Motorcharge
Well-Known Member
\Microsoft.NET\assembly\GAC_64\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2012-07-03 23:39 . 2012-07-03 23:39 495984 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-03-19 13:19 . 2010-03-19 13:19 155136 c:\windows\Installer\a628639.msi
+ 2010-03-19 00:29 . 2010-03-19 00:29 872448 c:\windows\Installer\a5ff4f3.msi
+ 2012-07-08 07:05 . 2012-07-08 07:05 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
- 2012-06-08 14:13 . 2012-06-08 14:13 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
+ 2012-07-08 04:15 . 2012-07-08 04:15 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2012-07-04 03:01 . 2012-07-04 03:01 553984 c:\windows\assembly\NativeImages_v4.0.30319_64\XamlBuildTask\d7ba8f0a500f25cbed7daa07e8d748ec\XamlBuildTask.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 462336 c:\windows\assembly\NativeImages_v4.0.30319_64\WsatConfig\c87183cbec623926230118ddb9c93662\WsatConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 243712 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\6ade3ca0064ec4387fd905877e1d56b8\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 314880 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.RegularE#\31c9a177e71d9ded2a09252d362bab1d\System.Web.RegularExpressions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 446464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity\39d7c8787069c77987c558d814cac079\System.Web.Entity.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 366592 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity.D#\3ff2fa87603d75f313a66cc051b0f5c7\System.Web.Entity.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 970240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DynamicD#\85c01837b7d52831601939d52c0cd04e\System.Web.DynamicData.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 329728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\e6e7ba45676b869bf66bfd909d7e4fd0\System.Web.DataVisualization.Design.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 578048 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\9b43e24c0322e7c075406de9f8c24f37\System.ServiceModel.Activation.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 994304 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\9b42e3a6e2cd58e1859d8f503e2f3808\System.Runtime.Remoting.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 308224 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Cach#\df3f39d99e99235afbdce9c30b3a9d48\System.Runtime.Caching.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 292352 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing.Desi#\cfe9bb29ab62c2263c904bc321a26bec\System.Drawing.Design.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 661504 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\1e723235ab95da7e59d03da7901857d9\System.Data.Services.Design.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 364544 c:\windows\assembly\NativeImages_v4.0.30319_64\MSBuild\d448d55698c8471a921d17e20c0ac885\MSBuild.ni.exe
+ 2012-07-04 00:53 . 2012-07-04 00:53 851456 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Uti#\0e541d178a5797ec61d0b97058e6cc2e\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 353792 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Fra#\60fcea7acc6c048071451efa6d2f5fa6\Microsoft.Build.Framework.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 661504 c:\windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\57a507991f1e7aeb0d3014fa0d3bbd2c\ComSvcConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 404992 c:\windows\assembly\NativeImages_v4.0.30319_32\XamlBuildTask\09f78ad9517d5d19de8498bac32fc9f8\XamlBuildTask.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 356864 c:\windows\assembly\NativeImages_v4.0.30319_32\WsatConfig\a61f64155e6b58da21013a5e4d6805c2\WsatConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 194560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\4cf2b2fb097e9f0e86bb6282ae407f38\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 224256 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.RegularE#\ea0b825a2dd1a056f6171170eb072d4a\System.Web.RegularExpressions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 861696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\a894d26d652bfc6ac4830fb2f70617a9\System.Web.Extensions.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 333824 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity\e2af30b84b1578b6f104141c1599dd8a\System.Web.Entity.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 297472 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity.D#\4470016734a7207843be5ab103e54617\System.Web.Entity.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 709632 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\c3531459f26b999ebc43cabbcf160f52\System.Web.DynamicData.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 259584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\5e61ee5474c0f76a50932fbb5c7c4df3\System.Web.DataVisualization.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 423424 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c43f1fd03a4b2e3d5d2f7bc5cab6d4d9\System.ServiceModel.Activation.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 771072 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\8c5442df8c423c3f53641723ab202576\System.Runtime.Remoting.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 241664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\422adb7d24779c5c2e89a02e183f35bb\System.Runtime.Caching.ni.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 226304 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing.Desi#\02fbf9c53252572c65734e4058139abc\System.Drawing.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 508928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\88d1242f0f9f61cdcd171ff51f61005e\System.Data.Services.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 274432 c:\windows\assembly\NativeImages_v4.0.30319_32\MSBuild\d47740fc85ad70c686adc9fc9dc6e7f5\MSBuild.ni.exe
+ 2012-07-04 02:59 . 2012-07-04 02:59 631296 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Uti#\3ad065635e1e0cd413081be61993cd38\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 258048 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Fra#\71a3a98ff5fb128d3abf6ecc3224ba6b\Microsoft.Build.Framework.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 136192 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Con#\f18a2a149b3e7f9cf74de1263c2ee337\Microsoft.Build.Conversion.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 475136 c:\windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\d1a54aac4ba266fc0ba95fd2be09098f\ComSvcConfig.ni.exe
+ 2012-07-04 02:59 . 2012-07-04 02:59 846336 c:\windows\assembly\NativeImages_v4.0.30319_32\AspNetMMCExt\f92703eb43edd152461756ff2d56ea46\AspNetMMCExt.ni.dll
+ 2010-03-18 13:15 . 2010-03-18 13:15 4368720 c:\windows\SysWOW64\mfc100u.dll
+ 2010-03-18 13:15 . 2010-03-18 13:15 4342088 c:\windows\SysWOW64\mfc100.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 9459912 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 1535176 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
+ 2009-07-14 04:54 . 2012-06-28 22:33 2539520 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-06-20 23:55 2539520 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-28 22:33 7094272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:45 . 2012-06-25 01:13 6366312 c:\windows\system32\FNTCACHE.DAT
+ 2010-03-18 20:47 . 2010-03-18 20:47 1587064 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1070960 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1836904 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 21:23 . 2010-03-18 21:23 5145936 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1697144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5078360 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Design.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1064816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1327968 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1587064 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1070960 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1836904 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5174608 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1697144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5078360 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Design.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1064816 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1327968 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1587064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1070960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1836904 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1697144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5078360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1327968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1064816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5145936 c:\windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5174608 c:\windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-07-08 04:15 . 2012-07-08 04:15 3809280 c:\windows\Installer\1ff590f6.msi
+ 2012-07-04 03:00 . 2012-07-04 03:00 1601536 c:\windows\assembly\NativeImages_v4.0.30319_64\System.WorkflowServ#\72007285279e0d6357db504999c8e124\System.WorkflowServices.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2886656 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Run#\71539c40fc382c7e30eb5e1717f6fac7\System.Workflow.Runtime.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 5921792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Com#\7bd32fb577201b5240b2558d8d1f9a7e\System.Workflow.ComponentModel.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 3743744 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Act#\ec781c38aff4dff4f53675068f55ced8\System.Workflow.Activities.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 2284544 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\13fa0cee801d37b2238052e053863f24\System.Web.Services.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2957312 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Mobile\547a0c7acf453e3c8919568476c6ee60\System.Web.Mobile.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 3767296 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\7b05d9433656ff2319a30220a6787ca6\System.Web.Extensions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1096704 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\660210d6d0196c39c9feea68e0332ece\System.Web.Extensions.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 5561856 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\32fcfe726e565e6169522c55dacc84e8\System.Web.DataVisualization.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 1495552 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\adcbcc0533c70ad5fe0b7646932c4228\System.ServiceModel.Web.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 2701312 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Services\2cd5f29ccbcceb62c1b875ad4cedab00\System.Data.Services.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 1498112 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.OracleC#\9ae2ebd5a18f5e129b09e1691126fce4\System.Data.OracleClient.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 1733120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity.#\20ec470ecb250aa5c95d14b8793cba5b\System.Data.Entity.Design.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1891328 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationBuildTa#\f1a22e22627669cfa6df30d1b4051988\PresentationBuildTasks.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1828864 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\a1c3a7e4ca00d2ee5f2ce009831d22b9\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 6004736 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build\8186ee6e68fbefb30dca7b41ec0386c4\Microsoft.Build.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 3815936 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Tas#\fc1a938d40998cf260926846cc958bd6\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 2521088 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Eng#\d0d3c1cf8ab4b8b5534a1e5a77d34f09\Microsoft.Build.Engine.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1003520 c:\windows\assembly\NativeImages_v4.0.30319_64\AspNetMMCExt\8aec154d31e76cd786ed5de7c1d0fbb3\AspNetMMCExt.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1226752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\d999b56c109e96bd8118b2104dca1d82\System.WorkflowServices.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1971200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\4055aa50edd533ff57682a696cd70b97\System.Workflow.Runtime.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 4476416 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Com#\a8d5bc70ddc43116bb89d96b172f5c3a\System.Workflow.ComponentModel.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2871296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\a58ab54e96487ccd5744a5c5707e7544\System.Workflow.Activities.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1923584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\e79c46b4fc7cff1216f7b2ecdc6ec075\System.Web.Services.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2329088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Mobile\1965fa47442aefcadaa6b45f4811c710\System.Web.Mobile.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 3092480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\32e81dde72f32b62d1f111bbd9959110\System.Web.Extensions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 4518400 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\5c4640a3048142037f9a78371d6598a7\System.Web.DataVisualization.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1075200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\3a2630d3ac7eca019bdf7cd898983a61\System.ServiceModel.Web.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 2026496 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\6878488ae42f08b42ea032b6bb68e75e\System.Data.Services.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1189376 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.OracleC#\d62b53e7a5528b03ff512c624a1fdb83\System.Data.OracleClient.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1409536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity.#\390d46839913e46c70f45f7a4b9070ba\System.Data.Entity.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1479168 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationBuildTa#\96e437d1e82e54e63ed96af50e96d03d\PresentationBuildTasks.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1138688 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a35ab055e66ff3e4a163dda05b501086\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 4248064 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build\5246fa832baabf6e3706fd537fe19062\Microsoft.Build.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 2873856 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Tas#\4c844fa0efbb47fd2307109f0ace11dc\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1931264 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Eng#\520f23eeaf6b5241a74a56338e8b89f8\Microsoft.Build.Engine.ni.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 12310216 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll
+ 2011-09-19 10:39 . 2012-07-14 01:10 10036408 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-520610219-17727062-633966983-1000-12288.dat
+ 2012-06-24 03:25 . 2012-06-25 01:12 10330864 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
+ 2012-07-08 07:04 . 2012-07-08 07:04 19333120 c:\windows\Installer\209123bb.msi
+ 2012-07-04 00:53 . 2012-07-04 00:53 15657984 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web\22352c9c1091b0fefc587c26a6b03429\System.Web.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 13271040 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Design\62b07636b9cefe089c666cb26bf71597\System.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 11993088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web\00171f60d3512845972c1dbbebf36278\System.Web.ni.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 10992128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Design\0cd11cee6f646aa41fffcf00cf0bc791\System.Design.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-06-07 01:33 1519304 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-06-07 1519304]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Advanced SystemCare 5"="c:\program files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-05-28 288128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-02-25 1770400]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2012-06-07 1564872]
.
c:\users\Bre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-10-9 0]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-9-18 102912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{537056B7-32A4-4408-9B54-0341963C7C9C}\IcoUltraMon.ico [2011-9-18 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"ConduitHelper"="c:\users\Public\Conduit\ConduitHelper\ConduitHelper.exe"
"Freecorder FLV Service"="c:\program files (x86)\Freecorder\FLVSrvc.exe" /run
"Gateway Photo Frame"="c:\program files (x86)\Gateway Photo Frame\ButtonMonitor.exe" -A
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 136176]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys [2009-01-29 6144]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-06-30 35840]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 136176]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2011-09-19 16008]
R3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\Drivers\motoandroid.sys [2009-07-10 31744]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2011-04-04 21504]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 9216]
R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys [2010-04-01 26624]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-07 24176]
R3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2009-10-20 114608]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-09-29 695400]
R3 SPC620;Philips SPC620NC PC Camera;c:\windows\system32\drivers\SPC620.sys [2007-09-28 581120]
R3 SPC620m;Philips SPC620NC PC Cameram;c:\windows\system32\drivers\SPC620m.sys [2007-09-28 8192]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-20 1255736]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 306400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-05-17 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-05-26 913792]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]
S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2012-01-28 66728]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 138752]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [2008-03-13 27136]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 15360]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 22:04]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 22:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-07-28 110360]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=sx2800&r=173604117307p0358v115k49i15222
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Bre\AppData\Roaming\Mozilla\Firefox\Profiles\y7r4no5l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://www.google.co.in/search?btnG=Google+Search&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
HKLM-Run-picop - c:\users\Bre\AppData\Roaming\picop.dll
HKLM-Run-ianex - c:\users\Bre\AppData\Roaming\ianex.dll
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-520610219-17727062-633966983-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-520610219-17727062-633966983-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
.
**************************************************************************
.
Completion time: 2012-07-13 21:16:15 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-14 01:16
ComboFix2.txt 2012-06-25 01:30
ComboFix3.txt 2012-06-21 00:13
.
Pre-Run: 140,212,453,376 bytes free
Post-Run: 143,948,693,504 bytes free
.
- - End Of File - - 3D47FEFFCD85DAFB75DD37E0EA6A38C1
+ 2012-07-03 23:39 . 2012-07-03 23:39 495984 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-03-19 13:19 . 2010-03-19 13:19 155136 c:\windows\Installer\a628639.msi
+ 2010-03-19 00:29 . 2010-03-19 00:29 872448 c:\windows\Installer\a5ff4f3.msi
+ 2012-07-08 07:05 . 2012-07-08 07:05 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
- 2012-06-08 14:13 . 2012-06-08 14:13 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
+ 2012-07-08 04:15 . 2012-07-08 04:15 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2012-07-04 03:01 . 2012-07-04 03:01 553984 c:\windows\assembly\NativeImages_v4.0.30319_64\XamlBuildTask\d7ba8f0a500f25cbed7daa07e8d748ec\XamlBuildTask.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 462336 c:\windows\assembly\NativeImages_v4.0.30319_64\WsatConfig\c87183cbec623926230118ddb9c93662\WsatConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 243712 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\6ade3ca0064ec4387fd905877e1d56b8\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 314880 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.RegularE#\31c9a177e71d9ded2a09252d362bab1d\System.Web.RegularExpressions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 446464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity\39d7c8787069c77987c558d814cac079\System.Web.Entity.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 366592 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity.D#\3ff2fa87603d75f313a66cc051b0f5c7\System.Web.Entity.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 970240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DynamicD#\85c01837b7d52831601939d52c0cd04e\System.Web.DynamicData.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 329728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\e6e7ba45676b869bf66bfd909d7e4fd0\System.Web.DataVisualization.Design.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 578048 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\9b43e24c0322e7c075406de9f8c24f37\System.ServiceModel.Activation.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 994304 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\9b42e3a6e2cd58e1859d8f503e2f3808\System.Runtime.Remoting.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 308224 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Cach#\df3f39d99e99235afbdce9c30b3a9d48\System.Runtime.Caching.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 292352 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing.Desi#\cfe9bb29ab62c2263c904bc321a26bec\System.Drawing.Design.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 661504 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\1e723235ab95da7e59d03da7901857d9\System.Data.Services.Design.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 364544 c:\windows\assembly\NativeImages_v4.0.30319_64\MSBuild\d448d55698c8471a921d17e20c0ac885\MSBuild.ni.exe
+ 2012-07-04 00:53 . 2012-07-04 00:53 851456 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Uti#\0e541d178a5797ec61d0b97058e6cc2e\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 353792 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Fra#\60fcea7acc6c048071451efa6d2f5fa6\Microsoft.Build.Framework.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 661504 c:\windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\57a507991f1e7aeb0d3014fa0d3bbd2c\ComSvcConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 404992 c:\windows\assembly\NativeImages_v4.0.30319_32\XamlBuildTask\09f78ad9517d5d19de8498bac32fc9f8\XamlBuildTask.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 356864 c:\windows\assembly\NativeImages_v4.0.30319_32\WsatConfig\a61f64155e6b58da21013a5e4d6805c2\WsatConfig.ni.exe
+ 2012-07-04 03:00 . 2012-07-04 03:00 194560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\4cf2b2fb097e9f0e86bb6282ae407f38\System.Windows.Forms.DataVisualization.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 224256 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.RegularE#\ea0b825a2dd1a056f6171170eb072d4a\System.Web.RegularExpressions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 861696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\a894d26d652bfc6ac4830fb2f70617a9\System.Web.Extensions.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 333824 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity\e2af30b84b1578b6f104141c1599dd8a\System.Web.Entity.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 297472 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity.D#\4470016734a7207843be5ab103e54617\System.Web.Entity.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 709632 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\c3531459f26b999ebc43cabbcf160f52\System.Web.DynamicData.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 259584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\5e61ee5474c0f76a50932fbb5c7c4df3\System.Web.DataVisualization.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 423424 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c43f1fd03a4b2e3d5d2f7bc5cab6d4d9\System.ServiceModel.Activation.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 771072 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\8c5442df8c423c3f53641723ab202576\System.Runtime.Remoting.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 241664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Cach#\422adb7d24779c5c2e89a02e183f35bb\System.Runtime.Caching.ni.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 226304 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing.Desi#\02fbf9c53252572c65734e4058139abc\System.Drawing.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 508928 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\88d1242f0f9f61cdcd171ff51f61005e\System.Data.Services.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 274432 c:\windows\assembly\NativeImages_v4.0.30319_32\MSBuild\d47740fc85ad70c686adc9fc9dc6e7f5\MSBuild.ni.exe
+ 2012-07-04 02:59 . 2012-07-04 02:59 631296 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Uti#\3ad065635e1e0cd413081be61993cd38\Microsoft.Build.Utilities.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 258048 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Fra#\71a3a98ff5fb128d3abf6ecc3224ba6b\Microsoft.Build.Framework.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 136192 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Con#\f18a2a149b3e7f9cf74de1263c2ee337\Microsoft.Build.Conversion.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 475136 c:\windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\d1a54aac4ba266fc0ba95fd2be09098f\ComSvcConfig.ni.exe
+ 2012-07-04 02:59 . 2012-07-04 02:59 846336 c:\windows\assembly\NativeImages_v4.0.30319_32\AspNetMMCExt\f92703eb43edd152461756ff2d56ea46\AspNetMMCExt.ni.dll
+ 2010-03-18 13:15 . 2010-03-18 13:15 4368720 c:\windows\SysWOW64\mfc100u.dll
+ 2010-03-18 13:15 . 2010-03-18 13:15 4342088 c:\windows\SysWOW64\mfc100.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 9459912 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 1535176 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
+ 2009-07-14 04:54 . 2012-06-28 22:33 2539520 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-06-20 23:55 2539520 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-28 22:33 7094272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:45 . 2012-06-25 01:13 6366312 c:\windows\system32\FNTCACHE.DAT
+ 2010-03-18 20:47 . 2010-03-18 20:47 1587064 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1070960 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1836904 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 21:23 . 2010-03-18 21:23 5145936 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1697144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5078360 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Design.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1064816 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1327968 c:\windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Build.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1587064 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.ComponentModel.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1070960 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Workflow.Activities.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1836904 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5174608 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1697144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.DataVisualization.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 5078360 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Design.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1064816 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll
+ 2010-03-18 20:47 . 2010-03-18 20:47 1327968 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Build.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1587064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1070960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1836904 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1697144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5078360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1327968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 1064816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5145936 c:\windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 5174608 c:\windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-07-08 04:15 . 2012-07-08 04:15 3809280 c:\windows\Installer\1ff590f6.msi
+ 2012-07-04 03:00 . 2012-07-04 03:00 1601536 c:\windows\assembly\NativeImages_v4.0.30319_64\System.WorkflowServ#\72007285279e0d6357db504999c8e124\System.WorkflowServices.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2886656 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Run#\71539c40fc382c7e30eb5e1717f6fac7\System.Workflow.Runtime.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 5921792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Com#\7bd32fb577201b5240b2558d8d1f9a7e\System.Workflow.ComponentModel.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 3743744 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Act#\ec781c38aff4dff4f53675068f55ced8\System.Workflow.Activities.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 2284544 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\13fa0cee801d37b2238052e053863f24\System.Web.Services.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2957312 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Mobile\547a0c7acf453e3c8919568476c6ee60\System.Web.Mobile.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 3767296 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\7b05d9433656ff2319a30220a6787ca6\System.Web.Extensions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1096704 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\660210d6d0196c39c9feea68e0332ece\System.Web.Extensions.Design.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 5561856 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\32fcfe726e565e6169522c55dacc84e8\System.Web.DataVisualization.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 1495552 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\adcbcc0533c70ad5fe0b7646932c4228\System.ServiceModel.Web.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 2701312 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Services\2cd5f29ccbcceb62c1b875ad4cedab00\System.Data.Services.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 1498112 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.OracleC#\9ae2ebd5a18f5e129b09e1691126fce4\System.Data.OracleClient.ni.dll
+ 2012-07-04 00:54 . 2012-07-04 00:54 1733120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity.#\20ec470ecb250aa5c95d14b8793cba5b\System.Data.Entity.Design.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1891328 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationBuildTa#\f1a22e22627669cfa6df30d1b4051988\PresentationBuildTasks.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1828864 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\a1c3a7e4ca00d2ee5f2ce009831d22b9\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 6004736 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build\8186ee6e68fbefb30dca7b41ec0386c4\Microsoft.Build.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 3815936 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Tas#\fc1a938d40998cf260926846cc958bd6\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 2521088 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Build.Eng#\d0d3c1cf8ab4b8b5534a1e5a77d34f09\Microsoft.Build.Engine.ni.dll
+ 2012-07-04 00:52 . 2012-07-04 00:52 1003520 c:\windows\assembly\NativeImages_v4.0.30319_64\AspNetMMCExt\8aec154d31e76cd786ed5de7c1d0fbb3\AspNetMMCExt.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1226752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\d999b56c109e96bd8118b2104dca1d82\System.WorkflowServices.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 1971200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\4055aa50edd533ff57682a696cd70b97\System.Workflow.Runtime.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 4476416 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Com#\a8d5bc70ddc43116bb89d96b172f5c3a\System.Workflow.ComponentModel.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2871296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\a58ab54e96487ccd5744a5c5707e7544\System.Workflow.Activities.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1923584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\e79c46b4fc7cff1216f7b2ecdc6ec075\System.Web.Services.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 2329088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Mobile\1965fa47442aefcadaa6b45f4811c710\System.Web.Mobile.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 3092480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\32e81dde72f32b62d1f111bbd9959110\System.Web.Extensions.ni.dll
+ 2012-07-04 03:00 . 2012-07-04 03:00 4518400 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\5c4640a3048142037f9a78371d6598a7\System.Web.DataVisualization.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1075200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\3a2630d3ac7eca019bdf7cd898983a61\System.ServiceModel.Web.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 2026496 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\6878488ae42f08b42ea032b6bb68e75e\System.Data.Services.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1189376 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.OracleC#\d62b53e7a5528b03ff512c624a1fdb83\System.Data.OracleClient.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1409536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity.#\390d46839913e46c70f45f7a4b9070ba\System.Data.Entity.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1479168 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationBuildTa#\96e437d1e82e54e63ed96af50e96d03d\PresentationBuildTasks.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1138688 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a35ab055e66ff3e4a163dda05b501086\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 4248064 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build\5246fa832baabf6e3706fd537fe19062\Microsoft.Build.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 2873856 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Tas#\4c844fa0efbb47fd2307109f0ace11dc\Microsoft.Build.Tasks.v4.0.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 1931264 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Build.Eng#\520f23eeaf6b5241a74a56338e8b89f8\Microsoft.Build.Engine.ni.dll
+ 2012-06-24 21:45 . 2012-06-24 21:45 12310216 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll
+ 2011-09-19 10:39 . 2012-07-14 01:10 10036408 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-520610219-17727062-633966983-1000-12288.dat
+ 2012-06-24 03:25 . 2012-06-25 01:12 10330864 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
+ 2012-07-08 07:04 . 2012-07-08 07:04 19333120 c:\windows\Installer\209123bb.msi
+ 2012-07-04 00:53 . 2012-07-04 00:53 15657984 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web\22352c9c1091b0fefc587c26a6b03429\System.Web.ni.dll
+ 2012-07-04 00:53 . 2012-07-04 00:53 13271040 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Design\62b07636b9cefe089c666cb26bf71597\System.Design.ni.dll
+ 2012-07-04 02:59 . 2012-07-04 02:59 11993088 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web\00171f60d3512845972c1dbbebf36278\System.Web.ni.dll
+ 2012-07-03 23:40 . 2012-07-03 23:40 10992128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Design\0cd11cee6f646aa41fffcf00cf0bc791\System.Design.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-06-07 01:33 1519304 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-06-07 1519304]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Advanced SystemCare 5"="c:\program files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-05-28 288128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-02-25 1770400]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2012-06-07 1564872]
.
c:\users\Bre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2011-10-9 0]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-9-18 102912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{537056B7-32A4-4408-9B54-0341963C7C9C}\IcoUltraMon.ico [2011-9-18 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"ConduitHelper"="c:\users\Public\Conduit\ConduitHelper\ConduitHelper.exe"
"Freecorder FLV Service"="c:\program files (x86)\Freecorder\FLVSrvc.exe" /run
"Gateway Photo Frame"="c:\program files (x86)\Gateway Photo Frame\ButtonMonitor.exe" -A
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 136176]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys [2009-01-29 6144]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-06-30 35840]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 136176]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2011-09-19 16008]
R3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\Drivers\motoandroid.sys [2009-07-10 31744]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2011-04-04 21504]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 9216]
R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys [2010-04-01 26624]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-07 24176]
R3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2009-10-20 114608]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-09-29 695400]
R3 SPC620;Philips SPC620NC PC Camera;c:\windows\system32\drivers\SPC620.sys [2007-09-28 581120]
R3 SPC620m;Philips SPC620NC PC Cameram;c:\windows\system32\drivers\SPC620m.sys [2007-09-28 8192]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-20 1255736]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 306400]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-05-17 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-05-26 913792]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]
S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2012-01-28 66728]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 138752]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [2008-03-13 27136]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-07-19 15360]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 22:04]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-18 22:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-07-28 110360]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=sx2800&r=173604117307p0358v115k49i15222
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Bre\AppData\Roaming\Mozilla\Firefox\Profiles\y7r4no5l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://www.google.co.in/search?btnG=Google+Search&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
HKLM-Run-picop - c:\users\Bre\AppData\Roaming\picop.dll
HKLM-Run-ianex - c:\users\Bre\AppData\Roaming\ianex.dll
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-520610219-17727062-633966983-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-520610219-17727062-633966983-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
.
**************************************************************************
.
Completion time: 2012-07-13 21:16:15 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-14 01:16
ComboFix2.txt 2012-06-25 01:30
ComboFix3.txt 2012-06-21 00:13
.
Pre-Run: 140,212,453,376 bytes free
Post-Run: 143,948,693,504 bytes free
.
- - End Of File - - 3D47FEFFCD85DAFB75DD37E0EA6A38C1