Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Malware infection  (Read 26872 times)

0 Members and 1 Guest are viewing this topic.

Sneakyone

  • Malware Removal Specialist


  • Beginner

    Thanked: 5
    Re: Malware infection
    « Reply #15 on: July 21, 2010, 09:58:33 PM »
    Hi, :)

    Download MBRCheck to your desktop.
    • Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    • It will show a black screen with some data on it.
    • A report called MBRcheckxxxx.txt will be on your desktop
    • Open this report and post its content in your next reply.

    ToniCarman

      Topic Starter


      Rookie

      Re: Malware infection
      « Reply #16 on: July 21, 2010, 11:44:59 PM »
      MBRCheck, version 1.1.1
      <c> 2010, AD

      \\.\C: -->  \\.\PhysicalDrive0
      \\.\D: -->  \\.\PhysicalDrive1
      \\.\E: -->  \\.\PhysicalDrive1

      Size                   Device Name               MBR Status
      ----------------------------------------------------------------------
      232 GB              \\.\PhysicalDrive0        MBR Code Faked!
      232 GB              \\.\PhysicalDrive1        Windows XP MBR code detected

      Found non-standard for infected MBR
      Enter 'Y' and hit entere for more options, or 'N' to exit:  y

      Options:
      [1] Dump the MBR of a physical disk to file.
      [2] Restore the MBR of a phyical disk with a standard boot code
      [3] Exit

      Enter your choice:


      Sneakyone

      • Malware Removal Specialist


      • Beginner

        Thanked: 5
        Re: Malware infection
        « Reply #17 on: July 21, 2010, 11:48:58 PM »
        Hi, :)

        Run MBRCheck.exe
        • Run MBRCheck.exe
        • Wait until you see the following line: Enter 'Y' and hit ENTER for more options, or 'N' to exit:
        • Please push the 'Y' key and then press Enter
        • When program ask you Enter your choice: enter 2 and press the Enter key
        • Now the program will ask you "Enter the physical disk number to fix (0-99, -1 to cancel):"
        • Enter 0 and press the Enter key.
        • The program will show Available MBR codes:, followed by a list of operating systems.  Please enter 1 for Windows XP, and then press Enter.
        • When asked Do you want to fix the MBR code? type in YES and press enter
        • Restart your PC.

        ToniCarman

          Topic Starter


          Rookie

          Re: Malware infection
          « Reply #18 on: July 21, 2010, 11:52:50 PM »
          ok, restarted



          Sneakyone

          • Malware Removal Specialist


          • Beginner

            Thanked: 5
            Re: Malware infection
            « Reply #19 on: July 21, 2010, 11:54:04 PM »
            Hi, :)

            Could you please run MBRCheck again and post the log here, to be sure it is gone.

            ToniCarman

              Topic Starter


              Rookie

              Re: Malware infection
              « Reply #20 on: July 21, 2010, 11:55:19 PM »
              MBRCheck, version 1.1.1
              <c> 2010, AD

              \\.\C: -->  \\.\PhysicalDrive0
              \\.\D: -->  \\.\PhysicalDrive1
              \\.\E: -->  \\.\PhysicalDrive1

              Size                   Device Name               MBR Status
              ----------------------------------------------------------------------
              232 GB              \\.\PhysicalDrive0        Windows XP MBR code detected
              232 GB              \\.\PhysicalDrive1        Windows XP MBR code detected

              Done! Press ENTER to exit....

              Sneakyone

              • Malware Removal Specialist


              • Beginner

                Thanked: 5
                Re: Malware infection
                « Reply #21 on: July 21, 2010, 11:59:49 PM »
                Hi, :)

                Please download ComboFix from BleepingComputer.com

                Alternate link: GeeksToGo.com

                Alternate link: Forospyware.com

                Rename ComboFix.exe to commy.exe before you save it to your Desktop
                • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
                • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
                • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
                • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

                Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

                Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


                • Click on Yes, to continue scanning for malware.
                • When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

                ToniCarman

                  Topic Starter


                  Rookie

                  Re: Malware infection
                  « Reply #22 on: July 22, 2010, 12:21:02 AM »
                  Yay! It ran!

                  Then automatically rebooted.

                  Combofix log:

                  ComboFix 10-07-21.02 - Toni 07/22/2010   2:11.4.2 - x86
                  Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00]
                  Running from: c:\documents and settings\Toni\desktop\commy.exe
                  Command switches used :: /stepdel
                  AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
                  FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
                  .

                  (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  c:\documents and settings\Toni\Application Data\Sky-Banners
                  c:\documents and settings\Toni\Application Data\Street-Ads
                  c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}
                  c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor
                  c:\windows\$NtUninstallMTF1011$
                  c:\windows\TEMP\logishrd\LVPrcInj01.dll
                  c:\documents and settings\Toni\Application Data\09f7619a.exe
                  c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest
                  c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js
                  c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul
                  c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf
                  c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk
                  c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
                  c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
                  c:\windows\$NtUninstallMTF1011$\apUninstall.exe
                  c:\windows\$NtUninstallMTF1011$\zrpt.xml
                  c:\windows\system32\ernel32.dll

                  .
                  (((((((((((((((((((((((((   Files Created from 2010-06-22 to 2010-07-22  )))))))))))))))))))))))))))))))
                  .

                  2010-07-21 13:54 . 2010-07-21 14:49   --------   d-----w-   C:\commy21098c
                  2010-07-21 11:25 . 2010-07-21 12:14   --------   d-----w-   C:\commy
                  2010-07-21 11:18 . 2010-07-21 11:18   --------   d-----w-   C:\_OTL
                  2010-07-20 10:57 . 2010-07-20 10:57   --------   d-----w-   c:\program files\CCleaner
                  2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Uniblue
                  2010-07-18 16:03 . 2010-07-18 16:03   4057620   ----a-w-   c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe
                  2010-07-18 16:03 . 2010-07-18 16:06   --------   d-----w-   c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy
                  2010-07-18 16:03 . 2010-07-18 16:03   331304   ----a-w-   c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe
                  2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\documents and settings\Toni\Application Data\OpenCandy
                  2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Winamp Detect
                  2010-07-18 16:01 . 2010-07-18 16:51   --------   d-----w-   c:\documents and settings\Toni\Application Data\Winamp
                  2010-07-18 16:01 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Winamp
                  2010-07-17 15:37 . 2010-07-21 16:00   --------   d-----w-   c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar
                  2010-07-15 16:36 . 2010-07-15 16:36   2944904   ----a-w-   c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[email protected]\chrome\temp\askToolbar.exe
                  2010-07-14 13:39 . 2010-07-14 13:39   --------   d-----w-   c:\documents and settings\Toni\Application Data\Avery
                  2010-07-14 13:24 . 2010-07-14 13:24   --------   d-----w-   c:\program files\Avery Dennison
                  2010-07-14 13:24 . 2010-07-14 13:24   --------   d-----w-   c:\documents and settings\All Users\Application Data\Avery
                  2010-07-14 13:10 . 2010-07-17 14:02   --------   d-----w-   c:\program files\Ask.com
                  2010-07-14 13:05 . 2010-07-14 13:07   89582136   ----a-w-   c:\program files\DesignPro5_5_Limited.exe
                  2010-07-14 09:10 . 2010-06-14 14:31   744448   -c----w-   c:\windows\system32\dllcache\helpsvc.exe
                  2010-07-12 15:35 . 2010-07-12 15:35   2272   ----a-w-   c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
                  2010-07-10 14:39 . 2010-07-10 14:39   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Malwarebytes

                  .
                  ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2010-07-22 06:17 . 2009-02-17 19:40   0   ----a-w-   c:\windows\system32\drivers\lvuvc.hs
                  2010-07-22 06:17 . 2009-02-17 19:38   0   ----a-w-   c:\windows\system32\drivers\logiflt.iad
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k7
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k6
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k5
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k4
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k3
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k2
                  2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k1
                  2010-07-22 06:16 . 2009-01-28 19:20   227220   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k0
                  2010-07-22 05:55 . 2010-04-09 13:47   1324   ----a-w-   c:\windows\system32\d3d9caps.dat
                  2010-07-20 19:53 . 2010-03-10 14:04   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
                  2010-07-18 00:58 . 2009-08-13 23:13   --------   d-----w-   c:\documents and settings\Toni\Application Data\Vso
                  2010-07-16 20:20 . 2010-03-22 17:58   --------   d-----w-   c:\program files\uTorrent
                  2010-07-15 15:39 . 2009-01-30 16:19   395984   ----a-w-   c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                  2010-07-14 13:33 . 2009-01-28 14:38   --------   d--h--w-   c:\program files\InstallShield Installation Information
                  2010-07-10 23:55 . 2010-02-11 12:30   --------   d-----w-   c:\documents and settings\All Users\Application Data\Roxio
                  2010-06-25 18:51 . 2009-02-04 05:06   --------   d-----w-   c:\documents and settings\Toni\Application Data\ZoomBrowser EX
                  2010-06-25 18:50 . 2009-01-31 18:06   --------   d-----w-   c:\documents and settings\All Users\Application Data\ZoomBrowser
                  2010-06-19 16:23 . 2009-02-03 02:26   --------   d-----w-   c:\documents and settings\Toni\Application Data\AdobeUM
                  2010-06-17 15:46 . 2010-06-16 20:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
                  2010-06-16 20:25 . 2009-01-30 07:02   --------   d-----w-   c:\program files\Common Files\Adobe
                  2010-06-16 19:40 . 2010-06-16 19:40   --------   d-----w-   c:\program files\Adobe Media Player
                  2010-06-16 19:39 . 2010-06-16 19:39   10134   ----a-r-   c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
                  2010-06-16 19:39 . 2010-06-16 19:39   --------   d-----w-   c:\program files\My Company Name
                  2010-06-16 19:34 . 2010-06-16 19:34   --------   d-----w-   c:\program files\Common Files\Adobe AIR
                  2010-06-16 16:18 . 2009-02-26 02:14   --------   d-----w-   c:\documents and settings\Toni\Application Data\Move Networks
                  2010-06-14 19:58 . 2010-06-14 19:58   --------   d-----w-   c:\documents and settings\All Users\Application Data\vsosdk
                  2010-06-14 14:31 . 2009-01-28 13:06   744448   ----a-w-   c:\windows\pchealth\helpctr\binaries\helpsvc.exe
                  2010-06-13 18:14 . 2010-06-13 18:06   --------   d-----w-   c:\program files\PeerGuardian2
                  2010-06-07 00:19 . 2010-05-04 17:20   --------   d-----w-   c:\program files\Microsoft Silverlight
                  2010-06-03 16:35 . 2009-07-09 01:42   1561896   ----a-w-   c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
                  2010-06-03 16:35 . 2009-01-28 18:24   746216   ----a-w-   c:\windows\system32\drivers\vetefile.sys
                  2010-06-03 16:35 . 2009-01-28 18:24   130280   ----a-w-   c:\windows\system32\drivers\veteboot.sys
                  2010-05-28 18:57 . 2009-01-28 18:24   91472   ----a-w-   c:\windows\system32\isafprod.dll
                  2010-05-04 17:20 . 2004-08-04 12:00   832512   ----a-w-   c:\windows\system32\wininet.dll
                  2010-05-04 17:20 . 2004-08-04 12:00   78336   ----a-w-   c:\windows\system32\ieencode.dll
                  2010-05-04 17:20 . 2004-08-04 12:00   17408   ----a-w-   c:\windows\system32\corpol.dll
                  2010-05-02 05:22 . 2004-08-04 12:00   1851264   ----a-w-   c:\windows\system32\win32k.sys
                  2010-04-29 19:39 . 2010-03-10 14:04   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
                  2010-04-29 19:39 . 2010-03-10 14:04   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
                  2010-02-02 17:02 . 2010-02-02 17:02   1438976   ----a-w-   c:\program files\MoveMediaPlayerWin_071505000011.exe
                  2010-02-01 01:43 . 2010-02-01 01:43   2107456   ----a-w-   c:\program files\Install_Facebook_Plug-In_1.0.1.exe
                  2010-01-31 12:26 . 2010-01-31 12:26   1533702   ----a-w-   c:\program files\gburner27.exe
                  2009-08-13 23:06 . 2009-08-13 23:05   7741336   ----a-w-   c:\program files\DivX521XP2K_1.exe
                  2009-08-13 22:54 . 2009-08-13 22:53   4526458   ----a-w-   c:\program files\WinAVI_Video_Converter.exe
                  2009-06-16 21:38 . 2009-06-16 21:38   2144584   ----a-w-   c:\program files\InstallFirefoxPluginV3.exe
                  2009-06-12 22:34 . 2009-06-12 22:30   24527365   ----a-w-   c:\program files\FreeVideoConverter.exe
                  2009-03-05 21:24 . 2009-03-05 21:24   4909440   ----a-w-   c:\program files\Silverlight.2.0.exe
                  .

                  (((((((((((((((((((((((((((((   SnapShot@2010-04-15_11.57.58   )))))))))))))))))))))))))))))))))))))))))
                  .
                  + 2009-06-26 23:10 . 2009-06-26 23:10   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll
                  + 2009-06-26 23:10 . 2009-06-26 23:10   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   49152              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   49152              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   57344              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   65536              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   45056              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
                  + 2009-07-12 00:32 . 2009-07-12 00:32   40960              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
                  + 2009-07-12 05:07 . 2009-07-12 05:07   57856              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
                  + 2009-07-12 05:19 . 2009-07-12 05:19   69632              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
                  + 2009-07-11 23:41 . 2009-07-11 23:41   97280              c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
                  + 2010-07-22 06:17 . 2010-07-22 06:17   16384              c:\windows\temp\Perflib_Perfdata_4e8.dat
                  - 2008-04-14 00:12 . 2010-01-23 08:11   46080              c:\windows\system32\tzchange.exe
                  + 2008-04-14 00:12 . 2010-04-21 13:28   46080              c:\windows\system32\tzchange.exe
                  + 2006-03-25 00:00 . 2006-03-25 00:00   45056              c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll
                  + 2005-05-24 00:00 . 2005-05-24 00:00   45056              c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll
                  + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\pxinsa64.exe
                  - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\pxinsa64.exe
                  + 2010-07-18 16:02 . 2009-04-28 20:20   72176              c:\windows\system32\pxhpinst.exe
                  + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\pxcpya64.exe
                  - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\pxcpya64.exe
                  + 2010-03-31 04:16 . 2010-03-31 04:16   99176              c:\windows\system32\PresentationHostProxy.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   44544              c:\windows\system32\pngfilt.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   44544              c:\windows\system32\pngfilt.dll
                  - 2004-08-04 12:00 . 2010-03-14 12:53   78958              c:\windows\system32\perfc009.dat
                  + 2004-08-04 12:00 . 2010-07-08 14:52   78958              c:\windows\system32\perfc009.dat
                  + 2009-11-07 05:07 . 2009-11-07 05:07   49488              c:\windows\system32\netfxperf.dll
                  + 2009-11-06 02:17 . 2009-11-06 02:17   11600              c:\windows\system32\mui\0409\mscorees.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   52224              c:\windows\system32\msfeedsbs.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   52224              c:\windows\system32\msfeedsbs.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   27648              c:\windows\system32\jsproxy.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   27648              c:\windows\system32\jsproxy.dll
                  + 2007-08-14 02:39 . 2010-05-04 12:39   13824              c:\windows\system32\ieudinit.exe
                  - 2007-08-14 02:39 . 2010-03-10 13:18   13824              c:\windows\system32\ieudinit.exe
                  - 2004-08-04 12:00 . 2010-03-11 12:38   44544              c:\windows\system32\iernonce.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   44544              c:\windows\system32\iernonce.dll
                  - 2004-08-04 12:00 . 2010-03-10 13:18   70656              c:\windows\system32\ie4uinit.exe
                  + 2004-08-04 12:00 . 2010-05-04 12:39   70656              c:\windows\system32\ie4uinit.exe
                  - 2007-08-14 02:36 . 2010-03-11 12:38   63488              c:\windows\system32\icardie.dll
                  + 2007-08-14 02:36 . 2010-05-04 17:20   63488              c:\windows\system32\icardie.dll
                  - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\drvins64.exe
                  + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\drvins64.exe
                  + 2009-07-09 07:00 . 2009-07-09 07:00   45200              c:\windows\system32\drivers\pxhelp20.sys
                  - 2009-07-09 08:00 . 2009-07-09 08:00   45200              c:\windows\system32\drivers\pxhelp20.sys
                  + 2007-08-14 02:36 . 2010-05-04 17:20   44544              c:\windows\system32\dllcache\pngfilt.dll
                  - 2007-08-14 02:36 . 2010-03-11 12:38   44544              c:\windows\system32\dllcache\pngfilt.dll
                  + 2009-01-28 15:29 . 2010-05-04 17:20   52224              c:\windows\system32\dllcache\msfeedsbs.dll
                  - 2009-01-28 15:29 . 2010-03-11 12:38   52224              c:\windows\system32\dllcache\msfeedsbs.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   27648              c:\windows\system32\dllcache\jsproxy.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   27648              c:\windows\system32\dllcache\jsproxy.dll
                  - 2009-01-28 15:29 . 2010-03-10 13:18   13824              c:\windows\system32\dllcache\ieudinit.exe
                  + 2009-01-28 15:29 . 2010-05-04 12:39   13824              c:\windows\system32\dllcache\ieudinit.exe
                  - 2007-08-14 02:39 . 2010-03-11 12:38   44544              c:\windows\system32\dllcache\iernonce.dll
                  + 2007-08-14 02:39 . 2010-05-04 17:20   44544              c:\windows\system32\dllcache\iernonce.dll
                  + 2007-08-14 02:45 . 2010-05-04 17:20   78336              c:\windows\system32\dllcache\ieencode.dll
                  - 2007-08-14 02:45 . 2010-03-11 12:38   78336              c:\windows\system32\dllcache\ieencode.dll
                  + 2007-08-14 02:39 . 2010-05-04 12:39   70656              c:\windows\system32\dllcache\ie4uinit.exe
                  - 2007-08-14 02:39 . 2010-03-10 13:18   70656              c:\windows\system32\dllcache\ie4uinit.exe
                  + 2009-01-28 15:29 . 2010-05-04 17:20   63488              c:\windows\system32\dllcache\icardie.dll
                  - 2009-01-28 15:29 . 2010-03-11 12:38   63488              c:\windows\system32\dllcache\icardie.dll
                  + 2007-08-14 02:42 . 2010-05-04 17:20   17408              c:\windows\system32\dllcache\corpol.dll
                  - 2007-08-14 02:42 . 2010-03-11 12:38   17408              c:\windows\system32\dllcache\corpol.dll
                  + 2010-03-05 14:37 . 2010-03-05 14:37   65536              c:\windows\system32\dllcache\asycfilt.dll
                  - 2009-01-28 13:12 . 2009-03-24 23:16   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
                  + 2009-01-28 13:12 . 2010-07-10 19:48   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
                  - 2009-01-28 13:12 . 2009-03-24 23:16   16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
                  + 2010-05-07 15:17 . 2010-07-10 19:48   16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
                  + 2004-08-04 12:00 . 2010-03-05 14:37   65536              c:\windows\system32\asycfilt.dll
                  - 2008-07-30 03:16 . 2008-07-30 03:16   32768              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                  + 2010-04-08 03:48 . 2010-04-08 03:48   32768              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
                  + 2010-03-23 09:31 . 2010-03-23 09:31   30544              c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
                  + 2010-04-01 15:42 . 2010-04-01 15:42   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
                  - 2008-05-28 04:49 . 2008-05-28 04:49   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
                  + 2010-03-31 18:51 . 2010-03-31 18:51   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
                  - 2008-05-28 04:49 . 2008-05-28 04:49   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
                  + 2010-03-31 18:51 . 2010-03-31 18:51   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
                  + 2010-03-31 18:51 . 2010-03-31 18:51   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
                  - 2008-05-28 04:49 . 2008-05-28 04:49   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
                  + 2010-03-31 19:32 . 2010-03-31 19:32   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
                  - 2008-05-28 05:30 . 2008-05-28 05:30   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
                  - 2003-02-21 03:19 . 2003-02-21 03:19   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
                  + 2010-03-31 19:32 . 2010-03-31 19:32   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\SharedReg12.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp10.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13688              c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13696              c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13672              c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   86864              c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
                  + 2010-06-16 19:40 . 2010-06-16 19:40   22016              c:\windows\Installer\a68879.msi
                  + 2010-06-16 19:34 . 2010-06-16 19:34   22528              c:\windows\Installer\a6885b.msi
                  + 2010-06-16 19:34 . 2010-06-16 19:34   27648              c:\windows\Installer\a68853.msi
                  + 2010-05-04 17:20 . 2010-05-04 17:20   49664              c:\windows\Installer\35251f9.msi
                  + 2010-06-15 00:32 . 2010-06-15 00:32   21504              c:\windows\Installer\1712a6bf.msi
                  + 2010-07-14 13:26 . 2010-07-14 13:26   40960              c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe
                  + 2010-06-16 20:25 . 2010-06-16 20:25   81920              c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe
                  + 2010-05-08 16:34 . 2010-05-08 16:34   25214              c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
                  + 2010-05-08 16:34 . 2010-05-08 16:34   25214              c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   23040              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   23040              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   61440              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   61440              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   27136              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   27136              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   11264              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   11264              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   12288              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   12288              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
                  + 2010-06-10 12:21 . 2010-06-10 12:21   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
                  - 2010-04-14 03:51 . 2010-04-14 03:51   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
                  + 2010-05-04 17:26 . 2010-06-04 07:01   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
                  + 2010-06-16 19:43 . 2010-06-16 19:43   81920              c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:33 . 2010-06-16 19:33   10134              c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe
                  + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe
                  + 2010-06-10 11:51 . 2010-03-11 12:38   44544              c:\windows\ie7updates\KB982381-IE7\pngfilt.dll
                  + 2010-06-10 11:51 . 2010-03-11 12:38   52224              c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll
                  + 2010-06-10 11:52 . 2010-03-11 12:38   27648              c:\windows\ie7updates\KB982381-IE7\jsproxy.dll
                  + 2010-06-10 11:52 . 2010-03-10 13:18   13824              c:\windows\ie7updates\KB982381-IE7\ieudinit.exe
                  + 2010-06-10 11:52 . 2010-03-11 12:38   44544              c:\windows\ie7updates\KB982381-IE7\iernonce.dll
                  + 2010-06-10 11:52 . 2010-03-11 12:38   78336              c:\windows\ie7updates\KB982381-IE7\ieencode.dll
                  + 2010-06-10 11:52 . 2010-03-10 13:18   70656              c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe
                  + 2010-06-10 11:52 . 2010-03-11 12:38   63488              c:\windows\ie7updates\KB982381-IE7\icardie.dll
                  + 2010-06-10 11:52 . 2010-03-11 12:38   17408              c:\windows\ie7updates\KB982381-IE7\corpol.dll
                  + 2010-06-10 12:23 . 2010-06-10 12:23   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll
                  + 2010-06-10 12:23 . 2010-06-10 12:23   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll
                  + 2010-06-10 12:27 . 2010-06-10 12:27   47616              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe
                  + 2010-06-10 12:29 . 2010-06-10 12:29   99840              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll
                  + 2010-06-24 07:11 . 2010-06-24 07:11   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
                  + 2010-06-24 07:13 . 2010-06-24 07:13   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
                  + 2010-06-10 12:31 . 2010-06-10 12:31   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll
                  + 2010-06-10 12:31 . 2010-06-10 12:31   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll
                  + 2010-06-10 12:30 . 2010-06-10 12:30   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll
                  + 2010-06-10 12:12 . 2010-06-10 12:12   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe
                  + 2010-06-24 07:09 . 2010-06-24 07:09   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
                  + 2010-06-10 12:10 . 2010-06-10 12:10   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll
                  + 2010-06-24 07:08 . 2010-06-24 07:08   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
                  + 2010-06-10 12:31 . 2010-06-10 12:31   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                  + 2010-06-10 12:10 . 2010-06-10 12:10   32768              c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                  - 2009-01-28 15:35 . 2009-01-28 15:35   32768              c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                  - 2009-10-17 07:14 . 2009-10-17 07:14   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                  - 2009-10-17 07:14 . 2009-10-17 07:14   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                  + 2010-06-10 12:23 . 2010-06-10 12:23   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
                  + 2010-05-26 07:00 . 2010-01-23 08:11   46080              c:\windows\$NtUninstallKB981793$\tzchange.exe
                  + 2010-05-26 07:00 . 2010-04-22 22:21   16896              c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
                  + 2010-06-10 12:12 . 2008-04-14 00:11   65024              c:\windows\$NtUninstallKB979482$\asycfilt.dll
                  + 2010-06-10 11:52 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll
                  + 2010-06-10 11:52 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll
                  + 2010-05-04 17:20 . 2010-05-04 17:20   44544              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll
                  + 2010-05-04 17:20 . 2010-05-04 17:20   52224              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll
                  + 2010-05-04 17:20 . 2010-05-04 17:20   27648              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll
                  + 2010-05-04 13:19 . 2010-05-04 13:19   13824              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe
                  + 2010-05-04 17:20 . 2010-05-04 17:20   44544              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll
                  + 2010-05-04 17:20 . 2010-05-04 17:20   78336              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll
                  + 2010-05-04 13:19 . 2010-05-04 13:19   70656              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe
                  + 2010-05-04 17:20 . 2010-05-04 17:20   63488              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll
                  + 2010-05-04 17:19 . 2010-05-04 17:19   17408              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll
                  + 2010-06-10 12:28 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB980218\update\spcustom.dll
                  + 2010-06-10 12:28 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB980218\spmsg.dll
                  + 2010-06-10 12:23 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB980195\update\spcustom.dll
                  + 2010-06-10 12:23 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB980195\spmsg.dll
                  + 2010-06-10 12:19 . 2009-05-26 09:01   26488              c:\windows\$hf_mig$\KB979559\update\spcustom.dll
                  + 2010-06-10 12:19 . 2009-05-26 09:01   17272              c:\windows\$hf_mig$\KB979559\spmsg.dll
                  + 2010-06-10 12:12 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB979482\update\spcustom.dll
                  + 2010-06-10 12:12 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB979482\spmsg.dll
                  + 2010-03-05 14:52 . 2010-03-05 14:52   65536              c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
                  + 2010-05-13 07:01 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB978542\update\spcustom.dll
                  + 2010-05-13 07:01 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB978542\spmsg.dll
                  + 2010-06-10 12:12 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB975562\update\spcustom.dll
                  + 2010-06-10 12:12 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB975562\spmsg.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                  - 2009-06-23 08:00 . 2009-06-23 08:00   9200              c:\windows\system32\drivers\cdralw2k.sys
                  + 2009-06-23 07:00 . 2009-06-23 07:00   9200              c:\windows\system32\drivers\cdralw2k.sys
                  - 2009-06-23 08:00 . 2009-06-23 08:00   9072              c:\windows\system32\drivers\cdr4_xp.sys
                  + 2009-06-23 07:00 . 2009-06-23 07:00   9072              c:\windows\system32\drivers\cdr4_xp.sys
                  + 2010-07-14 13:26 . 2010-07-14 13:26   2238              c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe
                  + 2009-01-28 18:22 . 2010-07-15 11:04   4096              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
                  - 2009-01-28 18:22 . 2010-04-14 03:47   4096              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
                  + 2010-06-24 07:04 . 2010-06-24 07:04   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                  - 2009-10-17 07:14 . 2009-10-17 07:14   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                  - 2009-10-17 07:13 . 2009-10-17 07:13   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                  + 2010-06-24 07:04 . 2010-06-24 07:04   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                  + 2009-06-26 23:07 . 2009-06-26 23:07   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll
                  + 2009-06-26 23:07 . 2009-06-26 23:07   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll
                  + 2009-06-26 23:10 . 2009-06-26 23:10   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll
                  + 2009-06-26 23:07 . 2009-06-26 23:07   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll
                  + 2009-07-12 05:12 . 2009-07-12 05:12   632656              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
                  + 2009-07-12 05:09 . 2009-07-12 05:09   554832              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
                  + 2009-07-12 05:08 . 2009-07-12 05:08   479232              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   233472              c:\windows\system32\webcheck.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   233472              c:\windows\system32\webcheck.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   105984              c:\windows\system32\url.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   105984              c:\windows\system32\url.dll
                  + 2009-07-10 02:03 . 2009-07-10 02:03   125424              c:\windows\system32\pxinsi64.exe
                  - 2009-07-10 03:03 . 2009-07-10 03:03   125424              c:\windows\system32\pxinsi64.exe
                  - 2009-07-10 03:03 . 2009-07-10 03:03   123888              c:\windows\system32\pxcpyi64.exe
                  + 2009-07-10 02:03 . 2009-07-10 02:03   123888              c:\windows\system32\pxcpyi64.exe
                  + 2010-03-31 04:10 . 2010-03-31 04:10   295264              c:\windows\system32\PresentationHost.exe
                  - 2004-08-04 12:00 . 2010-03-14 12:53   465072              c:\windows\system32\perfh009.dat
                  + 2004-08-04 12:00 . 2010-07-08 14:52   465072              c:\windows\system32\perfh009.dat
                  + 2004-08-04 12:00 . 2010-05-04 17:20   102912              c:\windows\system32\occache.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   102912              c:\windows\system32\occache.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   671232              c:\windows\system32\mstime.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   671232              c:\windows\system32\mstime.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   193024              c:\windows\system32\msrating.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   193024              c:\windows\system32\msrating.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   477696              c:\windows\system32\mshtmled.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   477696              c:\windows\system32\mshtmled.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   459264              c:\windows\system32\msfeeds.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   459264              c:\windows\system32\msfeeds.dll
                  + 2009-11-07 05:07 . 2009-11-07 05:07   297808              c:\windows\system32\mscoree.dll
                  + 2010-06-16 20:25 . 2010-06-16 20:25   223184              c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe
                  + 2010-06-16 19:43 . 2010-06-16 19:43   223184              c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe
                  + 2010-06-16 19:43 . 2010-06-16 19:43   268240              c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll
                  + 2009-01-28 13:06 . 2010-01-29 15:01   691712              c:\windows\system32\inetcomm.dll
                  - 2009-01-28 13:06 . 2008-04-11 19:04   691712              c:\windows\system32\inetcomm.dll
                  - 2007-08-14 02:34 . 2010-03-11 12:38   268288              c:\windows\system32\iertutil.dll
                  + 2007-08-14 02:34 . 2010-05-04 17:20   268288              c:\windows\system32\iertutil.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   192512              c:\windows\system32\iepeers.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   192512              c:\windows\system32\iepeers.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   385024              c:\windows\system32\iedkcs32.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   385024              c:\windows\system32\iedkcs32.dll
                  - 2007-07-11 20:27 . 2010-03-11 12:38   380928              c:\windows\system32\ieapfltr.dll
                  + 2007-07-11 20:27 . 2010-05-04 17:20   380928              c:\windows\system32\ieapfltr.dll
                  + 2004-08-04 12:00 . 2010-04-16 11:43   161792              c:\windows\system32\ieakui.dll
                  - 2004-08-04 12:00 . 2010-02-23 05:18   161792              c:\windows\system32\ieakui.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   230400              c:\windows\system32\ieaksie.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   230400              c:\windows\system32\ieaksie.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   153088              c:\windows\system32\ieakeng.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   153088              c:\windows\system32\ieakeng.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   133120              c:\windows\system32\extmgr.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   133120              c:\windows\system32\extmgr.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   214528              c:\windows\system32\dxtrans.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   214528              c:\windows\system32\dxtrans.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   347136              c:\windows\system32\dxtmsft.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   347136              c:\windows\system32\dxtmsft.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   832512              c:\windows\system32\dllcache\wininet.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   832512              c:\windows\system32\dllcache\wininet.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   233472              c:\windows\system32\dllcache\webcheck.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   233472              c:\windows\system32\dllcache\webcheck.dll
                  - 2007-08-14 02:44 . 2010-03-11 12:38   105984              c:\windows\system32\dllcache\url.dll
                  + 2007-08-14 02:44 . 2010-05-04 17:20   105984              c:\windows\system32\dllcache\url.dll
                  + 2007-08-14 02:44 . 2010-05-04 17:20   102912              c:\windows\system32\dllcache\occache.dll
                  - 2007-08-14 02:44 . 2010-03-11 12:38   102912              c:\windows\system32\dllcache\occache.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   671232              c:\windows\system32\dllcache\mstime.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   671232              c:\windows\system32\dllcache\mstime.dll
                  - 2007-08-14 02:44 . 2010-03-11 12:38   193024              c:\windows\system32\dllcache\msrating.dll
                  + 2007-08-14 02:44 . 2010-05-04 17:20   193024              c:\windows\system32\dllcache\msrating.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   477696              c:\windows\system32\dllcache\mshtmled.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   477696              c:\windows\system32\dllcache\mshtmled.dll
                  + 2009-01-28 15:29 . 2010-05-04 17:20   459264              c:\windows\system32\dllcache\msfeeds.dll
                  - 2009-01-28 15:29 . 2010-03-11 12:38   459264              c:\windows\system32\dllcache\msfeeds.dll
                  + 2009-01-28 14:49 . 2010-01-29 15:01   691712              c:\windows\system32\dllcache\inetcomm.dll
                  - 2009-01-28 14:49 . 2008-04-11 19:04   691712              c:\windows\system32\dllcache\inetcomm.dll
                  + 2007-08-14 02:43 . 2010-04-16 11:43   634656              c:\windows\system32\dllcache\iexplore.exe
                  + 2009-01-28 15:29 . 2010-05-04 17:20   268288              c:\windows\system32\dllcache\iertutil.dll
                  - 2009-01-28 15:29 . 2010-03-11 12:38   268288              c:\windows\system32\dllcache\iertutil.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   192512              c:\windows\system32\dllcache\iepeers.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   192512              c:\windows\system32\dllcache\iepeers.dll
                  - 2007-08-14 02:39 . 2010-03-11 12:38   385024              c:\windows\system32\dllcache\iedkcs32.dll
                  + 2007-08-14 02:39 . 2010-05-04 17:20   385024              c:\windows\system32\dllcache\iedkcs32.dll
                  - 2009-01-28 15:29 . 2010-03-11 12:38   380928              c:\windows\system32\dllcache\ieapfltr.dll
                  + 2009-01-28 15:29 . 2010-05-04 17:20   380928              c:\windows\system32\dllcache\ieapfltr.dll
                  + 2004-08-04 12:00 . 2010-04-16 11:43   161792              c:\windows\system32\dllcache\ieakui.dll
                  - 2004-08-04 12:00 . 2010-02-23 05:18   161792              c:\windows\system32\dllcache\ieakui.dll
                  + 2007-08-14 02:39 . 2010-05-04 17:20   230400              c:\windows\system32\dllcache\ieaksie.dll
                  - 2007-08-14 02:39 . 2010-03-11 12:38   230400              c:\windows\system32\dllcache\ieaksie.dll
                  - 2007-08-14 02:39 . 2010-03-11 12:38   153088              c:\windows\system32\dllcache\ieakeng.dll
                  + 2007-08-14 02:39 . 2010-05-04 17:20   153088              c:\windows\system32\dllcache\ieakeng.dll
                  + 2007-08-14 02:54 . 2010-05-04 17:20   133120              c:\windows\system32\dllcache\extmgr.dll
                  - 2007-08-14 02:54 . 2010-03-11 12:38   133120              c:\windows\system32\dllcache\extmgr.dll
                  + 2007-08-14 02:35 . 2010-05-04 17:20   214528              c:\windows\system32\dllcache\dxtrans.dll
                  - 2007-08-14 02:35 . 2010-03-11 12:38   214528              c:\windows\system32\dllcache\dxtrans.dll
                  + 2007-08-14 02:35 . 2010-05-04 17:20   347136              c:\windows\system32\dllcache\dxtmsft.dll
                  - 2007-08-14 02:35 . 2010-03-11 12:38   347136              c:\windows\system32\dllcache\dxtmsft.dll
                  + 2010-04-20 05:30 . 2010-04-20 05:30   285696              c:\windows\system32\dllcache\atmfd.dll
                  + 2009-01-28 14:40 . 2008-04-13 16:39   142592              c:\windows\system32\dllcache\aec.sys
                  - 2007-08-14 02:39 . 2010-03-11 12:38   124928              c:\windows\system32\dllcache\advpack.dll
                  + 2007-08-14 02:39 . 2010-05-04 17:20   124928              c:\windows\system32\dllcache\advpack.dll
                  - 2004-08-04 12:00 . 2008-04-14 00:09   285696              c:\windows\system32\atmfd.dll
                  + 2004-08-04 12:00 . 2010-04-20 05:30   285696              c:\windows\system32\atmfd.dll
                  + 2004-08-04 12:00 . 2010-05-04 17:20   124928              c:\windows\system32\advpack.dll
                  - 2004-08-04 12:00 . 2010-03-11 12:38   124928              c:\windows\system32\advpack.dll
                  + 2010-03-31 04:16 . 2010-03-31 04:16   130408              c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
                  + 2010-04-08 03:48 . 2010-04-08 03:48   970752              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
                  - 2008-07-30 03:16 . 2008-07-30 03:16   110592              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
                  + 2010-04-08 03:48 . 2010-04-08 03:48   110592              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
                  + 2010-03-23 09:31 . 2010-03-23 09:31   435024              c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
                  + 2010-02-09 16:22 . 2010-02-09 16:22   258048              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
                  - 2008-07-25 19:17 . 2008-07-25 19:17   258048              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
                  - 2008-05-28 04:49 . 2008-05-28 04:49   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
                  + 2010-03-31 18:51 . 2010-03-31 18:51   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
                  - 2008-05-28 04:48 . 2008-05-28 04:48   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
                  + 2010-03-31 18:49 . 2010-03-31 18:49   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
                  + 2010-03-31 19:32 . 2010-03-31 19:32   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
                  - 2008-05-28 05:30 . 2008-05-28 05:30   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
                  + 2010-06-10 12:22 . 2010-06-10 12:22   200192              c:\windows\Installer\be07f0b.msi
                  + 2010-02-25 04:14 . 2010-02-25 04:14   543232              c:\windows\Installer\be07e85.msp
                  + 2010-06-16 19:39 . 2010-06-16 19:39   454144              c:\windows\Installer\a68871.msi
                  + 2010-06-16 19:33 . 2010-06-16 19:33   356352              c:\windows\Installer\a6884b.msi
                  + 2010-06-16 19:32 . 2010-06-16 19:32   315392              c:\windows\Installer\a68843.msi
                  + 2010-06-16 19:32 . 2010-06-16 19:32   316928              c:\windows\Installer\a6883b.msi
                  + 2010-06-16 19:32 . 2010-06-16 19:32   356864              c:\windows\Installer\a68833.msi
                  + 2010-06-16 19:31 . 2010-06-16 19:31   359424              c:\windows\Installer\a6882b.msi
                  + 2010-06-16 19:31 . 2010-06-16 19:31   356352 

                  Sneakyone

                  • Malware Removal Specialist


                  • Beginner

                    Thanked: 5
                    Re: Malware infection
                    « Reply #23 on: July 22, 2010, 01:17:57 PM »
                    Hi, :)

                    Your log is cut off, could you please post the full log.

                    ToniCarman

                      Topic Starter


                      Rookie

                      Re: Malware infection
                      « Reply #24 on: July 22, 2010, 02:02:40 PM »
                      Oh goodness...sorry!

                      Here you go.

                      ComboFix 10-07-21.02 - Toni 07/22/2010   2:11.4.2 - x86
                      Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00]
                      Running from: c:\documents and settings\Toni\desktop\commy.exe
                      Command switches used :: /stepdel
                      AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
                      FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
                      .

                      (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\documents and settings\Toni\Application Data\Sky-Banners
                      c:\documents and settings\Toni\Application Data\Street-Ads
                      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}
                      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor
                      c:\windows\$NtUninstallMTF1011$
                      c:\windows\TEMP\logishrd\LVPrcInj01.dll
                      c:\documents and settings\Toni\Application Data\09f7619a.exe
                      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest
                      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js
                      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul
                      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf
                      c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk
                      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
                      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
                      c:\windows\$NtUninstallMTF1011$\apUninstall.exe
                      c:\windows\$NtUninstallMTF1011$\zrpt.xml
                      c:\windows\system32\ernel32.dll

                      .
                      (((((((((((((((((((((((((   Files Created from 2010-06-22 to 2010-07-22  )))))))))))))))))))))))))))))))
                      .

                      2010-07-21 13:54 . 2010-07-21 14:49   --------   d-----w-   C:\commy21098c
                      2010-07-21 11:25 . 2010-07-21 12:14   --------   d-----w-   C:\commy
                      2010-07-21 11:18 . 2010-07-21 11:18   --------   d-----w-   C:\_OTL
                      2010-07-20 10:57 . 2010-07-20 10:57   --------   d-----w-   c:\program files\CCleaner
                      2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Uniblue
                      2010-07-18 16:03 . 2010-07-18 16:03   4057620   ----a-w-   c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe
                      2010-07-18 16:03 . 2010-07-18 16:06   --------   d-----w-   c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy
                      2010-07-18 16:03 . 2010-07-18 16:03   331304   ----a-w-   c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe
                      2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\documents and settings\Toni\Application Data\OpenCandy
                      2010-07-18 16:03 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Winamp Detect
                      2010-07-18 16:01 . 2010-07-18 16:51   --------   d-----w-   c:\documents and settings\Toni\Application Data\Winamp
                      2010-07-18 16:01 . 2010-07-18 16:03   --------   d-----w-   c:\program files\Winamp
                      2010-07-17 15:37 . 2010-07-21 16:00   --------   d-----w-   c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar
                      2010-07-15 16:36 . 2010-07-15 16:36   2944904   ----a-w-   c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[email protected]\chrome\temp\askToolbar.exe
                      2010-07-14 13:39 . 2010-07-14 13:39   --------   d-----w-   c:\documents and settings\Toni\Application Data\Avery
                      2010-07-14 13:24 . 2010-07-14 13:24   --------   d-----w-   c:\program files\Avery Dennison
                      2010-07-14 13:24 . 2010-07-14 13:24   --------   d-----w-   c:\documents and settings\All Users\Application Data\Avery
                      2010-07-14 13:10 . 2010-07-17 14:02   --------   d-----w-   c:\program files\Ask.com
                      2010-07-14 13:05 . 2010-07-14 13:07   89582136   ----a-w-   c:\program files\DesignPro5_5_Limited.exe
                      2010-07-14 09:10 . 2010-06-14 14:31   744448   -c----w-   c:\windows\system32\dllcache\helpsvc.exe
                      2010-07-12 15:35 . 2010-07-12 15:35   2272   ----a-w-   c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
                      2010-07-10 14:39 . 2010-07-10 14:39   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Malwarebytes

                      .
                      ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-07-22 06:17 . 2009-02-17 19:40   0   ----a-w-   c:\windows\system32\drivers\lvuvc.hs
                      2010-07-22 06:17 . 2009-02-17 19:38   0   ----a-w-   c:\windows\system32\drivers\logiflt.iad
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k7
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k6
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k5
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k4
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k3
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k2
                      2010-07-22 06:16 . 2009-01-28 19:20   64   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k1
                      2010-07-22 06:16 . 2009-01-28 19:20   227220   ----a-w-   c:\windows\system32\drivers\kmxcfg.u2k0
                      2010-07-22 05:55 . 2010-04-09 13:47   1324   ----a-w-   c:\windows\system32\d3d9caps.dat
                      2010-07-20 19:53 . 2010-03-10 14:04   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
                      2010-07-18 00:58 . 2009-08-13 23:13   --------   d-----w-   c:\documents and settings\Toni\Application Data\Vso
                      2010-07-16 20:20 . 2010-03-22 17:58   --------   d-----w-   c:\program files\uTorrent
                      2010-07-15 15:39 . 2009-01-30 16:19   395984   ----a-w-   c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                      2010-07-14 13:33 . 2009-01-28 14:38   --------   d--h--w-   c:\program files\InstallShield Installation Information
                      2010-07-10 23:55 . 2010-02-11 12:30   --------   d-----w-   c:\documents and settings\All Users\Application Data\Roxio
                      2010-06-25 18:51 . 2009-02-04 05:06   --------   d-----w-   c:\documents and settings\Toni\Application Data\ZoomBrowser EX
                      2010-06-25 18:50 . 2009-01-31 18:06   --------   d-----w-   c:\documents and settings\All Users\Application Data\ZoomBrowser
                      2010-06-19 16:23 . 2009-02-03 02:26   --------   d-----w-   c:\documents and settings\Toni\Application Data\AdobeUM
                      2010-06-17 15:46 . 2010-06-16 20:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
                      2010-06-16 20:25 . 2009-01-30 07:02   --------   d-----w-   c:\program files\Common Files\Adobe
                      2010-06-16 19:40 . 2010-06-16 19:40   --------   d-----w-   c:\program files\Adobe Media Player
                      2010-06-16 19:39 . 2010-06-16 19:39   10134   ----a-r-   c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
                      2010-06-16 19:39 . 2010-06-16 19:39   --------   d-----w-   c:\program files\My Company Name
                      2010-06-16 19:34 . 2010-06-16 19:34   --------   d-----w-   c:\program files\Common Files\Adobe AIR
                      2010-06-16 16:18 . 2009-02-26 02:14   --------   d-----w-   c:\documents and settings\Toni\Application Data\Move Networks
                      2010-06-14 19:58 . 2010-06-14 19:58   --------   d-----w-   c:\documents and settings\All Users\Application Data\vsosdk
                      2010-06-14 14:31 . 2009-01-28 13:06   744448   ----a-w-   c:\windows\pchealth\helpctr\binaries\helpsvc.exe
                      2010-06-13 18:14 . 2010-06-13 18:06   --------   d-----w-   c:\program files\PeerGuardian2
                      2010-06-07 00:19 . 2010-05-04 17:20   --------   d-----w-   c:\program files\Microsoft Silverlight
                      2010-06-03 16:35 . 2009-07-09 01:42   1561896   ----a-w-   c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
                      2010-06-03 16:35 . 2009-01-28 18:24   746216   ----a-w-   c:\windows\system32\drivers\vetefile.sys
                      2010-06-03 16:35 . 2009-01-28 18:24   130280   ----a-w-   c:\windows\system32\drivers\veteboot.sys
                      2010-05-28 18:57 . 2009-01-28 18:24   91472   ----a-w-   c:\windows\system32\isafprod.dll
                      2010-05-04 17:20 . 2004-08-04 12:00   832512   ----a-w-   c:\windows\system32\wininet.dll
                      2010-05-04 17:20 . 2004-08-04 12:00   78336   ----a-w-   c:\windows\system32\ieencode.dll
                      2010-05-04 17:20 . 2004-08-04 12:00   17408   ----a-w-   c:\windows\system32\corpol.dll
                      2010-05-02 05:22 . 2004-08-04 12:00   1851264   ----a-w-   c:\windows\system32\win32k.sys
                      2010-04-29 19:39 . 2010-03-10 14:04   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
                      2010-04-29 19:39 . 2010-03-10 14:04   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
                      2010-02-02 17:02 . 2010-02-02 17:02   1438976   ----a-w-   c:\program files\MoveMediaPlayerWin_071505000011.exe
                      2010-02-01 01:43 . 2010-02-01 01:43   2107456   ----a-w-   c:\program files\Install_Facebook_Plug-In_1.0.1.exe
                      2010-01-31 12:26 . 2010-01-31 12:26   1533702   ----a-w-   c:\program files\gburner27.exe
                      2009-08-13 23:06 . 2009-08-13 23:05   7741336   ----a-w-   c:\program files\DivX521XP2K_1.exe
                      2009-08-13 22:54 . 2009-08-13 22:53   4526458   ----a-w-   c:\program files\WinAVI_Video_Converter.exe
                      2009-06-16 21:38 . 2009-06-16 21:38   2144584   ----a-w-   c:\program files\InstallFirefoxPluginV3.exe
                      2009-06-12 22:34 . 2009-06-12 22:30   24527365   ----a-w-   c:\program files\FreeVideoConverter.exe
                      2009-03-05 21:24 . 2009-03-05 21:24   4909440   ----a-w-   c:\program files\Silverlight.2.0.exe
                      .

                      (((((((((((((((((((((((((((((   SnapShot@2010-04-15_11.57.58   )))))))))))))))))))))))))))))))))))))))))
                      .
                      + 2009-06-26 23:10 . 2009-06-26 23:10   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll
                      + 2009-06-26 23:10 . 2009-06-26 23:10   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   49152              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   49152              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   61440              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   57344              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   65536              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   45056              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
                      + 2009-07-12 00:32 . 2009-07-12 00:32   40960              c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
                      + 2009-07-12 05:07 . 2009-07-12 05:07   57856              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
                      + 2009-07-12 05:19 . 2009-07-12 05:19   69632              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
                      + 2009-07-11 23:41 . 2009-07-11 23:41   97280              c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
                      + 2010-07-22 06:17 . 2010-07-22 06:17   16384              c:\windows\temp\Perflib_Perfdata_4e8.dat
                      - 2008-04-14 00:12 . 2010-01-23 08:11   46080              c:\windows\system32\tzchange.exe
                      + 2008-04-14 00:12 . 2010-04-21 13:28   46080              c:\windows\system32\tzchange.exe
                      + 2006-03-25 00:00 . 2006-03-25 00:00   45056              c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll
                      + 2005-05-24 00:00 . 2005-05-24 00:00   45056              c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll
                      + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\pxinsa64.exe
                      - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\pxinsa64.exe
                      + 2010-07-18 16:02 . 2009-04-28 20:20   72176              c:\windows\system32\pxhpinst.exe
                      + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\pxcpya64.exe
                      - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\pxcpya64.exe
                      + 2010-03-31 04:16 . 2010-03-31 04:16   99176              c:\windows\system32\PresentationHostProxy.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   44544              c:\windows\system32\pngfilt.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   44544              c:\windows\system32\pngfilt.dll
                      - 2004-08-04 12:00 . 2010-03-14 12:53   78958              c:\windows\system32\perfc009.dat
                      + 2004-08-04 12:00 . 2010-07-08 14:52   78958              c:\windows\system32\perfc009.dat
                      + 2009-11-07 05:07 . 2009-11-07 05:07   49488              c:\windows\system32\netfxperf.dll
                      + 2009-11-06 02:17 . 2009-11-06 02:17   11600              c:\windows\system32\mui\0409\mscorees.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   52224              c:\windows\system32\msfeedsbs.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   52224              c:\windows\system32\msfeedsbs.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   27648              c:\windows\system32\jsproxy.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   27648              c:\windows\system32\jsproxy.dll
                      + 2007-08-14 02:39 . 2010-05-04 12:39   13824              c:\windows\system32\ieudinit.exe
                      - 2007-08-14 02:39 . 2010-03-10 13:18   13824              c:\windows\system32\ieudinit.exe
                      - 2004-08-04 12:00 . 2010-03-11 12:38   44544              c:\windows\system32\iernonce.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   44544              c:\windows\system32\iernonce.dll
                      - 2004-08-04 12:00 . 2010-03-10 13:18   70656              c:\windows\system32\ie4uinit.exe
                      + 2004-08-04 12:00 . 2010-05-04 12:39   70656              c:\windows\system32\ie4uinit.exe
                      - 2007-08-14 02:36 . 2010-03-11 12:38   63488              c:\windows\system32\icardie.dll
                      + 2007-08-14 02:36 . 2010-05-04 17:20   63488              c:\windows\system32\icardie.dll
                      - 2009-07-10 03:03 . 2009-07-10 03:03   68080              c:\windows\system32\drvins64.exe
                      + 2009-07-10 02:03 . 2009-07-10 02:03   68080              c:\windows\system32\drvins64.exe
                      + 2009-07-09 07:00 . 2009-07-09 07:00   45200              c:\windows\system32\drivers\pxhelp20.sys
                      - 2009-07-09 08:00 . 2009-07-09 08:00   45200              c:\windows\system32\drivers\pxhelp20.sys
                      + 2007-08-14 02:36 . 2010-05-04 17:20   44544              c:\windows\system32\dllcache\pngfilt.dll
                      - 2007-08-14 02:36 . 2010-03-11 12:38   44544              c:\windows\system32\dllcache\pngfilt.dll
                      + 2009-01-28 15:29 . 2010-05-04 17:20   52224              c:\windows\system32\dllcache\msfeedsbs.dll
                      - 2009-01-28 15:29 . 2010-03-11 12:38   52224              c:\windows\system32\dllcache\msfeedsbs.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   27648              c:\windows\system32\dllcache\jsproxy.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   27648              c:\windows\system32\dllcache\jsproxy.dll
                      - 2009-01-28 15:29 . 2010-03-10 13:18   13824              c:\windows\system32\dllcache\ieudinit.exe
                      + 2009-01-28 15:29 . 2010-05-04 12:39   13824              c:\windows\system32\dllcache\ieudinit.exe
                      - 2007-08-14 02:39 . 2010-03-11 12:38   44544              c:\windows\system32\dllcache\iernonce.dll
                      + 2007-08-14 02:39 . 2010-05-04 17:20   44544              c:\windows\system32\dllcache\iernonce.dll
                      + 2007-08-14 02:45 . 2010-05-04 17:20   78336              c:\windows\system32\dllcache\ieencode.dll
                      - 2007-08-14 02:45 . 2010-03-11 12:38   78336              c:\windows\system32\dllcache\ieencode.dll
                      + 2007-08-14 02:39 . 2010-05-04 12:39   70656              c:\windows\system32\dllcache\ie4uinit.exe
                      - 2007-08-14 02:39 . 2010-03-10 13:18   70656              c:\windows\system32\dllcache\ie4uinit.exe
                      + 2009-01-28 15:29 . 2010-05-04 17:20   63488              c:\windows\system32\dllcache\icardie.dll
                      - 2009-01-28 15:29 . 2010-03-11 12:38   63488              c:\windows\system32\dllcache\icardie.dll
                      + 2007-08-14 02:42 . 2010-05-04 17:20   17408              c:\windows\system32\dllcache\corpol.dll
                      - 2007-08-14 02:42 . 2010-03-11 12:38   17408              c:\windows\system32\dllcache\corpol.dll
                      + 2010-03-05 14:37 . 2010-03-05 14:37   65536              c:\windows\system32\dllcache\asycfilt.dll
                      - 2009-01-28 13:12 . 2009-03-24 23:16   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
                      + 2009-01-28 13:12 . 2010-07-10 19:48   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
                      - 2009-01-28 13:12 . 2009-03-24 23:16   16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
                      + 2010-05-07 15:17 . 2010-07-10 19:48   16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
                      + 2004-08-04 12:00 . 2010-03-05 14:37   65536              c:\windows\system32\asycfilt.dll
                      - 2008-07-30 03:16 . 2008-07-30 03:16   32768              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                      + 2010-04-08 03:48 . 2010-04-08 03:48   32768              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
                      + 2010-03-23 09:31 . 2010-03-23 09:31   30544              c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
                      + 2010-04-01 15:42 . 2010-04-01 15:42   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
                      - 2008-05-28 04:49 . 2008-05-28 04:49   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
                      + 2010-03-31 18:51 . 2010-03-31 18:51   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
                      - 2008-05-28 04:49 . 2008-05-28 04:49   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
                      + 2010-03-31 18:51 . 2010-03-31 18:51   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
                      + 2010-03-31 18:51 . 2010-03-31 18:51   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
                      - 2008-05-28 04:49 . 2008-05-28 04:49   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
                      + 2010-03-31 19:32 . 2010-03-31 19:32   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
                      - 2008-05-28 05:30 . 2008-05-28 05:30   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
                      - 2003-02-21 03:19 . 2003-02-21 03:19   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
                      + 2010-03-31 19:32 . 2010-03-31 19:32   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\SharedReg12.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13648              c:\windows\Microsoft.NET\Framework\sbscmp10.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13688              c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13696              c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13656              c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13672              c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   13664              c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   86864              c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
                      + 2010-06-16 19:40 . 2010-06-16 19:40   22016              c:\windows\Installer\a68879.msi
                      + 2010-06-16 19:34 . 2010-06-16 19:34   22528              c:\windows\Installer\a6885b.msi
                      + 2010-06-16 19:34 . 2010-06-16 19:34   27648              c:\windows\Installer\a68853.msi
                      + 2010-05-04 17:20 . 2010-05-04 17:20   49664              c:\windows\Installer\35251f9.msi
                      + 2010-06-15 00:32 . 2010-06-15 00:32   21504              c:\windows\Installer\1712a6bf.msi
                      + 2010-07-14 13:26 . 2010-07-14 13:26   40960              c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe
                      + 2010-06-16 20:25 . 2010-06-16 20:25   81920              c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe
                      + 2010-05-08 16:34 . 2010-05-08 16:34   25214              c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
                      + 2010-05-08 16:34 . 2010-05-08 16:34   25214              c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   23040              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   23040              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   61440              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   61440              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   27136              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   27136              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   11264              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   11264              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   12288              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   12288              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
                      + 2010-06-10 12:21 . 2010-06-10 12:21   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
                      - 2010-04-14 03:51 . 2010-04-14 03:51   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
                      + 2010-05-04 17:26 . 2010-06-04 07:01   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
                      + 2010-06-16 19:43 . 2010-06-16 19:43   81920              c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:33 . 2010-06-16 19:33   10134              c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:31 . 2010-06-16 19:31   10134              c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe
                      + 2010-06-16 19:32 . 2010-06-16 19:32   10134              c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe
                      + 2010-06-10 11:51 . 2010-03-11 12:38   44544              c:\windows\ie7updates\KB982381-IE7\pngfilt.dll
                      + 2010-06-10 11:51 . 2010-03-11 12:38   52224              c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll
                      + 2010-06-10 11:52 . 2010-03-11 12:38   27648              c:\windows\ie7updates\KB982381-IE7\jsproxy.dll
                      + 2010-06-10 11:52 . 2010-03-10 13:18   13824              c:\windows\ie7updates\KB982381-IE7\ieudinit.exe
                      + 2010-06-10 11:52 . 2010-03-11 12:38   44544              c:\windows\ie7updates\KB982381-IE7\iernonce.dll
                      + 2010-06-10 11:52 . 2010-03-11 12:38   78336              c:\windows\ie7updates\KB982381-IE7\ieencode.dll
                      + 2010-06-10 11:52 . 2010-03-10 13:18   70656              c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe
                      + 2010-06-10 11:52 . 2010-03-11 12:38   63488              c:\windows\ie7updates\KB982381-IE7\icardie.dll
                      + 2010-06-10 11:52 . 2010-03-11 12:38   17408              c:\windows\ie7updates\KB982381-IE7\corpol.dll
                      + 2010-06-10 12:23 . 2010-06-10 12:23   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll
                      + 2010-06-10 12:23 . 2010-06-10 12:23   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll
                      + 2010-06-10 12:27 . 2010-06-10 12:27   47616              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe
                      + 2010-06-10 12:29 . 2010-06-10 12:29   99840              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll
                      + 2010-06-24 07:11 . 2010-06-24 07:11   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
                      + 2010-06-24 07:13 . 2010-06-24 07:13   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
                      + 2010-06-10 12:31 . 2010-06-10 12:31   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll
                      + 2010-06-10 12:31 . 2010-06-10 12:31   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll
                      + 2010-06-10 12:30 . 2010-06-10 12:30   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll
                      + 2010-06-10 12:12 . 2010-06-10 12:12   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe
                      + 2010-06-24 07:09 . 2010-06-24 07:09   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
                      + 2010-06-10 12:10 . 2010-06-10 12:10   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll
                      + 2010-06-24 07:08 . 2010-06-24 07:08   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
                      + 2010-06-10 12:31 . 2010-06-10 12:31   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                      + 2010-06-10 12:10 . 2010-06-10 12:10   32768              c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                      - 2009-01-28 15:35 . 2009-01-28 15:35   32768              c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                      - 2009-10-17 07:14 . 2009-10-17 07:14   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                      - 2009-10-17 07:14 . 2009-10-17 07:14   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                      + 2010-06-10 12:23 . 2010-06-10 12:23   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
                      + 2010-05-26 07:00 . 2010-01-23 08:11   46080              c:\windows\$NtUninstallKB981793$\tzchange.exe
                      + 2010-05-26 07:00 . 2010-04-22 22:21   16896              c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
                      + 2010-06-10 12:12 . 2008-04-14 00:11   65024              c:\windows\$NtUninstallKB979482$\asycfilt.dll
                      + 2010-06-10 11:52 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll
                      + 2010-06-10 11:52 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll
                      + 2010-05-04 17:20 . 2010-05-04 17:20   44544              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll
                      + 2010-05-04 17:20 . 2010-05-04 17:20   52224              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll
                      + 2010-05-04 17:20 . 2010-05-04 17:20   27648              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll
                      + 2010-05-04 13:19 . 2010-05-04 13:19   13824              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe
                      + 2010-05-04 17:20 . 2010-05-04 17:20   44544              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll
                      + 2010-05-04 17:20 . 2010-05-04 17:20   78336              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll
                      + 2010-05-04 13:19 . 2010-05-04 13:19   70656              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe
                      + 2010-05-04 17:20 . 2010-05-04 17:20   63488              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll
                      + 2010-05-04 17:19 . 2010-05-04 17:19   17408              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll
                      + 2010-06-10 12:28 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB980218\update\spcustom.dll
                      + 2010-06-10 12:28 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB980218\spmsg.dll
                      + 2010-06-10 12:23 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB980195\update\spcustom.dll
                      + 2010-06-10 12:23 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB980195\spmsg.dll
                      + 2010-06-10 12:19 . 2009-05-26 09:01   26488              c:\windows\$hf_mig$\KB979559\update\spcustom.dll
                      + 2010-06-10 12:19 . 2009-05-26 09:01   17272              c:\windows\$hf_mig$\KB979559\spmsg.dll
                      + 2010-06-10 12:12 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB979482\update\spcustom.dll
                      + 2010-06-10 12:12 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB979482\spmsg.dll
                      + 2010-03-05 14:52 . 2010-03-05 14:52   65536              c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
                      + 2010-05-13 07:01 . 2009-05-26 11:40   26488              c:\windows\$hf_mig$\KB978542\update\spcustom.dll
                      + 2010-05-13 07:01 . 2009-05-26 11:40   17272              c:\windows\$hf_mig$\KB978542\spmsg.dll
                      + 2010-06-10 12:12 . 2008-07-08 13:02   26488              c:\windows\$hf_mig$\KB975562\update\spcustom.dll
                      + 2010-06-10 12:12 . 2008-07-08 13:02   17272              c:\windows\$hf_mig$\KB975562\spmsg.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                      - 2009-06-23 08:00 . 2009-06-23 08:00   9200              c:\windows\system32\drivers\cdralw2k.sys
                      + 2009-06-23 07:00 . 2009-06-23 07:00   9200              c:\windows\system32\drivers\cdralw2k.sys
                      - 2009-06-23 08:00 . 2009-06-23 08:00   9072              c:\windows\system32\drivers\cdr4_xp.sys
                      + 2009-06-23 07:00 . 2009-06-23 07:00   9072              c:\windows\system32\drivers\cdr4_xp.sys
                      + 2010-07-14 13:26 . 2010-07-14 13:26   2238              c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe
                      + 2009-01-28 18:22 . 2010-07-15 11:04   4096              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
                      - 2009-01-28 18:22 . 2010-04-14 03:47   4096              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
                      + 2010-06-24 07:04 . 2010-06-24 07:04   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                      - 2009-10-17 07:14 . 2009-10-17 07:14   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                      - 2009-10-17 07:13 . 2009-10-17 07:13   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                      + 2010-06-24 07:04 . 2010-06-24 07:04   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                      + 2009-06-26 23:07 . 2009-06-26 23:07   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll
                      + 2009-06-26 23:07 . 2009-06-26 23:07   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll
                      + 2009-06-26 23:10 . 2009-06-26 23:10   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll
                      + 2009-06-26 23:07 . 2009-06-26 23:07   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll
                      + 2009-07-12 05:12 . 2009-07-12 05:12   632656              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
                      + 2009-07-12 05:09 . 2009-07-12 05:09   554832              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
                      + 2009-07-12 05:08 . 2009-07-12 05:08   479232              c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   233472              c:\windows\system32\webcheck.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   233472              c:\windows\system32\webcheck.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   105984              c:\windows\system32\url.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   105984              c:\windows\system32\url.dll
                      + 2009-07-10 02:03 . 2009-07-10 02:03   125424              c:\windows\system32\pxinsi64.exe
                      - 2009-07-10 03:03 . 2009-07-10 03:03   125424              c:\windows\system32\pxinsi64.exe
                      - 2009-07-10 03:03 . 2009-07-10 03:03   123888              c:\windows\system32\pxcpyi64.exe
                      + 2009-07-10 02:03 . 2009-07-10 02:03   123888              c:\windows\system32\pxcpyi64.exe
                      + 2010-03-31 04:10 . 2010-03-31 04:10   295264              c:\windows\system32\PresentationHost.exe
                      - 2004-08-04 12:00 . 2010-03-14 12:53   465072              c:\windows\system32\perfh009.dat
                      + 2004-08-04 12:00 . 2010-07-08 14:52   465072              c:\windows\system32\perfh009.dat
                      + 2004-08-04 12:00 . 2010-05-04 17:20   102912              c:\windows\system32\occache.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   102912              c:\windows\system32\occache.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   671232              c:\windows\system32\mstime.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   671232              c:\windows\system32\mstime.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   193024              c:\windows\system32\msrating.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   193024              c:\windows\system32\msrating.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   477696              c:\windows\system32\mshtmled.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   477696              c:\windows\system32\mshtmled.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   459264              c:\windows\system32\msfeeds.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   459264              c:\windows\system32\msfeeds.dll
                      + 2009-11-07 05:07 . 2009-11-07 05:07   297808              c:\windows\system32\mscoree.dll
                      + 2010-06-16 20:25 . 2010-06-16 20:25   223184              c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe
                      + 2010-06-16 19:43 . 2010-06-16 19:43   223184              c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe
                      + 2010-06-16 19:43 . 2010-06-16 19:43   268240              c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll
                      + 2009-01-28 13:06 . 2010-01-29 15:01   691712              c:\windows\system32\inetcomm.dll
                      - 2009-01-28 13:06 . 2008-04-11 19:04   691712              c:\windows\system32\inetcomm.dll
                      - 2007-08-14 02:34 . 2010-03-11 12:38   268288              c:\windows\system32\iertutil.dll
                      + 2007-08-14 02:34 . 2010-05-04 17:20   268288              c:\windows\system32\iertutil.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   192512              c:\windows\system32\iepeers.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   192512              c:\windows\system32\iepeers.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   385024              c:\windows\system32\iedkcs32.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   385024              c:\windows\system32\iedkcs32.dll
                      - 2007-07-11 20:27 . 2010-03-11 12:38   380928              c:\windows\system32\ieapfltr.dll
                      + 2007-07-11 20:27 . 2010-05-04 17:20   380928              c:\windows\system32\ieapfltr.dll
                      + 2004-08-04 12:00 . 2010-04-16 11:43   161792              c:\windows\system32\ieakui.dll
                      - 2004-08-04 12:00 . 2010-02-23 05:18   161792              c:\windows\system32\ieakui.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   230400              c:\windows\system32\ieaksie.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   230400              c:\windows\system32\ieaksie.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   153088              c:\windows\system32\ieakeng.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   153088              c:\windows\system32\ieakeng.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   133120              c:\windows\system32\extmgr.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   133120              c:\windows\system32\extmgr.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   214528              c:\windows\system32\dxtrans.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   214528              c:\windows\system32\dxtrans.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   347136              c:\windows\system32\dxtmsft.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   347136              c:\windows\system32\dxtmsft.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   832512              c:\windows\system32\dllcache\wininet.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   832512              c:\windows\system32\dllcache\wininet.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   233472              c:\windows\system32\dllcache\webcheck.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   233472              c:\windows\system32\dllcache\webcheck.dll
                      - 2007-08-14 02:44 . 2010-03-11 12:38   105984              c:\windows\system32\dllcache\url.dll
                      + 2007-08-14 02:44 . 2010-05-04 17:20   105984              c:\windows\system32\dllcache\url.dll
                      + 2007-08-14 02:44 . 2010-05-04 17:20   102912              c:\windows\system32\dllcache\occache.dll
                      - 2007-08-14 02:44 . 2010-03-11 12:38   102912              c:\windows\system32\dllcache\occache.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   671232              c:\windows\system32\dllcache\mstime.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   671232              c:\windows\system32\dllcache\mstime.dll
                      - 2007-08-14 02:44 . 2010-03-11 12:38   193024              c:\windows\system32\dllcache\msrating.dll
                      + 2007-08-14 02:44 . 2010-05-04 17:20   193024              c:\windows\system32\dllcache\msrating.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   477696              c:\windows\system32\dllcache\mshtmled.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   477696              c:\windows\system32\dllcache\mshtmled.dll
                      + 2009-01-28 15:29 . 2010-05-04 17:20   459264              c:\windows\system32\dllcache\msfeeds.dll
                      - 2009-01-28 15:29 . 2010-03-11 12:38   459264              c:\windows\system32\dllcache\msfeeds.dll
                      + 2009-01-28 14:49 . 2010-01-29 15:01   691712              c:\windows\system32\dllcache\inetcomm.dll
                      - 2009-01-28 14:49 . 2008-04-11 19:04   691712              c:\windows\system32\dllcache\inetcomm.dll
                      + 2007-08-14 02:43 . 2010-04-16 11:43   634656              c:\windows\system32\dllcache\iexplore.exe
                      + 2009-01-28 15:29 . 2010-05-04 17:20   268288              c:\windows\system32\dllcache\iertutil.dll
                      - 2009-01-28 15:29 . 2010-03-11 12:38   268288              c:\windows\system32\dllcache\iertutil.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   192512              c:\windows\system32\dllcache\iepeers.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   192512              c:\windows\system32\dllcache\iepeers.dll
                      - 2007-08-14 02:39 . 2010-03-11 12:38   385024              c:\windows\system32\dllcache\iedkcs32.dll
                      + 2007-08-14 02:39 . 2010-05-04 17:20   385024              c:\windows\system32\dllcache\iedkcs32.dll
                      - 2009-01-28 15:29 . 2010-03-11 12:38   380928              c:\windows\system32\dllcache\ieapfltr.dll
                      + 2009-01-28 15:29 . 2010-05-04 17:20   380928              c:\windows\system32\dllcache\ieapfltr.dll
                      + 2004-08-04 12:00 . 2010-04-16 11:43   161792              c:\windows\system32\dllcache\ieakui.dll
                      - 2004-08-04 12:00 . 2010-02-23 05:18   161792              c:\windows\system32\dllcache\ieakui.dll
                      + 2007-08-14 02:39 . 2010-05-04 17:20   230400              c:\windows\system32\dllcache\ieaksie.dll
                      - 2007-08-14 02:39 . 2010-03-11 12:38   230400              c:\windows\system32\dllcache\ieaksie.dll
                      - 2007-08-14 02:39 . 2010-03-11 12:38   153088              c:\windows\system32\dllcache\ieakeng.dll
                      + 2007-08-14 02:39 . 2010-05-04 17:20   153088              c:\windows\system32\dllcache\ieakeng.dll
                      + 2007-08-14 02:54 . 2010-05-04 17:20   133120              c:\windows\system32\dllcache\extmgr.dll
                      - 2007-08-14 02:54 . 2010-03-11 12:38   133120              c:\windows\system32\dllcache\extmgr.dll
                      + 2007-08-14 02:35 . 2010-05-04 17:20   214528              c:\windows\system32\dllcache\dxtrans.dll
                      - 2007-08-14 02:35 . 2010-03-11 12:38   214528              c:\windows\system32\dllcache\dxtrans.dll
                      + 2007-08-14 02:35 . 2010-05-04 17:20   347136              c:\windows\system32\dllcache\dxtmsft.dll
                      - 2007-08-14 02:35 . 2010-03-11 12:38   347136              c:\windows\system32\dllcache\dxtmsft.dll
                      + 2010-04-20 05:30 . 2010-04-20 05:30   285696              c:\windows\system32\dllcache\atmfd.dll
                      + 2009-01-28 14:40 . 2008-04-13 16:39   142592              c:\windows\system32\dllcache\aec.sys
                      - 2007-08-14 02:39 . 2010-03-11 12:38   124928              c:\windows\system32\dllcache\advpack.dll
                      + 2007-08-14 02:39 . 2010-05-04 17:20   124928              c:\windows\system32\dllcache\advpack.dll
                      - 2004-08-04 12:00 . 2008-04-14 00:09   285696              c:\windows\system32\atmfd.dll
                      + 2004-08-04 12:00 . 2010-04-20 05:30   285696              c:\windows\system32\atmfd.dll
                      + 2004-08-04 12:00 . 2010-05-04 17:20   124928              c:\windows\system32\advpack.dll
                      - 2004-08-04 12:00 . 2010-03-11 12:38   124928              c:\windows\system32\advpack.dll
                      + 2010-03-31 04:16 . 2010-03-31 04:16   130408              c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
                      + 2010-04-08 03:48 . 2010-04-08 03:48   970752              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
                      - 2008-07-30 03:16 . 2008-07-30 03:16   110592              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
                      + 2010-04-08 03:48 . 2010-04-08 03:48   110592              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
                      + 2010-03-23 09:31 . 2010-03-23 09:31   435024              c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
                      + 2010-02-09 16:22 . 2010-02-09 16:22   258048              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
                      - 2008-07-25 19:17 . 2008-07-25 19:17   258048              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
                      - 2008-05-28 04:49 . 2008-05-28 04:49   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
                      + 2010-03-31 18:51 . 2010-03-31 18:51   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
                      - 2008-05-28 04:48 . 2008-05-28 04:48   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
                      + 2010-03-31 18:49 . 2010-03-31 18:49   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
                      + 2010-03-31 19:32 . 2010-03-31 19:32   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
                      - 2008-05-28 05:30 . 2008-05-28 05:30   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
                      + 2010-06-10 12:22 . 2010-06-10 12:22   200192              c:\windows\Installer\be07f0b.msi
                      + 2010-02-25 04:14 . 2010-02-25 04:14   543232              c:\windows\Installer\be07e85.msp
                      + 2010-06-16 19:39 . 2010-06-16 19:39   454144              c:\windows\Installer\a68871.msi
                      + 2010-06-16 19:33 . 2010-06-16 19:33   356352              c:\windows\Installer\a6884b.msi
                      + 2010-06-16 19:32 . 2010-06-16 19:32   315392              c:\windows\Installer\a68843.msi
                      + 2010-06-16 19:32 . 2010-06-16 19:32   316928              c:\windows\Installer\a6883b.msi
                      + 2010-06-16 19:32 . 2010-06-16 19:32   356864              c:\windows\Installer\a68833.msi
                      + 2010-06-16 19:31 . 2010-06-16 19:31   359424              c:\windows\Installer\a6882b.msi
                      + 2010-06-16 19:31 . 2010-06-16 19:31   356352            &nbs

                      ToniCarman

                        Topic Starter


                        Rookie

                        Re: Malware infection
                        « Reply #25 on: July 22, 2010, 02:05:24 PM »
                        I guess it is too long. I will copy in multiple posts.

                        + 2010-06-16 19:31 . 2010-06-16 19:31   356352              c:\windows\Installer\a68823.msi
                        + 2010-06-16 19:31 . 2010-06-16 19:31   316416              c:\windows\Installer\a6881b.msi
                        + 2010-06-11 23:07 . 2010-06-11 23:07   168960              c:\windows\Installer\843fc78.msp
                        + 2010-05-08 16:34 . 2010-05-08 16:34   881664              c:\windows\Installer\28fe89.msi
                        + 2009-01-28 18:22 . 2010-07-15 11:04   409600              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
                        - 2009-01-28 18:22 . 2010-04-14 03:47   409600              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
                        - 2009-01-28 18:22 . 2010-04-14 03:47   286720              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
                        + 2009-01-28 18:22 . 2010-07-15 11:04   286720              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
                        + 2009-01-28 18:22 . 2010-07-15 11:04   249856              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
                        - 2009-01-28 18:22 . 2010-04-14 03:47   249856              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
                        - 2009-01-28 18:22 . 2010-04-14 03:47   794624              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
                        + 2009-01-28 18:22 . 2010-07-15 11:04   794624              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
                        + 2009-01-28 18:22 . 2010-07-15 11:04   135168              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
                        - 2009-01-28 18:22 . 2010-04-14 03:47   135168              c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
                        + 2010-07-14 13:10 . 2010-07-17 14:01   102400              c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
                        + 2010-06-10 11:51 . 2010-03-11 12:38   832512              c:\windows\ie7updates\KB982381-IE7\wininet.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   233472              c:\windows\ie7updates\KB982381-IE7\webcheck.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   105984              c:\windows\ie7updates\KB982381-IE7\url.dll
                        + 2010-06-10 11:52 . 2009-05-26 11:40   382840              c:\windows\ie7updates\KB982381-IE7\spuninst\updspapi.dll
                        + 2010-06-10 11:52 . 2008-07-08 13:02   231288              c:\windows\ie7updates\KB982381-IE7\spuninst\spuninst.exe
                        + 2010-06-10 11:51 . 2010-03-11 12:38   102912              c:\windows\ie7updates\KB982381-IE7\occache.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   671232              c:\windows\ie7updates\KB982381-IE7\mstime.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   193024              c:\windows\ie7updates\KB982381-IE7\msrating.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   477696              c:\windows\ie7updates\KB982381-IE7\mshtmled.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   459264              c:\windows\ie7updates\KB982381-IE7\msfeeds.dll
                        + 2010-06-10 11:52 . 2010-02-23 05:20   634648              c:\windows\ie7updates\KB982381-IE7\iexplore.exe
                        + 2010-06-10 11:52 . 2010-03-11 12:38   268288              c:\windows\ie7updates\KB982381-IE7\iertutil.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   192512              c:\windows\ie7updates\KB982381-IE7\iepeers.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   385024              c:\windows\ie7updates\KB982381-IE7\iedkcs32.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   380928              c:\windows\ie7updates\KB982381-IE7\ieapfltr.dll
                        + 2010-06-10 11:52 . 2010-02-23 05:18   161792              c:\windows\ie7updates\KB982381-IE7\ieakui.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   230400              c:\windows\ie7updates\KB982381-IE7\ieaksie.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   153088              c:\windows\ie7updates\KB982381-IE7\ieakeng.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   133120              c:\windows\ie7updates\KB982381-IE7\extmgr.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   214528              c:\windows\ie7updates\KB982381-IE7\dxtrans.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   347136              c:\windows\ie7updates\KB982381-IE7\dxtmsft.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   124928              c:\windows\ie7updates\KB982381-IE7\advpack.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_00504892\System.Drawing.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_01398cc1\System.Drawing.Design.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_7930f4fc\CustomMarshalers.dll
                        + 2010-06-10 12:26 . 2010-06-10 12:26   321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4d07b1ccecca66f320c1a0971dd614d1\WsatConfig.ni.exe
                        + 2010-06-10 12:29 . 2010-06-10 12:29   633856              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\31a06c9eb6c083d9b8710ac6ce1be937\WindowsLiveLocal.WriterPlugin.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   319488              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f0530ae077336e0eca143d4b32e8d34e\WindowsLive.Writer.Interop.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   258048              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e50904b2c1e6e1ac5a4c7df032c2123c\WindowsLive.Writer.Mshtml.ni.dll
                        + 2010-06-10 12:27 . 2010-06-10 12:27   843776              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c6f20d937db1a69d005f791db60ee326\WindowsLive.Writer.Controls.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   118784              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c35124ff18874635fa84856596f154cc\WindowsLive.Writer.Extensibility.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   152064              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c1992981a0cafba5e0d3753b8ec39b21\WindowsLive.Writer.HtmlParser.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   594944              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bea5a870bbb250130356c5dd8c2f3ca9\WindowsLive.Writer.HtmlEditor.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   428032              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b07e085adf681435595a729c5f8ca528\WindowsLive.Writer.Localization.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   119296              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a148f5e5315f10bd4dfb626fdcf001c2\WindowsLive.Writer.FileDestinations.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   851968              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\53a0614cafe16513d774a5d7b0473a73\WindowsLive.Writer.BlogClient.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   117760              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4190016a1225c8f33b8ebd96addb2a8e\WindowsLive.Writer.Instrumentation.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   322048              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\27e34aec3681f62ec3791cdfe9ac0230\WindowsLive.Writer.SpellChecker.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   108544              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\18dce358e91aedbd9656a6a0d0da582a\WindowsLive.Writer.Passport.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   174080              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\06657a351a8cafd8101bbd06c31c6194\WindowsLive.Writer.BrowserControl.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   145920              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\3aca1d7df14c17850246ef5ebca827c5\WindowsLive.Client.ni.dll
                        + 2010-06-24 07:11 . 2010-06-24 07:11   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3a9fac9aea3ad913781fafbdcbb0cae\WindowsFormsIntegration.ni.dll
                        + 2010-06-10 12:20 . 2010-06-10 12:20   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a7c702f75d47bf841b9587e582c2d0b2\WindowsFormsIntegration.ni.dll
                        + 2010-06-24 07:11 . 2010-06-24 07:11   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\4131a3627fec69291dbaed236f30dc65\UIAutomationClient.ni.dll
                        + 2010-06-10 12:20 . 2010-06-10 12:20   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3a78043c85333d5af49a0d958912ae4a\UIAutomationClient.ni.dll
                        + 2010-06-10 12:32 . 2010-06-10 12:32   400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\747e84d81d1de2041661f0f71b04734a\System.Xml.Linq.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d51dfbd8d5431eb89181baaa24863e15\System.Web.Routing.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\436dde9611932489da3dc8a1be170843\System.Web.RegularExpressions.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   859648              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\e8ef769b3e899e62b26daadee50b97ed\System.Web.Extensions.Design.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   328704              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\ce3b446b7bee5c47949c994ec89b1649\System.Web.Entity.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   301056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ad04fe1182e55e7c01066b62a4bee6b5\System.Web.Entity.Design.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\20ba0d4d182a1a9c1f54c00d3bc29a68\System.Web.DynamicData.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\c97ecf9250c2f0794262534f27f98b72\System.Web.Abstractions.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   627200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9c56656c88979cf18de6cbcb6587ba8f\System.Transactions.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   679936              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\42b2ffb594dbd5652a576a0dce28722c\System.Security.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   311296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   771584              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2077ce69bd24a095dd54683ae26454d4\System.Runtime.Remoting.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   621056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\f90965b9d9a6a6604c9a66f57c37c026\System.Net.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   998400              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   330752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e6bd59fec415e273c173170c6508180a\System.Management.Instrumentation.ni.dll
                        + 2010-06-10 12:25 . 2010-06-10 12:25   381440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e3eb86170cba4c80e6e22ca33c63c218\System.IO.Log.ni.dll
                        + 2010-06-10 12:27 . 2010-06-10 12:27   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cfa48936affc9a5fb89f0bf66cc52a47\System.IdentityModel.Selectors.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   280064              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.Wrapper.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   627712              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.ni.dll
                        + 2010-06-10 12:19 . 2010-06-10 12:19   208384              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\aeba6820f20655dec7fe0fe05aaeb818\System.Drawing.Design.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   455680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9ef70079beca3a9982a3aa76ebc0ddd8\System.DirectoryServices.Protocols.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   881152              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\277619716d9136216065bea970365c65\System.DirectoryServices.AccountManagement.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   939008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\90b67e13866b176ae6cbdb23144f724d\System.Data.Services.Client.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   354816              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\131a477d41a8669b15696128b94c2636\System.Data.Services.Design.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   756736              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\d4990681ce373d81a52b231ee4c4afea\System.Data.Entity.Design.ni.dll
                        + 2010-06-10 12:30 . 2010-06-10 12:30   135680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\9e9d66a3a0e16fceead505c25af569eb\System.Data.DataSetExtensions.ni.dll
                        + 2010-06-10 12:27 . 2010-06-10 12:27   971264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\39e4f9a276fb12125d8a1444d8b65a84\System.Configuration.Install.ni.dll
                        + 2010-06-10 12:30 . 2010-06-10 12:30   633856              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\849916c5cb3ff7763d15a3976766c2f6\System.AddIn.ni.dll
                        + 2010-06-10 12:26 . 2010-06-10 12:26   366080              c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\f38a426b90e6c526dcb2c435c7380450\SMSvcHost.ni.exe
                        + 2010-06-10 12:26 . 2010-06-10 12:26   256000              c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6cabc7d1700c224e8b41ff2f96a3087c\SMDiagnostics.ni.dll
                        + 2010-06-10 12:26 . 2010-06-10 12:26   320512              c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5c8f5ca36498f43980d64820d8186c8a\ServiceModelReg.ni.exe
                        + 2010-06-10 12:15 . 2010-06-10 12:15   258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae733e4062edba3a33bb0a632bef66bf\PresentationFramework.Royale.ni.dll
                        + 2010-06-24 07:10 . 2010-06-24 07:10   368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a10c2c7e38291c3ada631ad13e762818\PresentationFramework.Aero.ni.dll
                        + 2010-06-24 07:10 . 2010-06-24 07:10   539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll
                        + 2010-06-10 12:14 . 2010-06-10 12:14   368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3ffad524016f0aba7b11a8aa33301a65\PresentationFramework.Aero.ni.dll
                        + 2010-06-24 07:10 . 2010-06-24 07:10   224768              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bef0992fb684e71dbfab5c0a99316af\PresentationFramework.Classic.ni.dll
                        + 2010-06-24 07:10 . 2010-06-24 07:10   258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2f6687d394813d760496f60acf046384\PresentationFramework.Royale.ni.dll
                        + 2010-06-10 12:14 . 2010-06-10 12:14   224768              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\201968d038a23a4688310fed1eeaddaa\PresentationFramework.Classic.ni.dll
                        + 2010-06-10 12:14 . 2010-06-10 12:14   539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1ead87ca8eb84c595c77c70e3b2df88d\PresentationFramework.Luna.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   133632              c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7700963610c1af364aa934c3c824b7b4\MSBuild.ni.exe
                        + 2010-06-10 12:26 . 2010-06-10 12:26   386560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c74d4c69c49992dfb23ba512081dc3de\Microsoft.Transactions.Bridge.Dtc.ni.dll
                        + 2010-06-10 12:30 . 2010-06-10 12:30   144384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a6a9f24b1a8984eaafbabb1ee968e359\Microsoft.Build.Utilities.ni.dll
                        + 2010-06-10 12:30 . 2010-06-10 12:30   175104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\2fa81d363cb1496be2427d848a867409\Microsoft.Build.Utilities.v3.5.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   839680              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c4c360df9c1024ebc3f0de77f5cf8b1c\Microsoft.Build.Engine.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   222720              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c9386dcd89c2518a74115f3bfd861830\Microsoft.Build.Conversion.v3.5.ni.dll
                        + 2010-06-10 12:26 . 2010-06-10 12:26   410112              c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\abb62e3ed74c974f0282bc7ea5d3f1c1\ComSvcConfig.ni.exe
                        + 2010-06-10 12:27 . 2010-06-10 12:27   842240              c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\6d34f00b6a782d15bec70d6cdb00b5e8\AspNetMMCExt.ni.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
                        + 2010-06-10 12:10 . 2010-06-10 12:10   970752              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
                        + 2010-06-10 12:10 . 2010-06-10 12:10   438272              c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
                        - 2009-01-28 15:35 . 2009-01-28 15:35   110592              c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
                        + 2010-06-10 12:10 . 2010-06-10 12:10   110592              c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
                        - 2009-10-17 07:13 . 2009-10-17 07:13   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
                        - 2009-10-17 07:14 . 2009-10-17 07:14   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
                        + 2010-06-24 07:04 . 2010-06-24 07:04   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
                        + 2010-05-26 07:00 . 2009-05-26 09:01   382840              c:\windows\$NtUninstallKB981793$\spuninst\updspapi.dll
                        + 2010-05-26 07:00 . 2009-05-26 09:01   231288              c:\windows\$NtUninstallKB981793$\spuninst\spuninst.exe
                        + 2010-06-10 12:28 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB980218$\spuninst\updspapi.dll
                        + 2010-06-10 12:28 . 2009-05-26 11:40   231288              c:\windows\$NtUninstallKB980218$\spuninst\spuninst.exe
                        + 2010-06-10 12:28 . 2008-04-14 00:09   285696              c:\windows\$NtUninstallKB980218$\atmfd.dll
                        + 2010-06-10 12:23 . 2008-07-08 13:02   382840              c:\windows\$NtUninstallKB980195$\spuninst\updspapi.dll
                        + 2010-06-10 12:23 . 2008-07-08 13:02   231288              c:\windows\$NtUninstallKB980195$\spuninst\spuninst.exe
                        + 2010-06-10 12:19 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB979559$\spuninst\updspapi.dll
                        + 2010-06-10 12:19 . 2009-05-26 09:01   231288              c:\windows\$NtUninstallKB979559$\spuninst\spuninst.exe
                        + 2010-06-10 12:12 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB979482$\spuninst\updspapi.dll
                        + 2010-06-10 12:12 . 2009-05-26 11:40   231288              c:\windows\$NtUninstallKB979482$\spuninst\spuninst.exe
                        + 2010-06-10 12:13 . 2007-07-28 03:11   382840              c:\windows\$NtUninstallKB978695_WM9$\spuninst\updspapi.dll
                        + 2010-06-10 12:13 . 2007-07-28 03:11   231288              c:\windows\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe
                        + 2010-05-13 07:01 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB978542$\spuninst\updspapi.dll
                        + 2010-05-13 07:01 . 2009-05-26 11:40   231288              c:\windows\$NtUninstallKB978542$\spuninst\spuninst.exe
                        + 2010-05-13 07:00 . 2008-04-11 19:04   691712              c:\windows\$NtUninstallKB978542$\inetcomm.dll
                        + 2010-06-10 12:12 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB975562$\spuninst\updspapi.dll
                        + 2010-06-10 12:12 . 2008-07-08 13:02   231288              c:\windows\$NtUninstallKB975562$\spuninst\spuninst.exe
                        + 2010-06-10 11:52 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB982381-IE7\update\updspapi.dll
                        + 2010-06-10 11:52 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB982381-IE7\update\update.exe
                        + 2010-06-10 11:52 . 2008-07-08 13:02   231288              c:\windows\$hf_mig$\KB982381-IE7\spuninst.exe
                        + 2010-05-04 17:20 . 2010-05-04 17:20   841216              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\wininet.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   233472              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\webcheck.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   105984              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\url.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   102912              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\occache.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   671232              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mstime.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   193024              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msrating.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   477696              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtmled.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   459264              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeeds.dll
                        + 2010-04-16 11:08 . 2010-04-16 11:08   634648              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
                        + 2010-05-04 17:20 . 2010-05-04 17:20   268288              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iertutil.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   193024              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iepeers.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   388608              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iedkcs32.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   380928              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dll
                        + 2010-04-16 11:06 . 2010-04-16 11:06   161792              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakui.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   230400              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieaksie.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   153088              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakeng.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   132608              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\extmgr.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   214528              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtrans.dll
                        + 2010-05-04 17:20 . 2010-05-04 17:20   347136              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtmsft.dll
                        + 2010-05-04 17:19 . 2010-05-04 17:19   124928              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\advpack.dll
                        + 2010-06-10 12:28 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB980218\update\updspapi.dll
                        + 2010-06-10 12:28 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB980218\update\update.exe
                        + 2010-06-10 12:28 . 2009-05-26 11:40   231288              c:\windows\$hf_mig$\KB980218\spuninst.exe
                        + 2010-04-20 05:37 . 2010-04-20 05:37   285824              c:\windows\$hf_mig$\KB980218\SP3QFE\atmfd.dll
                        + 2010-06-10 12:23 . 2008-07-08 13:02   382840              c:\windows\$hf_mig$\KB980195\update\updspapi.dll
                        + 2010-06-10 12:23 . 2008-07-08 13:02   755576              c:\windows\$hf_mig$\KB980195\update\update.exe
                        + 2010-06-10 12:23 . 2008-07-08 13:02   231288              c:\windows\$hf_mig$\KB980195\spuninst.exe
                        + 2010-06-10 12:19 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB979559\update\updspapi.dll
                        + 2010-06-10 12:19 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB979559\update\update.exe
                        + 2010-06-10 12:19 . 2009-05-26 09:01   231288              c:\windows\$hf_mig$\KB979559\spuninst.exe
                        + 2010-06-10 12:12 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB979482\update\updspapi.dll
                        + 2010-06-10 12:12 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB979482\update\update.exe
                        + 2010-06-10 12:12 . 2009-05-26 11:40   231288              c:\windows\$hf_mig$\KB979482\spuninst.exe
                        + 2010-05-13 07:01 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB978542\update\updspapi.dll
                        + 2010-05-13 07:01 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB978542\update\update.exe
                        + 2010-05-13 07:01 . 2009-05-26 11:40   231288              c:\windows\$hf_mig$\KB978542\spuninst.exe
                        + 2010-01-29 14:53 . 2010-01-29 14:53   691712              c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll
                        + 2010-06-10 12:12 . 2009-05-26 11:40   382840              c:\windows\$hf_mig$\KB975562\update\updspapi.dll
                        + 2010-06-10 12:12 . 2009-05-26 11:40   755576              c:\windows\$hf_mig$\KB975562\update\update.exe
                        + 2010-06-10 12:12 . 2008-07-08 13:02   231288              c:\windows\$hf_mig$\KB975562\spuninst.exe
                        + 2009-06-26 23:07 . 2009-06-26 23:07   3780416              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90u.dll
                        + 2009-06-26 23:07 . 2009-06-26 23:07   3765048              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90.dll
                        + 2009-07-12 00:46 . 2009-07-12 00:46   1093120              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
                        + 2009-07-12 00:46 . 2009-07-12 00:46   1105920              c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
                        + 2004-08-04 12:00 . 2010-04-06 08:52   2462720              c:\windows\system32\WMVCore.dll
                        - 2004-08-04 12:00 . 2010-03-11 12:38   1168384              c:\windows\system32\urlmon.dll
                        + 2004-08-04 12:00 . 2010-05-04 17:20   1168384              c:\windows\system32\urlmon.dll
                        + 2004-08-04 12:00 . 2010-02-05 18:27   1291776              c:\windows\system32\quartz.dll
                        - 2004-08-04 12:00 . 2009-11-27 17:11   1291776              c:\windows\system32\quartz.dll
                        + 2004-08-04 12:00 . 2010-05-04 17:20   3600384              c:\windows\system32\mshtml.dll
                        + 2009-07-18 03:21 . 2010-06-16 20:25   5537232              c:\windows\system32\Macromed\Flash\NPSWF32.dll
                        - 2007-08-14 02:54 . 2010-03-11 12:38   6067200              c:\windows\system32\ieframe.dll
                        + 2007-08-14 02:54 . 2010-05-04 17:20   6067200              c:\windows\system32\ieframe.dll
                        + 2009-01-28 04:53 . 2010-07-14 16:27   4429288              c:\windows\system32\FNTCACHE.DAT
                        + 2004-08-04 12:00 . 2010-04-06 08:52   2462720              c:\windows\system32\dllcache\WMVCore.dll
                        + 2009-01-28 14:48 . 2010-05-02 05:22   1851264              c:\windows\system32\dllcache\win32k.sys
                        - 2007-08-14 02:54 . 2010-03-11 12:38   1168384              c:\windows\system32\dllcache\urlmon.dll
                        + 2007-08-14 02:54 . 2010-05-04 17:20   1168384              c:\windows\system32\dllcache\urlmon.dll
                        + 2008-05-07 05:12 . 2010-02-05 18:27   1291776              c:\windows\system32\dllcache\quartz.dll
                        - 2008-05-07 05:12 . 2009-11-27 17:11   1291776              c:\windows\system32\dllcache\quartz.dll
                        - 2009-08-12 21:03 . 2009-07-10 13:27   1315328              c:\windows\system32\dllcache\msoe.dll
                        + 2009-08-12 21:03 . 2010-01-29 15:01   1315328              c:\windows\system32\dllcache\msoe.dll
                        + 2007-08-14 02:54 . 2010-05-04 17:20   3600384              c:\windows\system32\dllcache\mshtml.dll
                        - 2009-01-28 15:29 . 2010-03-11 12:38   6067200              c:\windows\system32\dllcache\ieframe.dll
                        + 2009-01-28 15:29 . 2010-05-04 17:20   6067200              c:\windows\system32\dllcache\ieframe.dll
                        + 2009-11-07 05:06 . 2009-11-07 05:06   1130824              c:\windows\system32\dfshim.dll
                        + 2010-04-08 03:48 . 2010-04-08 03:48   5967872              c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
                        - 2008-11-25 12:59 . 2008-11-25 12:59   5242880              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
                        + 2010-03-23 09:32 . 2010-03-23 09:32   5242880              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
                        + 2010-03-23 09:32 . 2010-03-23 09:32   3182592              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
                        - 2008-05-28 05:35 . 2008-05-28 05:35   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
                        + 2010-04-01 15:42 . 2010-04-01 15:42   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
                        - 2008-05-28 05:35 . 2008-05-28 05:35   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
                        + 2010-04-01 15:42 . 2010-04-01 15:42   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
                        - 2008-05-28 04:48 . 2008-05-28 04:48   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
                        + 2010-03-31 18:50 . 2010-03-31 18:50   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
                        + 2010-03-31 18:50 . 2010-03-31 18:50   2527232              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
                        - 2008-05-28 04:43 . 2008-05-28 04:43   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
                        + 2010-04-01 15:42 . 2010-04-01 15:42   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
                        + 2010-06-16 20:25 . 2010-06-16 20:25   1093120              c:\windows\Installer\d825a5.msi
                        + 2010-05-03 20:27 . 2010-05-03 20:27   6825472              c:\windows\Installer\be07f42.msp
                        + 2010-05-03 20:11 . 2010-05-03 20:11   4149760              c:\windows\Installer\be07ee7.msp
                        + 2010-05-05 02:25 . 2010-05-05 02:25   7681024              c:\windows\Installer\be07ed1.msp
                        + 2010-05-10 21:17 . 2010-05-10 21:17   5520896              c:\windows\Installer\be07ebb.msp
                        + 2010-04-12 02:17 . 2010-04-12 02:17   2607104              c:\windows\Installer\be07e94.msp
                        + 2010-04-12 02:17 . 2010-04-12 02:17   4210688              c:\windows\Installer\be07e93.msp
                        + 2010-04-24 21:10 . 2010-04-24 21:10   8486400              c:\windows\Installer\be07e74.msp
                        + 2010-05-03 20:06 . 2010-05-03 20:06   5053952              c:\windows\Installer\be07e69.msp
                        + 2010-06-16 19:43 . 2010-06-16 19:43   1093120              c:\windows\Installer\a68889.msi
                        + 2009-10-16 22:07 . 2009-10-16 22:07   6115328              c:\windows\Installer\4b9138a.msp
                        + 2010-04-21 21:46 . 2010-04-21 21:46   5522432              c:\windows\Installer\4b91374.msp
                        + 2010-07-14 13:26 . 2010-07-14 13:26   6483968              c:\windows\Installer\47ec359.msi
                        + 2009-11-09 04:25 . 2009-11-09 04:25   1935360              c:\windows\Installer\43767ad.msp
                        + 2010-05-25 15:45 . 2010-05-25 15:45   8445440              c:\windows\Installer\3fb686e.msp
                        + 2010-07-01 02:52 . 2010-07-01 02:52   5522944              c:\windows\Installer\3fb6857.msp
                        + 2010-07-17 14:01 . 2010-07-17 14:01   1904640              c:\windows\Installer\24ef50.msi
                        + 2009-01-30 07:03 . 2010-07-13 16:53   3777536              c:\windows\Installer\12178a.msi
                        - 2009-01-30 07:03 . 2010-04-14 23:13   3777536              c:\windows\Installer\12178a.msi
                        + 2010-06-10 11:51 . 2010-03-11 12:38   1168384              c:\windows\ie7updates\KB982381-IE7\urlmon.dll
                        + 2010-06-10 11:51 . 2010-03-11 12:38   3599872              c:\windows\ie7updates\KB982381-IE7\mshtml.dll
                        + 2010-06-10 11:52 . 2010-03-11 12:38   6067200              c:\windows\ie7updates\KB982381-IE7\ieframe.dll
                        + 2009-01-28 15:38 . 2009-01-28 15:38   5283840              c:\windows\assembly\temp\PCP2T7DR5Y\PresentationFramework.dll
                        + 2009-01-28 15:35 . 2009-01-28 15:35   4210688              c:\windows\assembly\temp\4CMKJJJJJJ\PresentationCore.dll
                        + 2009-01-28 15:35 . 2009-01-28 15:35   1245184              c:\windows\assembly\temp\0ILZDDDDDD\WindowsBase.dll
                        + 2010-06-10 12:23 . 2010-06-10 12:23   1966080              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f636947c\System.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   4792320              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_79ae7e92\System.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   5513216              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_c444e089\System.Xml.dll
                        + 2010-06-10 12:23 . 2010-06-10 12:23   2088960              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_66bef7e9\System.Xml.dll
                        + 2010-06-10 12:23 . 2010-06-10 12:23   3018752              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b54f8c9d\System.Windows.Forms.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   7884800              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6b5a1c44\System.Windows.Forms.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   2244608              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_09d267e4\System.Drawing.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   3395584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_b8fadec9\System.Design.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   1470464              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_297bc57f\System.Design.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   8908800              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d460f315\mscorlib.dll
                        + 2010-06-10 12:24 . 2010-06-10 12:24   3391488              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7590502d\mscorlib.dll
                        + 2010-06-10 12:27 . 2010-06-10 12:27   6392832              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\af8ff11dbab485d5d13323bbf6a5be79\WindowsLive.Writer.PostEditor.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   2002432              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\590ced109c1eb276203e1561a695ab99\WindowsLive.Writer.CoreServices.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   1105920              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0654d7056eddd323f13f38ff67325ca7\WindowsLive.Writer.ApplicationFramework.ni.dll
                        + 2010-06-10 12:10 . 2010-06-10 12:10   3313664              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\f231461883859922a040002dddfb7b12\WindowsBase.ni.dll
                        + 2010-06-24 07:08 . 2010-06-24 07:08   3325440              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll
                        + 2010-06-24 07:11 . 2010-06-24 07:11   1049600              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\d8549ce90b26cdc3071224ab6f020189\UIAutomationClientsideProviders.ni.dll
                        + 2010-06-10 12:20 . 2010-06-10 12:20   1049600              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\48b66876f72f472db62de48ae4369406\UIAutomationClientsideProviders.ni.dll
                        + 2010-06-10 12:09 . 2010-06-10 12:09   7949824              c:\windows\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
                        + 2010-06-10 12:20 . 2010-06-10 12:20   5450752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
                        + 2010-06-10 12:32 . 2010-06-10 12:32   1356288              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\016b75f60a18535c8d6b3e5d861ab559\System.WorkflowServices.ni.dll
                        + 2010-06-10 12:32 . 2010-06-10 12:32   1908224              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6dacae37d337004345518976fb57099e\System.Workflow.Runtime.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   4514304              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c7b832bbc5bb11c6c7f128c801ce90d7\System.Workflow.ComponentModel.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   2992640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b9ea6ea910293cd6f13f765775867ebd\System.Workflow.Activities.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   2209280              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\5dfda43f1991ee6ba345d62b2be4801c\System.Web.Mobile.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   2403328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f08b3b8cdf548e3dfe61f342536175eb\System.Web.Extensions.ni.dll
                        + 2010-06-10 12:19 . 2010-06-10 12:19   1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2d6a5dbee4506bf643b853e41668afa3\System.Speech.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   1706496              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\169fe0ad9d59982a2a6b89779c09885b\System.ServiceModel.Web.ni.dll
                        + 2010-06-10 12:25 . 2010-06-10 12:25   2345472              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8b2710a63ecd363315ef16b257588b95\System.Runtime.Serialization.ni.dll
                        + 2010-06-24 07:11 . 2010-06-24 07:11   1035264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\af217ef58e5558991f331d482c2bdba6\System.Printing.ni.dll
                        + 2010-06-10 12:19 . 2010-06-10 12:19   1035264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\161b423dc4e86e569af019e838d39de5\System.Printing.ni.dll
                        + 2010-06-10 12:25 . 2010-06-10 12:25   1070080              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\ad4fb86064d7a1ebcb9ee997e7208ac1\System.IdentityModel.ni.dll
                        + 2010-06-10 12:18 . 2010-06-10 12:18   1587200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   1116672              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7deab2494d53763cd83c567e71e0d8e0\System.DirectoryServices.ni.dll
                        + 2010-06-10 12:28 . 2010-06-10 12:28   1801216              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\b81efadfee7702624b713c6d86f7e369\System.Deployment.ni.dll
                        + 2010-06-10 12:16 . 2010-06-10 12:16   6616576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll
                        + 2010-06-10 12:27 . 2010-06-10 12:27   2510336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f71abf392c5ca05a4e46a5d1c4c72856\System.Data.SqlXml.ni.dll
                        + 2010-06-10 12:31 . 2010-06-10 12:31   1328128              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\5e6311aff5ada83d0f854922fa62faf6\System.Data.Services.ni.dll
                        + 2010-06-10 12:29 . 2010-06-10 12:29   1115136              c:\windows\assembly\NativeImages_v2.0.5072

                        ToniCarman

                          Topic Starter


                          Rookie

                          Re: Malware infection
                          « Reply #26 on: July 22, 2010, 02:08:50 PM »
                          + 2010-06-10 12:29 . 2010-06-10 12:29   1115136              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f249a2dbc8dcb91860d0997c163c73ff\System.Data.OracleClient.ni.dll
                          + 2010-06-10 12:16 . 2010-06-10 12:16   2516480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3ba3367d03779ad6e76c5d4cdfe572a\System.Data.Linq.ni.dll
                          + 2010-06-10 12:30 . 2010-06-10 12:30   9924096              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6abf820d8ec57a0561c3367727d274df\System.Data.Entity.ni.dll
                          + 2010-06-10 12:16 . 2010-06-10 12:16   2295296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e98726349766935ec0e9b980f19a046a\System.Core.ni.dll
                          + 2010-06-10 12:16 . 2010-06-10 12:16   2128896              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\fc373f0a8dbd173c63b6b95551b1c673\ReachFramework.ni.dll
                          + 2010-06-24 07:10 . 2010-06-24 07:10   2128896              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll
                          + 2010-06-10 12:16 . 2010-06-10 12:16   1657856              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\ead93b6a4f0101cb99d09f3e3fc6491c\PresentationUI.ni.dll
                          + 2010-06-24 07:10 . 2010-06-24 07:10   1657856              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll
                          + 2010-06-10 12:09 . 2010-06-10 12:09   1451008              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\20ef773b20f6ce721ae60e5c2c2e8f80\PresentationBuildTasks.ni.dll
                          + 2010-06-10 12:30 . 2010-06-10 12:30   1712128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\935b855860088a86bb65d37a19f059cc\Microsoft.VisualBasic.ni.dll
                          + 2010-06-10 12:26 . 2010-06-10 12:26   1093120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7a266de493d30eed21cb60ebe300be53\Microsoft.Transactions.Bridge.ni.dll
                          + 2010-06-10 12:31 . 2010-06-10 12:31   2332160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\9db8f9f7fe63ca4451bb5316a3ebb009\Microsoft.JScript.ni.dll
                          + 2010-06-10 12:30 . 2010-06-10 12:30   1966080              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c96be82d6cb00367db4e3553272165ef\Microsoft.Build.Tasks.v3.5.ni.dll
                          + 2010-06-10 12:29 . 2010-06-10 12:29   1620992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3815de5b052187b5d9375681a6784255\Microsoft.Build.Tasks.ni.dll
                          + 2010-06-10 12:29 . 2010-06-10 12:29   1888768              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\43fc6723d08e9ce88701c29653efd224\Microsoft.Build.Engine.ni.dll
                          + 2010-06-24 07:07 . 2010-06-24 07:07   1249280              c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   3182592              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
                          - 2009-10-17 07:14 . 2009-10-17 07:14   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
                          - 2009-10-17 07:13 . 2009-10-17 07:13   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
                          + 2010-06-10 12:10 . 2010-06-10 12:10   5967872              c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
                          - 2009-10-17 07:13 . 2009-10-17 07:13   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
                          + 2010-06-24 07:07 . 2010-06-24 07:07   5279744              c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
                          + 2010-06-24 07:03 . 2010-06-24 07:03   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
                          - 2009-10-17 07:13 . 2009-10-17 07:13   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
                          - 2009-10-17 07:14 . 2009-10-17 07:14   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
                          + 2010-06-24 07:07 . 2010-06-24 07:07   4210688              c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
                          - 2009-01-28 15:35 . 2009-01-28 15:35   4210688              c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
                          + 2010-06-24 07:04 . 2010-06-24 07:04   4546560              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
                          - 2009-10-17 07:14 . 2009-10-17 07:14   4546560              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
                          + 2010-06-10 12:23 . 2010-06-10 12:23   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
                          - 2009-10-17 07:02 . 2009-10-17 07:02   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
                          + 2010-06-10 12:23 . 2010-06-10 12:23   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
                          - 2009-10-17 07:02 . 2009-10-17 07:02   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
                          + 2010-06-10 12:19 . 2009-08-14 13:21   1850624              c:\windows\$NtUninstallKB979559$\win32k.sys
                          + 2010-06-10 12:13 . 2009-05-20 08:56   2458112              c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
                          + 2010-05-13 07:00 . 2009-07-10 13:27   1315328              c:\windows\$NtUninstallKB978542$\msoe.dll
                          + 2010-06-10 12:12 . 2009-11-27 17:11   1291776              c:\windows\$NtUninstallKB975562$\quartz.dll
                          + 2010-05-04 17:20 . 2010-05-04 17:20   1171968              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\urlmon.dll
                          + 2010-05-04 17:20 . 2010-05-04 17:20   3603456              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtml.dll
                          + 2010-05-04 17:20 . 2010-05-04 17:20   6071296              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieframe.dll
                          + 2010-06-09 23:07 . 2009-06-29 08:33   2452872              c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dat
                          + 2010-05-02 06:34 . 2010-05-02 06:34   1860352              c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys
                          + 2010-01-29 14:53 . 2010-01-29 14:53   1315328              c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
                          + 2010-02-05 18:29 . 2010-02-05 18:29   1291776              c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
                          + 2009-01-28 15:27 . 2010-07-02 19:39   34045896              c:\windows\system32\MRT.exe
                          + 2010-04-02 23:29 . 2010-04-02 23:29   11413504              c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp
                          + 2010-05-11 15:30 . 2010-05-11 15:30   11194880              c:\windows\Installer\be07f58.msp
                          + 2010-04-02 16:30 . 2010-04-02 16:30   17456640              c:\windows\Installer\be07f2d.msp
                          + 2010-04-24 21:09 . 2010-04-24 21:09   11750912              c:\windows\Installer\be07ef2.msp
                          + 2010-04-12 02:17 . 2010-04-12 02:17   14599680              c:\windows\Installer\be07ea5.msp
                          + 2010-03-31 05:23 . 2010-03-31 05:23   15638528              c:\windows\Installer\43767bc.msp
                          + 2010-05-04 17:25 . 2010-05-04 17:25   20240896              c:\windows\Installer\352520c.msp
                          + 2010-05-04 17:20 . 2010-05-04 17:20   15710720              c:\windows\Installer\3525202.msp
                          + 2010-06-04 07:00 . 2010-06-04 07:00   20242432              c:\windows\Installer\2b89935.msp
                          + 2010-06-10 12:19 . 2010-06-10 12:19   12430848              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
                          + 2010-06-10 12:28 . 2010-06-10 12:28   11797504              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
                          + 2010-06-10 12:26 . 2010-06-10 12:26   17403904              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8b74f2fe3f3632f95ff4ddb8c4839a1e\System.ServiceModel.ni.dll
                          + 2010-06-10 12:18 . 2010-06-10 12:18   10683392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll
                          + 2010-06-10 12:13 . 2010-06-10 12:13   14327808              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ca898d942e4d85af4c3d5f14a77c359a\PresentationFramework.ni.dll
                          + 2010-06-24 07:09 . 2010-06-24 07:09   14328320              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll
                          + 2010-06-10 12:12 . 2010-06-10 12:12   12216320              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ba8f917fd89d7afa8885c2a326379f03\PresentationCore.ni.dll
                          + 2010-06-24 07:09 . 2010-06-24 07:09   12215808              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll
                          .
                          -- Snapshot reset to current date --
                          .
                          (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* empty entries & legit default entries are not shown
                          REGEDIT4

                          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                          2010-05-26 19:23   1385864   ----a-w-   c:\program files\Ask.com\GenericAskToolbar.dll

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

                          [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                          [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                          [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                          [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                          "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

                          [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                          [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                          [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                          [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                          "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
                          "nwiz"="nwiz.exe" [2008-09-18 1657376]
                          "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
                          "SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
                          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
                          "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-05-22 181488]
                          "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-05-28 230736]
                          "cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-01-28 771312]
                          "capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-01-28 173296]
                          "capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-01-28 259312]
                          "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2009-01-28 14088]
                          "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-01-27 788880]
                          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
                          "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
                          "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
                          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
                          "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
                          "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
                          "CPMonitor"="c:\program files\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
                          "Desktop Disc Tool"="c:\program files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
                          "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]

                          c:\documents and settings\Toni\Start Menu\Programs\Startup\
                          Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

                          c:\documents and settings\All Users\Start Menu\Programs\Startup\
                          Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
                          HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
                          Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]

                          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                          "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
                          2007-05-18 21:30   79368   ----a-w-   c:\windows\system32\UmxWNP.dll

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                          @="Service"

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                          "AntiVirusOverride"=dword:00000001
                          "FirewallOverride"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
                          "DisableMonitoring"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
                          "DisableMonitoring"=dword:00000001

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "EnableFirewall"= 0 (0x0)
                          "DisableNotifications"= 1 (0x1)

                          ToniCarman

                            Topic Starter


                            Rookie

                            Re: Malware infection
                            « Reply #27 on: July 22, 2010, 02:09:22 PM »
                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                            "%windir%\\system32\\sessmgr.exe"=
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                            "c:\\Program Files\\uTorrent\\uTorrent.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                            "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                            "c:\\Program Files\\iTunes\\iTunes.exe"=
                            "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                            "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                            "c:\\Program Files\\Roxio 2010\\Venue\\Venue.exe"=
                            "c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
                            "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

                            R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 11:08 PM 93712]
                            R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/13/2009 7:20 PM 64288]
                            R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2/11/2010 8:42 AM 21488]
                            R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2/11/2010 8:42 AM 15856]
                            R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 11:08 PM 63504]
                            R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 11:08 PM 45584]
                            R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2/11/2010 8:42 AM 25584]
                            R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 8:05 PM 457200]
                            R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 6:40 PM 127352]
                            R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 11:08 PM 134648]
                            R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 11:08 PM 66576]
                            R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 7:17 AM 1181328]
                            R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 2:24 PM 1010192]
                            R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 2:24 PM 801296]
                            R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 11:10 PM 281104]
                            R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 11:08 PM 88816]
                            R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [1/28/2009 2:24 PM 185680]
                            S1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 11:08 PM 115216]
                            S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2010 1:27 PM 136176]
                            S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 9:33 AM 219632]
                            S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 9:33 AM 1116656]
                            .
                            Contents of the 'Scheduled Tasks' folder

                            2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
                            - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

                            2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
                            - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

                            2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
                            - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

                            2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
                            - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

                            2010-07-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                            - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

                            2010-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job
                            - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

                            2010-06-23 c:\windows\Tasks\CAAntiSpywareScan_Daily as Toni at 10 24 AM.job
                            - c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2009-01-28 10:53]

                            2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                            - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26]

                            2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                            - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26]

                            2010-07-22 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
                            - c:\program files\Ask.com\UpdateTask.exe [2010-05-26 19:23]
                            .
                            .
                            ------- Supplementary Scan -------
                            .
                            uLocal Page = \blank.htm
                            uStart Page = hxxp://www.google.com/
                            IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            LSP: c:\windows\system32\VetRedir.dll
                            FF - ProfilePath - c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\
                            FF - prefs.js: browser.search.selectedEngine - Ask
                            FF - prefs.js: browser.startup.homepage - www.google.com
                            FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
                            FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
                            FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_1.dll
                            FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_3.dll
                            FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                            FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
                            FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                            FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
                            FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
                            FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                            FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

                            ---- FIREFOX POLICIES ----
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
                            c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
                            c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
                            c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
                            c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
                            c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
                            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
                            .
                            - - - - ORPHANS REMOVED - - - -

                            BHO-{675B23E3-279D-4AEF-B6F7-5783DA94959C} - c:\windows\system32\hbfqp.dll
                            BHO-{6892BD80-AD3F-4F86-BF67-05DDFC491C6E} - c:\windows\system32\lbfqp.dll
                            HKCU-Run-Usorijaxesab - c:\windows\dimspstl.dll
                            AddRemove-$NtUninstallMTF1011$ - c:\windows\$NtUninstallMTF1011$\apUninstall.exe



                            **************************************************************************

                            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2010-07-22 02:19
                            Windows 5.1.2600 Service Pack 3 NTFS

                            scanning hidden processes ... 

                            scanning hidden autostart entries ...

                            scanning hidden files ... 

                            scan completed successfully
                            hidden files: 0

                            **************************************************************************
                            .
                            --------------------- LOCKED REGISTRY KEYS ---------------------

                            [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                            @Denied: (A 2) (Everyone)
                            @="FlashBroker"
                            "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"

                            [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                            "Enabled"=dword:00000001

                            [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                            @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"

                            [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                            [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                            @Denied: (A 2) (Everyone)
                            @="IFlashBroker4"

                            [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                            @="{00020424-0000-0000-C000-000000000046}"

                            [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                            "Version"="1.0"
                            .
                            --------------------- DLLs Loaded Under Running Processes ---------------------

                            - - - - - - - > 'winlogon.exe'(712)
                            c:\windows\system32\UmxWnp.Dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

                            - - - - - - - > 'explorer.exe'(4608)
                            c:\windows\system32\WININET.dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
                            c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
                            c:\windows\system32\ieframe.dll
                            c:\windows\system32\WPDShServiceObj.dll
                            c:\windows\system32\PortableDeviceTypes.dll
                            c:\windows\system32\PortableDeviceApi.dll
                            .
                            ------------------------ Other Running Processes ------------------------
                            .
                            c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
                            c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
                            c:\program files\Bonjour\mDNSResponder.exe
                            c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
                            c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
                            c:\program files\Java\jre6\bin\jqs.exe
                            c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                            c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                            c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            c:\windows\system32\nvsvc32.exe
                            c:\windows\system32\HPZipm12.exe
                            c:\windows\RTHDCPL.EXE
                            c:\windows\system32\RUNDLL32.EXE
                            c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
                            c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                            c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
                            c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
                            c:\windows\system32\SearchIndexer.exe
                            c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                            c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                            c:\program files\Canon\CAL\CALMAIN.exe
                            c:\windows\system32\wbem\unsecapp.exe
                            c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
                            c:\program files\iPod\bin\iPodService.exe
                            .
                            **************************************************************************
                            .
                            Completion time: 2010-07-22  02:23:33 - machine was rebooted
                            ComboFix-quarantined-files.txt  2010-07-22 06:23
                            ComboFix2.txt  2010-04-16 12:27
                            ComboFix3.txt  2010-04-16 12:16
                            ComboFix4.txt  2010-04-15 11:59

                            Pre-Run: 108,868,366,336 bytes free
                            Post-Run: 108,861,652,992 bytes free

                            - - End Of File - - 5D4E06B3AA9DEF8BD66DE6468C4CB7D0

                            Sneakyone

                            • Malware Removal Specialist


                            • Beginner

                              Thanked: 5
                              Re: Malware infection
                              « Reply #28 on: July 22, 2010, 03:01:29 PM »
                              Hi, :)

                              Please download Malwarebytes Anti-Malware from Here.
                               

                              Double Click mbam-setup.exe to install the application.
                              • Make sure  a checkmark is placed next to Update Malwarebytes Anti-Malware  and Launch Malwarebytes Anti-Malware, then click Finish.
                              • If  an update is found, it will download and install the latest version.
                              • Once  the program has loaded, select "Perform Quick Scan", then click Scan.
                              • The  scan may take some time to finish,so please be patient.
                              • When  the scan is complete, click OK, then Show Results to view the results.
                              • Make  sure that everything is checked, and click Remove Selected.
                              • When  disinfection is completed, a log will open in Notepad and you may be  prompted to Restart.(See Extra Note)
                              • The log is automatically  saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
                              • Copy&Paste  the entire report in your next reply.
                              Extra Note:
                              If MBAM encounters a file that is difficult to  remove,you will be presented with 1 of 2 prompts,click OK to either and  let MBAM proceed with the disinfection process. If asked to restart the  computer, please do so immediatly.

                              ToniCarman

                                Topic Starter


                                Rookie

                                Re: Malware infection
                                « Reply #29 on: July 22, 2010, 05:56:53 PM »
                                Malwarebytes' log:


                                 Malwarebytes' Anti-Malware 1.46
                                www.malwarebytes.org

                                Database version: 4339

                                Windows 5.1.2600 Service Pack 3
                                Internet Explorer 7.0.5730.13

                                7/22/2010 7:58:40 PM
                                mbam-log-2010-07-22 (19-58-40).txt

                                Scan type: Quick scan
                                Objects scanned: 143606
                                Time elapsed: 6 minute(s), 21 second(s)

                                Memory Processes Infected: 0
                                Memory Modules Infected: 0
                                Registry Keys Infected: 5
                                Registry Values Infected: 0
                                Registry Data Items Infected: 0
                                Folders Infected: 0
                                Files Infected: 0

                                Memory Processes Infected:
                                (No malicious items detected)

                                Memory Modules Infected:
                                (No malicious items detected)

                                Registry Keys Infected:
                                HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.

                                Registry Values Infected:
                                (No malicious items detected)

                                Registry Data Items Infected:
                                (No malicious items detected)

                                Folders Infected:
                                (No malicious items detected)

                                Files Infected:
                                (No malicious items detected)