Here is my Combofix log:
ComboFix 09-05-03.6 - Carmagnoli 05/04/2009 18:50.4 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1657 [GMT -4:00]
Running from: c:\documents and settings\Carmagnoli\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator.DANTE\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\Carmagnoli\Local Settings\Temporary Internet Files\Cpvff.stt
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-04 to 2009-05-04 )))))))))))))))))))))))))))))))
.
2009-05-04 02:36 . 2009-05-04 02:36 -------- d-----w c:\program files\Windows Defender
2009-04-30 13:36 . 2009-04-30 13:36 -------- d-----w c:\documents and settings\Carmagnoli\Local Settings\Application Data\ApplicationHistory
2009-04-30 13:31 . 2009-04-30 13:31 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-04-30 13:30 . 2006-11-30 12:50 64360 ----a-w c:\windows\system32\drivers\mfeapfk.sys
2009-04-30 13:30 . 2006-11-30 12:50 72264 ----a-w c:\windows\system32\drivers\mfeavfk.sys
2009-04-30 13:30 . 2006-11-30 12:50 34152 ----a-w c:\windows\system32\drivers\mfebopk.sys
2009-04-30 13:30 . 2006-11-30 12:50 168776 ----a-w c:\windows\system32\drivers\mfehidk.sys
2009-04-30 13:30 . 2006-11-30 12:50 52136 ----a-w c:\windows\system32\drivers\mfetdik.sys
2009-04-30 13:30 . 2009-04-30 13:30 -------- d-----w c:\program files\Common Files\McAfee
2009-04-30 13:30 . 2009-04-30 13:31 -------- d-----w c:\program files\McAfee
2009-04-30 04:48 . 2009-04-30 04:48 -------- d-----w c:\windows\ie8updates
2009-04-30 04:42 . 2009-04-30 04:42 -------- d-----w c:\windows\system32\URTTEMP
2009-04-30 04:14 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-29 21:57 . 2009-05-04 22:18 100712 ----a-w c:\documents and settings\Administrator.DANTE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 21:48 . 2009-04-29 21:48 -------- d-----w c:\documents and settings\Administrator.DANTE\Application Data\CiscoCAA
2009-04-29 21:47 . 2009-04-29 21:47 -------- d-----w c:\documents and settings\Administrator.DANTE\Local Settings\Application Data\Mozilla
2009-04-29 04:10 . 2008-01-15 20:39 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-29 03:51 . 2009-04-29 03:51 -------- d-sh--w c:\documents and settings\Carmagnoli\IECompatCache
2009-04-29 03:50 . 2009-04-29 03:50 -------- d-sh--w c:\documents and settings\Carmagnoli\PrivacIE
2009-04-29 03:45 . 2009-04-29 03:45 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-04-29 03:45 . 2009-04-29 03:45 -------- d-sh--w c:\documents and settings\Carmagnoli\IETldCache
2009-04-29 03:27 . 2009-04-29 03:28 -------- dc-h--w c:\windows\ie8
2009-04-29 03:18 . 2009-04-29 22:16 -------- d-----w c:\documents and settings\Carmagnoli\Application Data\Twain
2009-04-29 03:13 . 2009-04-29 03:42 -------- d-----w c:\program files\WWShow
2009-04-29 03:08 . 2009-04-29 03:42 -------- d-----w c:\program files\Jcore
2009-04-29 02:47 . 2009-04-29 02:51 -------- d-----w c:\documents and settings\Carmagnoli\Application Data\HouseCall 6.6
2009-04-29 01:25 . 2009-04-30 03:16 -------- d-----w c:\documents and settings\Carmagnoli\Application Data\pidle
2009-04-15 02:36 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 02:36 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 02:36 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 02:36 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 02:36 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 02:36 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 02:36 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 02:36 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 02:36 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 02:12 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-15 02:12 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-09 19:39 . 2009-04-09 19:39 -------- d-----w c:\documents and settings\NetworkService\Application Data\DivX
2009-04-09 19:39 . 2009-04-09 19:39 -------- d-----w c:\documents and settings\NetworkService\Application Data\ArcSoft
2009-04-06 15:31 . 2009-04-06 15:31 -------- d-----w c:\documents and settings\LocalService\Application Data\Roxio
2009-04-06 15:31 . 2009-04-06 15:31 -------- d-----w c:\documents and settings\Carmagnoli\Application Data\Roxio
2009-04-06 15:30 . 2009-04-10 01:18 256 ----a-w c:\windows\system32\pool.bin
2009-04-06 15:30 . 2009-04-06 15:30 -------- d-----w c:\documents and settings\Carmagnoli\Application Data\Research In Motion
2009-04-06 15:26 . 2009-04-06 15:26 -------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2009-04-06 15:26 . 2009-04-06 15:26 -------- d-----w c:\documents and settings\All Users\Application Data\Sonic
2009-04-06 15:24 . 2009-04-06 15:24 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-04-06 15:24 . 2009-04-06 15:26 -------- d-----w c:\documents and settings\All Users\Application Data\Roxio
2009-04-06 15:24 . 2009-04-06 15:25 -------- d-----w c:\program files\Roxio
2009-04-06 15:24 . 2009-04-06 15:25 -------- d-----w c:\program files\Common Files\Roxio Shared
2009-04-06 15:21 . 2007-01-18 14:24 26496 ----a-r c:\windows\system32\drivers\RimSerial.sys
2009-04-06 15:20 . 2009-04-06 15:21 -------- d-----w c:\program files\Common Files\Research In Motion
2009-04-06 15:20 . 2009-04-06 15:20 -------- d-----w c:\program files\Research In Motion
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-04 22:41 . 2006-01-18 05:45 -------- d-----w c:\program files\Google
2009-05-04 22:26 . 2008-03-23 06:05 -------- d-----w c:\program files\DNA
2009-05-02 05:57 . 2009-04-03 14:13 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-02 05:54 . 2006-01-18 20:07 -------- d-----w c:\program files\Java
2009-04-30 05:36 . 2006-03-05 20:55 100712 ----a-w c:\documents and settings\Carmagnoli\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 03:16 . 2008-01-15 00:50 -------- d-----w c:\program files\Microsoft Works
2009-04-30 03:00 . 2006-01-15 17:00 -------- d-----w c:\program files\Trend Micro
2009-04-29 23:38 . 2007-05-22 23:30 1324 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-29 22:41 . 2006-09-11 02:32 -------- d-----w c:\program files\Common Files\Adobe
2009-04-29 02:31 . 2009-01-08 04:16 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-09 19:40 . 2008-11-29 01:14 -------- d-----w c:\program files\iTunes
2009-04-06 15:24 . 2005-01-10 15:25 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-16 03:46 . 2009-02-20 18:02 -------- d-----w c:\program files\Bethesda Softworks
2009-03-16 03:46 . 2005-01-10 15:26 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-08 08:34 . 2004-08-04 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2004-08-04 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2004-08-04 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2004-08-04 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2004-08-04 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2004-08-04 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2004-08-04 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2004-08-04 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2004-08-04 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2004-08-04 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-20 17:51 . 2008-03-16 01:09 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-04 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-04-22 07:12 . 2009-04-22 07:12 90624 ----a-w c:\program files\mozilla firefox\components\WWShow.dll
2009-01-29 01:30 . 2009-01-29 01:30 2048 --sha-w c:\windows\system32\sobazofe.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-04-30_02.06.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-10-19 02:47 . 2006-10-19 02:47 38400 c:\windows\system32\wpdshextres.dll
+ 2006-10-19 02:47 . 2006-10-19 01:47 38400 c:\windows\system32\wpdshextres.dll
+ 2003-02-21 09:16 . 2003-02-21 09:16 49152 c:\windows\system32\URTTEMP\regtlib.exe
+ 2009-04-30 03:18 . 2008-11-10 15:41 67472 c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2008-01-15 00:53 . 2008-11-10 15:41 67472 c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2009-05-04 02:40 . 2006-09-25 21:58 14640 c:\windows\system32\spmsg.dll
+ 2005-10-29 03:49 . 2005-10-29 03:49 84480 c:\windows\system32\pintool.exe
+ 2004-08-04 12:00 . 2009-04-30 13:35 75692 c:\windows\system32\perfc009.dat
+ 2008-01-15 00:53 . 2008-11-10 15:41 32656 c:\windows\system32\msonpmon.dll
+ 2005-10-29 03:49 . 2005-10-29 03:49 25600 c:\windows\system32\bcsprsrc.dll
+ 2005-10-28 20:40 . 2005-10-28 20:40 96792 c:\windows\system32\basecsp.dll
+ 2004-07-15 06:11 . 2004-07-15 06:11 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2004-06-22 17:51 . 2004-06-22 17:51 53248 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2004-07-15 18:28 . 2004-07-15 18:28 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-15 04:35 . 2004-07-15 04:35 66560 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2003-02-21 11:26 . 2003-02-21 11:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2003-02-21 11:26 . 2003-02-21 11:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2004-07-15 04:34 . 2004-07-15 04:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_PerfCounter.dll
+ 2003-02-20 23:09 . 2003-02-20 23:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_mscorsn.dll
+ 2004-07-15 04:32 . 2004-07-15 04:32 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_CORPerfMonExt.dll
+ 2003-02-21 11:25 . 2003-02-21 11:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2004-07-15 18:28 . 2004-07-15 18:28 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-21 11:25 . 2003-02-21 11:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2004-07-15 04:34 . 2004-07-15 04:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 23:09 . 2003-02-20 23:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2007-01-15 20:11 . 2007-01-15 20:11 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-20 22:43 . 2003-02-20 22:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\
0409\mscorsecr.dll
+ 2003-02-20 23:18 . 2003-02-20 23:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2007-04-14 00:58 . 2007-04-14 00:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2004-07-15 04:33 . 2004-07-15 04:33 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 23:06 . 2003-02-20 23:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2007-04-14 00:57 . 2007-04-14 00:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2004-07-15 04:32 . 2004-07-15 04:32 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2004-07-15 18:28 . 2004-07-15 18:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2003-02-21 11:25 . 2003-02-21 11:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2003-02-21 11:24 . 2003-02-21 11:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 23:22 . 2003-02-20 23:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2004-07-15 18:31 . 2004-07-15 18:31 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-10-08 18:30 . 2003-10-08 18:30 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
+ 2003-02-21 08:12 . 2003-02-21 08:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-21 11:24 . 2003-02-21 11:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2004-07-15 15:23 . 2004-07-15 15:23 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2007-04-14 00:57 . 2007-04-14 00:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2003-02-21 11:24 . 2003-02-21 11:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2007-04-14 01:30 . 2007-04-14 01:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2004-07-15 05:49 . 2004-07-15 05:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2004-07-15 05:49 . 2004-07-15 05:49 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2003-02-20 23:19 . 2003-02-20 23:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2003-02-20 23:19 . 2003-02-20 23:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2003-02-21 09:00 . 2003-02-21 09:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-21 07:55 . 2003-02-21 07:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-21 06:59 . 2003-02-21 06:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
- 2008-01-15 00:53 . 2009-04-29 22:55 35088 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 35088 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 18704 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 18704 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 20240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 20240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\cagicon.exe
+ 1998-12-24 16:23 . 1998-12-24 16:23 40960 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.6425\VBAME.DLL
+ 1998-08-09 18:07 . 1998-08-09 18:07 86016 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.6425\MSADDNDR.DLL
+ 2006-10-27 02:13 . 2006-10-27 02:13 72472 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\XL12CNVP.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 12096 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\WORDPOL.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 12080 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\VBIDEPOL.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 64288 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\VBIDEPIA.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 15672 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\SMARTTAGINSTALL.EXE
+ 2006-10-27 00:49 . 2006-10-27 00:49 34104 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\SETLANG.EXE
+ 2006-10-27 01:55 . 2006-10-27 01:55 55056 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\SCANOST.EXE
+ 2006-10-27 01:55 . 2006-10-27 01:55 76576 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\RM.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 40424 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\REFIEBAR.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 39208 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\RECALL.DLL
+ 2006-10-27 01:09 . 2006-10-27 01:09 48448 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\PUBTRAP.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 12112 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\PPTPOL.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 53048 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OUTLVBA.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 46936 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OSETUPPS.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 18760 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OPHPROXY.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 16728 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OMUOPTINPS.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 23392 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OISCTRL.DLL
+ 2006-10-27 20:11 . 2006-10-27 20:11 54680 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OFFRHD.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 11544 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OFFICEPL.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 12104 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSTAGPOL.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 20280 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSTAGPIA.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 43832 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSSH.DLL
+ 2006-10-27 20:26 . 2006-10-27 20:26 35152 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSOSTYLE.DLL
+ 2006-10-27 00:56 . 2006-10-27 00:56 67408 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSONPUI.DLL
+ 2006-10-27 00:56 . 2006-10-27 00:56 32592 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSONPMON.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 66368 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSOMSE.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 67896 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSOHTMED.EXE
+ 2006-10-27 20:01 . 2006-10-27 20:01 76088 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSOHEV.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 19768 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSMH.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 48424 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSE7.EXE
+ 2006-10-27 01:55 . 2006-10-27 01:55 21312 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MLSHEXT.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 89400 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\METCONV.DLL
+ 2006-10-27 02:41 . 2006-10-27 02:41 66368 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\INLAUNCH.DLL
+ 2008-01-15 00:50 . 2008-01-15 00:50 12096 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\GRAPHPOL.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 12096 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\EXCELPOL.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 35160 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\DUMPSTER.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 53576 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\AUTHZAX.DLL
+ 2006-10-27 02:18 . 2006-10-27 02:18 94016 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\ACCOLK.DLL
+ 2009-04-30 13:37 . 2009-04-30 13:37 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_a1ada9c0\System.Drawing.Design.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_27076bc0\CustomMarshalers.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 57344 c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 77824 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 66560 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 65536 c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 90112 c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 77824 c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 32768 c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 10576 c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 11112 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 11136 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 11152 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 32768 c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 11264 c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 28672 c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 19320 c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 26112 c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 32768 c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 33792 c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 12288 c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2003-02-20 22:43 . 2003-02-20 22:43 4096 c:\windows\system32\mui\
0409\mscoreer.dll
+ 2003-02-20 23:09 . 2003-02-20 23:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2003-02-21 11:25 . 2003-02-21 11:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2003-02-21 11:25 . 2003-02-21 11:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2004-07-15 18:31 . 2004-07-15 18:31 8192 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2003-02-21 11:24 . 2003-02-21 11:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2003-02-21 11:24 . 2003-02-21 11:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2009-04-30 04:48 . 2009-03-08 08:35 2048 c:\windows\ie8updates\KB968220-IE8\iecompat.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 6656 c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 6144 c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 4608 c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 8192 c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 7680 c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2006-04-10 17:00 . 2009-03-11 02:18 934792 c:\windows\system32\WgaTray.exe
+ 2006-04-10 17:00 . 2009-03-11 02:18 239496 c:\windows\system32\WgaLogon.dll
+ 2009-04-30 03:18 . 2008-11-10 15:41 864144 c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2008-01-15 00:53 . 2008-11-10 15:41 864144 c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2004-08-04 12:00 . 2009-04-30 13:35 413216 c:\windows\system32\perfh009.dat
- 2009-04-29 23:22 . 2009-04-29 23:22 148888 c:\windows\system32\javaws.exe
+ 2009-05-02 05:58 . 2009-05-02 05:57 148888 c:\windows\system32\javaws.exe
+ 2009-05-02 05:58 . 2009-05-02 05:57 144792 c:\windows\system32\javaw.exe
- 2009-04-29 23:22 . 2009-04-29 23:22 144792 c:\windows\system32\javaw.exe
+ 2009-05-02 05:58 . 2009-05-02 05:57 144792 c:\windows\system32\java.exe
- 2009-04-29 23:22 . 2009-04-29 23:22 144792 c:\windows\system32\java.exe
+ 2005-10-29 03:49 . 2005-10-29 03:49 151552 c:\windows\system32\ifxcardm.dll
- 2006-01-15 19:51 . 2009-04-06 15:28 351384 c:\windows\system32\FNTCACHE.DAT
+ 2006-01-15 19:51 . 2009-04-30 03:22 351384 c:\windows\system32\FNTCACHE.DAT
+ 2009-03-11 02:18 . 2009-03-11 02:18 934792 c:\windows\system32\dllcache\WgaTray.exe
+ 2009-03-11 02:18 . 2009-03-11 02:18 239496 c:\windows\system32\dllcache\wgaLogon.dll
+ 2005-10-29 03:49 . 2005-10-29 03:49 133120 c:\windows\system32\axaltocm.dll
+ 2004-07-15 15:23 . 2004-07-15 15:23 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2004-07-15 18:31 . 2004-07-15 18:31 573440 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2004-07-15 18:31 . 2004-07-15 18:31 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 18:31 . 2004-07-15 18:31 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 18:31 . 2004-07-15 18:31 372736 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 18:31 . 2004-07-15 18:31 303104 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 04:35 . 2004-07-15 04:35 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 23:09 . 2003-02-20 23:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-20 23:09 . 2003-02-20 23:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-21 08:42 . 2003-02-21 08:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_msvcr71.dll
+ 2004-07-15 04:25 . 2004-07-15 04:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_mscorjit.dll
+ 2004-07-15 04:24 . 2004-07-15 04:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_fusion.dll
+ 2004-07-15 05:49 . 2004-07-15 05:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_aspnet_isapi.dll
+ 2003-02-21 08:42 . 2003-02-21 08:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2004-07-15 04:33 . 2004-07-15 04:33 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-20 22:43 . 2003-02-20 22:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2007-04-14 00:58 . 2007-04-14 00:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 00:56 . 2007-04-14 00:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-15 04:32 . 2004-07-15 04:32 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2004-07-15 18:28 . 2004-07-15 18:28 720896 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 04:35 . 2004-07-15 04:35 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2004-07-15 04:24 . 2004-07-15 04:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-20 23:16 . 2003-02-20 23:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 14:21 . 2003-02-21 14:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2004-07-15 15:23 . 2004-07-15 15:23 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 15:11 . 2002-07-29 15:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2007-04-14 01:30 . 2007-04-14 01:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 09:04 . 2003-02-21 09:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 07:02 . 2003-02-21 07:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
- 2008-01-15 00:53 . 2009-04-29 22:55 888080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 888080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 272648 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pubs.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 272648 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pubs.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 922384 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 922384 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pptico.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 845584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 845584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\outicon.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 217864 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\misc.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 217864 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\misc.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 184080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\joticon.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 184080 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\joticon.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 159504 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 159504 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\inficon.exe
- 2008-04-14 15:19 . 2008-04-14 15:19 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-04-30 04:49 . 2009-04-30 04:49 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2007-06-07 23:51 . 2007-06-07 23:51 125320 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.6425\SSGEN.DLL
+ 2007-06-07 23:51 . 2007-06-07 23:51 465800 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.6425\OUTLFLTR.DLL
+ 2006-10-27 01:49 . 2006-10-27 01:49 509200 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\WRD12CVR.DLL
+ 2006-10-27 20:16 . 2006-10-27 20:16 408880 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\RTFHTML.DLL
+ 2006-10-27 02:07 . 2006-10-27 02:07 368968 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\PPSLAX.DLL
+ 2006-10-27 20:16 . 2006-10-27 20:16 138512 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OUTLCTL.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 254776 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OLKFSTUB.DLL
+ 2006-10-20 13:37 . 2006-10-20 13:37 637744 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OGALEGIT.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 416544 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\OFFICE.DLL
+ 2006-10-27 00:55 . 2006-10-27 00:55 145688 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSTORE.EXE
+ 2006-10-26 19:47 . 2006-10-26 19:47 727840 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSPROOF6.DLL
+ 2006-10-27 00:56 . 2006-10-27 00:56 864080 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSONPDRV.DLL
+ 2006-10-26 18:58 . 2006-10-26 18:58 290576 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MSCDM.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 460616 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\MODHELP.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 178488 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\IETAG.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 150320 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\GRAPHPIA.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 154960 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\ENVELOPE.DLL
+ 2006-10-27 01:55 . 2006-10-27 01:55 116544 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\EMABLT32.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 106824 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\DSSM.EXE
+ 2009-04-30 04:48 . 2007-11-30 12:39 382840 c:\windows\ie8updates\KB968220-IE8\spuninst\updspapi.dll
+ 2009-04-30 04:48 . 2007-11-30 12:39 231288 c:\windows\ie8updates\KB968220-IE8\spuninst\spuninst.exe
+ 2009-04-30 13:37 . 2009-04-30 13:37 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_a314a8d3\System.Drawing.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_67c901b7\System.Drawing.Design.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_fd10d397\CustomMarshalers.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 609160 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 118176 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 573440 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 372736 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 303104 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 423784 c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-04-30 13:35 . 2009-04-30 13:35 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 350064 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-04-30 03:16 . 2009-04-30 03:16 149352 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 720896 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2005-07-12 23:04 . 2009-03-11 02:18 1482112 c:\windows\system32\LegitCheckControl.dll
+ 2008-11-21 03:06 . 2008-11-21 03:06 1194848 c:\windows\system32\FM20.DLL
+ 2004-07-15 12:15 . 2004-07-15 12:15 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-15 18:29 . 2004-07-15 18:29 1339392 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-07-15 18:32 . 2004-07-15 18:32 2052096 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2007-04-14 01:35 . 2007-04-14 01:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-14 01:35 . 2007-04-14 01:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2004-07-15 18:29 . 2004-07-15 18:29 1703936 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 18:32 . 2004-07-15 18:32 1294336 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 04:28 . 2004-07-15 04:28 2502656 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_mscorwks.dll
+ 2004-07-15 04:26 . 2004-07-15 04:26 2510848 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_mscorsvr.dll
+ 2004-07-15 18:29 . 2004-07-15 18:29 2138112 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW3556\_mscorlib.dll
+ 2007-04-14 00:57 . 2007-04-14 00:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-14 00:57 . 2007-04-14 00:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-14 00:50 . 2007-04-14 00:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 11:25 . 2003-02-21 11:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
- 2008-01-15 00:53 . 2009-04-29 22:55 1172240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 1172240 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-01-15 00:53 . 2009-04-29 22:55 1165584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-01-15 00:53 . 2009-04-30 03:18 1165584 c:\windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\accicons.exe
+ 2006-10-26 19:47 . 2006-10-26 19:47 1512304 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\NLSD0000.DLL
+ 2008-01-15 00:49 . 2008-01-15 00:49 1276720 c:\windows\Installer\$PatchCache$\Managed\
00002119E20000000000000000F01FEC\12.0.4518\EXCELPIA.DLL
+ 2009-04-30 13:37 . 2009-04-30 13:37 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f828184f\System.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 4788224 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_e7211da1\System.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_59757f8c\System.Xml.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_1fcbaabc\System.Xml.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_f828382b\System.Windows.Forms.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_7d23ce0d\System.Windows.Forms.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_67706d0d\System.Drawing.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_c0607366\System.Design.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_7a6aaaf7\System.Design.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_563ba26f\mscorlib.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_128abf7d\mscorlib.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 1339392 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 2052096 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-04-30 13:37 . 2009-04-30 13:37 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 1703936 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-04-30 13:35 . 2009-04-30 13:35 1294336 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2009-04-30 04:42 . 2009-04-30 04:42 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2009-04-30 03:17 . 2009-04-30 03:17 1279848 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DeadAIM"="c:\program files\AIM\\DeadAIM.ocm" [2004-02-28 144896]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-01-13 170496]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2002-10-15 1818624]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2004-10-21 29696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-19 16844800]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
c:\documents and settings\Carmagnoli\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe [2007-12-7 28672]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-1-15 581632]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-4-14 6144]
Windows Home Server.lnk - c:\windows\Installer\{21E49794-7C13-4E84-8659-55BD378267D5}\WHSTrayApp.exe [2007-12-30 532512]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.10.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.3.0-enUS-downloader.exe"=
"c:\\Program Files\\Windows Home Server\\Discovery.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\ChemDraw\\ChemDraw.exe"=
"c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\Chem3D\\Chem3D.exe"=
"c:\\Documents and Settings\\Carmagnoli\\My Documents\\refworks\\RWDesktop.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"=
"c:\\Program Files\\Common Files\\ArcSoft\\Connection Service\\Bin\\ACDaemon.exe"=
"c:\\Program Files\\Cisco Systems\\Clean Access Agent\\CCAAgent.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\ComboFix\\NirCmd.cfexe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Warcraft
"3724:TCP"= 3724:TCP:warcraft2
R0 m5228;m5228; [x]
R0 m5281;m5281; [x]
R0 viasraid;viasraid; [x]
R1 $sys$crater;$sys$crater;c:\windows\system32\$sys$filesystem\crater.sys [2005-07-04 11904]
R1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [2008-12-17 123392]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-29 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-22 55024]
R2 MSSQL$CSSQL05;SQL Server (CSSQL05);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-27 29183504]
R2 WHSConnector;Windows Home Server Connector Service;c:\program files\Windows Home Server\WHSConnector.exe [2007-09-06 302112]
R3 DCamUSBUVT;ICM532A;c:\windows\system32\Drivers\usbuvt.sys [2002-10-22 95744]
R3 GETND5BV;VIA Networking Velocity-Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\DRIVERS\getnd5bv.sys [2005-10-28 45568]
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\DRIVERS\getnd5b.sys [2004-01-29 44544]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R3 PciCon;PciCon; [x]
R3 SaiH8000;SaiH8000;c:\windows\system32\DRIVERS\SaiH8000.sys [2004-07-30 56576]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
S0 $sys$cor;$sys$cor;c:\windows\System32\Drivers\$sys$cor.sys [2005-07-04 18432]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23e32721-7bb1-11dd-b590-001d7dd484f7}]
\Shell\AutoRun\command - g:\wd_windows_tools\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2009-05-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-pidle - c:\documents and settings\Carmagnoli\Application Data\pidle\pidle.exe
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Carmagnoli\Application Data\Mozilla\Firefox\Profiles\o0nvr439.default\
FF - prefs.js: browser.startup.homepage - hxxps://mymiami.muohio.edu/webapps/portal/frameset.jsp
FF - component: c:\program files\Mozilla Firefox\components\WWShow.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-04 18:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-05-04 18:52
ComboFix-quarantined-files.txt 2009-05-04 22:52
ComboFix2.txt 2009-04-30 02:10
ComboFix3.txt 2009-04-30 02:07
ComboFix4.txt 2009-04-29 22:25
Pre-Run: 74,748,596,224 bytes free
Post-Run: 75,181,936,640 bytes free
Current=3 Default=3 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
566 --- E O F --- 2009-05-04 14:31