Ken
Disastrous - I am having to send this from another pc. When I try to launch Firefox or chrome I get the message, "Illegal operation on a registry key that has been marked for deletion". This message appears for almost any program including DDS so I cannot post a log.
IE will not run at all.
HELP!!
During combofix's run a window appeared saying something like PEV.exe cannot run. It disappeared so I am not sure exactly what it said.
Here is the log for combofix:
ComboFix 10-09-08.03 - Ailsa 11/09/2010 9:39.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.751 [GMT 1:00]
Running from: c:\users\Ailsa\Downloads\Desktop\Combo-Fix.exe
Command switches used :: c:\users\Ailsa\Downloads\Desktop\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.
2010-09-11 08:51 . 2010-09-11 08:51 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-11 08:51 . 2010-09-11 08:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-10 18:00 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-09-10 13:44 . 2010-09-10 13:44 -------- d-----w- C:\$AVG
2010-09-10 13:44 . 2010-09-10 13:44 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-09-10 13:44 . 2010-09-10 13:44 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-09-10 13:44 . 2010-09-10 13:44 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-09-10 13:44 . 2010-09-10 13:44 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-09-10 13:44 . 2010-09-11 08:12 -------- d-----w- c:\windows\system32\drivers\Avg
2010-09-10 13:41 . 2010-09-10 13:41 -------- d-----w- c:\programdata\avg9
2010-09-10 07:36 . 2010-09-10 07:36 -------- d-----w- c:\program files\ESET
2010-09-09 22:39 . 2010-09-11 08:51 -------- d-----w- c:\users\Ailsa\AppData\Local\temp
2010-09-09 16:53 . 2010-09-09 16:53 -------- d-----w- c:\users\Ailsa\AppData\Roaming\Malwarebytes
2010-09-09 16:53 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-09 16:53 . 2010-09-09 16:53 -------- d-----w- c:\programdata\Malwarebytes
2010-09-09 16:53 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-09 16:53 . 2010-09-09 16:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-09 16:46 . 2010-09-09 16:46 -------- d-----w- c:\program files\ERUNT
2010-09-09 15:50 . 2010-09-09 15:50 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-09-04 18:20 . 2010-09-09 16:26 -------- d-----w- c:\users\Ailsa\AppData\Local\gxoowdbct
2010-08-16 17:21 . 2010-09-10 14:44 -------- d-----w- c:\users\Ailsa\AppData\Local\Windows
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 17:08 . 2009-03-14 12:04 -------- d-----w- c:\program files\Microsoft
2010-09-10 17:04 . 2009-03-14 12:09 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-10 14:31 . 2007-06-25 01:36 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-10 13:41 . 2009-01-16 20:42 -------- d-----w- c:\program files\AVG
2010-09-10 07:06 . 2010-07-02 13:05 -------- d-----w- c:\program files\LimeWire
2010-09-04 18:46 . 2009-07-28 00:22 680 ----a-w- c:\users\Ailsa\AppData\Local\d3d9caps.dat
2010-09-04 18:34 . 2009-03-31 21:14 -------- d-----w- c:\users\Ailsa\AppData\Roaming\Spotify
2010-08-19 23:26 . 2010-07-02 13:07 -------- d-----w- c:\users\Ailsa\AppData\Roaming\LimeWire
2010-08-18 21:15 . 2010-06-23 11:22 -------- d-----w- c:\users\Ailsa\AppData\Roaming\DivX
2010-08-12 02:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-10 01:42 . 2008-09-15 07:58 -------- d-----w- c:\users\Ailsa\AppData\Roaming\Apple Computer
2010-08-10 01:40 . 2008-09-15 07:55 -------- d-----w- c:\programdata\Apple
2010-07-11 02:18 . 2010-06-23 11:25 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-11 01:51 . 2010-07-11 01:51 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-11 01:51 . 2010-07-11 01:51 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-07-11 01:49 . 2010-07-11 01:49 84054 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-07-11 01:49 . 2010-07-11 01:49 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-07-11 01:47 . 2010-07-11 01:47 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-07-11 01:47 . 2010-06-23 11:22 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-07-11 01:47 . 2010-06-23 11:22 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-07-02 13:09 . 2010-07-02 13:09 610304 ----a-w- c:\users\Ailsa\AppData\Roaming\LimeWire\browser\xulrunner\js3250.dll
2010-07-02 13:01 . 2010-07-02 13:01 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-02 12:58 . 2010-07-02 12:58 71992 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-26 06:05 . 2010-09-10 17:10 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-09-10 17:10 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-09-10 17:10 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-09-10 17:10 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-23 11:22 . 2010-06-23 11:22 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-06-23 11:22 . 2010-06-23 11:22 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-06-23 11:21 . 2010-06-23 11:21 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-06-21 13:18 . 2010-08-11 16:00 2036736 ----a-w- c:\windows\system32\win32k.sys
2010-06-18 16:43 . 2010-08-11 16:00 36352 ----a-w- c:\windows\system32\rtutils.dll
2010-06-18 14:43 . 2010-08-11 16:00 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 14:43 . 2010-08-11 16:00 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 15:59 . 2010-08-11 16:00 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-12-08 10:10 . 2007-12-08 10:10 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2010-09-09_22.35.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-10 13:41 . 2010-09-10 13:41 65536 c:\windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.4053_none_3b0e32bdc9afe437\vcomp.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80KOR.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80JPN.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ITA.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80FRA.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ESP.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 57344 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ENU.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 65536 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80DEU.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 45056 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHT.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 40960 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHS.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 57856 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80u.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 69632 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 94720 c:\windows\winsxs\x86_microsoft-windows-ie-setup_31bf3856ad364e35_8.0.6001.18702_none_7c2a7e005d93bd9b\inseng.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23040_none_a9180e0d8d84c714\iesetup.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23040_none_a9180e0d8d84c714\iernonce.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18943_none_a8919be474643d34\iesetup.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18943_none_a8919be474643d34\iernonce.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18702_none_a8bbd77e7444b9cb\iesetup.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18702_none_a8bbd77e7444b9cb\iernonce.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 59904 c:\windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_8.0.6001.18702_none_3d86a1c07a097782\icardie.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 34816 c:\windows\winsxs\x86_microsoft-windows-ie-imagesupport_31bf3856ad364e35_8.0.6001.18702_none_20dfeb2e08d9ec0a\imgutil.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 66560 c:\windows\winsxs\x86_microsoft-windows-ie-iexpress_31bf3856ad364e35_8.0.6001.18702_none_4766ff3b547d623d\wextract.exe
+ 2010-09-10 17:11 . 2010-06-24 05:17 16896 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.23039_none_844ab3e55fe5699d\iecompat.dll
+ 2010-09-10 17:11 . 2010-06-24 04:49 16896 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18942_none_83af6eec46d5fe48\iecompat.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 48128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_8.0.6001.18702_none_d658a8dacff20c9e\mshtmler.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 66560 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_8.0.6001.18702_none_2b140bc159303551\mshtmled.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 45568 c:\windows\winsxs\x86_microsoft-windows-ie-htmlapplication_31bf3856ad364e35_8.0.6001.18702_none_3c45119b1f28ff3d\mshta.exe
+ 2010-09-10 17:10 . 2010-06-26 05:12 13312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23040_none_df9547f309cd816b\msfeedssync.exe
+ 2010-09-10 17:10 . 2010-06-26 06:49 55296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.23040_none_df9547f309cd816b\msfeedsbs.dll
+ 2010-09-10 17:10 . 2010-06-26 04:24 13312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18943_none_df0ed5c9f0acf78b\msfeedssync.exe
+ 2010-09-10 17:10 . 2010-06-26 06:03 55296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18943_none_df0ed5c9f0acf78b\msfeedsbs.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 13312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18702_none_df391163f08d7422\msfeedssync.exe
+ 2010-09-10 17:09 . 2009-03-08 11:31 55296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18702_none_df391163f08d7422\msfeedsbs.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 43008 c:\windows\winsxs\x86_microsoft-windows-ie-controls_31bf3856ad364e35_8.0.6001.18702_none_accc7a4465be292a\licmgr10.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 72704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_8.0.6001.18702_none_911d44271c9159e9\admparse.dll
+ 2010-09-10 17:10 . 2010-06-26 06:51 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23040_none_e5304c66d0de8f8c\WininetPlugin.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 25600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23040_none_e5304c66d0de8f8c\jsproxy.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18943_none_e4a9da3db7be05ac\WininetPlugin.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 25600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18943_none_e4a9da3db7be05ac\jsproxy.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18702_none_e4d415d7b79e8243\WininetPlugin.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 25600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18702_none_e4d415d7b79e8243\jsproxy.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 18944 c:\windows\winsxs\x86_microsoft-windows-i..tivexpolicyprovider_31bf3856ad364e35_8.0.6001.18702_none_6f561c09617d9439\corpol.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 46592 c:\windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_8.0.6001.18702_none_d0b191832934e44c\pngfilt.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 66560 c:\windows\System32\wextract.exe
+ 2007-04-18 09:41 . 2010-09-11 08:15 68624 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2010-09-11 08:15 73310 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-10 17:09 . 2009-03-08 11:31 46592 c:\windows\System32\pngfilt.dll
- 2006-11-02 07:33 . 2006-11-02 07:33 48128 c:\windows\System32\mshtmler.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 48128 c:\windows\System32\mshtmler.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 66560 c:\windows\System32\mshtmled.dll
- 2008-09-21 17:12 . 2008-01-19 07:33 45568 c:\windows\System32\mshta.exe
+ 2010-09-10 17:09 . 2009-03-08 11:31 45568 c:\windows\System32\mshta.exe
+ 2010-09-10 17:10 . 2010-06-26 04:24 13312 c:\windows\System32\msfeedssync.exe
+ 2010-09-10 17:10 . 2010-06-26 06:03 55296 c:\windows\System32\msfeedsbs.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 64512 c:\windows\System32\migration\WininetPlugin.dll
- 2008-10-15 22:09 . 2008-02-22 05:01 64512 c:\windows\System32\migration\WininetPlugin.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 43008 c:\windows\System32\licmgr10.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 25600 c:\windows\System32\jsproxy.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 94720 c:\windows\System32\inseng.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 34816 c:\windows\System32\imgutil.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 55808 c:\windows\System32\iernonce.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 59904 c:\windows\System32\icardie.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 18944 c:\windows\System32\corpol.dll
+ 2007-12-08 09:36 . 2010-09-11 08:14 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-12-08 09:36 . 2010-09-09 22:34 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-12-08 09:36 . 2010-09-09 22:34 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-12-08 09:36 . 2010-09-11 08:14 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-10 17:09 . 2009-03-08 11:32 72704 c:\windows\System32\admparse.dll
- 2008-09-21 17:12 . 2008-01-19 07:33 72704 c:\windows\System32\admparse.dll
+ 2010-06-04 02:01 . 2010-09-10 15:54 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-06-04 02:01 . 2010-06-04 02:01 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 2048 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18702_none_83daaad046b59436\iecompat.dll
+ 2008-09-23 21:03 . 2010-09-10 17:15 5158 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-03-24 16:10 . 2010-09-10 17:13 2010 c:\windows\System32\WDI\{88d4896f-f553-446a-9c75-9dec124ff8b7}.bin
+ 2008-09-14 00:00 . 2010-09-11 08:15 9644 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1851843919-258154983-2237051013-1003_UserData.bin
+ 2010-09-10 12:57 . 2010-09-10 12:57 9560 c:\windows\System32\networklist\icons\{92D7E619-1CB0-4823-AF71-5ACBBBF87053}_48.bin
+ 2010-09-10 12:57 . 2010-09-10 12:57 4280 c:\windows\System32\networklist\icons\{92D7E619-1CB0-4823-AF71-5ACBBBF87053}_32.bin
+ 2010-09-10 12:57 . 2010-09-10 12:57 2456 c:\windows\System32\networklist\icons\{92D7E619-1CB0-4823-AF71-5ACBBBF87053}_24.bin
- 2010-09-09 22:24 . 2010-09-09 22:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-11 08:08 . 2010-09-11 08:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-11 08:08 . 2010-09-11 08:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-09-09 22:24 . 2010-09-09 22:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-10 18:00 . 2010-03-05 22:19 420352 c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_8.0.6001.23000_none_2bcc9be85cd2112b\vbscript.dll
+ 2010-09-10 18:00 . 2010-03-05 14:01 420352 c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_8.0.6001.18909_none_2b4c2b7b43ac1f55\vbscript.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 420352 c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_8.0.6001.18702_none_2b4525a943b273a6\vbscript.dll
+ 2010-09-10 18:00 . 2009-12-04 16:15 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.22960_none_6611c986263fd953\jscript.dll
+ 2010-09-10 18:00 . 2009-06-06 12:55 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.22886_none_66022984264aac18\jscript.dll
+ 2010-09-10 18:00 . 2009-12-04 07:19 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.18869_none_65912f550d1a1d98\jscript.dll
+ 2010-09-10 18:00 . 2009-06-06 05:01 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.18795_none_656cbc830d360ee8\jscript.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.18702_none_65cb0af10cefc76a\jscript.dll
+ 2010-09-10 17:09 . 2009-03-08 11:22 156160 c:\windows\winsxs\x86_microsoft-windows-msls31_31bf3856ad364e35_8.0.6001.18702_none_aeeaf610b83f2e48\msls31.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 121344 c:\windows\winsxs\x86_microsoft-windows-js-debuggeride_31bf3856ad364e35_8.0.6001.18702_none_1de359b6148047cc\jsdebuggeride.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 256000 c:\windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_8.0.6001.18702_none_cb86fb78a76dcdde\ieinstal.exe
+ 2010-09-10 17:10 . 2010-06-26 06:48 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.23040_none_47e9c588dd2a86ef\ieui.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18943_none_4763535fc409fd0f\ieui.dll
+ 2010-09-10 17:09 . 2009-03-08 11:22 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18702_none_478d8ef9c3ea79a6\ieui.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 105984 c:\windows\winsxs\x86_microsoft-windows-ie-winsockautodialstub_31bf3856ad364e35_8.0.6001.18702_none_d315f3a07395d0ed\url.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 208384 c:\windows\winsxs\x86_microsoft-windows-ie-winfxdocobj_31bf3856ad364e35_8.0.6001.18702_none_d4a239fe30224f93\WinFXDocObj.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 759296 c:\windows\winsxs\x86_microsoft-windows-ie-vgx_31bf3856ad364e35_8.0.6001.18702_none_d02233c4fe8667df\VGX.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.23040_none_fed972b9e90803d9\iesysprep.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.18943_none_fe530090cfe779f9\iesysprep.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.18702_none_fe7d3c2acfc7f690\iesysprep.dll
+ 2010-09-10 17:10 . 2010-06-26 05:13 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.23040_none_a9180e0d8d84c714\ie4uinit.exe
+ 2010-09-10 17:10 . 2010-06-26 04:24 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18943_none_a8919be474643d34\ie4uinit.exe
+ 2010-09-10 17:09 . 2009-03-08 11:32 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18702_none_a8bbd77e7444b9cb\ie4uinit.exe
+ 2010-09-10 17:10 . 2010-06-26 06:51 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.23040_none_2aeb0342bb8fade9\sqmapi.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18943_none_2a649119a26f2409\sqmapi.dll
+ 2010-09-10 17:09 . 2009-03-08 21:09 140128 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18702_none_2a8eccb3a24fa0a0\sqmapi.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 193536 c:\windows\winsxs\x86_microsoft-windows-ie-ratings_31bf3856ad364e35_8.0.6001.18702_none_aa7d60ae7286ab24\msrating.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 109568 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_8.0.6001.18702_none_d0610d06fe575a49\PDMSetup.exe
+ 2010-09-10 17:09 . 2009-01-08 01:20 355832 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_8.0.6001.18702_none_d0610d06fe575a49\pdm.dll
+ 2010-09-10 17:09 . 2009-01-08 01:20 265720 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_8.0.6001.18702_none_d0610d06fe575a49\msdbg2.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 236544 c:\windows\winsxs\x86_microsoft-windows-ie-offlinefavorites_31bf3856ad364e35_8.0.6001.18702_none_44170552678500f2\webcheck.dll
+ 2010-09-10 17:10 . 2010-06-26 06:50 206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.23040_none_1a6dc115432e9357\occache.dll
+ 2010-09-10 17:10 . 2010-06-26 06:04 206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.18943_none_19e74eec2a0e0977\occache.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 109568 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.18702_none_1a118a8629ee860e\occache.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 233984 c:\windows\winsxs\x86_microsoft-windows-ie-jsprofilerui_31bf3856ad364e35_8.0.6001.18702_none_d5ea1c01e3fe67ea\jsprofilerui.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 118272 c:\windows\winsxs\x86_microsoft-windows-ie-jsprofilercore_31bf3856ad364e35_8.0.6001.18702_none_ed92bec9472aab53\JSProfilerCore.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 521216 c:\windows\winsxs\x86_microsoft-windows-ie-jscriptdebugui_31bf3856ad364e35_8.0.6001.18702_none_9d577137e370ad2c\jsdbgui.dll
+ 2010-09-10 17:10 . 2010-06-26 06:52 638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
+ 2010-09-10 17:10 . 2010-06-26 05:13 133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\ieUnatt.exe
+ 2010-09-10 17:10 . 2010-06-26 06:06 638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
+ 2010-09-10 17:10 . 2010-06-26 04:25 133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\ieUnatt.exe
+ 2010-09-10 17:09 . 2009-03-08 21:09 638816 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 132608 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\ieUnatt.exe
+ 2010-09-10 17:09 . 2009-03-08 11:35 144384 c:\windows\winsxs\x86_microsoft-windows-ie-impexp-extexport_31bf3856ad364e35_8.0.6001.18702_none_10e8e2fad95106ab\ExtExport.exe
+ 2010-09-10 17:09 . 2009-03-08 11:32 169472 c:\windows\winsxs\x86_microsoft-windows-ie-iexpress_31bf3856ad364e35_8.0.6001.18702_none_4766ff3b547d623d\iexpress.exe
+ 2010-09-10 17:10 . 2010-06-26 06:48 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.23040_none_2ad488dec9448079\IEShims.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18943_none_2a4e16b5b023f699\IEShims.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 196096 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18702_none_2a78524fb0047330\IEShims.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.23040_none_73763d48799c1a0b\ieproxy.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 247808 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18943_none_72efcb1f607b902b\ieproxy.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 246784 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18702_none_731a06b9605c0cc2\ieproxy.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 115712 c:\windows\winsxs\x86_microsoft-windows-ie-ielowutil_31bf3856ad364e35_8.0.6001.18702_none_e9612e8087062a88\ielowutil.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 125952 c:\windows\winsxs\x86_microsoft-windows-ie-iecleanup_31bf3856ad364e35_8.0.6001.18702_none_a0d17792aa595b3e\iecleanup.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 103936 c:\windows\winsxs\x86_microsoft-windows-ie-gc-setdepnx_31bf3856ad364e35_8.0.6001.18702_none_9396116207a33bbc\SetDepNx.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 107520 c:\windows\winsxs\x86_microsoft-windows-ie-gc-registeriepkeys_31bf3856ad364e35_8.0.6001.18702_none_0ad3f877399acafc\RegisterIEPKEYs.exe
+ 2010-09-10 17:10 . 2010-06-26 06:49 599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.23040_none_432de3356981e244\msfeeds.dll
+ 2010-09-10 17:10 . 2010-06-26 06:03 599040 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.18943_none_42a7710c50615864\msfeeds.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 594432 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.18702_none_42d1aca65041d4fb\msfeeds.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 216064 c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_8.0.6001.18702_none_7ab17169976f82c4\dxtrans.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 348160 c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_8.0.6001.18702_none_7ab17169976f82c4\dxtmsft.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.23040_none_1eec65b96ee1dbcd\iedvtool.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 743424 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.18943_none_1e65f39055c151ed\iedvtool.dll
+ 2010-09-10 17:09 . 2009-03-08 11:35 742912 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_8.0.6001.18702_none_1e902f2a55a1ce84\iedvtool.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.23040_none_200add98211957ee\iepeers.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.18943_none_1f846b6f07f8ce0e\iepeers.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 183808 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.18702_none_1faea70907d94aa5\iepeers.dll
+ 2010-09-10 17:09 . 2009-03-08 11:11 445952 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_8.0.6001.18702_none_de7d38b18189fc96\ieapfltr.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 163840 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_8.0.6001.18702_none_911d44271c9159e9\ieakui.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 229376 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_8.0.6001.18702_none_911d44271c9159e9\ieaksie.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 125952 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitengine_31bf3856ad364e35_8.0.6001.18702_none_87015889ddff063f\ieakeng.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.23040_none_5797c5628688b053\iedkcs32.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18943_none_571153396d682673\iedkcs32.dll
+ 2010-09-10 17:09 . 2009-03-08 21:09 391536 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18702_none_573b8ed36d48a30a\iedkcs32.dll
+ 2010-09-10 17:10 . 2010-06-26 06:51 919040 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.23040_none_e5304c66d0de8f8c\wininet.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 916480 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18943_none_e4a9da3db7be05ac\wininet.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 914944 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18702_none_e4d415d7b79e8243\wininet.dll
+ 2010-09-10 17:10 . 2010-06-26 06:49 611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.23040_none_c40cff8dab7e2868\mstime.dll
+ 2010-09-10 17:10 . 2010-06-26 06:03 611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.18943_none_c3868d64925d9e88\mstime.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 611840 c:\windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_8.0.6001.18702_none_c3b0c8fe923e1b1f\mstime.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 107008 c:\windows\winsxs\x86_microsoft-windows-i..-setieinstalleddate_31bf3856ad364e35_8.0.6001.18702_none_eb622404d6d4cb81\SetIEInstalledDate.exe
+ 2010-09-10 17:09 . 2009-03-08 11:32 128512 c:\windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_8.0.6001.18702_none_8eb687d4089bfe4d\advpack.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 208384 c:\windows\System32\WinFXDocObj.exe
- 2008-09-21 17:13 . 2008-01-19 07:33 208384 c:\windows\System32\WinFXDocObj.exe
+ 2010-09-10 17:09 . 2009-03-08 11:34 236544 c:\windows\System32\webcheck.dll
+ 2008-11-06 10:37 . 2010-09-10 17:13 291170 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2008-10-27 03:00 . 2010-09-10 12:54 409100 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2008-09-21 17:12 . 2008-01-19 07:36 105984 c:\windows\System32\url.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 105984 c:\windows\System32\url.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 107008 c:\windows\System32\SetIEInstalledDate.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 103936 c:\windows\System32\SetDepNx.exe
+ 2010-09-10 17:09 . 2009-03-08 11:33 107520 c:\windows\System32\RegisterIEPKEYs.exe
+ 2006-11-02 10:33 . 2010-09-11 08:15 656378 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-09-09 22:31 656378 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2010-09-11 08:15 126668 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2010-09-09 22:31 126668 c:\windows\System32\perfc009.dat
+ 2010-09-10 17:09 . 2009-03-08 11:33 109568 c:\windows\System32\PDMSetup.exe
+ 2010-09-10 17:10 . 2010-06-26 06:04 206848 c:\windows\System32\occache.dll
+ 2010-09-10 17:10 . 2010-06-26 06:03 611840 c:\windows\System32\mstime.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 193536 c:\windows\System32\msrating.dll
- 2008-09-21 17:13 . 2008-01-19 07:35 156160 c:\windows\System32\msls31.dll
+ 2010-09-10 17:09 . 2009-03-08 11:22 156160 c:\windows\System32\msls31.dll
+ 2010-09-10 17:10 . 2010-06-26 06:03 599040 c:\windows\System32\msfeeds.dll
+ 2010-09-10 18:00 . 2009-12-04 07:19 726528 c:\windows\System32\jscript.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 169472 c:\windows\System32\iexpress.exe
+ 2010-09-10 17:10 . 2010-06-26 06:02 164352 c:\windows\System32\ieui.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 184320 c:\windows\System32\iepeers.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 387584 c:\windows\System32\iedkcs32.dll
+ 2010-09-10 17:09 . 2009-03-08 11:11 445952 c:\windows\System32\ieapfltr.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 163840 c:\windows\System32\ieakui.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 229376 c:\windows\System32\ieaksie.dll
+ 2010-09-10 17:09 . 2009-03-08 11:33 125952 c:\windows\System32\ieakeng.dll
+ 2010-09-10 17:10 . 2010-06-26 04:24 173056 c:\windows\System32\ie4uinit.exe
+ 2006-11-02 12:47 . 2010-09-10 12:15 373808 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2010-08-12 14:33 373808 c:\windows\System32\FNTCACHE.DAT
+ 2010-09-10 17:09 . 2009-03-08 11:31 216064 c:\windows\System32\dxtrans.dll
+ 2010-09-10 17:09 . 2009-03-08 11:31 348160 c:\windows\System32\dxtmsft.dll
+ 2010-09-10 17:20 . 2010-09-10 17:20 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2007-12-08 09:36 . 2010-09-11 08:14 360448 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-08 09:36 . 2010-09-09 22:34 360448 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-09-10 17:09 . 2009-03-08 11:32 128512 c:\windows\System32\advpack.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 424448 c:\windows\Installer\4e9661.msi
+ 2010-09-10 17:08 . 2010-09-10 17:08 552448 c:\windows\Installer\4c995.msi
+ 2010-09-10 13:41 . 2010-09-10 13:41 1093120 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80u.dll
+ 2010-09-10 13:41 . 2010-09-10 13:41 1105920 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80.dll
+ 2010-09-10 17:10 . 2010-06-26 06:48 1987072 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.23040_none_2aeb0342bb8fade9\iertutil.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 1986560 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18943_none_2a649119a26f2409\iertutil.dll
+ 2010-09-10 17:09 . 2009-03-08 11:32 1985024 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18702_none_2a8eccb3a24fa0a0\iertutil.dll
+ 2010-09-10 17:10 . 2010-06-26 06:49 5954560 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.23040_none_f68a6b855134f8c2\mshtml.dll
+ 2010-09-10 17:10 . 2010-06-26 06:03 5951488 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18943_none_f603f95c38146ee2\mshtml.dll
+ 2010-09-10 17:09 . 2009-03-08 11:41 5937152 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18702_none_f62e34f637f4eb79\mshtml.dll
+ 2010-09-10 17:09 . 2009-02-07 04:07 3698584 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_8.0.6001.18702_none_de7d38b18189fc96\ieapfltr.dat
+ 2010-09-10 17:10 . 2010-06-26 06:51 1211904 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.23040_none_982a70c505d568f9\urlmon.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 1210368 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18943_none_97a3fe9becb4df19\urlmon.dll
+ 2010-09-10 17:09 . 2009-03-08 11:34 1206784 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18702_none_97ce3a35ec955bb0\urlmon.dll
+ 2010-09-10 17:10 . 2010-06-26 06:05 1210368 c:\windows\System32\urlmon.dll
- 2006-11-02 10:22 . 2010-08-23 22:09 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2010-09-10 20:29 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-09-10 17:10 . 2010-06-26 06:03 5951488 c:\windows\System32\mshtml.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 1986560 c:\windows\System32\iertutil.dll
+ 2010-09-10 17:09 . 2009-02-07 04:07 3698584 c:\windows\System32\ieapfltr.dat
+ 2010-09-10 17:09 . 2010-09-10 17:09 2317312 c:\windows\Installer\4c9a5.msi
+ 2010-09-10 17:10 . 2010-06-26 06:48 11078656 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.23040_none_47e9c588dd2a86ef\ieframe.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 11077120 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18943_none_4763535fc409fd0f\ieframe.dll
+ 2010-09-10 17:09 . 2009-03-08 11:39 11063808 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18702_none_478d8ef9c3ea79a6\ieframe.dll
+ 2010-09-10 17:10 . 2010-06-26 06:02 11077120 c:\windows\System32\ieframe.dll
+ 2010-09-10 15:53 . 2010-09-10 15:53 20303872 c:\windows\Installer\c8887e.msp
+ 2009-05-01 23:16 . 2010-09-10 18:00 299573751 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Google Update"="c:\users\Ailsa\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-06-14 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-29 4472832]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-24 45056]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-13 178712]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-08 54832]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-26 457216]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-10-17 858632]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Skytel"="Skytel.exe" [2007-05-29 1826816]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-23 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-09-10 2065760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-02-08 179712]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-07-28 721904]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-09-10 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-09-10 243024]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-09-10 308136]
.
Contents of the 'Scheduled Tasks' folder
2010-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1851843919-258154983-2237051013-1003Core.job
- c:\users\Ailsa\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-14 19:18]
2010-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1851843919-258154983-2237051013-1003UA.job
- c:\users\Ailsa\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-14 19:18]
2010-09-10 c:\windows\Tasks\Norton Security Scan for Ailsa.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-25 00:27]
2010-09-11 c:\windows\Tasks\User_Feed_Synchronization-{24B22FC6-9FD4-4B9E-AD2D-A56153674704}.job
- c:\windows\system32\msfeedssync.exe [2010-09-10 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.uk.acer.yahoo.com
uInternet Settings,ProxyOverride = <local>
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ailsa\AppData\Roaming\Mozilla\Firefox\Profiles\in1soth6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32asw.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Ailsa\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2736)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Completion time: 2010-09-11 09:54:59
ComboFix-quarantined-files.txt 2010-09-11 08:54
ComboFix2.txt 2010-09-09 22:39
Pre-Run: 12,871,581,696 bytes free
Post-Run: 14,034,448,384 bytes free
- - End Of File - - 6B9260D670BB72F1618384C828D2C9CD