 22:14 . 2011-03-04 06:35   420864              c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\vbscript.dll
+ 2011-10-16 22:14 . 2011-03-04 06:35   726528              c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\jscript.dll
+ 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2509553\update\updspapi.dll
+ 2011-10-21 23:02 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2509553\update\update.exe
+ 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2509553\spuninst.exe
+ 2008-06-20 11:16 . 2008-06-20 11:16   225856              c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip6.sys
+ 2008-06-20 11:59 . 2008-06-20 11:59   361600              c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
+ 2008-06-20 17:43 . 2008-06-20 17:43   245248              c:\windows\$hf_mig$\KB2509553\SP3QFE\mswsock.dll
+ 2011-03-03 06:53 . 2011-03-03 06:53   149504              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsapi.dll
+ 2008-10-16 15:07 . 2008-10-16 15:07   138496              c:\windows\$hf_mig$\KB2509553\SP3QFE\afd.sys
+ 2011-10-21 23:07 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2508429\update\updspapi.dll
+ 2011-10-21 23:07 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2508429\update\update.exe
+ 2011-10-21 23:07 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2508429\spuninst.exe
+ 2011-02-17 13:19 . 2011-02-17 13:19   357888              c:\windows\$hf_mig$\KB2508429\SP3QFE\srv.sys
+ 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2508272\update\updspapi.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2508272\update\update.exe
+ 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2508272\spuninst.exe
+ 2011-10-21 23:24 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2507938\update\updspapi.dll
+ 2011-10-21 23:24 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2507938\update\update.exe
+ 2011-10-21 23:24 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2507938\spuninst.exe
+ 2011-04-26 11:02 . 2011-04-26 11:02   293376              c:\windows\$hf_mig$\KB2507938\SP3QFE\winsrv.dll
+ 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2507618\update\updspapi.dll
+ 2011-10-21 23:08 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2507618\update\update.exe
+ 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2507618\spuninst.exe
+ 2011-02-15 13:05 . 2011-02-15 13:05   290432              c:\windows\$hf_mig$\KB2507618\SP3QFE\atmfd.dll
+ 2011-10-21 23:06 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2506212\update\updspapi.dll
+ 2011-10-21 23:06 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2506212\update\update.exe
+ 2011-10-21 23:06 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2506212\spuninst.exe
+ 2011-02-08 13:32 . 2011-02-08 13:32   974848              c:\windows\$hf_mig$\KB2506212\SP3QFE\mfc42u.dll
+ 2011-02-08 13:32 . 2011-02-08 13:32   978944              c:\windows\$hf_mig$\KB2506212\SP3QFE\mfc42.dll
+ 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2485663\update\updspapi.dll
+ 2011-10-21 23:25 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2485663\update\update.exe
+ 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2485663\spuninst.exe
+ 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2476490\update\updspapi.dll
+ 2011-10-21 23:23 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2476490\update\update.exe
+ 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2476490\spuninst.exe
+ 2010-12-20 17:30 . 2010-12-20 17:30   552448              c:\windows\$hf_mig$\KB2476490\SP3QFE\oleaut32.dll
+ 2011-10-16 22:18 . 2010-10-23 00:51   1748992              c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   3780424              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02   3765048              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2011-04-12 13:35 . 2011-10-17 18:48   1806809              c:\windows\SYSTEM32\wmdrmcet.dat
+ 2005-06-13 14:25 . 2011-09-06 13:20   1858944              c:\windows\SYSTEM32\win32k.sys
+ 2005-06-13 14:25 . 2011-08-22 23:48   1212416              c:\windows\SYSTEM32\urlmon.dll
+ 2011-04-12 13:35 . 2011-10-17 18:48   2169147              c:\windows\SYSTEM32\rdpwoxt.dat
+ 2005-06-13 14:26 . 2011-10-03 08:35   5971456              c:\windows\SYSTEM32\mshtml.dll
+ 2006-10-17 17:57 . 2011-08-22 23:48   2000384              c:\windows\SYSTEM32\iertutil.dll
+ 2008-10-15 03:07 . 2011-09-06 13:20   1858944              c:\windows\SYSTEM32\DLLCACHE\win32k.sys
+ 2005-06-13 14:25 . 2011-08-22 23:48   1212416              c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2005-06-13 14:26 . 2011-10-03 08:35   5971456              c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2007-05-09 16:55 . 2011-08-22 23:48   2000384              c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
- 2008-07-25 16:17 . 2008-07-25 16:17   5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2011-03-25 11:15 . 2011-03-25 11:15   5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2011-04-29 02:50 . 2011-04-29 02:50   3182592              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2010-03-23 11:32 . 2010-03-23 11:32   3182592              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   5912400              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2011-07-07 10:18 . 2011-07-07 10:18   4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-05-11 12:40 . 2010-05-11 12:40   4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 21:55 . 2010-09-23 21:55   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 21:55 . 2010-09-23 21:55   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 08:26 . 2010-09-23 08:26   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 17:02 . 2011-07-07 17:02   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 17:02 . 2011-07-07 17:02   2527232              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2011-07-08 18:59 . 2011-07-08 18:59   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-09-23 21:55 . 2010-09-23 21:55   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-05-10 12:35 . 2011-05-10 12:35   1587200              c:\windows\Installer\844cd40.msi
+ 2011-05-02 05:06 . 2011-05-02 05:06   2705920              c:\windows\Installer\67395e.msp
+ 2011-08-10 22:43 . 2011-08-10 22:43   3795968              c:\windows\Installer\673937.msp
+ 2011-04-29 17:28 . 2011-04-29 17:28   1995264              c:\windows\Installer\673923.msp
+ 2011-09-07 02:48 . 2011-09-07 02:48   8181248              c:\windows\Installer\4bcc47.msp
+ 2011-07-27 12:39 . 2011-07-27 12:39   9892352              c:\windows\Installer\4bcc3e.msp
+ 2011-04-28 17:23 . 2011-04-28 17:23   9607680              c:\windows\Installer\4bcc35.msp
+ 2011-02-25 19:25 . 2011-02-25 19:25   7968256              c:\windows\Installer\4bcc21.msp
+ 2011-04-29 17:30 . 2011-04-29 17:30   1197056              c:\windows\Installer\4bcc0d.msp
+ 2011-12-21 02:35 . 2011-12-21 02:35   2186240              c:\windows\Installer\3fa695.msi
+ 2011-12-23 15:24 . 2011-12-23 15:24   4683264              c:\windows\Installer\30d1d98.msi
+ 2011-10-18 07:39 . 2011-10-18 07:39   2188288              c:\windows\Installer\2c57fc6.msi
+ 2011-11-20 17:55 . 2011-11-20 17:55   3976192              c:\windows\Installer\1e8a474e.msi
+ 2009-04-03 23:21 . 2009-04-03 23:21   8543096              c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\OARTCONV.DLL
+ 2011-10-21 23:10 . 2010-12-20 23:59   1210880              c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   5961216              c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
+ 2011-10-21 23:10 . 2010-12-20 23:59   1991680              c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
+ 2011-10-21 23:32 . 2011-10-21 23:32   5025792              c:\windows\assembly\tmp\IQW39FLR\System.Windows.Forms.dll
+ 2011-10-21 23:48 . 2011-10-21 23:48   5062656              c:\windows\assembly\tmp\CKQW28EK\System.Design.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   1966080              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_da70838c\System.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   4792320              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_224a84f6\System.dll
+ 2011-10-21 22:59 . 2011-10-21 22:59   5513216              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_63f518c9\System.Xml.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   2088960              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_02b3d94d\System.Xml.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   3018752              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_3bf48c04\System.Windows.Forms.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   7884800              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_283f0e1f\System.Windows.Forms.dll
+ 2011-10-21 22:59 . 2011-10-21 22:59   2244608              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_d189fe0c\System.Drawing.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   1470464              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_a5054d6d\System.Design.dll
+ 2011-10-21 22:59 . 2011-10-21 22:59   3395584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_2e168141\System.Design.dll
+ 2011-10-21 22:58 . 2011-10-21 22:58   3391488              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_825915cd\mscorlib.dll
+ 2011-10-21 22:59 . 2011-10-21 22:59   8908800              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_56394594\mscorlib.dll
+ 2011-10-22 00:01 . 2011-10-22 00:01   3325440              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
+ 2011-10-22 00:08 . 2011-10-22 00:08   1049600              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
+ 2011-10-22 00:01 . 2011-10-22 00:01   7950848              c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
+ 2011-10-22 00:07 . 2011-10-22 00:07   5450752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
+ 2011-10-22 00:29 . 2011-10-22 00:29   1356288              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
+ 2011-10-22 00:29 . 2011-10-22 00:29   1908224              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
+ 2011-10-22 00:29 . 2011-10-22 00:29   4514304              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   2992640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
+ 2011-10-22 00:28 . 2011-10-22 00:28   2209280              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
+ 2011-10-22 00:27 . 2011-10-22 00:27   2405376              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
+ 2011-10-22 00:06 . 2011-10-22 00:06   1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
+ 2011-10-22 00:26 . 2011-10-22 00:26   1706496              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
+ 2011-10-22 00:11 . 2011-10-22 00:11   2345472              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
+ 2011-10-22 00:06 . 2011-10-22 00:06   1035776              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
+ 2011-10-22 00:11 . 2011-10-22 00:11   1070080              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
+ 2011-10-22 00:06 . 2011-10-22 00:06   1587200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   1116672              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   1801216              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
+ 2011-10-22 00:05 . 2011-10-22 00:05   6616576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   2510336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
+ 2011-10-22 00:24 . 2011-10-22 00:24   1328128              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
+ 2011-10-22 00:05 . 2011-10-22 00:05   2516480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
+ 2011-10-22 00:23 . 2011-10-22 00:23   9924096              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
+ 2011-10-22 00:05 . 2011-10-22 00:05   2295296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
+ 2011-10-22 00:04 . 2011-10-22 00:04   2128896              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
+ 2011-10-22 00:04 . 2011-10-22 00:04   1657856              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
+ 2011-10-22 00:01 . 2011-10-22 00:01   1451008              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
+ 2011-10-22 00:21 . 2011-10-22 00:21   1712128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
+ 2011-10-22 00:14 . 2011-10-22 00:14   1093120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
+ 2011-10-22 00:25 . 2011-10-22 00:25   2332160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   1620992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
+ 2011-10-22 00:18 . 2011-10-22 00:18   1966080              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-10-22 00:17 . 2011-10-22 00:17   1888768              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   3182592              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   3182592              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-03-11 23:54 . 2011-03-11 23:54   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-10-21 23:57 . 2011-10-21 23:57   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-03-11 23:54 . 2011-03-11 23:54   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-10-21 23:58 . 2011-10-21 23:58   4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-03-11 23:55 . 2011-03-11 23:55   4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2011-03-11 23:07 . 2011-03-11 23:07   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-10-21 22:57 . 2011-10-21 22:57   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-03-11 23:07 . 2011-03-11 23:07   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-10-21 23:14 . 2010-12-31 13:10   1854976              c:\windows\$NtUninstallKB2567053$\win32k.sys
+ 2011-10-16 22:20 . 2011-08-22 23:47   1214464              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\urlmon.dll
+ 2011-10-16 22:19 . 2011-10-03 08:34   5972992              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll
+ 2011-10-16 22:20 . 2011-08-22 23:47   2001408              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iertutil.dll
+ 2011-09-06 13:25 . 2011-09-06 13:25   1867904          &
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 27, 2011, 03:39:39 PM
+ 2011-09-06 13:25 . 2011-09-06 13:25   1867904              c:\windows\$hf_mig$\KB2567053\SP3QFE\win32k.sys
+ 2011-03-12 00:10 . 2011-10-05 15:09   48324552              c:\windows\SYSTEM32\MRT.exe
+ 2006-11-08 03:03 . 2011-08-23 22:48   11081728              c:\windows\SYSTEM32\ieframe.dll
+ 2007-05-09 16:55 . 2011-08-23 22:48   11081728              c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
+ 2011-07-13 03:49 . 2011-07-13 03:49   11459584              c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-09-11 17:24 . 2011-09-11 17:24   20333056              c:\windows\Installer\9ea8b19.msp
+ 2011-03-28 08:27 . 2011-03-28 08:27   15456256              c:\windows\Installer\673967.msp
+ 2011-10-21 23:41 . 2011-10-21 23:41   20333568              c:\windows\Installer\673957.msp
+ 2011-04-28 00:21 . 2011-04-28 00:21   17515520              c:\windows\Installer\67394b.msp
+ 2011-07-12 01:43 . 2011-07-12 01:43   11641344              c:\windows\Installer\67392e.msp
+ 2011-07-12 20:50 . 2011-07-12 20:50   17555968              c:\windows\Installer\4bcc05.msp
+ 2011-01-30 20:44 . 2011-01-30 20:44   12425728              c:\windows\Installer\12b8f5e8.msp
+ 2011-10-21 23:10 . 2010-12-21 11:29   11080704              c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
+ 2011-10-22 00:07 . 2011-10-22 00:07   12430848              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2011-10-22 00:26 . 2011-10-22 00:26   11800576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
+ 2011-10-22 00:12 . 2011-10-22 00:12   17403904              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
+ 2011-10-22 00:06 . 2011-10-22 00:06   10683392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
+ 2011-10-22 00:03 . 2011-10-22 00:03   14328320              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-10-22 00:02 . 2011-10-22 00:02   12215808              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-10-22 00:00 . 2011-10-22 00:00   11490816              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
+ 2011-10-21 23:38 . 2011-10-21 23:39   11490816              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\44ecf972f11f3c238782da31f27df7e5\mscorlib.ni.dll
+ 2011-10-16 22:19 . 2011-08-22 23:47   11084288              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieframe.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-12 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-09-16 63048]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54   551296   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-09-27 00:15   87424   ----a-w-   c:\windows\SYSTEM32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ      autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Icatch(VI) SnapDetect.lnk
backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Interstate Hotels & Resorts IHRCO VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Interstate Hotels & Resorts IHRCO VPN Client.lnk
backup=c:\windows\pss\Interstate Hotels & Resorts IHRCO VPN Client.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Daniel Clark^Start Menu^Programs^Startup^Adobe Media Player.lnk]
path=c:\documents and settings\Daniel Clark\Start Menu\Programs\Startup\Adobe Media Player.lnk
backup=c:\windows\pss\Adobe Media Player.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Daniel Clark^Start Menu^Programs^Startup^ChefTec Reset.lnk]
path=c:\documents and settings\Daniel Clark\Start Menu\Programs\Startup\ChefTec Reset.lnk
backup=c:\windows\pss\ChefTec Reset.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-12-17 17:28   684032   ----a-w-   c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 09:59   122880   ----a-w-   c:\windows\BCMSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12   15360   ----a-w-   c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 17:09   460784   ----a-w-   c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 15:55   206064   ----a-w-   c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 15:24   16384   ----a-w-   c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-06-22 04:44   126976   ----a-w-   c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-06-26 23:50   212992   ----a-w-   c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-06-10 01:55   49208   ----a-w-   c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-08-20 15:54   150016   ----a-w-   c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-06-22 04:48   155648   ----a-w-   c:\windows\SYSTEM32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12   1695232   ----a-w-   c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2003-09-10 20:35   26112   ----a-w-   c:\program files\Real\RealPlayer\realplay.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys [7/11/2011 12:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [9/13/2011 5:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [7/11/2011 12:13 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [7/11/2011 12:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 10:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 3:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 5:38 PM 116608]
R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [11/23/2011 2:36 AM 2391832]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [9/26/2011 6:15 PM 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [9/16/2011 3:10 PM 12856]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/11/2010 12:39 PM 366152]
R2 MSSQL$CSS;MSSQL$CSS;c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe -sCSS --> c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe -sCSS [?]
R2 MSSQL$CSS2;SQL Server (CSS2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 5:29 PM 29293408]
R3 Avgfwdx;Avgfwdx;c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys [5/23/2011 12:03 AM 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys [7/11/2011 12:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys [7/11/2011 12:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\SYSTEM32\DRIVERS\AVGIDSShim.sys [7/11/2011 12:14 AM 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [1/11/2010 12:39 PM 22216]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2011 7:18 AM 136176]
S3 Avgfwfd;AVG network filter service;c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys [5/23/2011 12:03 AM 30944]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2011 7:18 AM 136176]
S3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\lne100v5.sys [1/12/2004 12:04 PM 36013]
S3 SQLAgent$CSS;SQLAgent$CSS;c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlagent.EXE -i CSS --> c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlagent.EXE -i CSS [?]
S3 w89c940;Winbond W89C940 PCI Ethernet Adapter Driver;c:\windows\SYSTEM32\DRIVERS\w940nd.sys [1/13/2004 1:03 PM 16925]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\SYSTEM32\DRIVERS\wdcsam.sys [5/6/2008 3:06 PM 11520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-12 13:17]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-12 13:17]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147073921-3723718213-2921723908-1006Core.job
- c:\documents and settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-12-22 01:44]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147073921-3723718213-2921723908-1006UA.job
- c:\documents and settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-12-22 01:44]
.
2011-12-27 c:\windows\Tasks\User_Feed_Synchronization-{FB6057FE-6229-43CA-8B76-5EBAF0C57540}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://webaccess3.columbiasussex.com/gw/webacc
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - hxxp://10.73.30.30:8080/emc/setup.exe
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{5593D7A0-DC14-F3E4-89C6-0CC23DCD7B64} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-27 10:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Fdc]
"ImagePath"=multi:"System32\DRIVERS\fdc.sys\00"
--
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Flpydisk]
"ImagePath"=multi:"System32\DRIVERS\flpydisk.sys\00"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Fdc]
"ImagePath"=multi:"System32\DRIVERS\fdc.sys\00"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Flpydisk]
"ImagePath"=multi:"System32\DRIVERS\flpydisk.sys\00"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5 977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2a,8f,5e,d4,e0,b1,49,4d,94,30,a7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839 E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2a,8f,5e,d4,e0,b1,49,4d,94,30,a7,\
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\0a\03\13\1255X"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(2008)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(1856)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\ihrcovpn\IHRCO VPN Client\cvpnd.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\sessmgr.exe
.
**************************************************************************
.
Completion time: 2011-12-27  10:13:48 - machine was rebooted
ComboFix-quarantined-files.txt  2011-12-27 16:13
ComboFix2.txt  2011-05-08 18:18
ComboFix3.txt  2011-03-26 20:32
.
Pre-Run: 53,580,627,968 bytes free
Post-Run: 53,720,207,360 bytes free
.
- - End Of File - - A5B1FE122BEAB5813C4C5B64AC74B0B0
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: SuperDave on December 27, 2011, 05:05:26 PM
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/ (http://sites.google.com/site/sysprotantirootkit/)

Unzip it into a folder on your desktop.
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: jefraz on December 28, 2011, 07:54:23 AM
SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: Combo-Fix.sys
Service Name: ---
Module Base: F7647000
Module End: F7656000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: AEE01000
Module End: AEE19000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7995000
Module End: F7997000
Hidden: Yes

Module Name: \??\C:\ComboFix\catchme.sys
Service Name: catchme
Module Base: F77CF000
Module End: F77D7000
Hidden: Yes

Module Name: \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
Service Name: ---
Module Base: F79E5000
Module End: F79E7000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwOpenProcess
Address: AEC85F3C
Driver Base: AEC85000
Driver End: AEC88000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

Function Name: ZwTerminateProcess
Address: AEC85FE4
Driver Base: AEC85000
Driver End: AEC88000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

Function Name: ZwTerminateThread
Address: AEC86080
Driver Base: AEC85000
Driver End: AEC88000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

Function Name: ZwWriteVirtualMemory
Address: AEC8611C
Driver Base: AEC85000
Driver End: AEC88000
Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Collab\RSS
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Collab
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JavaScripts
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JSADM.exv
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\UserCache.bin
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.heu
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.swz
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\cacheSize.txt
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\AdobeUM
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\cert8.db
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\info.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\key3.db
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources\CurrentSettings.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources\Downloads
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\secmod.db
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim269.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim2DF.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim31C.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim328.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim334.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim34B.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim6AA.tmp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\urlcache.dat
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\userinfo.bag
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\0201D20472
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\0201E068C0
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\2B0000196C
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\0201D20472
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\0201E068C0
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\2B0000196C
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\2B00001FB4
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1024\2B0000023C
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1024
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\129\0201D2530B
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\129
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\3\05696D73656E64
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\3
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources\CurrentSettings.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources\Downloads
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\Contacts_cevenol.lst
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\imcatcher.cfc
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\immessages.dat
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\DESKTOP.INI
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\gtny\88D7456F-2D0E-40AA-BDBC-7BC292A1FF1A_CONFIRM.cache
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\gtny
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\channels.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chdata\chdata.cfg
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chdata
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chn.pk
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\DellSupportODBK.exe
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\DellSupportODBK.log
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\info
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\TransferAgentSetup.exe
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo\1157.cin
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo\901.cin
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1004.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1027.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1028.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1029.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1030.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1043.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1061.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1062.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1064.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1094.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1095.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1096.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1097.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1112.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1114.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1117.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1118.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1120.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1122.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1124.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1125.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1128.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1131.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1133.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1134.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1138.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1141.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1142.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1145.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1146.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1150.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1152.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1157.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1300.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1301.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\516.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\519.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\526.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\527.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\528.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\579.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\580.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\587.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\632.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\699.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\701.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\703.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\706.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\716.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\745.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\752.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\758.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\759.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\793.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\794.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\798.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\800.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\801.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\804.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\809.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\810.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\812.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\832.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\840.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\846.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\848.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\873.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\879.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\880.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\883.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\884.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\885.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\886.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\887.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\888.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\889.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\901.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\902.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\903.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\905.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\906.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\907.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\908.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\909.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\910.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\911.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\912.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\914.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\915.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\916.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\917.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\918.ucl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\channel.cfg
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571\DiagPlugin.dll
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config\groups.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config\ocxid.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\bios.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\computer_models.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\DAntivirus.cfg
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dell_inspiron_service_tag.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dell_printers.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dvd.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\inspiron_172X.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\popup.sini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\printers.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\trojan.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\vista_capbale_models.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\10675121.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\10886371.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\122779.html
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\696.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\697.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\global.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\globe.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\title.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\arg.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\DellSupportLauncher.exe
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\DellSupportODBK.exe
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\security\icon.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\security
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\system\icon.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\system
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\blank.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\confirm.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\gtagent_events.vbs
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\index.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\moreinfo.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\noitems.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\senddata.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\statinfo.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\survey.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\wait.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\bg.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\but_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\but_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\count_bg.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_d.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\dialog_strip.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\dialog_title.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_d.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_abort.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_fail.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_ok.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_d.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\left_but_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\left_but_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\msg_bg.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_a2.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_d.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\noproblems.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_d.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\right_but_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\right_but_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_a.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_b.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_c.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\spacer.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\wait.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\index.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\agent_infolet_exe.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\ab.ppk
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\AdpUtil.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Adp_GUI.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\adpicon.ico
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\button_cirlce.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\button_disable.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Chimes.wav
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\close_popup.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\close_popup_over.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\dot.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Ending_v.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Ending_x.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\field_bar.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\inprogress.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\installing.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\logo.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\main_bar.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\mini_logo.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\mini_topbar.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Notify.wav
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\progress_bg.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\progress_slice.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\topbar.gif
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ImgOver.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Initialize.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\main.htm
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\popupMsg.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Query.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Wrapper.js
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT\Generic.css
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT\global_adp_Text.xml
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\ccnotify.cfg
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\cybercoach.cfg
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\enginecf_ver.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs\default.glf
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs\Dell.glf
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\abort.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\cloak.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\De_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\En_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\errorlib.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Es_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Fr_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\func.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\generic.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\getmaindriver.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\It_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Jp_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Ko_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\mini.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Nl_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\oeonwindows.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\outlookexpress.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\PtB_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Sv_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\taskbarandstartmenu.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\xsystray.trn
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\ZhT_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Zh_LibText.ini
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\trainer.ppk
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\1.gdpb
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DeleteTempFolder.gdpb
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DeleteWow6432Node.gdpb
Status: Access denied

Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DisableHDAutorun.gdpb
Sta
Title: Re: Trojan horse Rootkit-Pakes.BI
Post by: SuperDave on December 28, 2011, 12:14:46 PM
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetAcceptTerms.png)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://i424.photobucket.com/albums/pp322/digistar/esetListThreats.png)
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://i424.photobucket.com/albums/pp322/digistar/esetBack.png) button.
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt