Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan horse Rootkit-Pakes.BI  (Read 12855 times)

0 Members and 1 Guest are viewing this topic.

jefraz

    Topic Starter


    Greenhorn

    • Experience: Beginner
    • OS: Unknown
    Trojan horse Rootkit-Pakes.BI
    « on: December 26, 2011, 01:09:48 PM »
    AVG Resident Shield Alert keeps coming up saying C:\WINDOWS\SYSTEM32\DRIVERS\volsnap.sys

    Trojan horse Rootkit-Pakes.BI

    Is there any way to fix this?

    - SuperAntispyware
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/25/2011 at 05:56 PM

    Application Version : 5.0.1142

    Core Rules Database Version : 8087
    Trace Rules Database Version: 5899

    Scan type       : Complete Scan
    Total Scan Time : 04:50:37

    Operating System Information
    Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
    Administrator

    Memory items scanned      : 510
    Memory threats detected   : 0
    Registry items scanned    : 40295
    Registry threats detected : 0
    File items scanned        : 53436
    File threats detected     : 389

    Adware.IEPlugin
       C:\WINDOWS\isp.ico

    Adware.ClearSearch
       C:\Program Files\ClearSearch

    Adware.BargainBuddy/NaviSearch
       C:\Program Files\BullsEye Network

    Adware.Tracking Cookie
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@atdmt[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@apmebf[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@media6degrees[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tradedoubler[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@bluestreak[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/hotbartenders/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adsonar[2].txt [ Cookie:[email protected]/adserving ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@valueclick[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@sexxyeyes[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@ru4[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/pagead/conversion/1068214132/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adbrite[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@webpower[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@specificclick[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@kanoodle[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@revsci[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@2o7[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tribalfusion[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@chitika[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@lucidmedia[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/pagead/conversion/1033212164/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@internetfuel[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adecn[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@advertise[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@nextag[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@interclick[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@insightexpress[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@revenue[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ftvi/france2/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@doubleclick[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@pointroll[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@questionmarket[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@trafficmp[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@serving-sys[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@fastclick[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@advertising[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@mediaplex[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@adknowledge[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][3].txt [ Cookie:[email protected]/ak/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@zedo[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@toplist[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@targetnet[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@yieldmanager[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/html ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@247realmedia[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@tacoda[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][3].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@insightexpressai[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@pathfinder[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@smartadserver[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@realmedia[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@edgeadx[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[2].txt [ Cookie:[email protected]/hc/76226072 ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@eyewonder[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@weborama[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\[email protected][2].txt [ Cookie:[email protected]/NeROITrack/908 ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@collective-media[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\Cookies\administrator@liveperson[4].txt [ Cookie:[email protected]/hc/37457093 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@mediaplex[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@atwola[3].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@tmpad[1].txt [ Cookie:daniel [email protected]/tmpad ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@doubleclick[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@questionmarket[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ix ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcsew60m1oifwznbkznc6j9ix_5x7j[1].txt [ Cookie:daniel [email protected]/dcsew60m1oifwznbkznc6j9ix_5x7j ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultadworld[2].txt [ Cookie:daniel@*adult URL*/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@burstnet[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@hitbox[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@2o7[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adult-traf[2].txt [ Cookie:daniel@*adult URL*/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsx8czs1erp17368wkcsn8pc_9z2q[1].txt [ Cookie:[email protected]/dcsx8czs1erp17368wkcsn8pc_9z2q ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/cgi-bin ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcsxx9nthdrp17fja823qwk9f_9k9t[2].txt [ Cookie:daniel [email protected]/dcsxx9nthdrp17fja823qwk9f_9k9t ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@cgi-bin[3].txt [ Cookie:daniel [email protected]/cgi-bin ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@2o7[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@maxserving[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@bizrate[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@webpower[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@spylog[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/cgi-bin ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@webpower[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@trafficmp[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@insightexpress[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@estat[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@qksrv[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@focalex[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@findwhat[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@bluestreak[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@dcskqeg2voifwznnd6alhtnei_8f3u[1].txt [ Cookie:daniel [email protected]/dcskqeg2voifwznnd6alhtnei_8f3u ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@fastclick[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@atdmt[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@advertising[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsuuftkberp17368wkcsn8pc_5z5u[2].txt [ Cookie:[email protected]/dcsuuftkberp17368wkcsn8pc_5z5u ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S005-01-3-24-203189-62747[1].txt [ Cookie:[email protected]/S005-01-3-24-203189-62747 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@overture[2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@cgi-bin[2].txt [ Cookie:daniel [email protected]/cgi-bin ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][2].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@revenue[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@boeingmedia[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@exitexchange[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@maxserving[1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel clark@S150235[2].txt [ Cookie:daniel [email protected]/S150235 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indiads[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@gieat[2].txt [ Cookie:[email protected]/gieat/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultactioncam[1].txt [ Cookie:daniel@*adult URL*/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcs9rrxib6twkffavyfc6qjmn_1l5y[1].txt [ Cookie:[email protected]/dcs9rrxib6twkffavyfc6qjmn_1l5y ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adultcheck[1].txt [ Cookie:daniel@*adult URL*/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@commission-junction[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S145588[2].txt [ Cookie:[email protected]/S145588 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@partypoker[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findwhat[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xxxtoolbar[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@partner2profit[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pornochicks[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@specificpop[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@clickability[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S005-01-5-9-246403-73932[1].txt [ Cookie:[email protected]/S005-01-5-9-246403-73932 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@yourmedia[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@roiservice[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@bravenet[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel [email protected][1].txt [ Cookie:daniel [email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@gieat[1].txt [ Cookie:[email protected]/gieat/gieat/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@perfettomedia[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@rgsex[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@rightmedia[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findtherightschool[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@metareward[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsklxjd7oifwzramfu7ehxd9_2j2f[1].txt [ Cookie:[email protected]/dcsklxjd7oifwzramfu7ehxd9_2j2f ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adknowledge[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@insightexpress[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[7].txt [ Cookie:[email protected]/cgi-bin/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@emarketmakers[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xiti[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcsqp2wy611e5hibqykurvsnu_2p1b[1].txt [ Cookie:[email protected]/dcsqp2wy611e5hibqykurvsnu_2p1b ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[3].txt [ Cookie:[email protected]/cgi-bin ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:daniel@www.*adult URL*/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@qnsr[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@local[1].txt [ Cookie:[email protected]/touchplc/local/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@revsci[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/adserver ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexsearchcom[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexlist[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@insightexpresserdd[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@homesexnetwork[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@xxx_rated[1].txt [ Cookie:[email protected]/ecards/adults/xxx_rated/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@paycounter[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@keywordmax[2].txt [ Cookie:[email protected]/tracking/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@toplist[4].txt [ Cookie:[email protected]/cgi-bin/toplist/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indextools[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@S150235[1].txt [ Cookie:[email protected]/S150235 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@adprofile[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@bizrate[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@cgi-bin[8].txt [ Cookie:[email protected]/cgi-bin/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@superstats[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@86793153[1].txt [ Cookie:[email protected]/hc/86793153 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@teacherscount[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@keywordmax[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@spamblockerutility[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@s[1].txt [ Cookie:[email protected]/s/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@onlinerewardcenter[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@home_porn_052[1].txt [ Cookie:[email protected]/homemadevids/home_porn_052/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@europcar[1].txt [ Cookie:[email protected]/europcar/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@resaweb[1].txt [ Cookie:[email protected]/europcar/resaweb/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pathfinder[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][5].txt [ Cookie:[email protected]/hc/33069911 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@vipsexcams[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@winfixer[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@entrepreneur[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@weborama[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/hc/LPneimanmarcus ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@findarticles[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@incentaclick[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/pagead/conversion/1072669019/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@ad[1].txt [ Cookie:[email protected]//ad/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@wTracker[2].txt [ Cookie:[email protected]/wTracker/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@dcs7z2vq0wo4xny3pd9f1blk5_3m5k[1].txt [ Cookie:[email protected]/dcs7z2vq0wo4xny3pd9f1blk5_3m5k ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@indexstats[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@clickbank[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/pagead/conversion/1072499559/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@kmpads[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@sexinfo101[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@thesexydump[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@petfinder[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@chokertraffic[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@hornymatches[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@pornhub[1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@azoogleads[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/hc/28856772 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\daniel@tripod[2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][2].txt [ Cookie:[email protected]/ ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/adserver ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\Cookies\[email protected][1].txt [ Cookie:[email protected]/ ]
       ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       s0.2mdn.net [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       2mdn.net [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       adknowledge.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       b.ads1.msn.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       doubleclick.net [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       ds.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       host-d.oddcast.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       macromedia.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       msnbcmedia.msn.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       naiadsystems.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       orders.webpower.com [ C:\DOCUMENTS AND SETTINGS\DANIEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\AMAXLLA6 ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\DANIEL@ATWOLA[1].TXT [ /ATWOLA ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\DANIEL@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
       C:\DOCUMENTS AND SETTINGS\DANIEL\COOKIES\[email protected][1].TXT [ /SERVEDBY.ADVERTISING ]
       ads1.msn.com [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       msnbcmedia.msn.com [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       s0.2mdn.net [ C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9ELQ2KPU ]
       C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\COOKIES\[email protected][1].TXT [ /Z1.ADSERVER ]
       C:\WINDOWS\SYSTEM32\ROBERT SHINDLER\COOKIES\ADMINISTRATOR@ZEDO[1].TXT [ /ZEDO ]
    - Malwarebytes' Anti-Malware
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 911122603

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    12/26/2011 1:47:01 PM
    mbam-log-2011-12-26 (13-47-01).txt

    Scan type: Quick scan
    Objects scanned: 205876
    Time elapsed: 9 minute(s), 58 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    - DDS logs (DDS.txt & Attach.txt)
    .
    DDS (Ver_2011-06-23.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702
    Run by Joe Frazier at 13:48:52 on 2011-12-26
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1354 [GMT -6:00]
    .
    AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: AVG Firewall *Enabled*
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\AVG\AVG2012\avgfws.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\ihrcovpn\IHRCO VPN Client\cvpnd.exe
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
    C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    C:\WINDOWS\system32\sessmgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://webaccess3.columbiasussex.com/gw/webacc
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
    uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [Google Update] "c:\documents and settings\daniel clark\local settings\application data\google\update\GoogleUpdate.exe" /c
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - hxxp://10.73.30.30:8080/emc/setup.exe
    DPF: {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_01-win.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 10.73.10.5
    TCP: Interfaces\{1B565AA0-3397-4046-A063-455480BF973B} : DhcpNameServer = 10.73.10.5
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    Notify: igfxcui - igfxsrvc.dll
    Notify: LMIinit - LMIinit.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
    R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
    R2 avgfws;AVG Firewall;c:\program files\avg\avg2012\avgfws.exe [2011-11-23 2391832]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-9-26 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-9-16 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-11-20 47640]
    R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-1-11 366152]
    R2 MSSQL$CSS;MSSQL$CSS;c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlservr.exe -scss --> c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlservr.exe -sCSS [?]
    R2 MSSQL$CSS2;SQL Server (CSS2);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2010-12-10 29293408]
    R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-11 22216]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-12 136176]
    S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-12 136176]
    S3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2004-1-12 36013]
    S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
    S3 SQLAgent$CSS;SQLAgent$CSS;c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlagent.exe -i css --> c:\program files\microsoft sql server\mssql$css\binn\mssql$css\binn\sqlagent.EXE -i CSS [?]
    S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2004-3-19 189792]
    S3 w89c940;Winbond W89C940 PCI Ethernet Adapter Driver;c:\windows\system32\drivers\w940nd.sys [2004-1-13 16925]
    S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
    S4 LMIRfsClientNP;LMIRfsClientNP;

    .
    =============== Created Last 30 ================
    .
    2011-12-26 15:32:45   472808   ----a-w-   c:\windows\system32\deployJava1.dll
    2011-12-25 18:58:52   --------   d-----w-   c:\documents and settings\daniel clark\application data\SUPERAntiSpyware.com
    2011-12-25 18:57:30   --------   d-----w-   c:\program files\SUPERAntiSpyware
    2011-12-25 18:57:30   --------   d-----w-   c:\documents and settings\all users\application data\SUPERAntiSpyware.com
    2011-12-25 18:40:38   --------   d-----w-   c:\program files\CCleaner
    2011-12-21 01:21:06   --------   d-----w-   c:\windows\system32\wbem\repository\FS
    2011-12-21 01:21:06   --------   d-----w-   c:\windows\system32\wbem\Repository
    2011-12-04 11:29:56   --------   d-----w-   c:\windows\system32\Robert Shindler
    2011-12-02 07:25:10   --------   d-----w-   c:\documents and settings\daniel clark\local settings\application data\RcIncidents
    .
    ==================== Find3M  ====================
    .
    2011-12-26 15:31:50   73728   ----a-w-   c:\windows\system32\javacpl.cpl
    2011-11-20 19:37:44   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-10-07 11:23:48   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
    2011-10-04 11:21:42   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
    2010-01-07 22:07:10   1394000   ----a-w-   c:\program files\mbam.exe
    2004-05-31 16:55:55   5245352   ----a-w-   c:\program files\SetupDl.EXE
    2004-05-05 20:59:20   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
    2004-04-23 16:38:25   10135688   ----a-w-   c:\program files\MPSetupXP.exe
    2004-02-23 19:52:57   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
    2004-02-23 19:50:49   6262872   ----a-w-   c:\program files\psa2se_us.exe
    2004-02-06 13:39:26   3401360   ----a-w-   c:\program files\Install_AIM.exe
    2003-11-09 01:26:08   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
    .
    ============= FINISH: 13:50:48.12 ===============

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 11/8/2003 5:05:29 PM
    System Uptime: 12/26/2011 1:19:03 PM (0 hours ago)
    .
    Motherboard: Dell Computer Corp. |  | 0G1548
    Processor:               Intel(R) Pentium(R) 4 CPU 2.20GHz | Microprocessor | 2192/400mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 74 GiB total, 49.837 GiB free.
    D: is CDROM ()
    E: is FIXED (FAT) - 0 GiB total, 0.024 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Winbond W89C940-Based Ethernet Adapter (Generic)
    Device ID: PCI\VEN_8E2E&DEV_3000&SUBSYS_00000000&REV_00\4&3B1CAF2B&0&20F0
    Manufacturer: Winbond Electronics Corporation
    Name: Winbond W89C940-Based Ethernet Adapter (Generic)
    PNP Device ID: PCI\VEN_8E2E&DEV_3000&SUBSYS_00000000&REV_00\4&3B1CAF2B&0&20F0
    Service: w89c940
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Packet Scheduler Miniport
    Device ID: ROOT\MS_PSCHEDMP\0004
    Manufacturer: Microsoft
    Name: Packet Scheduler Miniport #5
    PNP Device ID: ROOT\MS_PSCHEDMP\0004
    Service: PSched
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Cisco Systems VPN Adapter
    Device ID: ROOT\NET\0000
    Manufacturer: Cisco Systems
    Name: Cisco Systems VPN Adapter
    PNP Device ID: ROOT\NET\0000
    Service: CVirtA
    .
    ==== System Restore Points ===================
    .
    RP2764: 10/20/2011 2:16:28 PM - Restore Operation
    RP2765: 10/20/2011 2:42:20 PM - Restore Operation
    RP2766: 10/21/2011 11:04:09 AM - Installed TuneUp Utilities 2011
    RP2767: 10/21/2011 5:54:19 PM - Software Distribution Service 3.0
    RP2768: 10/22/2011 7:05:11 PM - System Checkpoint
    RP2769: 10/23/2011 7:34:33 PM - System Chec

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Trojan horse Rootkit-Pakes.BI
    « Reply #1 on: December 26, 2011, 06:12:42 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    Download Security Check by screen317 from one of the following links and save it to your desktop.

    Link 1
    Link 2

    * Double-click Security Check.bat
    * Follow the on-screen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt
    * Post the contents of that document in your next reply.

    Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
    *****************************************************
    Please download ComboFix from BleepingComputer.com

    Alternate link: GeeksToGo.com

    and save it to your Desktop.
    It would be easiest to download using Internet Explorer.
    If you want to use Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
    Double click ComboFix.exe & follow the prompts.
    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

    Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    Click on Yes, to continue scanning for malware.
    When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

    If you have problems with ComboFix usage, see How to use ComboFix
    Windows 8 and Windows 10 dual boot with two SSD's

    jefraz

      Topic Starter


      Greenhorn

      • Experience: Beginner
      • OS: Unknown
      Re: Trojan horse Rootkit-Pakes.BI
      « Reply #2 on: December 27, 2011, 09:40:12 AM »
      Thanks Dave!  Here is the requested information:
      Results of screen317's Security Check version 0.99.30 
       Windows XP Service Pack 3 x86   
       Internet Explorer 8 
      ``````````````````````````````
      Antivirus/Firewall Check:

       Windows Firewall Disabled! 
       AVG 2012     
       Antivirus up to date! 
      ```````````````````````````````
      Anti-malware/Other Utilities Check:

       Malwarebytes' Anti-Malware   
       HijackThis 2.0.2   
       CCleaner     
       Java Web Start   
       Java 2 Runtime Environment Standard Edition v1.3.1_01
       Java(TM) 6 Update 30 
      ````````````````````````````````
      Process Check: 
      objlist.exe by Laurent

       Malwarebytes' Anti-Malware mbamservice.exe 
       Malwarebytes' Anti-Malware mbamgui.exe 
       AVG avgwdsvc.exe
       AVG avgtray.exe
       AVG avgrsx.exe
       AVG avgnsx.exe
       AVG avgemc.exe
      ``````````End of Log````````````


      ComboFix 11-12-27.01 - Joe Frazier 12/27/2011   9:36.4.1 - x86
      Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1629 [GMT -6:00]
      Running from: c:\documents and settings\Daniel Clark\Desktop\Computer Cleanup\ComboFix.exe
      AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
      FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66}
      .
      .
      (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      c:\documents and settings\Administrator\Start Menu\Programs\NaviSearch
      c:\windows\system32\SET727.tmp
      c:\windows\system32\SET72B.tmp
      c:\windows\system32\SET733.tmp
      c:\windows\system32\SET73C.tmp
      c:\windows\system32\SET73D.tmp
      c:\windows\system32\SET73E.tmp
      c:\windows\system32\SET741.tmp
      .
       
       
      .
      .
      (((((((((((((((((((((((((   Files Created from 2011-11-27 to 2011-12-27  )))))))))))))))))))))))))))))))
      .
      .
      2011-12-26 15:32 . 2011-12-26 15:31   472808   ----a-w-   c:\windows\system32\deployJava1.dll
      2011-12-25 18:58 . 2011-12-25 18:58   --------   d-----w-   c:\documents and settings\Daniel Clark\Application Data\SUPERAntiSpyware.com
      2011-12-25 18:57 . 2011-12-25 18:58   --------   d-----w-   c:\program files\SUPERAntiSpyware
      2011-12-25 18:57 . 2011-12-25 18:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
      2011-12-25 18:40 . 2011-12-25 18:40   --------   d-----w-   c:\program files\CCleaner
      2011-12-21 01:21 . 2011-12-21 01:21   --------   d-----w-   c:\windows\system32\wbem\Repository
      2011-12-04 11:29 . 2011-12-08 13:58   --------   d-----w-   c:\windows\system32\Robert Shindler
      2011-12-02 07:25 . 2011-12-02 07:25   --------   d-----w-   c:\documents and settings\Daniel Clark\Local Settings\Application Data\RcIncidents
      .
      .
      .
      ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2011-12-26 15:31 . 2009-01-23 16:18   73728   ----a-w-   c:\windows\system32\javacpl.cpl
      2011-11-20 19:37 . 2011-11-20 19:37   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
      2011-10-07 11:23 . 2011-07-11 06:13   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
      2011-10-04 11:21 . 2011-07-11 06:14   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
      2010-01-07 22:07 . 2010-01-11 18:41   1394000   ----a-w-   c:\program files\mbam.exe
      2004-05-31 16:55 . 2004-03-18 19:32   5245352   ----a-w-   c:\program files\SetupDl.EXE
      2004-05-05 20:59 . 2004-05-05 20:59   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
      2004-04-23 16:38 . 2004-04-23 16:38   10135688   ----a-w-   c:\program files\MPSetupXP.exe
      2004-02-23 19:52 . 2004-02-23 19:51   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
      2004-02-23 19:50 . 2004-02-23 19:50   6262872   ----a-w-   c:\program files\psa2se_us.exe
      2004-02-06 13:39 . 2003-12-19 14:15   3401360   ----a-w-   c:\program files\Install_AIM.exe
      2003-11-09 01:26 . 2003-11-09 01:25   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
      .
      .
      (((((((((((((((((((((((((((((   SnapShot_2011-05-08_18.06.00   )))))))))))))))))))))))))))))))))))))))))
      .
      + 2009-07-12 05:02 . 2009-07-12 05:02   51008              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   61760              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   53568              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   63296              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   35648              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
      + 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
      + 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
      + 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_a4.dat
      + 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_47c.dat
      + 2011-06-22 17:47 . 2011-10-17 18:11   25307              c:\windows\SYSTEM32\winhstp.dat
      + 2007-01-29 08:58 . 2011-07-08 13:49   46080              c:\windows\SYSTEM32\tzchange.exe
      - 2007-01-29 08:58 . 2010-11-03 13:12   46080              c:\windows\SYSTEM32\tzchange.exe
      + 2011-11-20 17:54 . 2011-09-27 00:16   52096              c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\LMIproc.dll
      + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterui.dll
      + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterdat.dll
      + 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinter.dll
      + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterui.dll
      + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterdat.dll
      + 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinter.dll
      + 2003-09-10 20:15 . 2011-11-14 19:26   94634              c:\windows\SYSTEM32\PERFC009.DAT
      + 2002-08-29 10:00 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\oleaccrc.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\mshtmled.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\mshtmled.dll
      + 2006-11-08 03:03 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\msfeedsbs.dll
      - 2006-11-08 03:03 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\msfeedsbs.dll
      + 2011-11-20 17:54 . 2011-09-27 00:16   83360              c:\windows\SYSTEM32\LMIRfsClientNP.dll
      + 2011-11-20 17:54 . 2011-09-27 00:15   30592              c:\windows\SYSTEM32\LMIport.dll
      + 2011-09-16 21:10 . 2011-09-16 21:10   11552              c:\windows\SYSTEM32\lmimirr2.dll
      + 2011-09-16 21:10 . 2011-09-16 21:10   25248              c:\windows\SYSTEM32\lmimirr.dll
      + 2011-11-20 17:54 . 2011-09-27 00:15   87424              c:\windows\SYSTEM32\LMIinit.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\licmgr10.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\licmgr10.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\jsproxy.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\jsproxy.dll
      + 2008-05-06 21:06 . 2008-05-06 21:06   11520              c:\windows\SYSTEM32\DRIVERS\wdcsam.sys
      + 2002-08-29 10:00 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DRIVERS\ndistapi.sys
      + 2010-01-11 18:39 . 2011-08-31 22:00   22216              c:\windows\SYSTEM32\DRIVERS\mbam.sys
      + 2011-11-20 17:54 . 2011-09-16 21:10   47640              c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys
      + 2011-09-16 21:10 . 2011-09-16 21:10   10144              c:\windows\SYSTEM32\DRIVERS\lmimirr.sys
      + 2011-09-13 11:30 . 2011-09-13 11:30   32592              c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
      + 2011-08-08 11:08 . 2011-08-08 11:08   40016              c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
      + 2011-07-11 06:14 . 2011-07-11 06:14   24272              c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys
      + 2011-07-11 06:14 . 2011-07-11 06:14   23120              c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys
      + 2011-05-23 06:03 . 2011-05-23 06:03   30944              c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys
      - 2005-06-13 14:27 . 2008-04-14 00:11   45568              c:\windows\SYSTEM32\dnsrslvr.dll
      + 2005-06-13 14:27 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\dnsrslvr.dll
      - 2009-06-10 13:02 . 2010-12-20 23:59   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
      + 2009-06-10 13:02 . 2011-08-22 23:48   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
      + 2011-09-26 16:41 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\DLLCACHE\oleaccrc.dll
      + 2011-10-16 22:13 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DLLCACHE\ndistapi.sys
      - 2006-05-10 05:23 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
      + 2006-05-10 05:23 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
      + 2007-05-09 16:55 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
      - 2007-05-09 16:55 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
      + 2006-10-17 18:05 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
      - 2006-10-17 18:05 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
      - 2006-05-10 05:22 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
      + 2006-05-10 05:22 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
      + 2009-04-20 17:17 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\DLLCACHE\dnsrslvr.dll
      - 2010-12-09 14:30 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
      + 2010-12-09 14:30 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
      + 2005-06-13 14:25 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\csrsrv.dll
      - 2005-06-13 14:25 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\csrsrv.dll
      + 2011-05-23 06:03 . 2011-05-23 06:03   61280              c:\windows\SYSTEM32\avgfwdx.dll
      + 2011-07-08 19:00 . 2011-07-08 19:00   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
      - 2010-09-23 21:55 . 2010-09-23 21:55   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
      + 2011-07-07 17:04 . 2011-07-07 17:04   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      - 2010-09-23 08:26 . 2010-09-23 08:26   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      - 2010-09-23 08:26 . 2010-09-23 08:26   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2011-07-07 17:04 . 2011-07-07 17:04   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2011-07-07 17:03 . 2011-07-07 17:03   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      - 2010-09-23 08:26 . 2010-09-23 08:26   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      + 2011-07-07 18:09 . 2011-07-07 18:09   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2010-09-23 09:17 . 2010-09-23 09:17   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2010-09-23 09:17 . 2010-09-23 09:17   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2011-07-07 18:09 . 2011-07-07 18:09   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2011-10-20 01:51 . 2011-10-20 01:51   22016              c:\windows\Installer\36534e.msi
      + 2011-05-12 13:17 . 2011-05-12 13:17   24064              c:\windows\Installer\12b8f5e1.msi
      - 2005-05-25 21:25 . 2011-03-12 00:08   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
      + 2005-05-25 21:25 . 2011-10-21 23:38   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
      - 2011-03-12 00:22 . 2011-03-12 00:22   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      + 2011-10-21 23:36 . 2011-10-21 23:36   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      - 2011-03-11 23:41 . 2011-03-11 23:41   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
      + 2011-03-11 23:41 . 2011-10-21 23:42   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
      + 2011-10-21 23:11 . 2010-12-20 23:59   12800              c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   66560              c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   55296              c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   43520              c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   25600              c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
      + 2011-07-07 15:42 . 2011-07-07 15:47   20137              c:\windows\hpqins11.dat
      + 2011-10-21 22:57 . 2011-10-21 22:57   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_64433b8a\System.Drawing.Design.dll
      + 2011-10-21 22:57 . 2011-10-21 22:57   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_a1f745d8\CustomMarshalers.dll
      + 2011-10-22 00:08 . 2011-10-22 00:08   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
      + 2011-10-22 00:28 . 2011-10-22 00:28   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
      + 2011-10-22 00:27 . 2011-10-22 00:27   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
      + 2011-10-22 00:22 . 2011-10-22 00:22   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
      + 2011-10-22 00:22 . 2011-10-22 00:22   82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
      + 2011-10-22 00:03 . 2011-10-22 00:03   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
      + 2011-10-22 00:01 . 2011-10-22 00:01   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
      + 2011-10-22 00:25 . 2011-10-22 00:25   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
      + 2011-10-22 00:19 . 2011-10-22 00:19   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ba5f039c6cee5268d549382692b6e365\Microsoft.SqlServer.CustomControls.ni.dll
      + 2011-10-22 00:17 . 2011-10-22 00:17   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
      + 2011-10-22 00:17 . 2011-10-22 00:17   65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
      + 2011-10-22 00:13 . 2011-10-22 00:13   14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
      + 2011-10-22 00:11 . 2011-10-22 00:11   25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      - 2011-03-11 23:07 . 2011-03-11 23:07   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
      + 2011-10-21 22:56 . 2011-10-21 22:56   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
      + 2011-10-22 00:00 . 2010-11-03 13:12   46080              c:\windows\$NtUninstallKB2570791$\tzchange.exe
      + 2011-10-22 00:00 . 2011-07-09 00:32   16896              c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
      + 2011-10-21 23:00 . 2008-04-13 18:57   10112              c:\windows\$NtUninstallKB2566454$\ndistapi.sys
      + 2011-10-21 23:38 . 2002-08-29 10:00   16896              c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
      + 2011-10-21 23:02 . 2008-04-14 00:11   45568              c:\windows\$NtUninstallKB2509553$\dnsrslvr.dll
      + 2011-10-21 23:24 . 2010-12-09 14:30   33280              c:\windows\$NtUninstallKB2507938$\csrsrv.dll
      + 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2616676-v2\update\spcustom.dll
      + 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2616676-v2\spmsg.dll
      + 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
      + 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2592799\spmsg.dll
      + 2011-10-21 23:11 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
      + 2011-10-21 23:11 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
      + 2011-10-16 22:20 . 2011-08-22 23:47   12800              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
      + 2011-10-16 22:20 . 2011-08-22 23:47   66560              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
      + 2011-10-16 22:20 . 2011-08-22 23:47   55296              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
      + 2011-10-16 22:20 . 2011-08-22 23:47   43520              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
      + 2011-10-16 22:20 . 2011-08-22 23:47   25600              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
      + 2011-10-21 23:09 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
      + 2011-10-21 23:09 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570947\spmsg.dll
      + 2011-10-21 23:13 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
      + 2011-10-21 23:13 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570222\spmsg.dll
      + 2011-10-21 23:40 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
      + 2011-10-21 23:40 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567680\spmsg.dll
      + 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
      + 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567053\spmsg.dll
      + 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
      + 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2566454\spmsg.dll
      + 2011-10-16 22:13 . 2011-07-08 13:51   10496              c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
      + 2011-10-21 22:59 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
      + 2011-10-21 22:59 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2562937\spmsg.dll
      + 2011-10-21 23:03 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544893\update\spcustom.dll
      + 2011-10-21 23:03 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544893\spmsg.dll
      + 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544521-IE8\update\spcustom.dll
      + 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544521-IE8\spmsg.dll
      + 2011-10-21 23:01 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2541763\update\spcustom.dll
      + 2011-10-21 23:01 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2541763\spmsg.dll
      + 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
      + 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
      + 2011-10-21 23:10 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2535512\update\spcustom.dll
      + 2011-10-21 23:10 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2535512\spmsg.dll
      + 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2510531-IE8\update\spcustom.dll
      + 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2510531-IE8\spmsg.dll
      + 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2509553\update\spcustom.dll
      + 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2509553\spmsg.dll
      + 2009-04-20 17:06 . 2009-04-20 17:06   45568              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsrslvr.dll
      + 2011-10-21 23:07 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508429\update\spcustom.dll
      + 2011-10-21 23:07 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508429\spmsg.dll
      + 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508272\update\spcustom.dll
      + 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508272\spmsg.dll
      + 2011-10-21 23:24 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
      + 2011-10-21 23:24 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507938\spmsg.dll
      + 2011-04-26 11:02 . 2011-04-26 11:02   33280              c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
      + 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507618\update\spcustom.dll
      + 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507618\spmsg.dll
      + 2011-10-21 23:06 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2506212\update\spcustom.dll
      + 2011-10-21 23:06 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2506212\spmsg.dll
      + 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2485663\update\spcustom.dll
      + 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2485663\spmsg.dll
      + 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2476490\update\spcustom.dll
      + 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2476490\spmsg.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      + 2009-04-15 12:50 . 2011-02-17 12:32   5120              c:\windows\SYSTEM32\xpsp4res.dll
      - 2009-04-15 12:50 . 2010-08-26 12:52   5120              c:\windows\SYSTEM32\xpsp4res.dll
      - 2005-05-25 21:25 . 2011-03-12 00:08   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
      + 2005-05-25 21:25 . 2011-10-21 23:38   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
      - 2011-03-11 23:55 . 2011-03-11 23:55   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      + 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      + 2011-10-21 23:07 . 2010-08-26 12:52   5120              c:\windows\$NtUninstallKB2508429$\xpsp4res.dll
      + 2011-02-17 12:32 . 2011-02-17 12:32   5120              c:\windows\$hf_mig$\KB2508429\SP3QFE\xpsp4res.dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      - 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
      + 2009-07-12 05:05 . 2009-07-12 05:05   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
      + 2009-07-12 05:02 . 2009-07-12 05:02   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
      - 2005-06-13 14:25 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\winsrv.dll
      + 2005-06-13 14:25 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\winsrv.dll
      + 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\wininet.dll
      - 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\wininet.dll
      + 2005-06-13 14:25 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\vbscript.dll
      - 2005-06-13 14:25 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\url.dll
      + 2005-06-13 14:25 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\url.dll
      + 2008-07-30 00:59 . 2011-09-26 16:41   611328              c:\windows\SYSTEM32\uiautomationcore.dll
      + 2005-06-13 14:25 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\schannel.dll
      + 2011-06-22 17:47 . 2011-10-17 18:11   152788              c:\windows\SYSTEM32\rhttpmah.dat
      + 2010-12-24 14:18 . 2011-12-21 01:23   229224              c:\windows\SYSTEM32\Restore\rstrlog.dat
      + 2011-06-22 17:47 . 2011-10-17 18:11   320053              c:\windows\SYSTEM32\prinauiv.dat
      + 2003-09-10 20:15 . 2011-11-14 19:26   500748              c:\windows\SYSTEM32\PERFH009.DAT
      - 2005-06-13 14:25 . 2008-04-14 00:12   551936              c:\windows\SYSTEM32\oleaut32.dll
      + 2005-06-13 14:25 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\oleaut32.dll
      + 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\oleacc.dll
      - 2005-06-13 14:25 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\occache.dll
      + 2005-06-13 14:25 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\occache.dll
      - 2005-06-13 14:26 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\mswsock.dll
      + 2005-06-13 14:26 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\mswsock.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\mstime.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\mstime.dll
      - 2006-11-08 03:03 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\msfeeds.dll
      + 2006-11-08 03:03 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\msfeeds.dll
      - 2005-06-13 14:26 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\mfc42u.dll
      + 2005-06-13 14:26 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\mfc42u.dll
      + 2005-06-13 14:26 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\mfc42.dll
      + 2011-11-20 19:37 . 2011-11-20 19:37   247968              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.exe
      + 2011-11-20 19:37 . 2011-11-20 19:37   335520              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.dll
      + 2005-06-13 14:26 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\jscript.dll
      - 2005-06-13 14:26 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\jscript.dll
      + 2011-12-26 15:32 . 2011-12-26 15:31   157472              c:\windows\SYSTEM32\javaws.exe
      + 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\javaw.exe
      + 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\java.exe
      + 2005-06-13 14:26 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\inetcomm.dll
      - 2005-06-13 14:26 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\inetcomm.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\iepeers.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\iepeers.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\iedkcs32.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\iedkcs32.dll
      + 2005-06-13 14:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\ie4uinit.exe
      + 2002-09-03 18:42 . 2011-10-22 06:19   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
      - 2002-09-03 18:42 . 2011-03-12 01:05   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
      + 2011-04-12 19:55 . 2011-10-17 18:48   825939              c:\windows\SYSTEM32\dskquouh.dat
      + 2005-06-13 14:25 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DRIVERS\srv.sys
      - 2005-06-13 14:25 . 2008-04-14 00:13   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
      + 2005-06-13 14:25 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
      + 2005-06-13 14:25 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DRIVERS\mup.sys
      + 2005-06-13 14:25 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
      + 2011-07-11 06:14 . 2011-07-11 06:14   295248              c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
      + 2011-07-11 06:14 . 2011-07-11 06:14   134608              c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys
      + 2005-06-13 14:25 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
      - 2005-06-13 14:25 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
      + 2005-06-13 14:27 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\dnsapi.dll
      - 2010-06-18 17:45 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
      + 2010-06-18 17:45 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
      + 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
      - 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
      + 2006-09-18 14:15 . 2011-04-30 03:01   758784              c:\windows\SYSTEM32\DLLCACHE\vgx.dll
      + 2008-05-09 10:53 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\DLLCACHE\vbscript.dll
      - 2006-10-17 18:05 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
      + 2006-10-17 18:05 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
      + 2008-10-15 03:09 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DLLCACHE\srv.sys
      + 2008-12-05 06:54 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\DLLCACHE\schannel.dll
      + 2011-10-16 22:20 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DLLCACHE\rdpwd.sys
      + 2010-12-20 17:32 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\DLLCACHE\oleaut32.dll
      + 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\DLLCACHE\oleacc.dll
      - 2006-10-17 18:04 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
      + 2006-10-17 18:04 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
      + 2011-10-16 22:18 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DLLCACHE\mup.sys
      + 2008-06-20 17:46 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
      - 2008-06-20 17:46 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
      + 2006-05-10 05:23 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
      - 2006-05-10 05:23 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
      - 2007-05-09 16:55 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
      + 2007-05-09 16:55 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
      + 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
      + 2006-10-14 08:13 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
      - 2006-10-14 08:13 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
      + 2011-03-11 13:42 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\DLLCACHE\mfc42.dll
      + 2008-05-09 10:53 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
      - 2008-05-09 10:53 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
      - 2008-08-12 18:56 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
      + 2008-08-12 18:56 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
      + 2009-06-10 13:02 . 2011-08-22 23:48   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
      - 2009-06-10 13:02 . 2010-12-20 23:59   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
      + 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
      - 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
      - 2011-03-11 13:36 . 2010-12-20 23:59   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
      + 2011-03-11 13:36 . 2011-08-22 23:48   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
      + 2006-11-07 09:27 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
      - 2006-11-07 09:27 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
      + 2006-11-07 09:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
      + 2008-06-20 17:46 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\DLLCACHE\dnsapi.dll
      + 2005-06-13 14:27 . 2008-04-14 00:11   640000              c:\windows\SYSTEM32\DLLCACHE\dbghelp.dll
      + 2011-09-09 09:12 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\DLLCACHE\crypt32.dll
      + 2011-01-07 14:09 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\DLLCACHE\atmfd.dll
      + 2008-06-20 11:40 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
      - 2008-06-20 11:40 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
      + 2005-06-13 14:27 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\crypt32.dll
      - 2005-06-13 14:27 . 2008-04-14 00:11   599040              c:\windows\SYSTEM32\crypt32.dll
      + 2005-06-13 14:27 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\atmfd.dll
      - 2010-05-11 12:40 . 2010-05-11 12:40   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
      + 2011-07-07 10:18 . 2011-07-07 10:18   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
      + 2011-03-25 11:15 . 2011-03-25 11:15   363856              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
      + 2011-07-07 10:18 . 2011-07-07 10:18   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
      - 2010-05-11 12:40 . 2010-05-11 12:40   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
      - 2010-09-23 08:26 . 2010-09-23 08:26   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      + 2011-07-07 17:04 . 2011-07-07 17:04   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      - 2010-09-23 08:25 . 2010-09-23 08:25   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      + 2011-07-07 17:01 . 2011-07-07 17:01   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      - 2010-09-23 09:17 . 2010-09-23 09:17   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      + 2011-07-07 18:09 . 2011-07-07 18:09   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      + 2011-05-10 12:37 . 2011-05-10 12:37   689152              c:\windows\Installer\844cd51.msi
      + 2011-12-26 15:31 . 2011-12-26 15:31   901120              c:\windows\Installer\4975043.msi
      + 2011-10-17 18:27 . 2011-10-17 18:27   219648              c:\windows\Installer\3d86bf5d.msi
      + 2011-07-07 15:44 . 2011-07-07 15:44   344576              c:\windows\Installer\1da16103.msi
      - 2005-05-25 21:25 . 2011-03-12 00:08   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
      + 2005-05-25 21:25 . 2011-10-21 23:38   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
      - 2005-05-25 21:25 . 2011-03-12 00:08   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
      + 2005-05-25 21:25 . 2011-10-21 23:37   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
      + 2011-05-10 12:35 . 2011-05-10 12:35   371272              c:\windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
      + 2011-10-21 23:10 . 2010-12-20 23:59   916480              c:\windows\ie8updates\KB2586448-IE8\wininet.dll
      + 2011-10-21 23:10 . 2009-03-08 09:34   105984              c:\windows\ie8updates\KB2586448-IE8\url.dll
      + 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
      + 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
      + 2011-10-21 23:10 . 2010-12-20 23:59   206848              c:\windows\ie8updates\KB2586448-IE8\occache.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   611840              c:\windows\ie8updates\KB2586448-IE8\mstime.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   602112              c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
      + 2011-10-21 23:11 . 2010-12-20 23:59   247808              c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
      + 2011-10-21 23:10 . 2010-12-20 23:59   184320              c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
      + 2011-10-21 23:11 . 2010-12-20 23:59   743424              c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
      + 2011-10-21 23:11 . 2010-12-20 23:59   387584              c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
      + 2011-10-21 23:11 . 2010-12-20 12:55   173568              c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
      + 2011-10-21 23:00 . 2009-03-08 09:33   759296              c:\windows\ie8updates\KB2544521-IE8\vgx.dll
      + 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
      + 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
      + 2011-10-21 23:02 . 2010-03-10 06:15   420352              c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
      + 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
      + 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
      + 2011-10-21 23:02 . 2009-12-09 05:53   726528              c:\windows\ie8updates\KB2510531-IE8\jscript.dll
      + 2009-08-15 20:11 . 2011-07-07 15:51   116264              c:\windows\hpoins33.dat
      + 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\Driver Cache\I386\mrxsmb.sys
      + 2011-10-21 22:58 . 2011-10-21 22:58   835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b7a8f596\System.Drawing.dll
      + 2011-10-21 22:58 . 2011-10-21 22:58   192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fd54f924\System.Drawing.Design.dll
      + 2011-10-21 22:58 . 2011-10-21 22:58   118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_c86fa1ef\CustomMarshalers.dll
      + 2011-10-22 00:16 . 2011-10-22 00:16   321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
      + 2011-10-22 00:09 . 2011-10-22 00:09   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
      + 2011-10-22 00:08 . 2011-10-22 00:08   187904              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
      + 2011-10-22 00:08 . 2011-10-22 00:08   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
      + 2011-10-22 00:29 . 2011-10-22 00:29   400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
      + 2011-10-22 00:27 . 2011-10-22 00:27   129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
      + 2011-10-22 00:28 . 2011-10-22 00:28   202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
      + 2011-10

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Trojan horse Rootkit-Pakes.BI
      « Reply #3 on: December 27, 2011, 11:39:36 AM »
      That is not the complete ComboFix log. You should be able to find it on your C: drive in the ComboFix folder. If you can't find it, please run it again and post the complete log.
      Windows 8 and Windows 10 dual boot with two SSD's

      jefraz

        Topic Starter


        Greenhorn

        • Experience: Beginner
        • OS: Unknown
        Re: Trojan horse Rootkit-Pakes.BI
        « Reply #4 on: December 27, 2011, 03:32:14 PM »
        ComboFix 11-12-27.01 - Joe Frazier 12/27/2011   9:36.4.1 - x86
        Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1629 [GMT -6:00]
        Running from: c:\documents and settings\Daniel Clark\Desktop\Computer Cleanup\ComboFix.exe
        AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
        FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66}
        .
        .
        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        c:\documents and settings\Administrator\Start Menu\Programs\NaviSearch
        c:\windows\system32\SET727.tmp
        c:\windows\system32\SET72B.tmp
        c:\windows\system32\SET733.tmp
        c:\windows\system32\SET73C.tmp
        c:\windows\system32\SET73D.tmp
        c:\windows\system32\SET73E.tmp
        c:\windows\system32\SET741.tmp
        .
         
         
        .
        .
        (((((((((((((((((((((((((   Files Created from 2011-11-27 to 2011-12-27  )))))))))))))))))))))))))))))))
        .
        .
        2011-12-26 15:32 . 2011-12-26 15:31   472808   ----a-w-   c:\windows\system32\deployJava1.dll
        2011-12-25 18:58 . 2011-12-25 18:58   --------   d-----w-   c:\documents and settings\Daniel Clark\Application Data\SUPERAntiSpyware.com
        2011-12-25 18:57 . 2011-12-25 18:58   --------   d-----w-   c:\program files\SUPERAntiSpyware
        2011-12-25 18:57 . 2011-12-25 18:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
        2011-12-25 18:40 . 2011-12-25 18:40   --------   d-----w-   c:\program files\CCleaner
        2011-12-21 01:21 . 2011-12-21 01:21   --------   d-----w-   c:\windows\system32\wbem\Repository
        2011-12-04 11:29 . 2011-12-08 13:58   --------   d-----w-   c:\windows\system32\Robert Shindler
        2011-12-02 07:25 . 2011-12-02 07:25   --------   d-----w-   c:\documents and settings\Daniel Clark\Local Settings\Application Data\RcIncidents
        .
        .
        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2011-12-26 15:31 . 2009-01-23 16:18   73728   ----a-w-   c:\windows\system32\javacpl.cpl
        2011-11-20 19:37 . 2011-11-20 19:37   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
        2011-10-07 11:23 . 2011-07-11 06:13   230608   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
        2011-10-04 11:21 . 2011-07-11 06:14   16720   ----a-w-   c:\windows\system32\drivers\AVGIDSShim.sys
        2010-01-07 22:07 . 2010-01-11 18:41   1394000   ----a-w-   c:\program files\mbam.exe
        2004-05-31 16:55 . 2004-03-18 19:32   5245352   ----a-w-   c:\program files\SetupDl.EXE
        2004-05-05 20:59 . 2004-05-05 20:59   23040   ----a-w-   c:\program files\nCASEAdsUninstaller.exe
        2004-04-23 16:38 . 2004-04-23 16:38   10135688   ----a-w-   c:\program files\MPSetupXP.exe
        2004-02-23 19:52 . 2004-02-23 19:51   16706160   -c--a-w-   c:\program files\AdbeRdr60_enu_full.exe
        2004-02-23 19:50 . 2004-02-23 19:50   6262872   ----a-w-   c:\program files\psa2se_us.exe
        2004-02-06 13:39 . 2003-12-19 14:15   3401360   ----a-w-   c:\program files\Install_AIM.exe
        2003-11-09 01:26 . 2003-11-09 01:25   1951232   ----a-w-   c:\program files\s600Win2kXPv150.exe
        .
        .
        (((((((((((((((((((((((((((((   SnapShot_2011-05-08_18.06.00   )))))))))))))))))))))))))))))))))))))))))
        .
        + 2009-07-12 05:02 . 2009-07-12 05:02   51008              c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   59728              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   42832              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   43344              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   61264              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   62800              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   61760              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   61776              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   53568              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   63296              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   36688              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   35648              c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
        + 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
        + 2009-07-12 05:05 . 2009-07-12 05:05   59904              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
        + 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_a4.dat
        + 2011-12-27 15:54 . 2011-12-27 15:54   16384              c:\windows\Temp\Perflib_Perfdata_47c.dat
        + 2011-06-22 17:47 . 2011-10-17 18:11   25307              c:\windows\SYSTEM32\winhstp.dat
        + 2007-01-29 08:58 . 2011-07-08 13:49   46080              c:\windows\SYSTEM32\tzchange.exe
        - 2007-01-29 08:58 . 2010-11-03 13:12   46080              c:\windows\SYSTEM32\tzchange.exe
        + 2011-11-20 17:54 . 2011-09-27 00:16   52096              c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\LMIproc.dll
        + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterui.dll
        + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinterdat.dll
        + 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\LMIprinter.dll
        + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterui.dll
        + 2011-11-20 17:54 . 2011-09-27 00:16   55168              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinterdat.dll
        + 2011-11-20 17:54 . 2011-09-27 00:15   43392              c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\LMIprinter.dll
        + 2003-09-10 20:15 . 2011-11-14 19:26   94634              c:\windows\SYSTEM32\PERFC009.DAT
        + 2002-08-29 10:00 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\oleaccrc.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\mshtmled.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\mshtmled.dll
        + 2006-11-08 03:03 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\msfeedsbs.dll
        - 2006-11-08 03:03 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\msfeedsbs.dll
        + 2011-11-20 17:54 . 2011-09-27 00:16   83360              c:\windows\SYSTEM32\LMIRfsClientNP.dll
        + 2011-11-20 17:54 . 2011-09-27 00:15   30592              c:\windows\SYSTEM32\LMIport.dll
        + 2011-09-16 21:10 . 2011-09-16 21:10   11552              c:\windows\SYSTEM32\lmimirr2.dll
        + 2011-09-16 21:10 . 2011-09-16 21:10   25248              c:\windows\SYSTEM32\lmimirr.dll
        + 2011-11-20 17:54 . 2011-09-27 00:15   87424              c:\windows\SYSTEM32\LMIinit.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\licmgr10.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\licmgr10.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\jsproxy.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\jsproxy.dll
        + 2008-05-06 21:06 . 2008-05-06 21:06   11520              c:\windows\SYSTEM32\DRIVERS\wdcsam.sys
        + 2002-08-29 10:00 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DRIVERS\ndistapi.sys
        + 2010-01-11 18:39 . 2011-08-31 22:00   22216              c:\windows\SYSTEM32\DRIVERS\mbam.sys
        + 2011-11-20 17:54 . 2011-09-16 21:10   47640              c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys
        + 2011-09-16 21:10 . 2011-09-16 21:10   10144              c:\windows\SYSTEM32\DRIVERS\lmimirr.sys
        + 2011-09-13 11:30 . 2011-09-13 11:30   32592              c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
        + 2011-08-08 11:08 . 2011-08-08 11:08   40016              c:\windows\SYSTEM32\DRIVERS\avgmfx86.sys
        + 2011-07-11 06:14 . 2011-07-11 06:14   24272              c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys
        + 2011-07-11 06:14 . 2011-07-11 06:14   23120              c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys
        + 2011-05-23 06:03 . 2011-05-23 06:03   30944              c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys
        - 2005-06-13 14:27 . 2008-04-14 00:11   45568              c:\windows\SYSTEM32\dnsrslvr.dll
        + 2005-06-13 14:27 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\dnsrslvr.dll
        - 2009-06-10 13:02 . 2010-12-20 23:59   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
        + 2009-06-10 13:02 . 2011-08-22 23:48   12800              c:\windows\SYSTEM32\DLLCACHE\xpshims.dll
        + 2011-09-26 16:41 . 2011-09-26 16:41   20480              c:\windows\SYSTEM32\DLLCACHE\oleaccrc.dll
        + 2011-10-16 22:13 . 2011-07-08 14:02   10496              c:\windows\SYSTEM32\DLLCACHE\ndistapi.sys
        - 2006-05-10 05:23 . 2010-12-20 23:59   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
        + 2006-05-10 05:23 . 2011-08-22 23:48   66560              c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
        + 2007-05-09 16:55 . 2011-08-22 23:48   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
        - 2007-05-09 16:55 . 2010-12-20 23:59   55296              c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
        + 2006-10-17 18:05 . 2011-08-22 23:48   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
        - 2006-10-17 18:05 . 2010-12-20 23:59   43520              c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
        - 2006-05-10 05:22 . 2010-12-20 23:59   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
        + 2006-05-10 05:22 . 2011-08-22 23:48   25600              c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
        + 2009-04-20 17:17 . 2009-04-20 17:17   45568              c:\windows\SYSTEM32\DLLCACHE\dnsrslvr.dll
        - 2010-12-09 14:30 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
        + 2010-12-09 14:30 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\DLLCACHE\csrsrv.dll
        + 2005-06-13 14:25 . 2011-04-26 11:07   33280              c:\windows\SYSTEM32\csrsrv.dll
        - 2005-06-13 14:25 . 2010-12-09 14:30   33280              c:\windows\SYSTEM32\csrsrv.dll
        + 2011-05-23 06:03 . 2011-05-23 06:03   61280              c:\windows\SYSTEM32\avgfwdx.dll
        + 2011-07-08 19:00 . 2011-07-08 19:00   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
        - 2010-09-23 21:55 . 2010-09-23 21:55   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
        + 2011-07-07 17:04 . 2011-07-07 17:04   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
        - 2010-09-23 08:26 . 2010-09-23 08:26   77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
        - 2010-09-23 08:26 . 2010-09-23 08:26   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
        + 2011-07-07 17:04 . 2011-07-07 17:04   86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
        + 2011-07-07 17:03 . 2011-07-07 17:03   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
        - 2010-09-23 08:26 . 2010-09-23 08:26   81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
        + 2011-07-07 18:09 . 2011-07-07 18:09   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
        - 2010-09-23 09:17 . 2010-09-23 09:17   32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
        - 2010-09-23 09:17 . 2010-09-23 09:17   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
        + 2011-07-07 18:09 . 2011-07-07 18:09   24576              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
        + 2011-10-20 01:51 . 2011-10-20 01:51   22016              c:\windows\Installer\36534e.msi
        + 2011-05-12 13:17 . 2011-05-12 13:17   24064              c:\windows\Installer\12b8f5e1.msi
        - 2005-05-25 21:25 . 2011-03-12 00:08   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   90112              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   45056              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
        + 2005-05-25 21:25 . 2011-10-21 23:38   22528              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   30720              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   16384              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   34304              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\misc.exe
        - 2011-03-12 00:22 . 2011-03-12 00:22   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
        + 2011-10-21 23:36 . 2011-10-21 23:36   38240              c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
        - 2011-03-11 23:41 . 2011-03-11 23:41   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
        + 2011-03-11 23:41 . 2011-10-21 23:42   49152              c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
        + 2011-10-21 23:11 . 2010-12-20 23:59   12800              c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   66560              c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   55296              c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   43520              c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   25600              c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
        + 2011-07-07 15:42 . 2011-07-07 15:47   20137              c:\windows\hpqins11.dat
        + 2011-10-21 22:57 . 2011-10-21 22:57   90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_64433b8a\System.Drawing.Design.dll
        + 2011-10-21 22:57 . 2011-10-21 22:57   61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_a1f745d8\CustomMarshalers.dll
        + 2011-10-22 00:08 . 2011-10-22 00:08   60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
        + 2011-10-22 00:28 . 2011-10-22 00:28   37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
        + 2011-10-22 00:22 . 2011-10-22 00:22   94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
        + 2011-10-22 00:22 . 2011-10-22 00:22   82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
        + 2011-10-22 00:03 . 2011-10-22 00:03   47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
        + 2011-10-22 00:01 . 2011-10-22 00:01   39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
        + 2011-10-22 00:25 . 2011-10-22 00:25   55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
        + 2011-10-22 00:19 . 2011-10-22 00:19   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ba5f039c6cee5268d549382692b6e365\Microsoft.SqlServer.CustomControls.ni.dll
        + 2011-10-22 00:17 . 2011-10-22 00:17   74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
        + 2011-10-22 00:17 . 2011-10-22 00:17   65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
        + 2011-10-22 00:13 . 2011-10-22 00:13   14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
        + 2011-10-22 00:11 . 2011-10-22 00:11   25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
        - 2011-03-11 23:07 . 2011-03-11 23:07   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
        + 2011-10-21 22:56 . 2011-10-21 22:56   81920              c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
        + 2011-10-22 00:00 . 2010-11-03 13:12   46080              c:\windows\$NtUninstallKB2570791$\tzchange.exe
        + 2011-10-22 00:00 . 2011-07-09 00:32   16896              c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
        + 2011-10-21 23:00 . 2008-04-13 18:57   10112              c:\windows\$NtUninstallKB2566454$\ndistapi.sys
        + 2011-10-21 23:38 . 2002-08-29 10:00   16896              c:\windows\$NtUninstallKB2564958$\oleaccrc.dll
        + 2011-10-21 23:02 . 2008-04-14 00:11   45568              c:\windows\$NtUninstallKB2509553$\dnsrslvr.dll
        + 2011-10-21 23:24 . 2010-12-09 14:30   33280              c:\windows\$NtUninstallKB2507938$\csrsrv.dll
        + 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2616676-v2\update\spcustom.dll
        + 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2616676-v2\spmsg.dll
        + 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2592799\update\spcustom.dll
        + 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2592799\spmsg.dll
        + 2011-10-21 23:11 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2586448-IE8\update\spcustom.dll
        + 2011-10-21 23:11 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2586448-IE8\spmsg.dll
        + 2011-10-16 22:20 . 2011-08-22 23:47   12800              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\xpshims.dll
        + 2011-10-16 22:20 . 2011-08-22 23:47   66560              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtmled.dll
        + 2011-10-16 22:20 . 2011-08-22 23:47   55296              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeedsbs.dll
        + 2011-10-16 22:20 . 2011-08-22 23:47   43520              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\licmgr10.dll
        + 2011-10-16 22:20 . 2011-08-22 23:47   25600              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\jsproxy.dll
        + 2011-10-21 23:09 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570947\update\spcustom.dll
        + 2011-10-21 23:09 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570947\spmsg.dll
        + 2011-10-21 23:13 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
        + 2011-10-21 23:13 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2570222\spmsg.dll
        + 2011-10-21 23:40 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
        + 2011-10-21 23:40 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567680\spmsg.dll
        + 2011-10-21 23:14 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2567053\update\spcustom.dll
        + 2011-10-21 23:14 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2567053\spmsg.dll
        + 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
        + 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2566454\spmsg.dll
        + 2011-10-16 22:13 . 2011-07-08 13:51   10496              c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
        + 2011-10-21 22:59 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
        + 2011-10-21 22:59 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2562937\spmsg.dll
        + 2011-10-21 23:03 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544893\update\spcustom.dll
        + 2011-10-21 23:03 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544893\spmsg.dll
        + 2011-10-21 23:00 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2544521-IE8\update\spcustom.dll
        + 2011-10-21 23:00 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2544521-IE8\spmsg.dll
        + 2011-10-21 23:01 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2541763\update\spcustom.dll
        + 2011-10-21 23:01 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2541763\spmsg.dll
        + 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
        + 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
        + 2011-10-21 23:10 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2535512\update\spcustom.dll
        + 2011-10-21 23:10 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2535512\spmsg.dll
        + 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2510531-IE8\update\spcustom.dll
        + 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2510531-IE8\spmsg.dll
        + 2011-10-21 23:02 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2509553\update\spcustom.dll
        + 2011-10-21 23:02 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2509553\spmsg.dll
        + 2009-04-20 17:06 . 2009-04-20 17:06   45568              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsrslvr.dll
        + 2011-10-21 23:07 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508429\update\spcustom.dll
        + 2011-10-21 23:07 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508429\spmsg.dll
        + 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2508272\update\spcustom.dll
        + 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2508272\spmsg.dll
        + 2011-10-21 23:24 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507938\update\spcustom.dll
        + 2011-10-21 23:24 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507938\spmsg.dll
        + 2011-04-26 11:02 . 2011-04-26 11:02   33280              c:\windows\$hf_mig$\KB2507938\SP3QFE\csrsrv.dll
        + 2011-10-21 23:08 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2507618\update\spcustom.dll
        + 2011-10-21 23:08 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2507618\spmsg.dll
        + 2011-10-21 23:06 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2506212\update\spcustom.dll
        + 2011-10-21 23:06 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2506212\spmsg.dll
        + 2011-10-21 23:25 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2485663\update\spcustom.dll
        + 2011-10-21 23:25 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2485663\spmsg.dll
        + 2011-10-21 23:23 . 2010-07-05 13:15   26488              c:\windows\$hf_mig$\KB2476490\update\spcustom.dll
        + 2011-10-21 23:23 . 2010-07-05 13:15   17272              c:\windows\$hf_mig$\KB2476490\spmsg.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
        + 2009-04-15 12:50 . 2011-02-17 12:32   5120              c:\windows\SYSTEM32\xpsp4res.dll
        - 2009-04-15 12:50 . 2010-08-26 12:52   5120              c:\windows\SYSTEM32\xpsp4res.dll
        - 2005-05-25 21:25 . 2011-03-12 00:08   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
        + 2005-05-25 21:25 . 2011-10-21 23:38   3584              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   8192              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   2560              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
        - 2011-03-11 23:55 . 2011-03-11 23:55   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
        + 2011-10-21 23:57 . 2011-10-21 23:57   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
        + 2011-10-21 23:07 . 2010-08-26 12:52   5120              c:\windows\$NtUninstallKB2508429$\xpsp4res.dll
        + 2011-02-17 12:32 . 2011-02-17 12:32   5120              c:\windows\$hf_mig$\KB2508429\SP3QFE\xpsp4res.dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
        - 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
        + 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   653120              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   569664              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
        + 2009-07-12 05:05 . 2009-07-12 05:05   225280              c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
        + 2009-07-12 05:02 . 2009-07-12 05:02   159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
        - 2005-06-13 14:25 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\winsrv.dll
        + 2005-06-13 14:25 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\winsrv.dll
        + 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\wininet.dll
        - 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\wininet.dll
        + 2005-06-13 14:25 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\vbscript.dll
        - 2005-06-13 14:25 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\url.dll
        + 2005-06-13 14:25 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\url.dll
        + 2008-07-30 00:59 . 2011-09-26 16:41   611328              c:\windows\SYSTEM32\uiautomationcore.dll
        + 2005-06-13 14:25 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\schannel.dll
        + 2011-06-22 17:47 . 2011-10-17 18:11   152788              c:\windows\SYSTEM32\rhttpmah.dat
        + 2010-12-24 14:18 . 2011-12-21 01:23   229224              c:\windows\SYSTEM32\Restore\rstrlog.dat
        + 2011-06-22 17:47 . 2011-10-17 18:11   320053              c:\windows\SYSTEM32\prinauiv.dat
        + 2003-09-10 20:15 . 2011-11-14 19:26   500748              c:\windows\SYSTEM32\PERFH009.DAT
        - 2005-06-13 14:25 . 2008-04-14 00:12   551936              c:\windows\SYSTEM32\oleaut32.dll
        + 2005-06-13 14:25 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\oleaut32.dll
        + 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\oleacc.dll
        - 2005-06-13 14:25 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\occache.dll
        + 2005-06-13 14:25 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\occache.dll
        - 2005-06-13 14:26 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\mswsock.dll
        + 2005-06-13 14:26 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\mswsock.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\mstime.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\mstime.dll
        - 2006-11-08 03:03 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\msfeeds.dll
        + 2006-11-08 03:03 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\msfeeds.dll
        - 2005-06-13 14:26 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\mfc42u.dll
        + 2005-06-13 14:26 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\mfc42u.dll
        + 2005-06-13 14:26 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\mfc42.dll
        + 2011-11-20 19:37 . 2011-11-20 19:37   247968              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.exe
        + 2011-11-20 19:37 . 2011-11-20 19:37   335520              c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11e_ActiveX.dll
        + 2005-06-13 14:26 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\jscript.dll
        - 2005-06-13 14:26 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\jscript.dll
        + 2011-12-26 15:32 . 2011-12-26 15:31   157472              c:\windows\SYSTEM32\javaws.exe
        + 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\javaw.exe
        + 2011-12-26 15:32 . 2011-12-26 15:31   149280              c:\windows\SYSTEM32\java.exe
        + 2005-06-13 14:26 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\inetcomm.dll
        - 2005-06-13 14:26 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\inetcomm.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\iepeers.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\iepeers.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\iedkcs32.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\iedkcs32.dll
        + 2005-06-13 14:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\ie4uinit.exe
        + 2002-09-03 18:42 . 2011-10-22 06:19   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
        - 2002-09-03 18:42 . 2011-03-12 01:05   323520              c:\windows\SYSTEM32\FNTCACHE.DAT
        + 2011-04-12 19:55 . 2011-10-17 18:48   825939              c:\windows\SYSTEM32\dskquouh.dat
        + 2005-06-13 14:25 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DRIVERS\srv.sys
        - 2005-06-13 14:25 . 2008-04-14 00:13   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
        + 2005-06-13 14:25 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DRIVERS\rdpwd.sys
        + 2005-06-13 14:25 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DRIVERS\mup.sys
        + 2005-06-13 14:25 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DRIVERS\mrxsmb.sys
        + 2011-07-11 06:14 . 2011-07-11 06:14   295248              c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
        + 2011-07-11 06:14 . 2011-07-11 06:14   134608              c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys
        + 2005-06-13 14:25 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
        - 2005-06-13 14:25 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DRIVERS\afd.sys
        + 2005-06-13 14:27 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\dnsapi.dll
        - 2010-06-18 17:45 . 2010-06-18 17:45   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
        + 2010-06-18 17:45 . 2011-06-20 17:44   293376              c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
        + 2005-06-13 14:25 . 2011-08-22 23:48   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
        - 2005-06-13 14:25 . 2010-12-20 23:59   916480              c:\windows\SYSTEM32\DLLCACHE\wininet.dll
        + 2006-09-18 14:15 . 2011-04-30 03:01   758784              c:\windows\SYSTEM32\DLLCACHE\vgx.dll
        + 2008-05-09 10:53 . 2011-03-04 06:37   420864              c:\windows\SYSTEM32\DLLCACHE\vbscript.dll
        - 2006-10-17 18:05 . 2009-03-08 09:34   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
        + 2006-10-17 18:05 . 2011-08-22 23:48   105984              c:\windows\SYSTEM32\DLLCACHE\url.dll
        + 2008-10-15 03:09 . 2011-02-17 13:18   357888              c:\windows\SYSTEM32\DLLCACHE\srv.sys
        + 2008-12-05 06:54 . 2011-04-29 17:25   151552              c:\windows\SYSTEM32\DLLCACHE\schannel.dll
        + 2011-10-16 22:20 . 2011-06-24 14:10   139656              c:\windows\SYSTEM32\DLLCACHE\rdpwd.sys
        + 2010-12-20 17:32 . 2010-12-20 17:32   551936              c:\windows\SYSTEM32\DLLCACHE\oleaut32.dll
        + 2002-08-29 10:00 . 2011-09-26 16:41   220160              c:\windows\SYSTEM32\DLLCACHE\oleacc.dll
        - 2006-10-17 18:04 . 2010-12-20 23:59   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
        + 2006-10-17 18:04 . 2011-08-22 23:48   206848              c:\windows\SYSTEM32\DLLCACHE\occache.dll
        + 2011-10-16 22:18 . 2011-04-21 13:37   105472              c:\windows\SYSTEM32\DLLCACHE\mup.sys
        + 2008-06-20 17:46 . 2008-06-20 16:02   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
        - 2008-06-20 17:46 . 2008-06-20 17:46   245248              c:\windows\SYSTEM32\DLLCACHE\mswsock.dll
        + 2006-05-10 05:23 . 2011-08-22 23:48   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
        - 2006-05-10 05:23 . 2010-12-20 23:59   611840              c:\windows\SYSTEM32\DLLCACHE\mstime.dll
        - 2007-05-09 16:55 . 2010-12-20 23:59   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
        + 2007-05-09 16:55 . 2011-08-22 23:48   602112              c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
        + 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
        + 2006-10-14 08:13 . 2011-02-08 13:33   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
        - 2006-10-14 08:13 . 2010-09-18 18:23   974848              c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
        + 2011-03-11 13:42 . 2011-02-08 13:33   978944              c:\windows\SYSTEM32\DLLCACHE\mfc42.dll
        + 2008-05-09 10:53 . 2011-03-04 06:37   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
        - 2008-05-09 10:53 . 2009-12-09 05:53   726528              c:\windows\SYSTEM32\DLLCACHE\jscript.dll
        - 2008-08-12 18:56 . 2010-06-09 07:43   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
        + 2008-08-12 18:56 . 2011-05-02 15:31   692736              c:\windows\SYSTEM32\DLLCACHE\inetcomm.dll
        + 2009-06-10 13:02 . 2011-08-22 23:48   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
        - 2009-06-10 13:02 . 2010-12-20 23:59   247808              c:\windows\SYSTEM32\DLLCACHE\ieproxy.dll
        + 2005-06-13 14:26 . 2011-08-22 23:48   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
        - 2005-06-13 14:26 . 2010-12-20 23:59   184320              c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
        - 2011-03-11 13:36 . 2010-12-20 23:59   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
        + 2011-03-11 13:36 . 2011-08-22 23:48   743424              c:\windows\SYSTEM32\DLLCACHE\iedvtool.dll
        + 2006-11-07 09:27 . 2011-08-22 23:48   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
        - 2006-11-07 09:27 . 2010-12-20 23:59   387584              c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
        + 2006-11-07 09:26 . 2011-08-22 11:56   174080              c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
        + 2008-06-20 17:46 . 2011-03-03 06:55   149504              c:\windows\SYSTEM32\DLLCACHE\dnsapi.dll
        + 2005-06-13 14:27 . 2008-04-14 00:11   640000              c:\windows\SYSTEM32\DLLCACHE\dbghelp.dll
        + 2011-09-09 09:12 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\DLLCACHE\crypt32.dll
        + 2011-01-07 14:09 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\DLLCACHE\atmfd.dll
        + 2008-06-20 11:40 . 2011-08-17 13:49   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
        - 2008-06-20 11:40 . 2008-08-14 10:04   138496              c:\windows\SYSTEM32\DLLCACHE\afd.sys
        + 2005-06-13 14:27 . 2011-09-09 09:12   599040              c:\windows\SYSTEM32\crypt32.dll
        - 2005-06-13 14:27 . 2008-04-14 00:11   599040              c:\windows\SYSTEM32\crypt32.dll
        + 2005-06-13 14:27 . 2011-02-15 12:56   290432              c:\windows\SYSTEM32\atmfd.dll
        - 2010-05-11 12:40 . 2010-05-11 12:40   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
        + 2011-07-07 10:18 . 2011-07-07 10:18   388936              c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
        + 2011-03-25 11:15 . 2011-03-25 11:15   363856              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
        + 2011-07-07 10:18 . 2011-07-07 10:18   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
        - 2010-05-11 12:40 . 2010-05-11 12:40   989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
        - 2010-09-23 08:26 . 2010-09-23 08:26   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
        + 2011-07-07 17:04 . 2011-07-07 17:04   102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
        - 2010-09-23 08:25 . 2010-09-23 08:25   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
        + 2011-07-07 17:01 . 2011-07-07 17:01   315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
        - 2010-09-23 09:17 . 2010-09-23 09:17   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
        + 2011-07-07 18:09 . 2011-07-07 18:09   258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
        + 2011-05-10 12:37 . 2011-05-10 12:37   689152              c:\windows\Installer\844cd51.msi
        + 2011-12-26 15:31 . 2011-12-26 15:31   901120              c:\windows\Installer\4975043.msi
        + 2011-10-17 18:27 . 2011-10-17 18:27   219648              c:\windows\Installer\3d86bf5d.msi
        + 2011-07-07 15:44 . 2011-07-07 15:44   344576              c:\windows\Installer\1da16103.msi
        - 2005-05-25 21:25 . 2011-03-12 00:08   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
        + 2005-05-25 21:25 . 2011-10-21 23:38   114688              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
        - 2005-05-25 21:25 . 2011-03-12 00:08   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
        + 2005-05-25 21:25 . 2011-10-21 23:37   167936              c:\windows\Installer\{91110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
        + 2011-05-10 12:35 . 2011-05-10 12:35   371272              c:\windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
        + 2011-10-21 23:10 . 2010-12-20 23:59   916480              c:\windows\ie8updates\KB2586448-IE8\wininet.dll
        + 2011-10-21 23:10 . 2009-03-08 09:34   105984              c:\windows\ie8updates\KB2586448-IE8\url.dll
        + 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
        + 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
        + 2011-10-21 23:10 . 2010-12-20 23:59   206848              c:\windows\ie8updates\KB2586448-IE8\occache.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   611840              c:\windows\ie8updates\KB2586448-IE8\mstime.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   602112              c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
        + 2011-10-21 23:11 . 2010-12-20 23:59   247808              c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
        + 2011-10-21 23:10 . 2010-12-20 23:59   184320              c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
        + 2011-10-21 23:11 . 2010-12-20 23:59   743424              c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
        + 2011-10-21 23:11 . 2010-12-20 23:59   387584              c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
        + 2011-10-21 23:11 . 2010-12-20 12:55   173568              c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
        + 2011-10-21 23:00 . 2009-03-08 09:33   759296              c:\windows\ie8updates\KB2544521-IE8\vgx.dll
        + 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
        + 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
        + 2011-10-21 23:02 . 2010-03-10 06:15   420352              c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
        + 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
        + 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
        + 2011-10-21 23:02 . 2009-12-09 05:53   726528              c:\windows\ie8updates\KB2510531-IE8\jscript.dll
        + 2009-08-15 20:11 . 2011-07-07 15:51   116264              c:\windows\hpoins33.dat
        + 2008-11-12 11:07 . 2011-07-15 13:29   456320              c:\windows\Driver Cache\I386\mrxsmb.sys
        + 2011-10-21 22:58 . 2011-10-21 22:58   835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b7a8f596\System.Drawing.dll
        + 2011-10-21 22:58 . 2011-10-21 22:58   192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fd54f924\System.Drawing.Design.dll
        + 2011-10-21 22:58 . 2011-10-21 22:58   118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_c86fa1ef\CustomMarshalers.dll
        + 2011-10-22 00:16 . 2011-10-22 00:16   321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
        + 2011-10-22 00:09 . 2011-10-22 00:09   240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
        + 2011-10-22 00:08 . 2011-10-22 00:08   187904              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
        + 2011-10-22 00:08 . 2011-10-22 00:08   447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
        + 2011-10-22 00:29 . 2011-10-22 00:29   400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
        + 2011-10-22 00:28 . 2011-10-22 00:28   202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   859648              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   328704              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   301056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
        + 2011-10-22 00:27 . 2011-10-22 00:27   547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
        + 2011-10-22 00:26 . 2011-10-22 00:26   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dl

        jefraz

          Topic Starter


          Greenhorn

          • Experience: Beginner
          • OS: Unknown
          Re: Trojan horse Rootkit-Pakes.BI
          « Reply #5 on: December 27, 2011, 03:37:16 PM »
          + 2011-10-22 00:26 . 2011-10-22 00:26   627200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
          + 2011-10-22 00:26 . 2011-10-22 00:26   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   679936              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   311296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   621056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   998400              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   330752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
          + 2011-10-22 00:11 . 2011-10-22 00:11   381440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
          + 2011-10-22 00:11 . 2011-10-22 00:11   212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   280064              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   627712              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
          + 2011-10-22 00:06 . 2011-10-22 00:06   208384              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   455680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   881152              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   939008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   354816              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   756736              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
          + 2011-10-22 00:22 . 2011-10-22 00:22   135680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   971264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
          + 2011-10-22 00:21 . 2011-10-22 00:21   633856              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
          + 2011-10-22 00:15 . 2011-10-22 00:15   366080              c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
          + 2011-10-22 00:15 . 2011-10-22 00:15   256000              c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
          + 2011-10-22 00:15 . 2011-10-22 00:15   320512              c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
          + 2011-10-22 00:04 . 2011-10-22 00:04   539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
          + 2011-10-22 00:04 . 2011-10-22 00:04   368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
          + 2011-10-22 00:04 . 2011-10-22 00:04   224768              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
          + 2011-10-22 00:04 . 2011-10-22 00:04   258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   133632              c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
          + 2011-10-22 00:14 . 2011-10-22 00:14   386560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
          + 2011-10-22 00:21 . 2011-10-22 00:21   989184              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\bae550eab1420c5c5281e115e0ecd6cb\Microsoft.SqlServer.WizardFrameworkLite.ni.dll
          + 2011-10-22 00:19 . 2011-10-22 00:19   530432              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\b43153b1799dfe26e130630eb467aefd\Microsoft.SqlServer.GridControl.ni.dll
          + 2011-10-22 00:21 . 2011-10-22 00:21   355840              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\1eeab1daf96463188df131a0822ece69\Microsoft.SqlServer.Setup.ni.dll
          + 2011-10-22 00:18 . 2011-10-22 00:18   231936              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\e9b9b40429d65e4c254a7caa8a957c4b\Microsoft.NetEnterpriseServers.ExceptionMessageBox.ni.dll
          + 2011-10-22 00:18 . 2011-10-22 00:18   144384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
          + 2011-10-22 00:18 . 2011-10-22 00:18   175104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   839680              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   222720              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   220672              c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
          + 2011-10-22 00:13 . 2011-10-22 00:13   410112              c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
          + 2011-10-22 00:11 . 2011-10-22 00:11   842240              c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
          - 2011-03-11 23:54 . 2011-03-11 23:54   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
          + 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2616676-v2$\spuninst\updspapi.dll
          + 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2616676-v2$\spuninst\spuninst.exe
          + 2011-10-21 23:23 . 2008-04-14 00:11   599040              c:\windows\$NtUninstallKB2616676-v2$\crypt32.dll
          + 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2592799$\spuninst\updspapi.dll
          + 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2592799$\spuninst\spuninst.exe
          + 2011-10-21 23:14 . 2008-10-16 14:43   138496              c:\windows\$NtUninstallKB2592799$\afd.sys
          + 2011-10-21 23:09 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570947$\spuninst\updspapi.dll
          + 2011-10-21 23:09 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570947$\spuninst\spuninst.exe
          + 2011-10-22 00:00 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
          + 2011-10-22 00:00 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
          + 2011-10-21 23:13 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2570222$\spuninst\updspapi.dll
          + 2011-10-21 23:13 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2570222$\spuninst\spuninst.exe
          + 2011-10-21 23:13 . 2008-04-14 00:13   139656              c:\windows\$NtUninstallKB2570222$\rdpwd.sys
          + 2011-10-21 23:40 . 2011-04-26 11:07   293376              c:\windows\$NtUninstallKB2567680$\winsrv.dll
          + 2011-10-21 23:40 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2567680$\spuninst\updspapi.dll
          + 2011-10-21 23:40 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2567680$\spuninst\spuninst.exe
          + 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2567053$\spuninst\updspapi.dll
          + 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2567053$\spuninst\spuninst.exe
          + 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2566454$\spuninst\updspapi.dll
          + 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2566454$\spuninst\spuninst.exe
          + 2011-10-21 23:38 . 2008-07-30 00:59   161296              c:\windows\$NtUninstallKB2564958$\uiautomationcore.dll
          + 2011-10-21 23:38 . 2011-08-12 18:51   382840              c:\windows\$NtUninstallKB2564958$\spuninst\updspapi.dll
          + 2011-10-21 23:38 . 2011-08-12 18:51   231288              c:\windows\$NtUninstallKB2564958$\spuninst\spuninst.exe
          + 2011-10-21 23:38 . 2002-08-29 10:00   163328              c:\windows\$NtUninstallKB2564958$\oleacc.dll
          + 2011-10-21 22:59 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2562937$\spuninst\updspapi.dll
          + 2011-10-21 22:59 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2562937$\spuninst\spuninst.exe
          + 2011-10-21 23:03 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2544893$\spuninst\updspapi.dll
          + 2011-10-21 23:03 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2544893$\spuninst\spuninst.exe
          + 2011-10-21 23:03 . 2010-06-09 07:43   692736              c:\windows\$NtUninstallKB2544893$\inetcomm.dll
          + 2011-10-21 23:01 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2541763$\spuninst\updspapi.dll
          + 2011-10-21 23:01 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2541763$\spuninst\spuninst.exe
          + 2011-10-21 23:01 . 2010-06-30 12:31   149504              c:\windows\$NtUninstallKB2541763$\schannel.dll
          + 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2536276-v2$\spuninst\updspapi.dll
          + 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe
          + 2011-10-21 23:25 . 2010-02-24 13:11   455680              c:\windows\$NtUninstallKB2536276-v2$\mrxsmb.sys
          + 2011-10-21 23:10 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2535512$\spuninst\updspapi.dll
          + 2011-10-21 23:10 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2535512$\spuninst\spuninst.exe
          + 2011-10-21 23:10 . 2008-04-13 19:17   105344              c:\windows\$NtUninstallKB2535512$\mup.sys
          + 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2509553$\spuninst\updspapi.dll
          + 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2509553$\spuninst\spuninst.exe
          + 2011-10-21 23:02 . 2008-06-20 17:46   245248              c:\windows\$NtUninstallKB2509553$\mswsock.dll
          + 2011-10-21 23:02 . 2008-06-20 17:46   147968              c:\windows\$NtUninstallKB2509553$\dnsapi.dll
          + 2011-10-21 23:02 . 2008-08-14 10:04   138496              c:\windows\$NtUninstallKB2509553$\afd.sys
          + 2011-10-21 23:07 . 2010-08-26 13:39   357248              c:\windows\$NtUninstallKB2508429$\srv.sys
          + 2011-10-21 23:07 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2508429$\spuninst\updspapi.dll
          + 2011-10-21 23:07 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2508429$\spuninst\spuninst.exe
          + 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2508272$\spuninst\updspapi.dll
          + 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2508272$\spuninst\spuninst.exe
          + 2011-10-21 23:24 . 2010-06-18 17:45   293376              c:\windows\$NtUninstallKB2507938$\winsrv.dll
          + 2011-10-21 23:24 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2507938$\spuninst\updspapi.dll
          + 2011-10-21 23:24 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2507938$\spuninst\spuninst.exe
          + 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2507618$\spuninst\updspapi.dll
          + 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2507618$\spuninst\spuninst.exe
          + 2011-10-21 23:08 . 2011-01-07 14:09   290048              c:\windows\$NtUninstallKB2507618$\atmfd.dll
          + 2011-10-21 23:06 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2506212$\spuninst\updspapi.dll
          + 2011-10-21 23:06 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2506212$\spuninst\spuninst.exe
          + 2011-10-21 23:06 . 2010-09-18 18:23   974848              c:\windows\$NtUninstallKB2506212$\mfc42u.dll
          + 2011-10-21 23:06 . 2010-09-18 06:53   974848              c:\windows\$NtUninstallKB2506212$\mfc42.dll
          + 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2485663$\spuninst\updspapi.dll
          + 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2485663$\spuninst\spuninst.exe
          + 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$NtUninstallKB2476490$\spuninst\updspapi.dll
          + 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$NtUninstallKB2476490$\spuninst\spuninst.exe
          + 2011-10-21 23:23 . 2008-04-14 00:12   551936              c:\windows\$NtUninstallKB2476490$\oleaut32.dll
          + 2011-10-21 23:09 . 2009-05-26 11:40   382840              c:\windows\$NtUninstallKB2412687$\spuninst\updspapi.dll
          + 2011-10-21 23:09 . 2009-05-26 11:40   231288              c:\windows\$NtUninstallKB2412687$\spuninst\spuninst.exe
          + 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2616676-v2\update\updspapi.dll
          + 2011-10-21 23:23 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2616676-v2\update\update.exe
          + 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2616676-v2\spuninst.exe
          + 2011-09-09 09:11 . 2011-09-09 09:11   599552              c:\windows\$hf_mig$\KB2616676-v2\SP3QFE\crypt32.dll
          + 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2592799\update\updspapi.dll
          + 2011-10-21 23:14 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2592799\update\update.exe
          + 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2592799\spuninst.exe
          + 2011-10-16 22:20 . 2011-08-17 13:41   138496              c:\windows\$hf_mig$\KB2592799\SP3QFE\afd.sys
          + 2011-10-21 23:11 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2586448-IE8\update\updspapi.dll
          + 2011-10-21 23:11 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2586448-IE8\update\update.exe
          + 2011-10-21 23:11 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2586448-IE8\spuninst.exe
          + 2011-10-16 22:20 . 2011-08-22 23:47   919552              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   105984              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\url.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   206848              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\occache.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   611840              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mstime.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   602112              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\msfeeds.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   247808              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieproxy.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   184320              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iepeers.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   743424              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedvtool.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   387584              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iedkcs32.dll
          + 2011-10-16 22:20 . 2011-08-22 11:52   174080              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ie4uinit.exe
          + 2011-10-21 23:09 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2570947\update\updspapi.dll
          + 2011-10-21 23:09 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2570947\update\update.exe
          + 2011-10-21 23:09 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2570947\spuninst.exe
          + 2011-10-21 23:13 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2570222\update\updspapi.dll
          + 2011-10-21 23:13 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2570222\update\update.exe
          + 2011-10-21 23:13 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2570222\spuninst.exe
          + 2011-10-16 22:20 . 2011-06-24 14:09   139656              c:\windows\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys
          + 2011-10-21 23:40 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2567680\update\updspapi.dll
          + 2011-10-21 23:40 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2567680\update\update.exe
          + 2011-10-21 23:40 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2567680\spuninst.exe
          + 2011-06-20 17:43 . 2011-06-20 17:43   293376              c:\windows\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
          + 2011-10-21 23:14 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2567053\update\updspapi.dll
          + 2011-10-21 23:14 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2567053\update\update.exe
          + 2011-10-21 23:14 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2567053\spuninst.exe
          + 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2566454\update\updspapi.dll
          + 2011-10-21 23:00 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2566454\update\update.exe
          + 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2566454\spuninst.exe
          + 2011-10-21 22:59 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2562937\update\updspapi.dll
          + 2011-10-21 22:59 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2562937\update\update.exe
          + 2011-10-21 22:59 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2562937\spuninst.exe
          + 2011-10-21 23:03 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2544893\update\updspapi.dll
          + 2011-10-21 23:03 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2544893\update\update.exe
          + 2011-10-21 23:03 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2544893\spuninst.exe
          + 2011-10-16 22:15 . 2011-05-02 15:30   692736              c:\windows\$hf_mig$\KB2544893\SP3QFE\inetcomm.dll
          + 2011-10-21 23:00 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2544521-IE8\update\updspapi.dll
          + 2011-10-21 23:00 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2544521-IE8\update\update.exe
          + 2011-10-21 23:00 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2544521-IE8\spuninst.exe
          + 2011-10-16 22:13 . 2011-04-30 02:59   758784              c:\windows\$hf_mig$\KB2544521-IE8\SP3QFE\vgx.dll
          + 2011-10-21 23:01 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2541763\update\updspapi.dll
          + 2011-10-21 23:01 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2541763\update\update.exe
          + 2011-10-21 23:01 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2541763\spuninst.exe
          + 2011-04-29 17:23 . 2011-04-29 17:23   151552              c:\windows\$hf_mig$\KB2541763\SP3QFE\schannel.dll
          + 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2536276-v2\update\updspapi.dll
          + 2011-10-21 23:25 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2536276-v2\update\update.exe
          + 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2536276-v2\spuninst.exe
          + 2011-10-16 22:22 . 2011-07-15 13:29   457856              c:\windows\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys
          + 2011-10-21 23:10 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2535512\update\updspapi.dll
          + 2011-10-21 23:10 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2535512\update\update.exe
          + 2011-10-21 23:10 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2535512\spuninst.exe
          + 2011-10-16 22:18 . 2011-04-21 13:52   105472              c:\windows\$hf_mig$\KB2535512\SP3QFE\mup.sys
          + 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2510531-IE8\update\updspapi.dll
          + 2011-10-21 23:02 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2510531-IE8\update\update.exe
          + 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2510531-IE8\spuninst.exe
          + 2011-10-16 22:14 . 2011-03-04 06:35   420864              c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\vbscript.dll
          + 2011-10-16 22:14 . 2011-03-04 06:35   726528              c:\windows\$hf_mig$\KB2510531-IE8\SP3QFE\jscript.dll
          + 2011-10-21 23:02 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2509553\update\updspapi.dll
          + 2011-10-21 23:02 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2509553\update\update.exe
          + 2011-10-21 23:02 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2509553\spuninst.exe
          + 2008-06-20 11:16 . 2008-06-20 11:16   225856              c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip6.sys
          + 2008-06-20 11:59 . 2008-06-20 11:59   361600              c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
          + 2008-06-20 17:43 . 2008-06-20 17:43   245248              c:\windows\$hf_mig$\KB2509553\SP3QFE\mswsock.dll
          + 2011-03-03 06:53 . 2011-03-03 06:53   149504              c:\windows\$hf_mig$\KB2509553\SP3QFE\dnsapi.dll
          + 2008-10-16 15:07 . 2008-10-16 15:07   138496              c:\windows\$hf_mig$\KB2509553\SP3QFE\afd.sys
          + 2011-10-21 23:07 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2508429\update\updspapi.dll
          + 2011-10-21 23:07 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2508429\update\update.exe
          + 2011-10-21 23:07 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2508429\spuninst.exe
          + 2011-02-17 13:19 . 2011-02-17 13:19   357888              c:\windows\$hf_mig$\KB2508429\SP3QFE\srv.sys
          + 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2508272\update\updspapi.dll
          + 2011-10-21 23:08 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2508272\update\update.exe
          + 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2508272\spuninst.exe
          + 2011-10-21 23:24 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2507938\update\updspapi.dll
          + 2011-10-21 23:24 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2507938\update\update.exe
          + 2011-10-21 23:24 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2507938\spuninst.exe
          + 2011-04-26 11:02 . 2011-04-26 11:02   293376              c:\windows\$hf_mig$\KB2507938\SP3QFE\winsrv.dll
          + 2011-10-21 23:08 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2507618\update\updspapi.dll
          + 2011-10-21 23:08 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2507618\update\update.exe
          + 2011-10-21 23:08 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2507618\spuninst.exe
          + 2011-02-15 13:05 . 2011-02-15 13:05   290432              c:\windows\$hf_mig$\KB2507618\SP3QFE\atmfd.dll
          + 2011-10-21 23:06 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2506212\update\updspapi.dll
          + 2011-10-21 23:06 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2506212\update\update.exe
          + 2011-10-21 23:06 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2506212\spuninst.exe
          + 2011-02-08 13:32 . 2011-02-08 13:32   974848              c:\windows\$hf_mig$\KB2506212\SP3QFE\mfc42u.dll
          + 2011-02-08 13:32 . 2011-02-08 13:32   978944              c:\windows\$hf_mig$\KB2506212\SP3QFE\mfc42.dll
          + 2011-10-21 23:25 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2485663\update\updspapi.dll
          + 2011-10-21 23:25 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2485663\update\update.exe
          + 2011-10-21 23:25 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2485663\spuninst.exe
          + 2011-10-21 23:23 . 2010-07-05 13:16   382840              c:\windows\$hf_mig$\KB2476490\update\updspapi.dll
          + 2011-10-21 23:23 . 2010-07-05 13:15   755576              c:\windows\$hf_mig$\KB2476490\update\update.exe
          + 2011-10-21 23:23 . 2010-07-05 13:15   231288              c:\windows\$hf_mig$\KB2476490\spuninst.exe
          + 2010-12-20 17:30 . 2010-12-20 17:30   552448              c:\windows\$hf_mig$\KB2476490\SP3QFE\oleaut32.dll
          + 2011-10-16 22:18 . 2010-10-23 00:51   1748992              c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
          + 2009-07-12 05:02 . 2009-07-12 05:02   3780424              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
          + 2009-07-12 05:02 . 2009-07-12 05:02   3765048              c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
          + 2011-04-12 13:35 . 2011-10-17 18:48   1806809              c:\windows\SYSTEM32\wmdrmcet.dat
          + 2005-06-13 14:25 . 2011-09-06 13:20   1858944              c:\windows\SYSTEM32\win32k.sys
          + 2005-06-13 14:25 . 2011-08-22 23:48   1212416              c:\windows\SYSTEM32\urlmon.dll
          + 2011-04-12 13:35 . 2011-10-17 18:48   2169147              c:\windows\SYSTEM32\rdpwoxt.dat
          + 2005-06-13 14:26 . 2011-10-03 08:35   5971456              c:\windows\SYSTEM32\mshtml.dll
          + 2006-10-17 17:57 . 2011-08-22 23:48   2000384              c:\windows\SYSTEM32\iertutil.dll
          + 2008-10-15 03:07 . 2011-09-06 13:20   1858944              c:\windows\SYSTEM32\DLLCACHE\win32k.sys
          + 2005-06-13 14:25 . 2011-08-22 23:48   1212416              c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
          + 2005-06-13 14:26 . 2011-10-03 08:35   5971456              c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
          + 2007-05-09 16:55 . 2011-08-22 23:48   2000384              c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
          - 2008-07-25 16:17 . 2008-07-25 16:17   5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
          + 2011-03-25 11:15 . 2011-03-25 11:15   5025792              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
          + 2011-04-29 02:50 . 2011-04-29 02:50   3182592              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
          - 2010-03-23 11:32 . 2010-03-23 11:32   3182592              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
          + 2011-07-07 10:18 . 2011-07-07 10:18   5912400              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
          + 2011-07-07 10:18 . 2011-07-07 10:18   4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
          - 2010-05-11 12:40 . 2010-05-11 12:40   4550656              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
          + 2011-07-08 18:59 . 2011-07-08 18:59   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
          - 2010-09-23 21:55 . 2010-09-23 21:55   1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
          + 2011-07-08 18:59 . 2011-07-08 18:59   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
          - 2010-09-23 21:55 . 2010-09-23 21:55   1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
          - 2010-09-23 08:26 . 2010-09-23 08:26   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
          + 2011-07-07 17:02 . 2011-07-07 17:02   2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
          + 2011-07-07 17:02 . 2011-07-07 17:02   2527232              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
          + 2011-07-08 18:59 . 2011-07-08 18:59   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
          - 2010-09-23 21:55 . 2010-09-23 21:55   2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
          + 2011-05-10 12:35 . 2011-05-10 12:35   1587200              c:\windows\Installer\844cd40.msi
          + 2011-05-02 05:06 . 2011-05-02 05:06   2705920              c:\windows\Installer\67395e.msp
          + 2011-08-10 22:43 . 2011-08-10 22:43   3795968              c:\windows\Installer\673937.msp
          + 2011-04-29 17:28 . 2011-04-29 17:28   1995264              c:\windows\Installer\673923.msp
          + 2011-09-07 02:48 . 2011-09-07 02:48   8181248              c:\windows\Installer\4bcc47.msp
          + 2011-07-27 12:39 . 2011-07-27 12:39   9892352              c:\windows\Installer\4bcc3e.msp
          + 2011-04-28 17:23 . 2011-04-28 17:23   9607680              c:\windows\Installer\4bcc35.msp
          + 2011-02-25 19:25 . 2011-02-25 19:25   7968256              c:\windows\Installer\4bcc21.msp
          + 2011-04-29 17:30 . 2011-04-29 17:30   1197056              c:\windows\Installer\4bcc0d.msp
          + 2011-12-21 02:35 . 2011-12-21 02:35   2186240              c:\windows\Installer\3fa695.msi
          + 2011-12-23 15:24 . 2011-12-23 15:24   4683264              c:\windows\Installer\30d1d98.msi
          + 2011-10-18 07:39 . 2011-10-18 07:39   2188288              c:\windows\Installer\2c57fc6.msi
          + 2011-11-20 17:55 . 2011-11-20 17:55   3976192              c:\windows\Installer\1e8a474e.msi
          + 2009-04-03 23:21 . 2009-04-03 23:21   8543096              c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\OARTCONV.DLL
          + 2011-10-21 23:10 . 2010-12-20 23:59   1210880              c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
          + 2011-10-21 23:10 . 2010-12-20 23:59   5961216              c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
          + 2011-10-21 23:10 . 2010-12-20 23:59   1991680              c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
          + 2011-10-21 23:32 . 2011-10-21 23:32   5025792              c:\windows\assembly\tmp\IQW39FLR\System.Windows.Forms.dll
          + 2011-10-21 23:48 . 2011-10-21 23:48   5062656              c:\windows\assembly\tmp\CKQW28EK\System.Design.dll
          + 2011-10-21 22:57 . 2011-10-21 22:57   1966080              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_da70838c\System.dll
          + 2011-10-21 22:58 . 2011-10-21 22:58   4792320              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_224a84f6\System.dll
          + 2011-10-21 22:59 . 2011-10-21 22:59   5513216              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_63f518c9\System.Xml.dll
          + 2011-10-21 22:58 . 2011-10-21 22:58   2088960              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_02b3d94d\System.Xml.dll
          + 2011-10-21 22:57 . 2011-10-21 22:57   3018752              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_3bf48c04\System.Windows.Forms.dll
          + 2011-10-21 22:58 . 2011-10-21 22:58   7884800              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_283f0e1f\System.Windows.Forms.dll
          + 2011-10-21 22:59 . 2011-10-21 22:59   2244608              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_d189fe0c\System.Drawing.dll
          + 2011-10-21 22:58 . 2011-10-21 22:58   1470464              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_a5054d6d\System.Design.dll
          + 2011-10-21 22:59 . 2011-10-21 22:59   3395584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_2e168141\System.Design.dll
          + 2011-10-21 22:58 . 2011-10-21 22:58   3391488              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_825915cd\mscorlib.dll
          + 2011-10-21 22:59 . 2011-10-21 22:59   8908800              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_56394594\mscorlib.dll
          + 2011-10-22 00:01 . 2011-10-22 00:01   3325440              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
          + 2011-10-22 00:08 . 2011-10-22 00:08   1049600              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
          + 2011-10-22 00:01 . 2011-10-22 00:01   7950848              c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
          + 2011-10-22 00:07 . 2011-10-22 00:07   5450752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
          + 2011-10-22 00:29 . 2011-10-22 00:29   1356288              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
          + 2011-10-22 00:29 . 2011-10-22 00:29   1908224              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
          + 2011-10-22 00:29 . 2011-10-22 00:29   4514304              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
          + 2011-10-22 00:28 . 2011-10-22 00:28   2992640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
          + 2011-10-22 00:28 . 2011-10-22 00:28   1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
          + 2011-10-22 00:28 . 2011-10-22 00:28   2209280              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
          + 2011-10-22 00:27 . 2011-10-22 00:27   2405376              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
          + 2011-10-22 00:06 . 2011-10-22 00:06   1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
          + 2011-10-22 00:26 . 2011-10-22 00:26   1706496              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
          + 2011-10-22 00:11 . 2011-10-22 00:11   2345472              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
          + 2011-10-22 00:06 . 2011-10-22 00:06   1035776              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
          + 2011-10-22 00:11 . 2011-10-22 00:11   1070080              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
          + 2011-10-22 00:06 . 2011-10-22 00:06   1587200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   1116672              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   1801216              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
          + 2011-10-22 00:05 . 2011-10-22 00:05   6616576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   2510336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
          + 2011-10-22 00:24 . 2011-10-22 00:24   1328128              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
          + 2011-10-22 00:05 . 2011-10-22 00:05   2516480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
          + 2011-10-22 00:23 . 2011-10-22 00:23   9924096              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
          + 2011-10-22 00:05 . 2011-10-22 00:05   2295296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
          + 2011-10-22 00:04 . 2011-10-22 00:04   2128896              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
          + 2011-10-22 00:04 . 2011-10-22 00:04   1657856              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
          + 2011-10-22 00:01 . 2011-10-22 00:01   1451008              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
          + 2011-10-22 00:21 . 2011-10-22 00:21   1712128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
          + 2011-10-22 00:14 . 2011-10-22 00:14   1093120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
          + 2011-10-22 00:25 . 2011-10-22 00:25   2332160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   1620992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
          + 2011-10-22 00:18 . 2011-10-22 00:18   1966080              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
          + 2011-10-22 00:17 . 2011-10-22 00:17   1888768              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   3182592              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   3182592              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
          - 2011-03-11 23:54 . 2011-03-11 23:54   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
          + 2011-10-21 23:57 . 2011-10-21 23:57   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
          - 2011-03-11 23:54 . 2011-03-11 23:54   5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
          + 2011-10-21 23:58 . 2011-10-21 23:58   4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
          - 2011-03-11 23:55 . 2011-03-11 23:55   4550656              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
          + 2011-10-21 22:57 . 2011-10-21 22:57   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
          - 2011-03-11 23:07 . 2011-03-11 23:07   1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
          + 2011-10-21 22:57 . 2011-10-21 22:57   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
          - 2011-03-11 23:07 . 2011-03-11 23:07   1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
          + 2011-10-21 23:14 . 2010-12-31 13:10   1854976              c:\windows\$NtUninstallKB2567053$\win32k.sys
          + 2011-10-16 22:20 . 2011-08-22 23:47   1214464              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\urlmon.dll
          + 2011-10-16 22:19 . 2011-10-03 08:34   5972992              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll
          + 2011-10-16 22:20 . 2011-08-22 23:47   2001408              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\iertutil.dll
          + 2011-09-06 13:25 . 2011-09-06 13:25   1867904          &

          jefraz

            Topic Starter


            Greenhorn

            • Experience: Beginner
            • OS: Unknown
            Re: Trojan horse Rootkit-Pakes.BI
            « Reply #6 on: December 27, 2011, 03:39:39 PM »
            + 2011-09-06 13:25 . 2011-09-06 13:25   1867904              c:\windows\$hf_mig$\KB2567053\SP3QFE\win32k.sys
            + 2011-03-12 00:10 . 2011-10-05 15:09   48324552              c:\windows\SYSTEM32\MRT.exe
            + 2006-11-08 03:03 . 2011-08-23 22:48   11081728              c:\windows\SYSTEM32\ieframe.dll
            + 2007-05-09 16:55 . 2011-08-23 22:48   11081728              c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
            + 2011-07-13 03:49 . 2011-07-13 03:49   11459584              c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
            + 2011-09-11 17:24 . 2011-09-11 17:24   20333056              c:\windows\Installer\9ea8b19.msp
            + 2011-03-28 08:27 . 2011-03-28 08:27   15456256              c:\windows\Installer\673967.msp
            + 2011-10-21 23:41 . 2011-10-21 23:41   20333568              c:\windows\Installer\673957.msp
            + 2011-04-28 00:21 . 2011-04-28 00:21   17515520              c:\windows\Installer\67394b.msp
            + 2011-07-12 01:43 . 2011-07-12 01:43   11641344              c:\windows\Installer\67392e.msp
            + 2011-07-12 20:50 . 2011-07-12 20:50   17555968              c:\windows\Installer\4bcc05.msp
            + 2011-01-30 20:44 . 2011-01-30 20:44   12425728              c:\windows\Installer\12b8f5e8.msp
            + 2011-10-21 23:10 . 2010-12-21 11:29   11080704              c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
            + 2011-10-22 00:07 . 2011-10-22 00:07   12430848              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
            + 2011-10-22 00:26 . 2011-10-22 00:26   11800576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
            + 2011-10-22 00:12 . 2011-10-22 00:12   17403904              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
            + 2011-10-22 00:06 . 2011-10-22 00:06   10683392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
            + 2011-10-22 00:03 . 2011-10-22 00:03   14328320              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
            + 2011-10-22 00:02 . 2011-10-22 00:02   12215808              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
            + 2011-10-22 00:00 . 2011-10-22 00:00   11490816              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
            + 2011-10-21 23:38 . 2011-10-21 23:39   11490816              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\44ecf972f11f3c238782da31f27df7e5\mscorlib.ni.dll
            + 2011-10-16 22:19 . 2011-08-22 23:47   11084288              c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\ieframe.dll
            .
            -- Snapshot reset to current date --
            .
            (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* empty entries & legit default entries are not shown
            REGEDIT4
            .
            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-12 39408]
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
            "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
            "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-09-16 63048]
            .
            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
            "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
            2011-05-04 17:54   551296   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
            2011-09-27 00:15   87424   ----a-w-   c:\windows\SYSTEM32\LMIinit.dll
            .
            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
            BootExecute   REG_MULTI_SZ      autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
            .
            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
            @=""
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
            backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
            backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
            backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Icatch(VI) SnapDetect.lnk
            backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Interstate Hotels & Resorts IHRCO VPN Client.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Interstate Hotels & Resorts IHRCO VPN Client.lnk
            backup=c:\windows\pss\Interstate Hotels & Resorts IHRCO VPN Client.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
            backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
            path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
            backup=c:\windows\pss\Service Manager.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^Daniel Clark^Start Menu^Programs^Startup^Adobe Media Player.lnk]
            path=c:\documents and settings\Daniel Clark\Start Menu\Programs\Startup\Adobe Media Player.lnk
            backup=c:\windows\pss\Adobe Media Player.lnkStartup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^Daniel Clark^Start Menu^Programs^Startup^ChefTec Reset.lnk]
            path=c:\documents and settings\Daniel Clark\Start Menu\Programs\Startup\ChefTec Reset.lnk
            backup=c:\windows\pss\ChefTec Reset.lnkStartup
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
            2002-12-17 17:28   684032   ----a-w-   c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
            2003-08-29 09:59   122880   ----a-w-   c:\windows\BCMSMMSG.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
            2008-04-14 00:12   15360   ----a-w-   c:\windows\SYSTEM32\ctfmon.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
            2007-03-15 17:09   460784   ----a-w-   c:\program files\DellSupport\DSAgnt.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
            2009-05-21 15:55   206064   ----a-w-   c:\program files\Dell Support Center\bin\sprtcmd.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
            2007-11-15 15:24   16384   ----a-w-   c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
            2005-06-22 04:44   126976   ----a-w-   c:\windows\SYSTEM32\hkcmd.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
            2003-06-26 23:50   212992   ----a-w-   c:\program files\HP\hpcoretech\hpcmpmgr.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
            2010-06-10 01:55   49208   ----a-w-   c:\program files\HP\HP Software Update\hpwuschd2.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
            2008-08-20 15:54   150016   ----a-w-   c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
            2005-06-22 04:48   155648   ----a-w-   c:\windows\SYSTEM32\igfxtray.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
            2008-04-14 00:12   1695232   ----a-w-   c:\program files\Messenger\msmsgs.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
            2003-09-10 20:35   26112   ----a-w-   c:\program files\Real\RealPlayer\realplay.exe
            .
            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)
            .
            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "c:\\Program Files\\Messenger\\msmsgs.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
            "c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
            "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
            "c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpsvc.exe"=
            "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
            "c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
            "c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
            "c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
            "c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
            .
            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
            "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
            .
            R0 AVGIDSEH;AVGIDSEH;c:\windows\SYSTEM32\DRIVERS\AVGIDSEH.sys [7/11/2011 12:14 AM 23120]
            R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [9/13/2011 5:30 AM 32592]
            R1 Avgldx86;AVG AVI Loader Driver;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [7/11/2011 12:13 AM 230608]
            R1 Avgtdix;AVG TDI Driver;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [7/11/2011 12:14 AM 295248]
            R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 10:27 AM 12880]
            R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 3:55 PM 67664]
            R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 5:38 PM 116608]
            R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [11/23/2011 2:36 AM 2391832]
            R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
            R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
            R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [9/26/2011 6:15 PM 374152]
            R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [9/16/2011 3:10 PM 12856]
            R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/11/2010 12:39 PM 366152]
            R2 MSSQL$CSS;MSSQL$CSS;c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe -sCSS --> c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe -sCSS [?]
            R2 MSSQL$CSS2;SQL Server (CSS2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 5:29 PM 29293408]
            R3 Avgfwdx;Avgfwdx;c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys [5/23/2011 12:03 AM 30944]
            R3 AVGIDSDriver;AVGIDSDriver;c:\windows\SYSTEM32\DRIVERS\AVGIDSDriver.sys [7/11/2011 12:14 AM 134608]
            R3 AVGIDSFilter;AVGIDSFilter;c:\windows\SYSTEM32\DRIVERS\AVGIDSFilter.sys [7/11/2011 12:14 AM 24272]
            R3 AVGIDSShim;AVGIDSShim;c:\windows\SYSTEM32\DRIVERS\AVGIDSShim.sys [7/11/2011 12:14 AM 16720]
            R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [1/11/2010 12:39 PM 22216]
            S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2011 7:18 AM 136176]
            S3 Avgfwfd;AVG network filter service;c:\windows\SYSTEM32\DRIVERS\avgfwdx.sys [5/23/2011 12:03 AM 30944]
            S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2011 7:18 AM 136176]
            S3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\lne100v5.sys [1/12/2004 12:04 PM 36013]
            S3 SQLAgent$CSS;SQLAgent$CSS;c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlagent.EXE -i CSS --> c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlagent.EXE -i CSS [?]
            S3 w89c940;Winbond W89C940 PCI Ethernet Adapter Driver;c:\windows\SYSTEM32\DRIVERS\w940nd.sys [1/13/2004 1:03 PM 16925]
            S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\SYSTEM32\DRIVERS\wdcsam.sys [5/6/2008 3:06 PM 11520]
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
            hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
            .
            Contents of the 'Scheduled Tasks' folder
            .
            2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-12 13:17]
            .
            2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-12 13:17]
            .
            2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147073921-3723718213-2921723908-1006Core.job
            - c:\documents and settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-12-22 01:44]
            .
            2011-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2147073921-3723718213-2921723908-1006UA.job
            - c:\documents and settings\Daniel Clark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-12-22 01:44]
            .
            2011-12-27 c:\windows\Tasks\User_Feed_Synchronization-{FB6057FE-6229-43CA-8B76-5EBAF0C57540}.job
            - c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
            .
            .
            ------- Supplementary Scan -------
            .
            uStart Page = hxxp://webaccess3.columbiasussex.com/gw/webacc
            uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
            uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
            uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
            DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
            DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
            DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - hxxp://10.73.30.30:8080/emc/setup.exe
            .
            - - - - ORPHANS REMOVED - - - -
            .
            ShellIconOverlayIdentifiers-{5593D7A0-DC14-F3E4-89C6-0CC23DCD7B64} - (no file)
            .
            .
            .
            **************************************************************************
            .
            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2011-12-27 10:02
            Windows 5.1.2600 Service Pack 3 NTFS
            .
            scanning hidden processes ... 
            .
            scanning hidden autostart entries ...
            .
            scanning hidden files ... 
            .
            scan completed successfully
            hidden files: 0
            .
            **************************************************************************
            .
            [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Fdc]
            "ImagePath"=multi:"System32\DRIVERS\fdc.sys\00"
            --
            .
            [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Flpydisk]
            "ImagePath"=multi:"System32\DRIVERS\flpydisk.sys\00"
            .
            [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Fdc]
            "ImagePath"=multi:"System32\DRIVERS\fdc.sys\00"
            .
            [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Flpydisk]
            "ImagePath"=multi:"System32\DRIVERS\flpydisk.sys\00"
            .
            --------------------- LOCKED REGISTRY KEYS ---------------------
            .
            [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
            @Denied: (2) (LocalSystem)
            "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5 977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
               d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2a,8f,5e,d4,e0,b1,49,4d,94,30,a7,\
            "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839 E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
               d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2a,8f,5e,d4,e0,b1,49,4d,94,30,a7,\
            .
            [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
            "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
               00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
            .
            [HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
            "value"="?\0a\03\13\1255X"
            .
            --------------------- DLLs Loaded Under Running Processes ---------------------
            .
            - - - - - - - > 'winlogon.exe'(2008)
            c:\program files\SUPERAntiSpyware\SASWINLO.DLL
            c:\windows\system32\WININET.dll
            c:\windows\system32\LMIinit.dll
            .
            - - - - - - - > 'explorer.exe'(1856)
            c:\windows\system32\WININET.dll
            c:\progra~1\WINDOW~2\wmpband.dll
            c:\windows\system32\ieframe.dll
            c:\windows\system32\webcheck.dll
            c:\windows\system32\WPDShServiceObj.dll
            c:\windows\system32\PortableDeviceTypes.dll
            c:\windows\system32\PortableDeviceApi.dll
            c:\windows\system32\LMIRfsClientNP.dll
            .
            ------------------------ Other Running Processes ------------------------
            .
            c:\progra~1\AVG\AVG2012\avgrsx.exe
            c:\program files\AVG\AVG2012\avgcsrvx.exe
            c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
            c:\program files\ihrcovpn\IHRCO VPN Client\cvpnd.exe
            c:\program files\AVG\AVG2012\avgnsx.exe
            c:\program files\AVG\AVG2012\avgemcx.exe
            c:\program files\Java\jre6\bin\jqs.exe
            c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
            c:\program files\LogMeIn\x86\RaMaint.exe
            c:\program files\LogMeIn\x86\LogMeIn.exe
            c:\program files\Microsoft SQL Server\Mssql$CSS\Binn\MSSQL$CSS\Binn\sqlservr.exe
            c:\program files\Dell Support Center\bin\sprtsvc.exe
            c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
            c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
            c:\windows\system32\sessmgr.exe
            .
            **************************************************************************
            .
            Completion time: 2011-12-27  10:13:48 - machine was rebooted
            ComboFix-quarantined-files.txt  2011-12-27 16:13
            ComboFix2.txt  2011-05-08 18:18
            ComboFix3.txt  2011-03-26 20:32
            .
            Pre-Run: 53,580,627,968 bytes free
            Post-Run: 53,720,207,360 bytes free
            .
            - - End Of File - - A5B1FE122BEAB5813C4C5B64AC74B0B0

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Trojan horse Rootkit-Pakes.BI
            « Reply #7 on: December 27, 2011, 05:05:26 PM »
            SysProt Antirootkit

            Download
            SysProt Antirootkit from the link below (you will find it at the bottom
            of the page under attachments, or you can get it from one of the
            mirrors).

            http://sites.google.com/site/sysprotantirootkit/

            Unzip it into a folder on your desktop.
            • Double click Sysprot.exe to start the program.
            • Click on the Log tab.
            • In the Write to log box select the following items.
              • Process << Selected
              • Kernel Modules << Selected
              • SSDT << Selected
              • Kernel Hooks << Selected
              • IRP Hooks << NOT Selected
              • Ports << NOT Selected
              • Hidden Files << Selected
            • At the bottom of the page
              • Hidden Objects Only << Selected
            • Click on the Create Log button on the bottom right.
            • After a few seconds a new window should appear.
            • Select Scan Root Drive. Click on the Start button.
            • When it is complete a new window will appear to indicate that the scan is finished.
            • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
            Windows 8 and Windows 10 dual boot with two SSD's

            jefraz

              Topic Starter


              Greenhorn

              • Experience: Beginner
              • OS: Unknown
              Re: Trojan horse Rootkit-Pakes.BI
              « Reply #8 on: December 28, 2011, 07:54:23 AM »
              SysProt AntiRootkit v1.0.1.0
              by swatkat

              ******************************************************************************************
              ******************************************************************************************

              No Hidden Processes found

              ******************************************************************************************
              ******************************************************************************************
              Kernel Modules:
              Module Name: Combo-Fix.sys
              Service Name: ---
              Module Base: F7647000
              Module End: F7656000
              Hidden: Yes

              Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
              Service Name: ---
              Module Base: AEE01000
              Module End: AEE19000
              Hidden: Yes

              Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
              Service Name: ---
              Module Base: F7995000
              Module End: F7997000
              Hidden: Yes

              Module Name: \??\C:\ComboFix\catchme.sys
              Service Name: catchme
              Module Base: F77CF000
              Module End: F77D7000
              Hidden: Yes

              Module Name: \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
              Service Name: ---
              Module Base: F79E5000
              Module End: F79E7000
              Hidden: Yes

              ******************************************************************************************
              ******************************************************************************************
              SSDT:
              Function Name: ZwOpenProcess
              Address: AEC85F3C
              Driver Base: AEC85000
              Driver End: AEC88000
              Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

              Function Name: ZwTerminateProcess
              Address: AEC85FE4
              Driver Base: AEC85000
              Driver End: AEC88000
              Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

              Function Name: ZwTerminateThread
              Address: AEC86080
              Driver Base: AEC85000
              Driver End: AEC88000
              Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

              Function Name: ZwWriteVirtualMemory
              Address: AEC8611C
              Driver Base: AEC85000
              Driver End: AEC88000
              Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys

              ******************************************************************************************
              ******************************************************************************************
              No Kernel Hooks found

              ******************************************************************************************
              ******************************************************************************************
              Hidden files/folders:
              Object: C:\Qoobox\BackEnv\AppData.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Cache.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Cookies.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Desktop.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Favorites.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\History.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Music.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\NetHood.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Personal.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Pictures.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Programs.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Recent.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\SendTo.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\SetPath.bat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\StartUp.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\SysPath.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\Templates.folder.dat
              Status: Access denied

              Object: C:\Qoobox\BackEnv\VikPev00
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Collab\RSS
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Collab
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JavaScripts
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\JSADM.exv
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Preferences
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\Updater
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0\UserCache.bin
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat\7.0
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Acrobat
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.heu
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.swz
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6\cacheSize.txt
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache\8B2PP3D6
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player\AssetCache
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe\Flash Player
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Adobe
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\AdobeUM
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\cert8.db
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\info.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\key3.db
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources\CurrentSettings.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources\Downloads
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\Resources
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\secmod.db
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim269.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim2DF.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim31C.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim328.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim334.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim34B.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\aim6AA.tmp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache\urlcache.dat
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\urlcache
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol\userinfo.bag
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\americancevenol
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\0201D20472
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\0201E068C0
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0\2B0000196C
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\0
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\0201D20472
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\0201E068C0
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\2B0000196C
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1\2B00001FB4
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1024\2B0000023C
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\1024
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\129\0201D2530B
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\129
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\3\05696D73656E64
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache\3
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\bartcache
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources\CurrentSettings.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources\Downloads
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim\Resources
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Aim
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\Contacts_cevenol.lst
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\imcatcher.cfc
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog\immessages.dat
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\Camfrog
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\DESKTOP.INI
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\gtny\88D7456F-2D0E-40AA-BDBC-7BC292A1FF1A_CONFIRM.cache
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\gtny
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\channels.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chdata\chdata.cfg
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chdata
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\chn.pk
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\DellSupportODBK.exe
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\DellSupportODBK.log
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\info
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP\TransferAgentSetup.exe
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIP
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo\1157.cin
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo\901.cin
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\CIPInfo
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1004.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1027.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1028.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1029.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1030.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1043.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1061.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1062.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1064.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1094.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1095.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1096.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1097.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1112.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1114.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1117.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1118.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1120.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1122.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1124.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1125.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1128.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1131.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1133.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1134.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1138.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1141.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1142.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1145.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1146.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1150.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1152.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1157.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1300.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\1301.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\516.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\519.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\526.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\527.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\528.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\579.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\580.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\587.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\632.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\699.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\701.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\703.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\706.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\716.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\745.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\752.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\758.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\759.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\793.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\794.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\798.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\800.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\801.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\804.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\809.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\810.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\812.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\832.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\840.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\846.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\848.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\873.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\879.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\880.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\883.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\884.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\885.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\886.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\887.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\888.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\889.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\901.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\902.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\903.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\905.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\906.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\907.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\908.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\909.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\910.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\911.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\912.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\914.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\915.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\916.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\917.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\918.ucl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config\channel.cfg
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\Config
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571\DiagPlugin.dll
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config\groups.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config\ocxid.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\config
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\bios.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\computer_models.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\DAntivirus.cfg
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dell_inspiron_service_tag.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dell_printers.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\dvd.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\inspiron_172X.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\popup.sini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\printers.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\trojan.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag\vista_capbale_models.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\diag
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\10675121.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\10886371.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\122779.html
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\696.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\697.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\global.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\globe.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs\title.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\faqs
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\arg.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\DellSupportLauncher.exe
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix\DellSupportODBK.exe
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\fix
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\security\icon.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\security
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\system\icon.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon\system
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\group_icon
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\blank.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\confirm.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\gtagent_events.vbs
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\index.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\moreinfo.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\noitems.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\senddata.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\statinfo.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\survey.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html\wait.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\html
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\bg.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\but_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\but_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\close_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\count_bg.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\delete_d.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\dialog_strip.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\dialog_title.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\first_d.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_abort.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_fail.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\fix_ok.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\help_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\last_d.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\left_but_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\left_but_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\min_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\msg_bg.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_a2.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\next_d.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\noproblems.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\prev_d.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\right_but_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\right_but_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_a.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_b.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\settings_c.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\spacer.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images\wait.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\images
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\index.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\agent_infolet_exe.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\ab.ppk
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\AdpUtil.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Adp_GUI.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\adpicon.ico
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\button_cirlce.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\button_disable.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Chimes.wav
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\close_popup.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\close_popup_over.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\dot.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Ending_v.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Ending_x.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\field_bar.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\inprogress.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\installing.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\logo.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\main_bar.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\mini_logo.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\mini_topbar.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\Notify.wav
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\progress_bg.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\progress_slice.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common\topbar.gif
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Common
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\De
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\En
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Es
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Fr
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ImgOver.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Initialize.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\It
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Jp
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Ko
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\main.htm
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Nl
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\popupMsg.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\PtB
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Query.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Sv
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Wrapper.js
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\Zh
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT\Generic.css
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT\global_adp_Text.xml
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal\ZhT
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\adpglobal
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\ccnotify.cfg
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\cybercoach.cfg
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\enginecf_ver.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs\default.glf
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs\Dell.glf
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\glfs
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\abort.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\cloak.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\De_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\En_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\errorlib.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Es_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Fr_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\func.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\generic.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\getmaindriver.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\It_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Jp_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Ko_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\mini.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Nl_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\oeonwindows.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\outlookexpress.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\PtB_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Sv_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\taskbarandstartmenu.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\xsystray.trn
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\ZhT_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir\Zh_LibText.ini
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\LibDir
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration\trainer.ppk
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\configuration
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\1.gdpb
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DeleteTempFolder.gdpb
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DeleteWow6432Node.gdpb
              Status: Access denied

              Object: C:\WINDOWS\SYSTEM32\Robert Shindler\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\item_templ\coach\lessons\DisableHDAutorun.gdpb
              Sta

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Trojan horse Rootkit-Pakes.BI
              « Reply #9 on: December 28, 2011, 12:14:46 PM »
              I'd like to scan your machine with ESET OnlineScan

              •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
              ESET OnlineScan
              •Click the button.
              •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
              • Click on to download the ESET Smart Installer. Save it to your desktop.
              • Double click on the icon on your desktop.
              •Check
              •Click the button.
              •Accept any security warnings from your browser.
              •Check
              •Push the Start button.
              •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
              •When the scan completes, push
              •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
              •Push the button.
              •Push
              A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
              Windows 8 and Windows 10 dual boot with two SSD's