c:\windows\system32\msxml4.dll
- 2004-08-04 12:00 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2004-08-04 12:00 . 2010-06-14 07:41 1172480 c:\windows\system32\msxml3.dll
+ 2004-08-04 12:00 . 2008-05-19 11:33 4445184 c:\windows\system32\msi.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 3076096 c:\windows\system32\mshtml.dll
+ 2008-03-20 22:06 . 2008-03-20 22:06 1480232 c:\windows\system32\LegitCheckControl.dll
+ 2009-08-20 20:09 . 2009-08-20 20:09 1193832 c:\windows\system32\FM20.DLL
+ 2004-08-04 12:00 . 2010-04-06 08:52 2462720 c:\windows\system32\dllcache\WMVCore.dll
+ 2004-08-04 12:00 . 2006-10-19 01:47 1329152 c:\windows\system32\dllcache\WMSPDMOE.dll
+ 2004-08-04 12:00 . 2006-10-19 01:47 8231936 c:\windows\system32\dllcache\wmploc.dll
+ 2004-08-04 12:00 . 2006-10-19 01:47 1117696 c:\windows\system32\dllcache\WMADMOE.dll
+ 2009-04-17 12:26 . 2010-10-26 13:25 1853312 c:\windows\system32\dllcache\win32k.sys
+ 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2009-07-18 16:05 . 2010-11-05 05:05 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-08-22 01:49 . 2006-11-01 22:31 1669120 c:\windows\system32\dllcache\setup_wm.exe
+ 2009-06-03 19:09 . 2010-02-05 18:27 1291776 c:\windows\system32\dllcache\quartz.dll
- 2009-06-03 19:09 . 2009-11-27 17:11 1291776 c:\windows\system32\dllcache\quartz.dll
+ 2010-07-16 12:05 . 2010-07-16 12:05 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2009-08-22 06:17 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-08-22 06:17 . 2010-04-27 13:05 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-07 23:02 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-08-22 06:17 . 2010-04-27 13:59 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2004-08-04 12:00 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2004-08-04 12:00 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2009-08-22 06:13 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2009-08-22 06:13 . 2010-01-29 15:01 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2008-05-19 11:33 . 2008-05-19 11:33 4445184 c:\windows\system32\dllcache\msi.dll
+ 2009-07-18 16:05 . 2010-11-05 05:05 3076096 c:\windows\system32\dllcache\mshtml.dll
- 2010-03-11 04:28 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2010-03-11 04:28 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2010-03-10 04:33 . 2010-11-05 05:05 1025024 c:\windows\system32\dllcache\browseui.dll
- 2010-03-10 04:33 . 2010-03-10 04:33 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2009-11-12 01:06 . 2009-11-12 01:06 1130824 c:\windows\system32\dfshim.dll
+ 2010-11-22 06:05 . 2009-09-04 22:29 1892184 c:\windows\system32\D3DX9_42.dll
+ 2010-11-23 02:29 . 2005-05-26 20:34 2297552 c:\windows\system32\d3dx9_26.dll
+ 2010-11-23 02:29 . 2005-03-18 22:19 2337488 c:\windows\system32\d3dx9_25.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 1025024 c:\windows\system32\browseui.dll
- 2004-08-04 12:00 . 2010-03-10 04:33 1025024 c:\windows\system32\browseui.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1663320 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1303896 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 6346600 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 3545952 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 2650464 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsLexicons0009.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 4881752 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\NlsData0009.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 2199880 c:\windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
+ 2010-03-18 18:16 . 2010-03-18 18:16 2207568 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.XML.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 4982120 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1711496 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.DataVisualization.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 6067048 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.ServiceModel.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1026936 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 3481928 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 4464480 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Entity.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 2970968 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Data.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1339736 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1462648 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.Presentation.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1199968 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Activities.dll
+ 2010-03-18 20:26 . 2010-03-18 20:26 1163264 c:\windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\netfx_core_x86.msi
+ 2010-03-18 18:16 . 2010-03-18 18:16 5196112 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1141592 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 2989456 c:\windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2010-03-18 18:16 . 2010-03-18 18:16 1972552 c:\windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
+ 2010-03-18 18:16 . 2010-03-18 18:16 6730056 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1303896 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 3481928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 4982120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 6067048 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 1339736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 6346600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 2970968 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 3545952 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-11-22 06:02 . 2010-11-22 06:02 5196112 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1160192 c:\windows\Installer\c89042d9.msi
+ 2010-11-22 06:01 . 2010-11-22 06:01 2317312 c:\windows\Installer\c89042d0.msi
+ 2010-12-31 03:27 . 2010-12-31 03:27 1094656 c:\windows\Installer\6d32d.msi
+ 2010-09-17 11:04 . 2010-09-17 11:04 9401856 c:\windows\Installer\58c2369.msp
+ 2010-08-13 22:59 . 2010-08-13 22:59 8182272 c:\windows\Installer\58c2361.msp
+ 2010-08-13 23:02 . 2010-08-13 23:02 2545664 c:\windows\Installer\58c2359.msp
+ 2010-08-04 20:12 . 2010-08-04 20:12 1004544 c:\windows\Installer\58c2351.msp
+ 2011-01-01 09:23 . 2011-01-01 09:23 1867776 c:\windows\Installer\4260db.msi
+ 2011-01-01 01:36 . 2011-01-01 01:36 2283008 c:\windows\Installer\3aeb9.msi
+ 2010-10-04 21:00 . 2010-10-04 21:00 7973888 c:\windows\Installer\18a25097.msp
+ 2008-09-04 20:52 . 2008-09-04 20:52 4337664 c:\windows\Installer\18a25082.msp
+ 2010-08-09 21:44 . 2010-08-09 21:44 3778048 c:\windows\Installer\18a2505b.msp
+ 2010-01-11 21:35 . 2010-01-11 21:35 4480000 c:\windows\Installer\18a2501a.msp
+ 2006-02-27 21:31 . 2006-02-27 21:31 1269248 c:\windows\Installer\18a25006.msp
+ 2010-10-04 18:59 . 2010-10-04 18:59 8300032 c:\windows\Installer\18a24ff3.msp
+ 2006-03-28 20:37 . 2006-03-28 20:37 6956032 c:\windows\Installer\18a24fe0.msp
+ 2006-08-29 22:50 . 2006-08-29 22:50 3210240 c:\windows\Installer\18a24fc6.msp
+ 2010-10-04 18:55 . 2010-10-04 18:55 9629696 c:\windows\Installer\18a24fb2.msp
+ 2010-08-27 18:36 . 2010-08-27 18:36 2807296 c:\windows\Installer\18a24f9d.msp
+ 2004-03-10 14:13 . 2004-03-10 14:13 2602496 c:\windows\Installer\18a24f82.msp
+ 2010-08-18 15:19 . 2010-08-18 15:19 8400896 c:\windows\Installer\18a24f6f.msp
+ 2004-09-13 05:35 . 2004-09-13 05:35 1452544 c:\windows\Installer\18a24f5b.msp
+ 2009-08-20 20:27 . 2009-08-20 20:27 3622400 c:\windows\Installer\18a24f08.msp
+ 2010-05-24 18:54 . 2010-05-24 18:54 6704640 c:\windows\Installer\18a24eb2.msp
+ 2009-08-19 22:04 . 2009-08-19 22:04 4542296 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\WRD12CNV.DLL
+ 2009-08-22 06:17 . 2010-04-28 02:25 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-08-22 06:17 . 2010-04-27 13:05 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-07 23:02 . 2010-04-27 13:05 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-08-22 06:17 . 2010-04-27 13:59 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-11-22 06:04 . 2010-11-22 06:04 3779072 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d17606e813f01376bd0def23726ecc62\WindowsBase.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1055744 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\5904383f7c86f1374a14198872dfa7d8\UIAutomationClientsideProviders.ni.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 9000960 c:\windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 5571584 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1776640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 4496384 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\9cf13572472dc2efe8f3b7c2ab6198d3\System.Windows.Forms.DataVisualization.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1828352 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\87e09dfbe3a44d6b00d3a5895f5a21a6\System.Web.Services.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1992192 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\61a931da70f8078539a51cef3888d02d\System.Speech.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1127424 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56\System.ServiceModel.Discovery.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1388032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b\System.ServiceModel.Activities.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 2625024 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1011200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1047040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\eb9369fc9393d29afe51e45cb49aa4be\System.Printing.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1159168 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\6a6f4be744ed5bc5273cbcf0fcf303e3\System.Management.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1065984 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 1651200 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1151488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\5166bf93ac5239837c9c92b58d183ea6\System.DirectoryServices.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1872384 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\90fd7fc9fbf5f4eed9135996b515a38a\System.Deployment.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 6754816 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\92cccedc7cda413ff6fc6492cb256b58\System.Data.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 2538496 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\1fdd0961d8d07ef4d1fcaf30f0050c0a\System.Data.SqlXml.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 1332736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\685c7df1332a74aaa899f2bdb3beabc3\System.Data.Services.Client.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 2499072 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\87a713cee613d08ee04ae9483a9d4716\System.Data.Linq.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 7025664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 4103168 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\931ad0783c03deb967760d5c2387274a\System.Activities.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 3691520 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\a57e34a36f38a007aa24f1bd07a167ab\System.Activities.Presentation.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1506304 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\607df7a11c3334146664bc74130bc38f\System.Activities.Core.Presentation.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 2842624 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\42f0e1a4e3081c50503d74ebc0540a60\ReachFramework.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1622528 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\15578874ee1464dc6a3545d4be842e59\PresentationUI.ni.dll
+ 2010-11-22 07:32 . 2010-11-22 07:32 1819648 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\e8ab3b63bade82c3522613f2b1240c0d\Microsoft.VisualBasic.ni.dll
+ 2010-11-22 07:33 . 2010-11-22 07:33 1134080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\a7b5a07abe981fc8d777ff40a0e45102\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2010-11-22 07:32 . 2010-11-22 07:32 1167872 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2eef2f34c0295f1fe5d6d4441f9e790b\Microsoft.VisualBasic.Activities.Compiler.ni.dll
+ 2010-11-22 07:32 . 2010-11-22 07:32 1079808 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\9952f66fc592ffc21b024803c8c955fd\Microsoft.Transactions.Bridge.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 2441728 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\08b2c2639708ab20748653185d6b67be\Microsoft.JScript.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 1612288 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\05503f37aef5261d80ccca19f8078679\Microsoft.CSharp.ni.dll
+ 2010-10-10 16:21 . 2008-04-13 17:28 2940928 c:\windows\$NtUninstallwmp11$\wmploc.dll
+ 2010-10-10 16:21 . 2010-03-19 22:05 4874240 c:\windows\$NtUninstallwmp11$\wmp.dll
+ 2010-10-10 16:20 . 2008-04-14 00:12 1001472 c:\windows\$NtUninstallWMFDist11$\wmvdmoe2.dll
+ 2010-10-10 16:20 . 2010-04-08 18:03 2113536 c:\windows\$NtUninstallWMFDist11$\wmvcore.dll
+ 2010-10-10 16:20 . 2008-04-14 00:12 1119744 c:\windows\$NtUninstallWMFDist11$\wmsdmoe2.dll
+ 2010-10-10 16:20 . 2008-06-10 10:11 1053696 c:\windows\$NtUninstallWMFDist11$\wmnetmgr.dll
+ 2010-06-11 07:00 . 2010-03-10 04:33 1509888 c:\windows\$NtUninstallKB982381$\shdocvw.dll
+ 2010-06-11 07:00 . 2010-02-26 05:43 3073024 c:\windows\$NtUninstallKB982381$\mshtml.dll
+ 2010-06-11 07:00 . 2010-03-10 04:33 1025024 c:\windows\$NtUninstallKB982381$\browseui.dll
+ 2010-08-12 07:00 . 2009-10-23 15:28 3558912 c:\windows\$NtUninstallKB981997$\moviemk.exe
+ 2010-10-14 07:00 . 2010-06-23 13:44 1851904 c:\windows\$NtUninstallKB981957$\win32k.sys
+ 2010-08-12 07:02 . 2010-02-16 14:08 2146304 c:\windows\$NtUninstallKB981852$\ntoskrnl.exe
+ 2010-08-12 07:02 . 2010-02-16 13:25 2024448 c:\windows\$NtUninstallKB981852$\ntkrpamp.exe
+ 2010-08-12 07:02 . 2010-02-16 13:25 2024448 c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe
+ 2010-08-12 07:02 . 2010-02-16 14:08 2146304 c:\windows\$NtUninstallKB981852$\ntkrnlmp.exe
+ 2010-10-14 07:01 . 2008-04-14 00:12 1287168 c:\windows\$NtUninstallKB979687$\ole32.dll
+ 2010-04-15 07:02 . 2009-12-08 19:26 2145280 c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
+ 2010-04-15 07:02 . 2009-12-08 18:43 2023936 c:\windows\$NtUninstallKB979683$\ntkrpamp.exe
+ 2010-04-15 07:02 . 2009-12-08 18:43 2023936 c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
+ 2010-04-15 07:02 . 2009-12-08 19:26 2145280 c:\windows\$NtUninstallKB979683$\ntkrnlmp.exe
+ 2010-06-11 07:01 . 2009-08-14 13:21 1850624 c:\windows\$NtUninstallKB979559$\win32k.sys
+ 2010-04-15 07:01 . 2009-07-12 16:21 4874240 c:\windows\$NtUninstallKB979402_WM9$\wmp.dll
+ 2010-06-11 07:00 . 2009-05-26 20:53 2174976 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
+ 2010-05-12 15:03 . 2009-07-10 13:27 1315328 c:\windows\$NtUninstallKB978542$\msoe.dll
+ 2010-06-11 07:00 . 2009-11-27 17:11 1291776 c:\windows\$NtUninstallKB975562$\quartz.dll
+ 2010-10-14 07:02 . 2008-04-14 00:11 1028096 c:\windows\$NtUninstallKB2387149$\mfc42.dll
+ 2010-10-14 07:02 . 2010-06-24 12:10 1509888 c:\windows\$NtUninstallKB2360131$\shdocvw.dll
+ 2010-10-14 07:02 . 2010-06-24 12:10 3073024 c:\windows\$NtUninstallKB2360131$\mshtml.dll
+ 2010-10-14 07:02 . 2010-06-24 12:10 1025024 c:\windows\$NtUninstallKB2360131$\browseui.dll
+ 2010-08-03 07:00 . 2008-06-17 19:02 8461312 c:\windows\$NtUninstallKB2286198$\shell32.dll
+ 2010-08-12 07:02 . 2010-04-16 16:09 1509888 c:\windows\$NtUninstallKB2183461$\shdocvw.dll
+ 2010-08-12 07:02 . 2010-04-16 16:09 3073024 c:\windows\$NtUninstallKB2183461$\mshtml.dll
+ 2010-08-12 07:02 . 2010-04-16 16:09 1025024 c:\windows\$NtUninstallKB2183461$\browseui.dll
+ 2010-08-12 07:01 . 2010-05-02 05:22 1851264 c:\windows\$NtUninstallKB2160329$\win32k.sys
+ 2010-08-12 07:02 . 2009-07-31 04:35 1172480 c:\windows\$NtUninstallKB2079403$\msxml3.dll
+ 2010-04-16 16:00 . 2010-04-16 16:00 1509888 c:\windows\$hf_mig$\KB982381\SP3QFE\shdocvw.dll
+ 2010-04-16 16:00 . 2010-04-16 16:00 3073536 c:\windows\$hf_mig$\KB982381\SP3QFE\mshtml.dll
+ 2010-04-16 16:00 . 2010-04-16 16:00 1025024 c:\windows\$hf_mig$\KB982381\SP3QFE\browseui.dll
+ 2010-08-11 17:25 . 2010-06-18 13:43 3558912 c:\windows\$hf_mig$\KB981997\SP3QFE\moviemk.exe
+ 2010-08-31 13:38 . 2010-08-31 13:38 1861888 c:\windows\$hf_mig$\KB981957\SP3QFE\win32k.sys
+ 2010-08-11 17:26 . 2010-04-27 13:50 2190080 c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe
+ 2010-08-11 17:26 . 2010-04-27 13:14 2024448 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrpamp.exe
+ 2010-04-28 11:14 . 2010-04-28 11:14 2066944 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe
+ 2010-08-11 17:26 . 2010-04-27 13:54 2146304 c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlmp.exe
+ 2010-07-16 12:04 . 2010-07-16 12:04 1289216 c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
+ 2010-04-14 11:02 . 2010-02-16 12:52 2190080 c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
+ 2010-04-14 11:02 . 2010-02-16 12:12 2024448 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrpamp.exe
+ 2010-04-14 11:02 . 2010-02-16 12:12 2066944 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
+ 2010-04-14 11:02 . 2010-02-16 12:50 2146304 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlmp.exe
+ 2010-05-02 06:34 . 2010-05-02 06:34 1860352 c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys
+ 2010-01-29 14:53 . 2010-01-29 14:53 1315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
+ 2010-02-05 18:29 . 2010-02-05 18:29 1291776 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
+ 2010-09-09 14:25 . 2010-09-09 14:25 1510400 c:\windows\$hf_mig$\KB2360131\SP3QFE\shdocvw.dll
+ 2010-09-09 14:25 . 2010-09-09 14:25 3074560 c:\windows\$hf_mig$\KB2360131\SP3QFE\mshtml.dll
+ 2010-09-09 14:25 . 2010-09-09 14:25 1025024 c:\windows\$hf_mig$\KB2360131\SP3QFE\browseui.dll
+ 2010-07-27 06:28 . 2010-07-27 06:28 8463360 c:\windows\$hf_mig$\KB2286198\SP3QFE\shell32.dll
+ 2010-06-24 12:11 . 2010-06-24 12:11 1509888 c:\windows\$hf_mig$\KB2183461\SP3QFE\shdocvw.dll
+ 2010-06-24 12:11 . 2010-06-24 12:11 3073536 c:\windows\$hf_mig$\KB2183461\SP3QFE\mshtml.dll
+ 2010-06-24 12:11 . 2010-06-24 12:11 1025024 c:\windows\$hf_mig$\KB2183461\SP3QFE\browseui.dll
+ 2010-06-24 02:14 . 2010-06-24 02:14 1861120 c:\windows\$hf_mig$\KB2160329\SP3QFE\win32k.sys
+ 2010-06-14 07:39 . 2010-06-14 07:39 1172480 c:\windows\$hf_mig$\KB2079403\SP3QFE\msxml3.dll
+ 2004-08-04 12:00 . 2010-08-26 03:36 10841088 c:\windows\system32\wmp.dll
+ 2010-04-15 07:00 . 2010-12-15 08:00 37366216 c:\windows\system32\MRT.exe
+ 2004-08-04 12:00 . 2010-08-26 03:36 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2010-11-23 02:16 . 2010-11-23 02:16 36753408 c:\windows\Installer\44194f0.msi
+ 2010-12-21 02:36 . 2010-12-21 02:36 20304384 c:\windows\Installer\1da9f7d9.msp
+ 2005-09-25 16:46 . 2005-09-25 16:46 16084480 c:\windows\Installer\18a25033.msp
+ 2009-07-20 17:03 . 2009-07-20 17:03 16465408 c:\windows\Installer\18a24edb.msp
+ 2010-08-18 15:12 . 2010-08-18 15:12 17516032 c:\windows\Installer\18a24ec6.msp
+ 2004-01-30 08:19 . 2004-01-30 08:19 56269996 c:\windows\Installer\144d5716.msp
+ 2009-08-17 21:39 . 2009-08-17 21:39 15119720 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\XL12CNV.EXE
+ 2009-08-17 20:40 . 2009-08-17 20:40 17309040 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\MSO.DLL
+ 2010-11-22 06:04 . 2010-11-22 06:04 13006336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 17919488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll
+ 2010-11-22 07:35 . 2010-11-22 07:35 13273600 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\642a7b3d47828fb0070a55cfeb58f42b\System.Data.Entity.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 17629184 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7f91eecda3ff7ce478146b6458580c98\PresentationFramework.ni.dll
+ 2010-11-22 06:04 . 2010-11-22 06:04 11057664 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\3963e9ce8d44f50e8367e92a8e3e42e6\PresentationCore.ni.dll
+ 2010-11-22 06:03 . 2010-11-22 06:03 14415872 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll
+ 2010-10-14 07:02 . 2009-07-14 03:43 10841088 c:\windows\$NtUninstallKB2378111_WM9$\wmp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-12-14 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="c:\windows\TPPALDR.EXE" [2001-10-05 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-18 7561216]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2010-11-22 274608]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-12-31 3395600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:English /KBD:2\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\autopatcher.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\autopatcher2.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\autopatcherx.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\autopatchery.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10736:TCP"= 10736:TCP:BitComet 10736 TCP
"10736:UDP"= 10736:UDP:BitComet 10736 UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/1/2011 4:26 AM 64288]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/31/2010 6:26 PM 293968]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/31/2010 6:26 PM 17744]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 4:05 AM 1389400]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
2011-01-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 09:05]
2011-01-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-839522115-1035525444-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
2011-01-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-839522115-1035525444-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
2011-01-01 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-08-22 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.atcomet.com/m/
FF - ProfilePath - c:\documents and settings\Nick Traskal\Application Data\Mozilla\Firefox\Profiles\kyunrjud.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - BearShare Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-01 13:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500KS-00MJB0 rev.02.01C03 -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89D21555]<<
c:\docume~1\NICKTR~1\LOCALS~1\Temp\catchme.sys
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x89d277b0]; MOV EAX, [0x89d2782c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x89DDE030]
3 CLASSPNP[0xBA0F8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000066[0x89DF1510]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x89E50940]
\Driver\atapi[0x89DEC2C8] -> IRP_MJ_CREATE -> 0x89D21555
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD2500KS-00MJB0_____________________02.01C03#5&1726dd96&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x89D2139B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
**************************************************************************
.
Completion time: 2011-01-01 13:32:17
ComboFix-quarantined-files.txt 2011-01-01 18:32
ComboFix2.txt 2010-04-10 07:26
Pre-Run: 41,998,036,992 bytes free
Post-Run: 42,342,014,976 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - C61D1A115F67F439763046901DB64635