Hi again.
Ive done what you asked and run the scanes as well. Kaspersky said I ahd no infections and the scan log was empty and not able to be saved. Ive had to split the post as the text of the scans exceeds the post character limit.
Here is the Combo fix scan
ComboFix 09-01-01.02 - Andrew 2009-01-03 21:09:10.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1554 [GMT 11:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: ActiveArmor Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Andrew\Application Data\FrostWire
c:\documents and settings\Andrew\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\documents and settings\Andrew\Application Data\FrostWire\checkandupdate.txt
c:\documents and settings\Andrew\Application Data\FrostWire\createtimes.cache
c:\documents and settings\Andrew\Application Data\FrostWire\downloads.dat
c:\documents and settings\Andrew\Application Data\FrostWire\fileurns.bak
c:\documents and settings\Andrew\Application Data\FrostWire\fileurns.cache
c:\documents and settings\Andrew\Application Data\FrostWire\filters.props
c:\documents and settings\Andrew\Application Data\FrostWire\frostwire.props
c:\documents and settings\Andrew\Application Data\FrostWire\gnutella.net
c:\documents and settings\Andrew\Application Data\FrostWire\installation.props
c:\documents and settings\Andrew\Application Data\FrostWire\intent.props
c:\documents and settings\Andrew\Application Data\FrostWire\library.dat
c:\documents and settings\Andrew\Application Data\FrostWire\mojito.props
c:\documents and settings\Andrew\Application Data\FrostWire\questions.props
c:\documents and settings\Andrew\Application Data\FrostWire\responses.cache
c:\documents and settings\Andrew\Application Data\FrostWire\simpp.xml
c:\documents and settings\Andrew\Application Data\FrostWire\spam.dat
c:\documents and settings\Andrew\Application Data\FrostWire\tables.props
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme.fwtp
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme\theme.txt
c:\documents and settings\Andrew\Application Data\FrostWire\themes\frostwirePro_theme\version.txt
c:\documents and settings\Andrew\Application Data\FrostWire\ttrees.cache
c:\documents and settings\Andrew\Application Data\FrostWire\ttroot.cache
c:\documents and settings\Andrew\Application Data\FrostWire\version.xml
c:\documents and settings\Andrew\Application Data\FrostWire\xml\data\audio.sxml2
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2009-01-03 21:07 . 2009-01-03 09:10 2,888,937 -ra------ C:\ComboFix.exe
2009-01-03 21:05 . 2009-01-03 21:05 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-03 21:04 . 2009-01-03 21:04 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-03 19:43 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-01-03 19:43 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-01-03 19:43 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\program files\Windows Desktop Search
2009-01-03 15:33 . 2009-01-03 15:33 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Windows Desktop Search
2009-01-03 14:13 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-01-03 14:12 . 2009-01-03 14:12 <DIR> d-------- c:\program files\MSBuild
2009-01-03 14:12 . 2009-01-03 14:12 <DIR> d-------- c:\program files\Microsoft Works
2009-01-03 14:11 . 2009-01-03 14:11 <DIR> d-------- c:\program files\Microsoft.NET
2009-01-03 14:10 . 2009-01-03 14:10 <DIR> d-------- c:\program files\Microsoft Visual Studio 8
2009-01-03 14:09 . 2009-01-03 14:12 <DIR> d-------- c:\windows\SHELLNEW
2009-01-03 14:09 . 2009-01-03 14:09 <DIR> dr-h----- C:\MSOCache
2009-01-03 14:09 . 2009-01-03 14:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-03 13:25 . 2009-01-03 13:25 <DIR> d-------- c:\windows\Logs
2009-01-03 13:25 . 2009-01-03 13:25 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Turbine
2009-01-03 13:25 . 2007-03-12 16:42 3,495,784 --a------ c:\windows\system32\d3dx9_33.dll
2009-01-03 10:10 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-01-03 10:09 . 2009-01-03 10:09 <DIR> d-------- c:\windows\system32\URTTEMP
2009-01-01 17:54 . 2009-01-01 17:59 <DIR> d-------- c:\documents and settings\Kate\Application Data\Smilebox
2009-01-01 13:45 . 2009-01-03 19:14 49 --a------ c:\windows\NeroDigital.ini
2008-12-31 16:03 . 2008-12-31 16:08 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Image Zone Express
2008-12-31 07:51 . 2008-12-31 08:06 <DIR> d-------- c:\documents and settings\Kate\Application Data\Image Zone Express
2008-12-28 17:15 . 2008-12-28 17:15 <DIR> d-------- C:\VundoFix Backups
2008-12-28 17:15 . 2008-12-28 20:46 269 --a------ c:\windows\wininit.ini
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-28 16:19 . 2008-12-28 16:19 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-28 16:10 . 2008-12-28 16:44 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-28 16:10 . 2008-12-28 17:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-28 09:07 . 2008-12-28 09:26 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Ventrilo
2008-12-28 09:06 . 2008-12-28 09:06 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-28 09:06 . 2008-12-28 09:06 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-12-28 09:00 . 2008-12-28 09:00 <DIR> d-------- c:\windows\system32\Lang
2008-12-28 09:00 . 2008-12-28 09:00 940,794 --a------ c:\windows\system32\LoopyMusic.wav
2008-12-28 09:00 . 2008-12-28 09:00 146,650 --a------ c:\windows\system32\BuzzingBee.wav
2008-12-28 08:13 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2008-12-26 22:23 . 2008-12-26 22:23 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\Kate\Application Data\muvee Technologies
2008-12-25 22:14 . 2008-12-25 22:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\muvee Technologies
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ultima_T15
2008-12-25 22:09 . 2008-12-25 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\EnterNHelp
2008-12-25 22:09 . 2008-12-25 22:14 20 ---h----- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2008-12-25 22:07 . 2008-12-25 22:07 <DIR> d-------- c:\documents and settings\Kate\Application Data\Nikon
2008-12-25 22:07 . 2006-05-26 12:03 4,644,864 -ra------ c:\windows\system32\NkNEFPlugin.dll
2008-12-25 22:07 . 2003-03-19 13:28 2,179,072 --a------ c:\windows\system32\mfc71d.dll
2008-12-25 22:07 . 2002-01-06 06:48 974,848 --a------ c:\windows\system32\mfc70.dll
2008-12-25 22:07 . 2003-03-19 12:04 765,952 --a------ c:\windows\system32\msvcp71d.dll
2008-12-25 22:07 . 2003-03-19 12:03 544,768 --a------ c:\windows\system32\msvcr71d.dll
2008-12-25 22:07 . 2002-01-05 20:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2008-12-25 22:07 . 2002-01-06 05:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Nikon
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\program files\Common Files\muvee Technologies
2008-12-25 22:06 . 2008-12-25 22:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nikon
2008-12-25 22:06 . 2006-04-28 14:39 495,616 -ra------ c:\windows\system32\DRAGNKL1.dll
2008-12-25 22:06 . 2006-04-28 15:05 180,224 -ra------ c:\windows\system32\Strato4.dll
2008-12-25 22:06 . 2006-04-28 15:04 180,224 -ra------ c:\windows\system32\picn1120.dll
2008-12-25 22:06 . 2006-04-28 15:04 155,648 -ra------ c:\windows\system32\picn1020.dll
2008-12-25 22:06 . 2006-04-28 15:08 110,592 -ra------ c:\windows\system32\RCSigProc.dll
2008-12-25 22:06 . 2006-04-28 15:08 76,800 -ra------ c:\windows\system32\RedEye.dll
2008-12-25 22:05 . 2008-12-25 22:05 <DIR> d-------- c:\program files\ArcSoft
2008-12-25 22:05 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-12-25 22:04 . 2008-12-25 22:07 <DIR> d-------- c:\program files\Common Files\Nikon
2008-12-20 14:35 . 2005-02-28 20:10 205,824 --a------ c:\windows\pw32a.dll
2008-12-20 08:34 . 2008-12-20 08:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-17 21:16 . 2008-12-17 21:16 <DIR> d-------- c:\documents and settings\Kate\Application Data\Apple Computer
2008-12-16 12:59 . 2008-12-20 12:55 <DIR> d-------- c:\documents and settings\Jacob\Application Data\AVGTOOLBAR
2008-12-15 21:32 . 2008-12-15 21:32 <DIR> d-------- c:\documents and settings\Jacob\Application Data\HP
2008-12-15 21:31 . 2008-12-15 21:31 <DIR> d-------- c:\documents and settings\Jacob
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\HP
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam\Application Data\AVGTOOLBAR
2008-12-15 21:30 . 2008-12-15 21:30 <DIR> d-------- c:\documents and settings\Liam
2008-12-15 21:30 . 2008-04-14 23:00 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-15 18:51 . 2008-12-15 18:51 <DIR> d-------- c:\documents and settings\Andrew\Application Data\CyberLink
2008-12-15 18:40 . 2008-12-15 18:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Cyberlink
2008-12-15 18:40 . 2006-06-04 15:48 198,144 --------- c:\windows\system32\_psisdecd.dll
2008-12-15 18:39 . 2008-12-15 18:39 <DIR> d-------- c:\program files\CyberLink
2008-12-15 18:39 . 2006-06-04 15:48 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-14 16:20 . 2008-12-14 16:20 <DIR> d-------- c:\program files\Bagpipe Player
2008-12-14 16:20 . 1998-12-23 20:23 6,112 --a------ c:\windows\system32\drivers\genport2.sys
2008-12-14 16:20 . 1998-12-23 19:20 6,112 --a------ c:\windows\system32\drivers\genport.sys
2008-12-14 16:20 . 2008-12-14 16:20 0 --a------ c:\windows\PROTOCOL.INI
2008-12-14 16:19 . 2008-12-14 16:19 <DIR> d-------- c:\documents and settings\Andrew\WINDOWS
2008-12-14 16:19 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe
2008-12-14 16:12 . 2008-12-14 16:12 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-14 15:55 . 2008-12-14 15:55 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-12-14 09:26 . 2008-12-14 09:26 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-14 09:26 . 2008-12-14 09:26 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-14 09:20 . 2008-12-14 09:20 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Leadertech
2008-12-14 09:13 . 2008-12-22 08:14 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Pro
2008-12-14 09:13 . 2008-12-14 09:13 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools
2008-12-14 09:12 . 2008-12-23 19:42 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-12-14 09:12 . 2008-12-14 09:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-14 09:11 . 2008-12-14 09:12 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:15 <DIR> d-------- c:\documents and settings\Andrew\Application Data\DAEMON Tools Lite
2008-12-14 09:08 . 2008-12-14 09:08 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-14 09:00 . 2008-12-14 09:26 <DIR> d-------- c:\program files\Java
2008-12-14 09:00 . 2008-12-14 09:00 <DIR> d-------- c:\program files\Common Files\Java
2008-12-14 08:59 . 2008-12-14 08:59 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-13 21:50 . 2008-12-31 07:47 <DIR> d-------- c:\documents and settings\Kate\Application Data\HP
2008-12-13 21:50 . 2008-12-26 16:51 <DIR> d-------- c:\documents and settings\Kate\Application Data\AVGTOOLBAR
2008-12-13 21:40 . 2008-12-13 21:45 <DIR> d-------- c:\documents and settings\Andrew\Application Data\HP
2008-12-13 18:10 . 2008-12-13 18:10 <DIR> d--hs---- c:\documents and settings\Andrew\UserData
2008-12-13 15:28 . 2008-12-16 20:10 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Apple Computer
2008-12-13 14:52 . 2008-12-13 22:30 <DIR> d-------- c:\documents and settings\Andrew\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 22:12 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-29 06:07 --------- d-----w c:\program files\Ahead
2008-12-29 06:05 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-25 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-15 07:39 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-13 10:46 --------- d-----w c:\program files\Fellowes
2008-12-13 10:46 --------- d-----w c:\documents and settings\All Users\Application Data\Fellowes
2008-12-13 10:39 --------- d-----w c:\program files\HP
2008-12-13 10:39 --------- d-----w c:\program files\Common Files\HP
2008-12-13 10:39 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-12-13 10:38 --------- d-----w c:\program files\Hewlett-Packard
2008-12-13 10:37 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-12-13 07:45 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-13 04:37 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-12-13 04:36 --------- d-----w c:\program files\Essentials Codec Pack
2008-12-13 04:32 --------- d-----w c:\program files\Common Files\Ahead
2008-12-13 04:28 --------- d-----w c:\program files\QuickTime
2008-12-13 04:28 --------- d-----w c:\program files\iTunes
2008-12-13 04:28 --------- d-----w c:\program files\iPod
2008-12-13 04:28 --------- d-----w c:\program files\Bonjour
2008-12-13 04:28 --------- d-----w c:\program files\Apple Software Update
2008-12-13 04:28 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-13 04:27 --------- d-----w c:\program files\Common Files\Apple
2008-12-13 04:27 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-12-13 04:10 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-13 03:52 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-12-13 03:52 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-12-13 03:52 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-13 03:52 --------- d-----w c:\program files\AVG
2008-12-13 03:47 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-13 03:47 --------- d-----w c:\program files\AvRack
2008-12-13 03:46 --------- d-----w c:\program files\Realtek AC97
2008-12-13 03:46 --------- d-----w c:\program files\NVIDIA Corporation
2008-12-13 02:53 --------- d-----w c:\program files\microsoft frontpage
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 03:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 03:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 03:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 03:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 03:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 03:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 03:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 03:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-03_ 9.23.10.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-02 23:09:22 7,680 ----a-w c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-01-03 03:12:40 110,592 ----a-w c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-01-02 23:09:20 12,288 ----a-w c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-01-02 23:09:23 33,792 ----a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-01-03 03:12:40 65,536 ----a-w c:\windows\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL
+ 2009-01-03 03:12:41 4,608 ----a-w c:\windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll
+ 2009-01-03 03:12:39 1,215,328 ----a-w c:\windows\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll
+ 2009-01-03 03:12:39 82,784 ----a-w c:\windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
+ 2009-01-02 23:10:30 8,192 ----a-w c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-01-02 23:10:31 32,768 ----a-w c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-01-02 23:09:24 4,608 ----a-w c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-01-03 03:12:37 31,560 ----a-w c:\windows\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL
+ 2009-01-02 23:09:24 26,112 ----a-w c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-01-02 23:10:51 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-01-02 23:10:51 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-01-02 23:10:52 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-01-02 23:10:48 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:49 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:50 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:51 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:52 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-01-02 23:10:52 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-01-02 23:10:52 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-01-02 23:10:52 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-01-02 23:10:52 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-01-02 23:10:51 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-01-02 23:10:34 720,896 ----a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-01-03 03:12:40 8,007,680 ----a-w c:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
+ 2009-01-03 03:12:37 16,712 ----a-w c:\windows\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll
+ 2009-01-03 03:11:56 80,696 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
+ 2009-01-03 03:12:19 1,612,592 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll
+ 2009-01-03 03:12:19 1,276,720 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-01-03 03:12:19 150,320 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-01-03 03:12:37 404,296 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll
+ 2009-01-03 03:12:20 88,896 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-01-03 03:12:20 146,232 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
+ 2009-01-03 03:12:32 17,208 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll
+ 2009-01-03 03:12:20 920,376 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2009-01-03 03:12:20 35,648 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-01-03 03:12:20 248,632 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-01-03 03:12:20 232,248 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll
+ 2009-01-03 03:12:19 20,280 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-01-03 03:12:20 781,104 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-01-03 03:12:40 13,312 ----a-w c:\windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll
+ 2009-01-03 03:12:19 371,496 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2009-01-03 03:12:20 64,288 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-01-02 23:09:20 28,672 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-01-02 23:10:31 299,008 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-01-02 23:09:20 6,144 ----a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2009-01-02 23:09:20 11,264 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-01-02 23:09:20 32,768 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-01-02 23:09:20 6,656 ----a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-01-03 03:12:40 229,376 ----a-w c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2009-01-02 23:09:24 1,564,672 ----a-w c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2009-01-03 03:12:40 4,096 ----a-w c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-01-03 03:12:19 416,544 ----a-w c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-01-03 03:11:55 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll
+ 2009-01-03 03:11:56 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-01-03 03:12:24 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-01-03 03:12:37 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-01-03 03:12:37 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll
+ 2009-01-03 03:12:33 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
+ 2009-01-03 03:12:32 12,632 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2009-01-03 03:12:33 12,112 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-01-03 03:12:35 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll
+ 2009-01-03 03:12:29 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-01-03 03:12:36 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-01-03 03:12:29 12,080 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-01-03 03:12:29 11,544 ----a-w c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-01-02 23:10:33 32,768 ----a-w c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2009-01-03 03:12:40 16,384 ----a-w c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2009-01-02 23:09:25 77,824 ----a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-01-02 23:10:32 303,104 ----a-w c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-01-02 23:10:33 1,294,336 ----a-w c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2009-01-02 23:10:30 1,703,936 ----a-w c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-01-02 23:10:34 90,112 ----a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-01-02 23:09:25 65,536 ----a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-01-02 23:10:32 466,944 ----a-w c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-01-02 23:10:31 241,664 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-01-02 23:10:31 66,560 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2009-01-02 23:10:33 372,736 ----a-w c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-01-02 23:10:34 241,664 ----a-w c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-01-02 23:10:32 323,584 ----a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-01-02 23:10:31 131,072 ----a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-01-02 23:10:32 77,824 ----a-w c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-01-02 23:10:33 126,976 ----a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-01-02 23:10:30 819,200 ----a-w c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-01-02 23:10:31 57,344 ----a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-01-02 23:10:31 573,440 ----a-w c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-01-02 23:10:34 1,257,472 ----a-w c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-01-02 23:10:31 2,052,096 ----a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-01-02 23:10:33 1,339,392 ----a-w c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML.dll
+ 2009-01-02 23:10:35 1,224,704 ----a-w c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-01-03 03:12:37 118,112 ----a-w c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-01-03 03:12:43 367,400 ----a-w c:\windows\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll
+ 2009-01-03 03:12:37 609,104 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-01-03 03:12:37 43,840 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll
+ 2009-01-03 03:12:37 39,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll
+ 2009-01-03 03:12:37 60,200 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll
+ 2009-01-03 03:12:39 211,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll
+ 2009-01-03 03:12:39 105,248 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll
+ 2009-01-03 03:12:39 330,520 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll
+ 2009-01-03 03:12:39 39,712 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll
+ 2009-01-03 03:12:39 39,704 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll
+ 2009-01-03 03:12:39 72,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll
+ 2009-01-03 03:12:39 47,832 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
+ 2009-01-03 03:12:39 39,624 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll
+ 2009-01-02 23:10:44 61,440 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_f8d253ab\CustomMarshalers.dll
+ 2009-01-02 23:11:02 3,379,200 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_596e4449\mscorlib.dll
+ 2009-01-02 23:10:58 1,466,368 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_4503235e\System.Design.dll
+ 2009-01-02 23:10:46 90,112 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_3dbb04d0\System.Drawing.Design.dll
+ 2009-01-02 23:10:59 835,584 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_783b79a7\System.Drawing.dll
+ 2009-01-02 23:10:53 3,014,656 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_9404abe4\System.Windows.Forms.dll
+ 2009-01-02 23:10:56 2,088,960 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_6cfe2999\System.Xml.dll
+ 2009-01-02 23:10:43 1,953,792 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_7a56fb16\System.dll
+ 2009-01-03 03:09:38 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-03 03:13:50 1,165,584 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-01-03 03:13:50 20,240 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-03 03:13:50 159,504 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-01-03 03:13:50 184,080 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-01-03 03:13:50 217,864 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-01-03 03:13:50 18,704 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-01-03 03:13:50 35,088 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-03 03:13:50 845,584 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-01-03 03:13:50 922,384 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-03 03:13:50 272,648 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-01-03 03:13:50 888,080 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-03 03:13:50 1,172,240 ----a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2007-12-12 04:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
+ 2005-03-18 05:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 05:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 05:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 01:38:58 2,676,224 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 05:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 05:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 05:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 05:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 05:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 04:53:06 2,846,720 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 08:32:54 563,712 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 06:23:14 567,296 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 04:15:56 576,000 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 06:21:34 577,024 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 03:11:52 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 06:20:50 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2003-02-20 15:59:44 16,896 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2003-02-20 16:55:06 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-20 16:02:16 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2003-02-20 18:04:20 155,648 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-20 20:24:08 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2003-02-20 18:00:36 98,304 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-20 08:19:42 24,576 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2004-07-14 14:49:16 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-20 08:19:22 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2004-07-14 14:49:18 20,480 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2004-07-14 14:49:26 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2004-07-14 14:49:22 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2002-07-29 00:11:50 219,136 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-20 20:24:10 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-20 20:24:32 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2004-07-14 13:32:22 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2004-07-15 00:23:28 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2004-07-15 00:23:44 626,688 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2003-02-20 20:24:34 12,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-20 20:24:36 33,792 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-20 17:12:24 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-20 23:21:40 524,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2003-02-20 08:16:32 798,720 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2004-07-14 13:24:30 282,624 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-10-08 03:30:14 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
+ 2003-02-20 20:24:38 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2004-07-15 03:31:00 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2004-07-15 03:31:04 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-20 20:24:40 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2004-07-14 13:35:30 196,608 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-20 20:24:42 15,872 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-20 08:22:24 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-20 20:24:44 26,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 20:24:52 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2004-07-15 03:28:58 720,896 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 03:28:56 299,008 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-20 20:24:54 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-20 20:25:02 6,144 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-20 20:24:58 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-20 20:25:06 11,264 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-20 20:25:02 6,656 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2004-07-15 03:28:50 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2004-07-15 03:28:50 49,152 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-20 20:25:06 1,564,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2004-07-14 13:32:44 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-14 13:32:46 233,472 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2003-02-20 08:09:14 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2004-07-14 13:25:06 315,392 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-14 13:33:04 102,400 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2004-07-15 03:29:02 2,138,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-20 07:43:52 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-20 08:06:34 65,536 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2004-07-14 13:33:22 143,360 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2004-07-14 13:33:24 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 08:09:18 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2004-07-14 13:26:52 2,510,848 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-20 08:09:24 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2004-07-14 13:28:34 2,502,656 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-20 17:42:22 348,160 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-20 08:18:34 20,480 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-20 07:43:36 22,528 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\
0409\mscorsecr.dll
+ 2004-08-10 05:20:00 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-20 08:09:46 73,728 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2004-07-14 13:34:50 94,208 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 20:25:24 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2004-07-15 03:28:48 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-20 20:25:30 12,288 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2003-02-20 08:09:34 253,952 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-20 08:09:34 122,880 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2004-07-14 13:35:04 319,488 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 20:26:38 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2004-07-15 03:32:00 1,294,336 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 03:31:14 303,104 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 03:29:02 1,703,936 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 03:28:54 90,112 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2004-07-15 03:31:16 1,224,704 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-20 20:26:48 65,536 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2004-07-15 03:28:58 466,944 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 03:28:56 241,664 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-14 13:35:12 66,560 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2004-07-15 03:31:58 372,736 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 03:31:12 241,664 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 03:28:58 323,584 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 03:31:54 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 03:28:52 77,824 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-15 03:28:54 126,976 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2004-07-15 03:29:00 1,257,472 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 03:28:58 819,200 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 03:28:52 57,344 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 03:31:16 573,440 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 03:32:02 2,052,096 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 03:29:00 1,339,392 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-06-22 02:51:38 53,248 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2004-07-15 00:23:20 737,280 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2004-07-14 21:15:14 1,032,192 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-14 15:11:56 31,744 ----a-w c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2005-02-05 08:45:26 2,222,800 ----a-w c:\windows\system32\d3dx9_24.dll
+ 2005-03-18 06:19:58 2,337,488 ----a-w c:\windows\system32\d3dx9_25.dll
+ 2005-12-05 07:09:18 2,323,664 ----a-w c:\windows\system32\d3dx9_28.dll
- 2008-04-14 12:00:00 29,696 -c--a-w c:\windows\system32\dllcache\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 -c--a-w c:\windows\system32\dllcache\mimefilt.dll
- 2008-04-14 12:00:00 98,304 -c--a-w c:\windows\system32\dllcache\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 -c--a-w c:\windows\system32\dllcache\nlhtml.dll
- 2008-04-14 12:00:00 192,000 -c--a-w c:\windows\system32\dllcache\offfilt.dll
+ 2008-03-07 17:02:08 192,000 -c--a-w c:\windows\system32\dllcache\offfilt.dll
+ 2006-10-26 03:10:08 1,190,688 ----a-w c:\windows\system32\FM20.DLL
+ 2006-10-26 03:10:06 33,088 ----a-w c:\windows\system32\FM20ENU.DLL
- 2008-12-25 11:08:30 106,216 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-03 09:59:51 278,944 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2006-10-26 02:45:04 207,360 ----a-w c:\windows\system32\INKED.DLL
- 2008-04-14 12:00:00 29,696 ----a-w c:\windows\system32\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 ----a-w c:\windows\system32\mimefilt.dll
+ 2008-05-26 11:17:44 34,816 ------w c:\windows\system32\msscb.dll
+ 2008-05-26 11:17:26 60,416 ------w c:\windows\system32\msscntrs.dll
+ 2008-05-26 11:17:38 11,776 ------w c:\windows\system32\msshooks.dll
+ 2008-05-26 11:18:34 231,936 ------w c:\windows\system32\msshsq.dll
+ 2008-05-26 11:17:26 87,552 ------w c:\windows\system32\mssitlb.dll
+ 2008-05-26 11:18:26 350,208 ------w c:\windows\system32\mssph.dll
+ 2008-05-26 11:18:56 203,776 ------w c:\windows\system32\mssphtb.dll
+ 2008-05-26 11:17:28 32,768 ------w c:\windows\system32\mssprxy.dll
+ 2008-05-26 11:21:26 1,418,240 ------w c:\windows\system32\mssrch.dll
+ 2006-07-23 23:50:38 125,744 ----a-w c:\windows\system32\MSSTDFMT.DLL
+ 2008-05-26 11:18:42 44,032 ------w c:\windows\system32\msstrc.dll
+ 2003-02-20 07:43:36 4,096 ----a-w c:\windows\system32\mui\
0409\mscoreer.dll
- 2008-04-14 12:00:00 98,304 ----a-w c:\windows\system32\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 ----a-w c:\windows\system32\nlhtml.dll
+ 2008-05-26 11:19:36 273,408 ------w c:\windows\system32\oeph.dll
+ 2008-05-26 11:19:16 11,264 ------w c:\windows\system32\oephRes.dll
- 2008-04-14 12:00:00 192,000 ----a-w c:\windows\system32\offfilt.dll
+ 2008-03-07 17:02:08 192,000 ----a-w c:\windows\system32\offfilt.dll
- 2008-12-26 11:22:46 58,596 ----a-w c:\windows\system32\perfc009.dat
+ 2009-01-03 04:33:17 70,184 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-26 11:22:46 392,296 ----a-w c:\windows\system32\perfh009.dat
+ 2009-01-03 04:33:17 424,572 ----a-w c:\windows\system32\perfh009.dat
+ 2008-05-26 11:18:08 71,680 ------w c:\windows\system32\propdefs.dll
+ 2008-05-26 11:17:48 754,176 ------w c:\windows\system32\propsys.dll
+ 2008-05-26 11:18:32 38,400 ------w c:\windows\system32\rtffilt.dll
+ 2006-07-23 23:50:40 39,728 ----a-w c:\windows\system32\SCP32.DLL
+ 2008-05-26 11:17:56 87,552 ------w c:\windows\system32\searchfilterhost.exe
+ 2008-05-26 11:18:44 439,808 ------w c:\windows\system32\searchindexer.exe
+ 2008-05-26 11:18:18 184,832 ------w c:\windows\system32\searchprotocolhost.exe
+ 2006-10-26 08:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 08:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2006-10-26 08:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 08:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2006-10-26 08:56:12 33,104 ----a-w c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
- 2006-09-25 06:58:48 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-09-26 23:46:30 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2008-05-26 11:17:30 301,568 ------w c:\windows\system32\srchadmin.dll
+ 2008-05-26 10:59:40 106,605 ------w c:\windows\system32\structuredqueryschema.bin
+ 2008-05-26 10:59:42 18,904 ------w c:\windows\system32\structuredqueryschematrivial.bin
+ 2008-05-26 11:21:08 1,582,592 ------w c:\windows\system32\tquery.dll
+ 2008-05-26 11:19:20 97,792 ------w c:\windows\system32\UncCplExt.dll
+ 2008-05-26 11:19:22 143,872 ------w c:\windows\system32\UncDMS.dll
+ 2008-05-26 11:19:28 108,032 ------w c:\windows\system32\UncNE.dll
+ 2008-05-26 11:19:28 131,072 ------w c:\windows\system32\UncPH.dll
+ 2008-05-26 11:19:26 2,048 ------w c:\windows\system32\UncRes.dll
+ 2003-02-20 18:16:08 49,152 ----a-w c:\windows\system32\URTTEMP\regtlib.exe
+ 2006-07-23 23:50:40 47,920 ----a-w c:\windows\system32\VBAME.DLL
+ 2006-10-26 02:45:04 293,376 ----a-w c:\windows\system32\WISPTIS.EXE
+ 2005-12-05 07:07:30 61,136 ----a-w c:\windows\system32\xinput9_1_0.dll
+ 2008-05-26 11:18:34 56,320 ------w c:\windows\system32\xmlfilter.dll
+ 2009-01-03 10:00:07 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_744.dat
+ 2005-09-22 12:49:12 95,744 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2005-09-22 14:16:02 1,093,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-22 14:16:06 1,079,808 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-22 14:16:08 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-22 14:16:10 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-22 13:58:06 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2005-09-22 13:58:06 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2005-09-22 13:58:06 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2005-09-22 13:58:06 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2005-09-22 13:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2005-09-22 13:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2005-09-22 13:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2005-09-22 14:35:10 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-09-30 270336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-02-24 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-14 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-09 303104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"MediaFace Integration"="c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe" [2004-07-01 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2008-04-03 151552]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2005-02-24 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Andrew\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-12-25 118784]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Games\\THQ\\Pandemic Studios\\Full Spectrum Warrior\\Launcher.locked"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-13 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-13 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-13 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-13 76040]
R2 GenPort;GenPort;c:\windows\system32\drivers\GenPort.sys [2008-12-14 6112]
R2 GenPort2;GenPort2;c:\windows\system32\drivers\GenPort2.sys [2008-12-14 6112]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{284db057-c917-11dd-b930-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.news.com.au/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-03 21:10:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(804)
c:\windows\system32\nvappfilter.dll
.
Completion time: 2009-01-03 21:11:08
ComboFix-quarantined-files.txt 2009-01-03 10:11:03
ComboFix2.txt 2009-01-02 22:23:55
Pre-Run: 41,593,163,776 bytes free
Post-Run: 42,452,430,848 bytes free
646 --- E O F --- 2008-12-17 23:27:37
The HJT scan is on the next post