Combofix part 2:
((((((((((((((((((((((((((((( SnapShot@2009-09-13_17.50.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-20 18:12 . 2009-09-20 18:12 65536 c:\windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087\vcomp.dll
+ 2009-09-17 17:16 . 2005-08-01 15:01 57344 c:\windows\twain_32\SNPSTD3D\TwainUI.dll
+ 2009-09-17 17:16 . 2005-08-01 15:01 57344 c:\windows\twain_32\SNPSTD3C\TwainUI.dll
+ 2009-09-17 17:16 . 2005-08-01 15:01 57344 c:\windows\twain_32\SNPSTD3B\TwainUI.dll
+ 2009-09-17 17:16 . 2005-08-01 15:01 57344 c:\windows\twain_32\SNPSTD3A\TwainUI.dll
+ 2007-07-23 17:17 . 2009-09-21 18:35 54074 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-21 18:36 67356 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-05 02:21 . 2009-09-21 18:05 11328 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1729058323-3176270510-1616200201-1000_UserData.bin
+ 2003-02-21 04:16 . 2003-02-21 04:16 49152 c:\windows\System32\URTTEMP\regtlib.exe
+ 2009-09-17 17:16 . 2007-04-03 16:21 57344 c:\windows\System32\DriverStore\FileRepository\snpstd3.inf_cda2b4e6\vsnpstd3.dll
+ 2009-09-17 17:16 . 2005-08-01 15:01 57344 c:\windows\System32\DriverStore\FileRepository\snpstd3.inf_cda2b4e6\TwainUI.dll
+ 2009-09-17 17:16 . 2005-11-23 12:55 53248 c:\windows\System32\DriverStore\FileRepository\snpstd3.inf_cda2b4e6\csnpstd3.dll
- 2009-02-05 02:14 . 2009-09-13 17:21 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-05 02:14 . 2009-09-21 18:03 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:52 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-21 17:54 . 2009-09-21 17:56 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-21 17:54 . 2009-09-21 17:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2009-09-21 17:54 . 2009-09-21 17:54 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:56 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:52 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:53 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-21 17:52 . 2009-09-21 17:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2004-07-15 01:11 . 2004-07-15 01:11 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2004-06-22 12:51 . 2004-06-22 12:51 53248 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2004-07-15 13:28 . 2004-07-15 13:28 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-14 23:35 . 2004-07-14 23:35 66560 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2004-07-15 13:28 . 2004-07-15 13:28 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2004-07-14 23:34 . 2004-07-14 23:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2003-02-20 17:43 . 2003-02-20 17:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2003-02-20 18:18 . 2003-02-20 18:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2004-07-14 23:33 . 2004-07-14 23:33 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 18:06 . 2003-02-20 18:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2004-07-14 23:32 . 2004-07-14 23:32 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2004-07-15 13:28 . 2004-07-15 13:28 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2003-02-21 06:25 . 2003-02-21 06:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 18:22 . 2003-02-20 18:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2004-07-15 13:31 . 2004-07-15 13:31 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-10-08 13:30 . 2003-10-08 13:30 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
+ 2003-02-21 03:12 . 2003-02-21 03:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2004-07-15 10:23 . 2004-07-15 10:23 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2004-07-14 23:32 . 2004-07-14 23:32 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2004-07-15 00:49 . 2004-07-15 00:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2004-07-15 00:49 . 2004-07-15 00:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2004-07-15 00:49 . 2004-07-15 00:49 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2003-02-20 18:19 . 2003-02-20 18:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2003-02-20 18:19 . 2003-02-20 18:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2003-02-21 04:00 . 2003-02-21 04:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-21 02:55 . 2003-02-21 02:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-21 01:59 . 2003-02-21 01:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2009-09-13 20:04 . 2009-09-13 20:04 21504 c:\windows\Installer\16fd6c.msi
+ 2009-09-13 20:04 . 2009-09-13 20:04 27648 c:\windows\Installer\16fd66.msi
- 2006-11-02 10:25 . 2009-08-30 23:44 86016 c:\windows\inf\infstor.dat
+ 2006-11-02 10:25 . 2009-09-17 17:17 86016 c:\windows\inf\infstor.dat
- 2006-11-02 10:25 . 2009-08-30 23:44 51200 c:\windows\inf\infpub.dat
+ 2006-11-02 10:25 . 2009-09-17 17:17 51200 c:\windows\inf\infpub.dat
+ 2009-09-20 18:12 . 2009-09-20 18:12 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_8d328dd8\System.Drawing.Design.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_56478107\CustomMarshalers.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 57344 c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 77824 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 66560 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 65536 c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 90112 c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 77824 c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 32768 c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 32768 c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 11264 c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 28672 c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 26112 c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 32768 c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 33792 c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 12288 c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2003-02-20 17:43 . 2003-02-20 17:43 4096 c:\windows\System32\MUI\0409\mscoreer.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 8192 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 6656 c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 6144 c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 4608 c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 8192 c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 7680 c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2006-11-02 10:33 . 2009-09-20 18:11 598850 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-20 18:11 106120 c:\windows\System32\perfc009.dat
+ 2009-09-17 17:16 . 2006-09-19 08:07 827392 c:\windows\System32\DriverStore\FileRepository\snpstd3.inf_cda2b4e6\vsnpstd3.exe
- 2009-02-05 02:14 . 2009-09-13 17:21 131072 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-05 02:14 . 2009-09-21 18:03 131072 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2004-07-15 10:23 . 2004-07-15 10:23 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2004-07-15 13:31 . 2004-07-15 13:31 573440 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 372736 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 303104 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-14 23:35 . 2004-07-14 23:35 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2004-08-10 15:20 . 2004-08-10 15:20 106496 c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-21 03:42 . 2003-02-21 03:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2004-07-14 23:33 . 2004-07-14 23:33 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-20 17:43 . 2003-02-20 17:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2004-07-14 23:33 . 2004-07-14 23:33 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2004-07-14 23:25 . 2004-07-14 23:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-14 23:32 . 2004-07-14 23:32 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2004-07-15 13:28 . 2004-07-15 13:28 720896 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-14 23:35 . 2004-07-14 23:35 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2004-07-14 23:24 . 2004-07-14 23:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-20 18:16 . 2003-02-20 18:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 09:21 . 2003-02-21 09:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2004-07-15 10:23 . 2004-07-15 10:23 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 10:11 . 2002-07-29 10:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2004-07-15 00:49 . 2004-07-15 00:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 04:04 . 2003-02-21 04:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 02:02 . 2003-02-21 02:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 213504 c:\windows\Installer\c99b96.msi
+ 2009-09-20 13:44 . 2009-09-20 13:44 261632 c:\windows\Installer\61ad74.msi
- 2006-11-02 10:25 . 2009-08-30 23:44 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 10:25 . 2009-09-17 17:17 143360 c:\windows\inf\infstrng.dat
+ 2009-09-20 18:13 . 2009-09-20 18:13 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_2b37531e\System.Drawing.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_65c4c98b\System.Drawing.Design.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_ede1abc9\CustomMarshalers.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 573440 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 372736 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 303104 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 720896 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-06-05 09:41 . 2009-09-20 18:12 3279875 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
- 2006-11-02 10:22 . 2009-09-13 17:46 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-09-21 18:32 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-02-05 02:14 . 2009-09-13 17:21 1556480 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-05 02:14 . 2009-09-21 18:03 1556480 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2004-07-15 07:15 . 2004-07-15 07:15 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-15 13:29 . 2004-07-15 13:29 1339392 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-07-15 13:32 . 2004-07-15 13:32 2052096 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 13:29 . 2004-07-15 13:29 1257472 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 13:31 . 2004-07-15 13:31 1224704 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2004-07-15 13:29 . 2004-07-15 13:29 1703936 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 13:32 . 2004-07-15 13:32 1294336 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-14 23:28 . 2004-07-14 23:28 2502656 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2004-07-14 23:26 . 2004-07-14 23:26 2510848 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2004-07-15 13:29 . 2004-07-15 13:29 2138112 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2009-09-20 18:09 . 2009-09-20 18:09 3443712 c:\windows\Installer\c6ee02.msi
+ 2009-09-13 21:19 . 2009-09-13 21:19 2215424 c:\windows\Installer\5b2dc3.msi
+ 2009-09-13 20:09 . 2009-09-13 20:09 3938816 c:\windows\Installer\16fea3.msi
+ 2009-09-20 18:12 . 2009-09-20 18:12 1953792 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_9f304231\System.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 4763648 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_6b3b824b\System.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 5505024 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_e3e93f13\System.Xml.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_e29ff741\System.Xml.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 3014656 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a30a2653\System.Windows.Forms.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 7880704 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_9c71edfc\System.Windows.Forms.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_65e93b1d\System.Drawing.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_d774c69b\System.Design.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 1466368 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_afcae024\System.Design.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 8880128 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b06f5cc8\mscorlib.dll
+ 2009-09-20 18:13 . 2009-09-20 18:13 3379200 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_45d89daf\mscorlib.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 1224704 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 1339392 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 2052096 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 1257472 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 1703936 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-09-20 18:12 . 2009-09-20 18:12 1294336 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2009-09-20 18:08 . 2009-09-20 18:08 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2009-09-17 17:16 . 2007-04-06 16:29 10342784 c:\windows\System32\DriverStore\FileRepository\snpstd3.inf_cda2b4e6\snpstd3.sys
+ 2009-09-20 18:11 . 2009-09-20 18:11 19210240 c:\windows\Installer\c99b90.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-08-30 23:41 218160 ----a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-11 2007832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-02-07 262144]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware2\mbam.exe" [2009-09-10 1312080]
"Turbine Download Manager Tray Icon"="c:\program files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe" [2009-09-20 472568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\C:\0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F5F06F40-D905-41D7-9C4E-651F5AB846AC}"= UDP:5353:Adobe CSI CS4
"{74F62B14-A768-4AB8-950A-4C74AA38A745}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{1B9D7951-6486-4832-B437-58F39ED2CB58}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{0081E1AD-118A-424C-A420-A9D393665C13}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{D6368C98-4B50-49C7-9F0E-B9289B23B600}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{53CC6A46-724C-40F2-ADE4-DEBB4B457DB3}"= UDP:5353:Adobe CSI CS4
"{38212378-4C07-4A42-AC4F-70BFD62F249D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A83AFD3A-6738-4B83-920C-F3BF37ED63FC}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{70DF70AC-145B-443A-A324-F34106464240}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{13692021-5419-4FF9-AC9C-3897CCF4F15F}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{109A5013-B24F-4AEA-8EC7-64D004DE4BBB}c:\\program files\\team fortress 2\\hl2.exe"= UDP:c:\program files\team fortress 2\hl2.exe:hl2
"UDP Query User{FB3924FC-E7F2-4DCF-A1CC-A877C56EFF67}c:\\program files\\team fortress 2\\hl2.exe"= TCP:c:\program files\team fortress 2\hl2.exe:hl2
"TCP Query User{FAC1569E-8923-4B5E-8183-A6AA50861AEA}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{D187C165-6662-4444-8B11-D26D645D6060}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{B1C1C000-F3C1-41DF-AE40-3D104FA3802F}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{EC309C56-C451-44D2-BFEF-751BC86595FF}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{E2CDA4DA-2F6D-458A-AADB-762AC7DC3EA2}c:\\program files\\xchat\\xchat.exe"= UDP:c:\program files\xchat\xchat.exe:XChat IRC Client
"UDP Query User{D888DD60-B5D9-4BE5-9451-E8CA3D1ABEA0}c:\\program files\\xchat\\xchat.exe"= TCP:c:\program files\xchat\xchat.exe:XChat IRC Client
"TCP Query User{C7C28DDA-45E2-4AB2-AEBE-8517CA503BF9}c:\\program files\\microsoft chat\\cchat.exe"= UDP:c:\program files\microsoft chat\cchat.exe:Microsoft Chat
"UDP Query User{EF7EFC75-99A0-4DC5-823E-5287549DCFD3}c:\\program files\\microsoft chat\\cchat.exe"= TCP:c:\program files\microsoft chat\cchat.exe:Microsoft Chat
"TCP Query User{1212A521-0101-4F92-9C69-F1AA4152A9B8}c:\\windows\\system32\\javaw.exe"= UDP:c:\windows\system32\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{9A45A62A-75CC-4EAE-BEC1-ADB88E2236C2}c:\\windows\\system32\\javaw.exe"= TCP:c:\windows\system32\javaw.exe:Java(TM) Platform SE binary
"TCP Query User{8ACF5768-08AE-44C9-8EFE-4EA9FEE2ABE1}c:\\program files\\java\\jre6\\bin\\javaw.exe"= UDP:c:\program files\java\jre6\bin\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{12EA07CC-17DF-4E3D-982E-E0F6EE244535}c:\\program files\\java\\jre6\\bin\\javaw.exe"= TCP:c:\program files\java\jre6\bin\javaw.exe:Java(TM) Platform SE binary
"TCP Query User{BE1D6881-5218-4634-8169-B07AD7EFA046}c:\\program files\\gametap web player\\bin\\release\\gametapplayer.exe"= UDP:c:\program files\gametap web player\bin\release\gametapplayer.exe:GameTap Headless Application
"UDP Query User{664E72B9-1C01-47AD-9D83-F205B80BB284}c:\\program files\\gametap web player\\bin\\release\\gametapplayer.exe"= TCP:c:\program files\gametap web player\bin\release\gametapplayer.exe:GameTap Headless Application
"TCP Query User{4797D5B9-96EC-4BA4-99A8-4F60B216800E}c:\\program files\\ea games\\american mcgee's alice\\alice.exe"= UDP:c:\program files\ea games\american mcgee's alice\alice.exe:American McGee's Alice
"UDP Query User{B9164609-67AC-4F7E-8A86-671D9B1AA9CC}c:\\program files\\ea games\\american mcgee's alice\\alice.exe"= TCP:c:\program files\ea games\american mcgee's alice\alice.exe:American McGee's Alice
"TCP Query User{B8929E70-B6B6-43A7-B685-27F408109A49}c:\\program files\\gametap web player\\bin\\release\\gametapplayer.exe"= UDP:c:\program files\gametap web player\bin\release\gametapplayer.exe:GameTap Headless Application
"UDP Query User{CBE64D25-42D8-41DD-823B-7580D7FFE1BA}c:\\program files\\gametap web player\\bin\\release\\gametapplayer.exe"= TCP:c:\program files\gametap web player\bin\release\gametapplayer.exe:GameTap Headless Application
"{FC14F6C1-5629-4DA3-9618-4A93C215F571}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8AFF59C0-F8B3-4332-BAA5-87068CFDFAF5}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{FD660F16-53FC-4913-846A-E93CB57C8870}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{23FF3633-A910-478F-8905-A8A85CFFBEBD}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E8F597F5-9A33-43F7-8D29-F382CC520F09}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B06B7B1E-83DC-468F-8603-7ADBDDCC0CA6}"= UDP:c:\program files\Pando Networks\Media Booster\PMB.exe

ando Media Booster
"{5CC737E4-1E79-49FB-A127-8AF1C4F6D0A6}"= TCP:c:\program files\Pando Networks\Media Booster\PMB.exe

ando Media Booster
"TCP Query User{B6F4F494-017D-4868-A9D4-CAED4C4AC811}c:\\program files\\pando networks\\media booster\\pmb.exe"= UDP:c:\program files\pando networks\media booster\pmb.exe

ando Media Booster
"UDP Query User{5A7290D3-4B34-423E-8BC2-68D580935D2B}c:\\program files\\pando networks\\media booster\\pmb.exe"= TCP:c:\program files\pando networks\media booster\pmb.exe

ando Media Booster
"{2DB6CFEC-BF6D-45C6-B132-B5739DF2BBDF}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{47DB2A9D-CB88-4719-98B3-6A266C7AAD0A}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6982B654-0F5D-4C1D-84E6-382CD164F6C7}"= UDP:c:\program files\Spotify\spotify.exe:Spotify
"{FD99BD80-7502-4F04-B754-9A5C85C457D8}"= TCP:c:\program files\Spotify\spotify.exe:Spotify
"{1302AE23-A0F6-4D52-8A4D-E0CCE160CBE9}"= UDP:c:\program files\Spotify\spotify.exe:Spotify
"{11AACA35-6380-4959-B0B6-FA472E894FE7}"= TCP:c:\program files\Spotify\spotify.exe:Spotify
"{82FC70D3-BA9D-439C-AC5B-039B47E667E5}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{F3428E68-A875-41D6-B9EF-A747F6C5553A}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{34B8BAC4-1664-427A-B915-85AADE3C3980}c:\\program files\\secondlife\\slvoice.exe"= UDP:c:\program files\secondlife\slvoice.exe:SLVoice
"UDP Query User{2E667820-49A4-4945-A184-68BD91391ACF}c:\\program files\\secondlife\\slvoice.exe"= TCP:c:\program files\secondlife\slvoice.exe:SLVoice
"{FE73858A-A0E2-40C3-8823-3F57B6BFE7B6}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{0AF96662-8DEA-4D7A-9048-F5656A862E33}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{5E6813CB-A420-42CE-87F7-AF2BDA585B11}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{82331550-B05B-42C5-9CD2-CBFA7A3DDB52}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{4F379B3D-5EF5-498C-B371-9838E49CDE55}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"TCP Query User{5DFBFA1B-BF69-4079-8315-F0B85DA9B011}c:\\program files\\turbine\\dungeons and dragons online - eberron unlimited\\dndclient.exe"= UDP:c:\program files\turbine\dungeons and dragons online - eberron unlimited\dndclient.exe:dndclient
"UDP Query User{3737B3D8-5B18-48EC-9F5F-1C894BB4905C}c:\\program files\\turbine\\dungeons and dragons online - eberron unlimited\\dndclient.exe"= TCP:c:\program files\turbine\dungeons and dragons online - eberron unlimited\dndclient.exe:dndclient
"{44AB8058-46B4-4750-BCF0-48D006681998}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{E001E90D-778E-4F43-8809-C9BBF76DFE93}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{7D4BE065-55B0-479F-A4B4-D103DBF56B24}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{03E8EA4B-A6B9-4F40-9CAD-FCB6F4E5D581}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe:TurbineMessageService
"{21B718A8-99A6-4C97-9759-2022BAB17ED5}"= UDP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
"{AF1D4155-B65F-4D2E-A97C-751E5ABD9AEE}"= TCP:c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:TurbineNetworkService
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\xchat\\xchat.exe"= c:\program files\xchat\xchat.exe:*:Enabled:XChat IRC Client
R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [20/11/2006 08:14 AM 38400]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [17/11/2006 06:58 AM 31360]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [07/09/2009 09:49 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [07/09/2009 09:49 PM 108552]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\System32\drivers\HssDrv.sys [02/07/2009 03:34 AM 33840]
R3 MGHwCtrl;MGHwCtrl;c:\windows\System32\drivers\MGHwCtrl.sys [23/07/2007 06:24 PM 19456]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr61.sys [28/09/2007 02:37 PM 316928]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\System32\drivers\tap0901.sys [22/07/2009 08:13 PM 28592]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\System32\drivers\btnetBus.sys [07/12/2008 01:44 PM 30088]
S3 CrystalSysInfo;CrystalSysInfo;c:\program files\MediaCoder\SysInfo.sys [25/09/2007 03:59 PM 15152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\Autorun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA844-CC51-11CF-AAFA-00AA00B6015C}]
rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\CChat25.inf,PerUserRemove
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=14986&l=dis
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\
www.msi
FF - ProfilePath - c:\users\Kopa\AppData\Roaming\Mozilla\Firefox\Profiles\hekitc3k.default\
FF - prefs.js: browser.search.selectedEngine - Element
FF - prefs.js: browser.startup.homepage - hxxp://gaiaonline.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59287&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\users\Kopa\AppData\Roaming\Mozilla\Firefox\Profiles\hekitc3k.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Kopa\AppData\Roaming\Mozilla\Firefox\Profiles\hekitc3k.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\users\Kopa\AppData\Roaming\Mozilla\Firefox\Profiles\hekitc3k.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-21 19:35
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\agrsmsvc.exe
c:\windows\System32\ASTSRV.EXE
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\windows\System32\CTSVCCDA.EXE
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe
c:\windows\System32\o2flash.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\microsoft shared\ink\InputPersonalization.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-09-21 19:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-21 18:48
ComboFix2.txt 2009-09-20 14:26
ComboFix3.txt 2009-09-15 11:02
ComboFix4.txt 2009-09-13 19:18
ComboFix5.txt 2009-09-21 17:52
Pre-Run: 13,505,298,432 bytes free
Post-Run: 14,288,429,056 bytes free
931 --- E O F --- 2009-09-13 10:20
DDS report:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Kopa at 21:33:25.29 on 21/09/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_15
============== Pseudo HJT Report ===============
uStart Page = hxxp://uk.ask.com?o=14986&l=dis
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [FixCamera] c:\windows\FixCamera.exe
mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware2\mbam.exe" /runcleanupscript
mRun: [Turbine Download Manager Tray Icon] "c:\program files\turbine\turbine download manager\TurbineDownloadManagerIcon.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "c:\program files\fiddler2\Fiddler.exe"
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\
www.msi
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\kopa\appdata\roaming\mozilla\firefox\profiles\hekitc3k.default\
FF - prefs.js: browser.search.selectedEngine - Element
FF - prefs.js: browser.startup.homepage - hxxp://gaiaonline.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59287&p=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\users\kopa\appdata\roaming\mozilla\firefox\profiles\hekitc3k.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\virtools\3d life player\npvirtools.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\kopa\appdata\roaming\mozilla\firefox\profiles\hekitc3k.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\users\kopa\appdata\roaming\mozilla\firefox\profiles\hekitc3k.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-09-21 20:04 19,456 a------- c:\windows\system32\kbiwkmuodtocri.dll
2009-09-21 20:04 43 a------- c:\windows\system32\kbiwkmvssmngqm.dat
2009-09-21 19:35 <DIR> --d----- C:\$RECYCLE.BIN
2009-09-21 19:33 18,944 a------- c:\windows\system32\kbiwkmvcvoqpwy.dll
2009-09-21 19:33 1,783 a------- c:\windows\system32\kbiwkmrssxqohd.dat
2009-09-21 19:32 41,472 a------- c:\windows\system32\kbiwkmqyxvarea.dll
2009-09-21 18:50 <DIR> --d----- C:\Combo-Fix21880C
2009-09-20 19:13 <DIR> --d----- c:\programdata\Turbine
2009-09-20 19:13 <DIR> --d----- c:\progra~2\Turbine
2009-09-20 19:12 <DIR> --d----- c:\program files\Turbine
2009-09-20 19:08 <DIR> --d----- c:\windows\system32\URTTEMP
2009-09-20 18:34 <DIR> --d----- c:\users\kopa\appdata\roaming\GarageGames
2009-09-20 17:55 <DIR> --d----- C:\ROTH
2009-09-20 14:44 <DIR> -cd-h--- c:\programdata\{3D91BFA3-4B91-4808-862D-BF7B5E9B6BA9}
2009-09-20 14:44 <DIR> -cd-h--- c:\progra~2\{3D91BFA3-4B91-4808-862D-BF7B5E9B6BA9}
2009-09-20 14:44 <DIR> --d----- c:\program files\ProjectPokemon
2009-09-17 18:16 20,480 a------- c:\windows\FixCamera.exe
2009-09-17 18:16 827,392 a------- c:\windows\vsnpstd3.exe
2009-09-17 18:16 262,144 a------- c:\windows\tsnpstd3.exe
2009-09-17 18:16 15,498 a------- c:\windows\snpstd3.ini
2009-09-17 18:16 13,023 a------- c:\windows\snpstd3.src
2009-09-17 18:16 10,342,784 a------- c:\windows\system32\drivers\snpstd3.sys
2009-09-17 18:16 172,032 a------- c:\windows\system32\rsnpstd3.dll
2009-09-17 18:16 57,344 a------- c:\windows\system32\vsnpstd3.dll
2009-09-17 18:16 53,248 a------- c:\windows\system32\csnpstd3.dll
2009-09-17 18:16 53,248 a------- c:\windows\csnpstd3.dll
2009-09-17 18:16 <DIR> --d----- c:\program files\common files\snpstd3
2009-09-15 12:04 <DIR> --d----- c:\program files\ESET
2009-09-14 08:18 <DIR> --d----- c:\programdata\WindowsSearch
2009-09-13 18:14 <DIR> --d----- C:\Combo-Fix
2009-09-11 20:40 11,776 -------- c:\windows\system32\cngaudit.dll
2009-09-11 17:18 229,888 a------- c:\windows\PEV.exe
2009-09-11 17:18 161,792 a------- c:\windows\SWREG.exe
2009-09-11 17:18 98,816 a------- c:\windows\sed.exe
2009-09-11 17:14 897,608 a------- c:\windows\system32\drivers\tcpip.sys
2009-09-11 17:14 104,960 a------- c:\windows\system32\netiohlp.dll
2009-09-11 17:14 27,136 a------- c:\windows\system32\NETSTAT.EXE
2009-09-11 17:14 19,968 a------- c:\windows\system32\ARP.EXE
2009-09-11 17:14 11,264 a------- c:\windows\system32\MRINFO.EXE
2009-09-11 17:14 10,240 a------- c:\windows\system32\finger.exe
2009-09-11 17:14 9,728 a------- c:\windows\system32\TCPSVCS.EXE
2009-09-11 17:14 8,704 a------- c:\windows\system32\HOSTNAME.EXE
2009-09-11 17:14 17,920 a------- c:\windows\system32\ROUTE.EXE
2009-09-11 17:14 17,920 a------- c:\windows\system32\netevent.dll
2009-09-11 17:13 2,501,921 a------- c:\windows\system32\wlan.tmf
2009-09-11 17:13 293,376 a------- c:\windows\system32\wlanmsm.dll
2009-09-11 17:13 513,024 a------- c:\windows\system32\wlansvc.dll
2009-09-11 17:13 302,592 a------- c:\windows\system32\wlansec.dll
2009-09-11 17:13 127,488 a------- c:\windows\system32\L2SecHC.dll
2009-09-11 17:13 2,868,224 a------- c:\windows\system32\mf.dll
2009-09-11 10:26 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware2
2009-09-11 10:14 <DIR> --d----- c:\program files\Trend Micro7
2009-09-11 10:00 <DIR> --d----- c:\program files\Trend Micro0
2009-09-09 17:16 0 a------- c:\windows\system32\cd.dat
2009-09-08 23:13 <DIR> --d-h--- c:\windows\PIF
2009-09-08 14:22 <DIR> --d----- c:\program files\Trend Micro9
2009-09-08 14:15 <DIR> --d----- c:\program files\Trend Micro3
2009-09-08 14:00 <DIR> --d----- c:\program files\Trend Micro2
2009-09-07 22:18 233,389,203 a------- c:\windows\MEMORY.DMP
2009-09-07 21:49 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-09-07 21:49 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-09-07 21:49 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-09-07 21:49 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-09-07 21:33 <DIR> --d----- c:\program files\Trend Micro
2009-09-06 23:36 <DIR> --d----- c:\users\kopa\dwhelper
2009-09-05 22:41 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-05 22:41 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-05 19:05 <DIR> --d----- C:\found.000
2009-09-03 15:05 <DIR> --d----- c:\program files\Sophos
2009-09-03 15:02 <DIR> --d----- c:\users\kopa\Pavark
2009-08-31 00:45 <DIR> --d----- C:\Hotspot Shield
2009-08-31 00:41 <DIR> --d----- c:\program files\Hotspot Shield
2009-08-29 20:42 <DIR> --d----- c:\program files\Windows Installer Clean Up
2009-08-29 20:41 <DIR> --d----- c:\program files\MSECACHE
2009-08-29 20:11 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-08-29 19:58 <DIR> --d----- c:\programdata\WLInstaller
2009-08-28 17:05 <DIR> --d----- c:\windows\pss
2009-08-27 03:03 2,048 a------- c:\windows\system32\tzres.dll
2009-08-26 19:25 1,744 a------- c:\windows\wininit.ini
2009-08-26 18:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2009-08-26 18:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-08-26 18:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2009-08-26 18:26 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-08-26 04:18 <DIR> --d----- C:\PerfLogs
==================== Find3M ====================
2009-09-21 20:09 66,048 a------- c:\windows\system32\drivers\kbiwkmwmqxbsse.sys
2009-09-17 18:17 143,360 a------- c:\windows\inf\infstrng.dat
2009-09-17 18:17 86,016 a------- c:\windows\inf\infstor.dat
2009-09-17 18:17 51,200 a------- c:\windows\inf\infpub.dat
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-28 13:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 13:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 13:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 13:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-26 04:31 174 a--sh--- c:\program files\desktop.ini
2009-08-26 04:18 665,600 a------- c:\windows\inf\drvindex.dat
2009-08-26 03:24 101,888 a------- c:\windows\system32\ifxcardm.dll
2009-08-26 03:23 82,432 a------- c:\windows\system32\axaltocm.dll
2009-08-10 13:12 40,768 a------- c:\users\kopa\appdata\roaming\nvModes.dat
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-18 17:06 827,904 a------- c:\windows\system32\wininet.dll
2009-07-18 17:01 78,336 a------- c:\windows\system32\ieencode.dll
2009-07-18 10:46 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 15:35 71,680 a------- c:\windows\system32\atl.dll
2009-07-14 14:00 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-07-14 13:59 4,096 a------- c:\windows\system32\dxmasf.dll
2009-07-14 13:58 7,680 a------- c:\windows\system32\spwmp.dll
2009-07-14 11:59 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-07-10 12:15 306,544 a------- c:\windows\WLXPGSS.SCR
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 21:39:58.89 ===============