Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

help with malware removal just added uninstall list

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 13th, 2010, 4:26 pm

Hello sunny21b,

The steps presented in these posts are for this person and machine ONLY. Do not apply these steps to your own system, without the guidance of a trained malware removal helper. Doing so, may possibly damage your system, preventing it from starting.

Please do not make any changes to your system: do not add or remove any software, run any scans or "fix" programs and/or remove any files unless instructed to do so, by me. Please read these instructions carefully before executing and then perform the steps, in the order given. If you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.


You didn't answer this question from before:
The IP address: 69.31.52.2 refers to the ISP below. Is this familiar to you?
ISP: PILOSOFT INC
Domain: PILOSOFT.COM

From my last post... You said you had no problem with the instructions... did you check the settings and verify they are as requested earlier?
Did you check your firewall to make sure it is not blocking MBAM from being updated?

Please let me know if the settings are as posted earlier.

Thanks,
Wingman
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA
Advertisement
Register to Remove

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 14th, 2010, 4:15 pm

wingman-
sorry about the question. no i have no idea what that is, unless if its something attached to another program or internet explorer i have. i always copy and print your instructions so that i can follow them precisely when exucuting so i don't have to have any windows open when doing so. also, now my screen will black out when i get on the internet, only for a few seconds and then come back upto where/what i was working on
thanks
sunny21b
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 14th, 2010, 7:35 pm

wingman-
tried eset again-it worked!!:)

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-03 03:50:05
# local_time=2010-10-03 11:50:05 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 4987399 4987399 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=108231
# found=2
# cleaned=0
# scan_time=3839
C:\Documents and Settings\debra\My Documents\Nero-7.11.10.0_all_update.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
C:\Documents and Settings\debra\My Documents\Nero-9.4.13.2d_trial.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-11 09:35:07
# local_time=2010-10-11 05:35:07 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=10247
# found=0
# cleaned=0
# scan_time=620
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-11 09:41:25
# local_time=2010-10-11 05:41:25 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=6944
# found=0
# cleaned=0
# scan_time=340
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-11 10:26:47
# local_time=2010-10-11 06:26:47 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=110124
# found=2
# cleaned=2
# scan_time=2700
C:\Documents and Settings\debra\My Documents\Nero-7.11.10.0_all_update.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\debra\My Documents\Nero-9.4.13.2d_trial.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-11 11:42:10
# local_time=2010-10-11 07:42:10 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=110518
# found=0
# cleaned=0
# scan_time=3045
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-13 09:03:51
# local_time=2010-10-13 05:03:51 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=108980
# found=0
# cleaned=0
# scan_time=3106
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=false
# utc_time=2010-10-14 12:13:28
# local_time=2010-10-13 08:13:28 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=107664
# found=0
# cleaned=0
# scan_time=3057
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb391fd8f17f14458953904597fbce52
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-14 09:10:28
# local_time=2010-10-14 05:10:28 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=6143 16777215 0 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 48935 48935 0 0
# scanned=109601
# found=0
# cleaned=0
# scan_time=3120
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 15th, 2010, 10:20 am

Hello sunny21b,

The steps presented in these posts are for this person and machine ONLY. Do not apply these steps to your own system, without the guidance of a trained malware removal helper. Doing so, may possibly damage your system, preventing it from starting.

Please do not make any changes to your system: do not add or remove any software, run any scans or "fix" programs and/or remove any files unless instructed to do so, by me. Please read these instructions carefully before executing and then perform the steps, in the order given. If you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.


Step 1.
I need you to answer these questions:
Are you using a router? If yes... Have you reset the router, according to the manufactures manual?

Checked your Internet Explorer LAN settings in the Connections tab... as discussed earlier?
- Make sure the LAN settings is set to Automatically connect... with no explicit IP addresses being used.

Did you check your firewall to make sure it is not blocking MBAM from being updated?


Step2.
Access to MBAM's manual updates?
Please try to download MBAM updates manually. http://data.mbamupdates.com/tools/mbam-rules.exe
Once downloaded, double click on mbam-rules.exe to install the updates.
Note: These manual updates are typically far behind the in program updates...
- if you are able to update manually... run a new scan, post the results then try update via the program's interface. If you can update via the program run a FULL scan.


Please answer my questions and try to access the manual updates for MBAM.
Post results from new MBAM scan if applicable.

Thanks,
Wingman
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 15th, 2010, 12:12 pm

wingman-
yes i am using a router and have reset it according to the manufacturers manual. i have checked my internet explorer lan settings in the connections tab and is set to automatically connect with no explicit ip address. firewall is not blocking mbam. i cannot access manual updates. internet will not connect to that address.
thank you for all your help so far, this seems to be a real bugger
sunny21b:)
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 15th, 2010, 7:23 pm

Hello sunny21b,

The steps presented in these posts are for this person and machine ONLY. Do not apply these steps to your own system, without the guidance of a trained malware removal helper. Doing so, may possibly damage your system, preventing it from starting.

Please do not make any changes to your system: do not add or remove any software, run any scans or "fix" programs and/or remove any files unless instructed to do so, by me. Please read these instructions carefully before executing and then perform the steps, in the order given. If you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.

Thank you for answering my questions. This machine is not used for business purposes or connected to a business network is it?
When you tried to access the manual update site... did you try using both IE and Firefox? If you did, let me know, if you only tried IE, please try FF and see what happens, letting me know the results.

Step 1.
ERUNT - Emergency Recovery Utility NT
Please run this again, as changes may have occurred between the last run and now. Better to be safe than to be sorry.
Modifying the Registry can create unforeseen problems, so it's always wise to create a backup before doing so.
Run:
  1. Please navigate to Start >> All Programs >> ERUNT... double-click ERUNT from the menu.
  2. Click on OK within the pop-up menu.
  3. In the next menu under C:\WINDOWS\ERDNT\DD-MM-YYYY under Backup options make sure both the following are selected:
    • System registry.
    • Current user registry.
  4. Next click on "OK"... at the prompt... reply "Yes".
    After a short duration the Registry backup is complete! pop-up message will appear.
  5. Now click on "OK". A registry backup has now been created.
< STOP > If you did not successfully complete this step. < STOP > Do not continue with any other steps, post back and let me know!

Step 2.
Boot XP to Safe Mode
Make sure you have downloaded anything you need... You should already have Rkill and MBAM...
  1. Restart your computer.
  2. Continually tap the F8 key (usually)... as your computer is booting (when menu appears).
    The key used for your computer may be different... F8 is commonly the key used.
  3. Use up-arrow key to select "Safe Mode with Networking" and press Enter.
      If you have a multiple boot system (more than 1 OS installed) or you have Recovery Console installed...
      you will be shown the multi boot screen.
    • Highlight the OS you want to start.
    • Press Enter
  4. Once the system starts ...it will show various files/drivers being loaded. Windows will load your desktop.
  5. Reply "Yes" to the Safe Mode startup, if prompted.

Step 3.
Rkill
You should still have this on your desktop, if so, ignore the download instructions.
Note: If your security software warns about Rkill, please ignore and allow the download to continue.
Please download Rkill... by Grinler. Save it to your Desktop.
Alternate download links: Two, Three or Four

  1. Double click on the Rkill Desktop icon.
  2. A command window will open then disappear upon completion, this is normal.
    1. If this does not happen... delete the file, then download and use the next link provided.
    2. If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    Do not reboot your machine until asked to do so. If no version of Rkill would run, please let me know.
    When finished, Notepad will open with a log file, automatically saved at C:\rkill.log.
  3. Please copy and paste the contents of the rkill.log file, in your next reply.
    Please leave Rkill on the Desktop unless instructed otherwise.
Note: If you get an alert that Rkill is infected, ignore it. The alert is a fake warning given by the rogue software, trying to "protect" itself from being terminated or removed. If you see such a warning, leave the warning on the screen, then run Rkill again. By not closing the warning, this sometimes allows you to bypass the malware's attempt to protect itself, so that Rkill can perform its routine.


Step 4.
Malwarebytes' Anti-Malware
  1. Please start MBAM (Malwarebytes' Anti-Malware) again.
  2. Press the Update tab.. then press the Check for Updates...button. <<---Important!
    Once any updates are installed or you get the message that you are up-to-date
  3. Press the Scanner tab...
  4. Select FULL SCAN this time... then press the Scan...button. This scan will take a while, so please be patient.
    When the scan finishes...
  5. Check all items except any items (if present) in the C:\System Volume Information folder... then click on Remove Selected.
  6. Let MBAM remove what it can... if there are files to be deleted on reboot... please reboot the machine so MBAM can finish the removal.
    If you rebooted, then you'll need to start MBAM again.
  7. Press the LOG... tab. Locate the most current log file.
    Please copy and paste the most recent log (from this new run) in your next reply.

Step 5.
Please include in your next reply:
  1. Any problem executing the instructions?
  2. RKILL - rkill.log contents
  3. MBAM scan results
  4. How is the computer behaving?
Thanks,
Wingman
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 16th, 2010, 6:20 pm

wingman-
no problem with the instructions. to be able to update mbam tho i had to disconnect the wireless router and plug the computer directly into the cable router. now tho when i reboot, my welcome screen gives me two choices : log in as admin or me. this is new. my boot time is over 8 mins. also, my task bar is white and looks outdated and all my screens (my computer,control panel are all white (still with icons). if i try to delete a program (just wanted to see response) it tells me it is unable or windoows installer could not be accessed or incorectly installed. oddly, it says my soluto program was last used on 7/7/2010, yet this app runs everytime i reboot.
i am anxiously awaiting your response, as this just gets curioser and curiouser.
thanks
sunny21b






This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as debra on 10/16/2010 at 17:10:45.


Services Stopped:


Processes terminated by Rkill or while it was running:


C:\Documents and Settings\debra\Desktop\rkill.com


Rkill completed on 10/16/2010 at 17:10:46.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4798

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/16/2010 5:07:17 PM
mbam-log-2010-10-16 (17-07-17).txt

Scan type: Full scan (C:\|)
Objects scanned: 254637
Time elapsed: 2 hour(s), 48 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\10DPP6O2VE (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\BSK91O3T6D (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 16th, 2010, 7:00 pm

wingman-
btw-
i had to replug the wireless router-the x box and second computer are hooked into it.
sunny 21b
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 16th, 2010, 7:07 pm

wingman-
out of curiousity-when i open services manager,try to turn on windows installer, it tells me i am working in safe mode. i'm not to my knowledge.
thanks
sunny21b
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 17th, 2010, 10:11 am

also-
no sound
this computer is not used for anything but home use
sunny21b
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 17th, 2010, 5:12 pm

Hello sunny21b,
Thank you for answering my questions. Please do not try to remove or add any programs while we are attempting to clean this computer, as instructed earlier. It would be best if the use of this computer is minimized to only these cleaning instructions, if possible.

The steps presented in these posts are for this person and machine ONLY. Do not apply these steps to your own system, without the guidance of a trained malware removal helper. Doing so, may possibly damage your system, preventing it from starting.

Please do not make any changes to your system: do not add or remove any software, run any scans or "fix" programs and/or remove any files unless instructed to do so, by me. Please read these instructions carefully before executing and then perform the steps, in the order given. If you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.
Thank you for answering my questions. This machine is not used for business purposes or connected to a business network is it?
When you tried to access the manual update site... did you try using both IE and Firefox? If you did, let me know, if you only tried IE, please try FF and see what happens, letting me know the results.

Step 1.
ERUNT - Emergency Recovery Utility NT
Please run this again, as changes may have occurred between the last run and now. Better to be safe than to be sorry.
Modifying the Registry can create unforeseen problems, so it's always wise to create a backup before doing so.
Run:
  1. Please navigate to Start >> All Programs >> ERUNT... double-click ERUNT from the menu.
  2. Click on OK within the pop-up menu.
  3. In the next menu under C:\WINDOWS\ERDNT\DD-MM-YYYY under Backup options make sure both the following are selected:
    • System registry.
    • Current user registry.
  4. Next click on "OK"... at the prompt... reply "Yes".
    After a short duration the Registry backup is complete! pop-up message will appear.
  5. Now click on "OK". A registry backup has now been created.
< STOP > If you did not successfully complete this step. < STOP > Do not continue with any other steps, post back and let me know!

Step 2.
Defogger
CD Emulator Software (Daemon Tools, Alcohol, etc) use drivers that can interfere with rootkit scans, so we'll temporarily disable them.
Disable Drivers
Please download DeFogger... by jpshortstuff. Save it to your desktop.
  1. Double click DeFogger.exe to run the tool. The application window will appear.
  2. Click the Disable button to disable your CD Emulation drivers.
  3. Click Yes to continue. A 'Finished!' message will appear. Click OK.
  4. Click OK when DeFogger asks to reboot the machine.
Do not re-enable these drivers until otherwise instructed.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Step 3.
ComboFix
Please download ImageComboFix.exe... © Copyrighted to sUBs. Save it to your desktop. <<--- IMPORTANT!! .
Alternate download sites: Mirror #2 or Mirror #3

If you previously downloaded ComboFix, please delete that version and download it again. This tool is frequently updated.

This program is a powerful tool, intended by its creator, to be "used under the guidance and supervision of trained malware removers".
Using this tool incorrectly could cause problems with your operating system... preventing it from ever starting again!


The first thing you need to do is print out How-To-Use-ComboFix. Read these instructions thoroughly.
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!

  1. Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  2. Double click the ComboFix.exe icon on your desktop to begin execution. If you receive the "Open File - Security Warning"... press Run.
  3. Press Yes to the Disclaimer prompt.
    ComboFix screen appears... preparing to run. ComboFix will now begin creating a System Restore Point and then backup your registry.
  4. If not already installed... Press Yes to the "Install Recovery Console" prompt.
  5. Press Yes at the Recovery Console installation results prompt... Even if unsuccessful, have ComboFix continue the scan.
    Do Not use your keyboard or mouse click anywhere in the ComboFix window, as this may cause the program to stall or crash!
    ComboFix will disconnect you from the Internet, may cause your desktop to disappear and also change your clock settings... this is normal, so don't worry. They will be restored when finished. The ComboFix window data will be changing with various "Stages"... completed. When finished the screen will show that a log is being created.
    ComboFix disables autorun of all CD, floppy and USB devices to assist with malware removal and increase security.
    When finished... Notepad will open ... ComboFix will produce a log file called "log.txt".
  6. Please copy/paste the contents of log.txt... in your next reply.
Do NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is a powerful tool intended by its creator to be used under the guidance and supervision of an expert, NOT for general public or personal use. Using this tool incorrectly could lead to serious problems with your operating system such as preventing it from ever starting again. This site, sUBs and myself will not be responsible for any damage caused to your machine by misusing or running ComboFix on your own. Please read Combofix's Disclaimer.

** Enable your Antivirus and Firewall, before connecting to the Internet again! **

Step 4.
Please include in your next reply:
  1. Any problem executing the instructions?
  2. Combofix - log.txt file contents.
  3. How is the computer behaving?
Thanks,
Wingman
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 18th, 2010, 10:12 am

wingman- i got this "security check"(new screen) when i was checking out article in bing/msn.when i tried to close asked me if i was sure i wanted to navigate away from page. no prob with instructions, guess i still havae some things to work out,. screens normal,sound does work. thanks, sunny21b

Ever wondered what your IQ was?
Well heres your chance to find out once and for all how smart you REALLY are! Take our IQ test to find out!

Play Frogger Now
Play frogger with 1 click download of gamevance!
Play Bubble Boomers

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 09:42 on 18/10/2010 (debra)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-



ComboFix 10-10-17.04 - debra 10/18/2010 9:50.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1506 [GMT -4:00]
Running from: c:\documents and settings\debra\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-09-18 to 2010-10-18 )))))))))))))))))))))))))))))))
.

2010-10-16 22:21 . 2008-02-15 17:45 172032 ----a-w- c:\windows\system32\igfxres.dll
2010-10-16 03:16 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-16 03:16 . 2010-10-16 03:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-16 03:16 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-15 18:00 . 2010-09-09 22:52 6084944 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{EAB4CF40-1044-4FED-8AC1-7A6429E6E694}\mpengine.dll
2010-10-10 19:24 . 2010-10-10 19:24 14808 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-10-10 19:24 . 2010-10-10 19:24 718296 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-10-07 10:22 . 2010-10-07 10:22 -------- d-----w- C:\rsit
2010-10-07 10:16 . 2010-10-07 20:31 -------- d-----w- c:\program files\ERUNT
2010-10-03 14:42 . 2010-10-03 14:42 -------- d-----w- c:\program files\ESET
2010-10-02 21:15 . 2010-10-02 21:15 -------- d-----w- C:\_OTL
2010-09-30 23:45 . 2010-09-30 23:46 -------- d-----w- c:\documents and settings\Administrator
2010-09-25 20:19 . 2010-09-25 20:23 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2010-09-24 21:47 . 2010-09-24 21:47 73728 ----a-w- c:\windows\system32\javacpl.cpl

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

------- Sigcheck -------

[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-09-26_12.13.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-06 09:49 . 2010-10-06 09:49 21880 c:\windows\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe
- 2010-09-02 21:27 . 2010-09-02 21:27 21880 c:\windows\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe
+ 2008-07-12 19:08 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
- 2008-07-12 19:08 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
+ 2008-04-14 08:00 . 2010-08-27 05:57 99840 c:\windows\system32\srvsvc.dll
- 2009-09-16 21:55 . 2009-05-26 09:01 17272 c:\windows\system32\spmsg.dll
+ 2009-09-16 21:55 . 2010-02-22 14:23 17272 c:\windows\system32\spmsg.dll
+ 2010-10-17 17:11 . 2008-10-16 20:14 30720 c:\windows\system32\ReinstallBackups\0021\DriverFiles\l251x86.sys
+ 2008-04-14 08:00 . 2010-10-18 13:48 95894 c:\windows\system32\perfc009.dat
+ 2008-04-23 00:16 . 2010-09-10 05:58 66560 c:\windows\system32\mshtmled.dll
- 2008-04-23 00:16 . 2009-03-08 09:31 66560 c:\windows\system32\mshtmled.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-07-12 19:10 . 2010-09-10 05:58 43520 c:\windows\system32\licmgr10.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 25600 c:\windows\system32\jsproxy.dll
+ 2009-04-20 22:07 . 2008-10-16 19:14 30720 c:\windows\system32\drivers\l251x86.sys
- 2009-04-20 22:07 . 2008-10-16 20:14 30720 c:\windows\system32\drivers\l251x86.sys
+ 2009-06-11 21:46 . 2010-09-10 05:58 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-06-11 21:46 . 2010-06-24 12:22 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2008-04-14 08:00 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-23 00:16 . 2009-03-08 09:31 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-04-20 01:20 . 2010-09-10 05:58 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-04-20 01:20 . 2010-06-24 12:21 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-07-12 19:10 . 2010-09-10 05:58 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-05-02 20:50 . 2010-08-26 11:08 13312 c:\windows\system32\dllcache\iecompat.dll
+ 2010-10-06 09:26 . 2010-10-13 20:00 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-20 01:24 . 2010-10-13 20:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-04-20 01:24 . 2010-09-22 09:08 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-10-06 09:26 . 2010-10-13 20:00 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-04-20 01:24 . 2010-09-22 09:08 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-03-23 09:31 . 2010-03-23 09:31 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2010-09-22 13:43 . 2010-09-22 13:43 30544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
- 2010-04-01 15:42 . 2010-04-01 15:42 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2010-09-23 19:55 . 2010-09-23 19:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-03-31 18:51 . 2010-03-31 18:51 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2010-09-23 06:26 . 2010-09-23 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-03-31 18:51 . 2010-03-31 18:51 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-23 06:26 . 2010-09-23 06:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-23 06:26 . 2010-09-23 06:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-03-31 18:51 . 2010-03-31 18:51 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-03-31 19:32 . 2010-03-31 19:32 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2010-09-23 07:17 . 2010-09-23 07:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-03-31 19:32 . 2010-03-31 19:32 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2010-09-23 07:17 . 2010-09-23 07:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 97624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\XamlBuildTask\v4.0_4.0.0.0__31bf3856ad364e35\XamlBuildTask.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 97624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\XamlBuildTask\v4.0_4.0.0.0__31bf3856ad364e35\XamlBuildTask.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 29544 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml.Hosting\v4.0_4.0.0.0__31bf3856ad364e35\System.Xaml.Hosting.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 29544 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml.Hosting\v4.0_4.0.0.0__31bf3856ad364e35\System.Xaml.Hosting.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 70040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 70040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 24928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Routing.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 24928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Routing.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 81272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.RegularExpressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 81272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.RegularExpressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 33144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 33144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 93576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 93576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 24944 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Abstractions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 24944 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Abstractions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 28024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.WasHosting\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 28024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.WasHosting\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 12168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.ServiceMoniker40\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.ServiceMoniker40.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 12168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.ServiceMoniker40\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.ServiceMoniker40.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 95592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Caching\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Caching.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 95592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Caching\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Caching.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 86888 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 86888 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 21880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Workflow.Compiler.exe
- 2010-09-02 21:27 . 2010-09-02 21:27 21880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Workflow.Compiler.exe
- 2010-09-02 21:27 . 2010-09-02 21:27 40304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\v4.0_2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 40304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\v4.0_2.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 67968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Conversion.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v4.0.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 67968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Conversion.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v4.0.dll
+ 2010-10-13 20:53 . 2010-10-13 20:53 21504 c:\windows\Installer\308910.msi
+ 2009-04-20 21:07 . 2010-10-13 19:57 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-04 23:01 . 2010-09-02 21:24 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-06-04 23:01 . 2010-09-29 17:47 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-10-17 17:12 . 2010-06-18 11:39 16896 c:\windows\ie8updates\KB2362765-IE8\iecompat.dll
+ 2010-10-13 19:56 . 2010-06-24 12:22 12800 c:\windows\ie8updates\KB2360131-IE8\xpshims.dll
+ 2010-10-13 19:56 . 2009-03-08 09:31 66560 c:\windows\ie8updates\KB2360131-IE8\mshtmled.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 55296 c:\windows\ie8updates\KB2360131-IE8\msfeedsbs.dll
+ 2010-10-13 19:56 . 2009-03-08 09:34 43008 c:\windows\ie8updates\KB2360131-IE8\licmgr10.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 25600 c:\windows\ie8updates\KB2360131-IE8\jsproxy.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_085a998e\System.Drawing.Design.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_945fd75e\CustomMarshalers.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 54784 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml.Hosting\2c1f1921083ab03b9959e5066debdbe0\System.Xaml.Hosting.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 46592 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\cd5eab31a63de65b6d752b0af5b1bfbd\System.Web.DynamicData.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\70ee6267f7bad40e8707d402277770c3\System.Web.DynamicData.Design.ni.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-06-13 03:52 . 2010-06-13 03:52 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-04-21 23:07 . 2010-08-26 12:52 5120 c:\windows\system32\xpsp4res.dll
- 2009-04-21 23:07 . 2010-07-22 05:57 5120 c:\windows\system32\xpsp4res.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2008-04-23 00:16 . 2010-06-24 12:22 916480 c:\windows\system32\wininet.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 916480 c:\windows\system32\wininet.dll
- 2008-04-14 08:00 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll
+ 2008-04-14 08:00 . 2010-08-27 08:02 119808 c:\windows\system32\t2embed.dll
+ 2008-04-14 08:00 . 2010-08-16 08:45 590848 c:\windows\system32\rpcrt4.dll
- 2008-04-14 08:00 . 2010-07-22 15:49 590848 c:\windows\system32\rpcrt4.dll
+ 2008-04-14 08:00 . 2010-10-18 13:48 526546 c:\windows\system32\perfh009.dat
+ 2008-04-23 00:16 . 2010-09-10 05:58 206848 c:\windows\system32\occache.dll
- 2008-04-23 00:16 . 2010-06-24 12:22 206848 c:\windows\system32\occache.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 611840 c:\windows\system32\mstime.dll
- 2008-04-23 00:16 . 2010-06-24 12:22 611840 c:\windows\system32\mstime.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 602112 c:\windows\system32\msfeeds.dll
+ 2008-04-14 08:00 . 2010-09-18 16:23 974848 c:\windows\system32\mfc42u.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 974848 c:\windows\system32\mfc42.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
+ 2008-07-12 19:10 . 2010-09-10 05:58 184320 c:\windows\system32\iepeers.dll
- 2008-07-12 19:10 . 2010-06-24 12:21 184320 c:\windows\system32\iepeers.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-22 03:39 . 2010-06-23 12:08 173056 c:\windows\system32\ie4uinit.exe
+ 2008-04-22 03:39 . 2010-08-26 12:22 173056 c:\windows\system32\ie4uinit.exe
- 2009-04-19 05:59 . 2010-08-12 09:19 317152 c:\windows\system32\FNTCACHE.DAT
+ 2009-04-19 05:59 . 2010-10-13 20:00 317152 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-14 08:00 . 2010-08-26 13:39 357248 c:\windows\system32\drivers\srv.sys
+ 2009-04-20 01:16 . 2010-07-12 12:55 218112 c:\windows\system32\dllcache\wordpad.exe
- 2008-04-23 00:16 . 2010-06-24 12:22 916480 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 08:00 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 08:00 . 2010-08-27 08:02 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 08:00 . 2010-08-26 13:39 357248 c:\windows\system32\dllcache\srv.sys
- 2008-04-14 08:00 . 2010-07-22 15:49 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2008-04-14 08:00 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 206848 c:\windows\system32\dllcache\occache.dll
- 2008-04-23 00:16 . 2010-06-24 12:22 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 611840 c:\windows\system32\dllcache\mstime.dll
- 2008-04-23 00:16 . 2010-06-24 12:22 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-04-20 01:20 . 2010-09-10 05:58 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-04-14 08:00 . 2010-09-18 16:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 974848 c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 08:00 . 2010-09-18 06:53 954368 c:\windows\system32\dllcache\mfc40.dll
- 2009-06-11 21:46 . 2010-06-24 12:21 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-06-11 21:46 . 2010-09-10 05:58 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2008-07-12 19:10 . 2010-06-24 12:21 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2008-07-12 19:10 . 2010-09-10 05:58 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-06-12 11:48 . 2010-06-24 12:21 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-06-12 11:48 . 2010-09-10 05:58 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-22 03:39 . 2010-06-23 12:08 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-22 03:39 . 2010-08-26 12:22 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 08:00 . 2008-04-14 08:00 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 08:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 08:00 . 2010-09-01 11:51 285824 c:\windows\system32\dllcache\atmfd.dll
- 2008-04-14 08:00 . 2008-04-14 08:00 617472 c:\windows\system32\comctl32.dll
+ 2008-04-14 08:00 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
+ 2008-04-14 08:00 . 2010-09-01 11:51 285824 c:\windows\system32\atmfd.dll
- 2010-03-23 09:31 . 2010-03-23 09:31 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2010-09-22 13:43 . 2010-09-22 13:43 435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2010-09-23 06:26 . 2010-09-23 06:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-03-31 18:51 . 2010-03-31 18:51 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-03-31 18:49 . 2010-03-31 18:49 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2010-09-23 06:25 . 2010-09-23 06:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2010-09-23 07:17 . 2010-09-23 07:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2010-03-31 19:32 . 2010-03-31 19:32 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 431984 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 431984 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 511344 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 511344 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 826208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 826208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 321912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 321912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 137568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 137568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 132464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 132464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 237928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 237928 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 316272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 316272 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 170872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activation.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 170872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activation.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 683368 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 683368 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 178040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 178040 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 804720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 804720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 587624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 587624 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 220024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v4.0.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 220024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v4.0.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 107376 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 107376 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 714600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 714600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 498520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 498520 c:\windows\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 495984 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 495984 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-09-24 01:02 . 2010-09-24 01:02 798208 c:\windows\Installer\130e41.msp
+ 2010-10-10 19:31 . 2010-10-10 19:31 807936 c:\windows\Installer\10f2fe.msi
+ 2009-04-20 21:07 . 2010-10-13 19:57 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-10-17 17:12 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB2362765-IE8\spuninst\updspapi.dll
+ 2010-10-17 17:12 . 2010-02-22 14:23 231288 c:\windows\ie8updates\KB2362765-IE8\spuninst\spuninst.exe
+ 2010-10-13 19:56 . 2010-06-24 12:22 916480 c:\windows\ie8updates\KB2360131-IE8\wininet.dll
+ 2010-10-13 19:56 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2360131-IE8\spuninst\updspapi.dll
+ 2010-10-13 19:56 . 2009-05-26 09:01 231288 c:\windows\ie8updates\KB2360131-IE8\spuninst\spuninst.exe
+ 2010-10-13 19:56 . 2010-06-24 12:22 206848 c:\windows\ie8updates\KB2360131-IE8\occache.dll
+ 2010-10-13 19:56 . 2010-06-24 12:22 611840 c:\windows\ie8updates\KB2360131-IE8\mstime.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 599040 c:\windows\ie8updates\KB2360131-IE8\msfeeds.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 247808 c:\windows\ie8updates\KB2360131-IE8\ieproxy.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 184320 c:\windows\ie8updates\KB2360131-IE8\iepeers.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 743424 c:\windows\ie8updates\KB2360131-IE8\iedvtool.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 387584 c:\windows\ie8updates\KB2360131-IE8\iedkcs32.dll
+ 2010-10-13 19:56 . 2010-06-23 12:08 173056 c:\windows\ie8updates\KB2360131-IE8\ie4uinit.exe
+ 2010-10-09 13:13 . 2010-10-09 13:13 737280 c:\windows\ERDNT\10-9-2010\Users\00000002\UsrClass.dat
+ 2010-10-09 13:13 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-9-2010\ERDNT.EXE
+ 2010-10-07 20:32 . 2010-10-07 20:32 737280 c:\windows\ERDNT\10-7-2010\Users\00000002\UsrClass.dat
+ 2010-10-07 10:18 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-7-2010\ERDNT.EXE
+ 2010-10-18 13:39 . 2010-10-18 13:39 745472 c:\windows\ERDNT\10-18-2010\Users\00000002\UsrClass.dat
+ 2010-10-18 13:39 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-18-2010\ERDNT.EXE
+ 2010-10-16 01:41 . 2010-10-16 01:41 741376 c:\windows\ERDNT\10-15-2010\Users\00000002\UsrClass.dat
+ 2010-10-16 01:41 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-15-2010\ERDNT.EXE
+ 2010-10-11 21:17 . 2010-10-11 21:17 737280 c:\windows\ERDNT\10-11-2010\Users\00000002\UsrClass.dat
+ 2010-10-11 21:17 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-11-2010\ERDNT.EXE
+ 2010-10-10 19:18 . 2010-10-10 19:18 737280 c:\windows\ERDNT\10-10-2010\Users\00000002\UsrClass.dat
+ 2010-10-10 19:18 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-10-2010\ERDNT.EXE
+ 2010-08-12 01:38 . 2010-08-12 01:38 261632 c:\windows\assembly\temp\HM65E0M8UF\System.Transactions.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_88197fc6\System.Drawing.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_aa2c5ab5\System.Drawing.Design.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_654cdd17\CustomMarshalers.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 858112 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\949f003f46907061d419194bbab1e969\System.Web.Extensions.Design.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 332288 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity\ead4acbace0206d097bcb7e3554ee30e\System.Web.Entity.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 296448 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity.D#\c118c9ff40f0b77579b35ba90bb97813\System.Web.Entity.Design.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 705536 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\657e5ae30667f5bd383b6eab0ba930e8\System.Web.DynamicData.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 256512 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\de6b964c2e8db3ee167093e5049cccc2\System.Web.DataVisualization.Design.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 421888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\fc01c3cc005c3d93bf3d18a499c146ea\System.ServiceModel.Activation.ni.dll
+ 2010-10-06 22:04 . 2010-10-06 22:04 767488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\e64beb56d931b885a37803e5a67e42f9\System.Runtime.Remoting.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 499712 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\f39fc502f046bf7eb96bf99cd86cffb6\System.Data.Services.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 471040 c:\windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\798be93e1d4264f21ba138e3bc1b9553\ComSvcConfig.ni.exe
+ 2010-10-06 22:03 . 2010-10-06 22:03 842752 c:\windows\assembly\NativeImages_v4.0.30319_32\AspNetMMCExt\d32865ba4e0933c13913a7d52ae17eea\AspNetMMCExt.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\cc98a0bb34f05eb3bc30429130b7ba6f\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ccdaee504d3494430b0751dea03acb7b\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2010-10-06 22:02 . 2010-10-06 22:02 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a52489428fbe6cbaf074de2e3e547076\WindowsLive.Writer.HtmlParser.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\510eaad39eb70b9144379f5320ba2ef4\WindowsLive.Writer.BlogClient.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\7f9a1ae146571025fd49914b5c71a39b\System.Web.Routing.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\b1646e54b708b9824f4193f87eb00c0e\System.Web.Extensions.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\504a93e73da77c502ecf98bfdfc1485e\System.Web.Entity.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f22334fbd9497d79448fffef515ae0cc\System.Web.Entity.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\af5452305588da228a74e30324681d20\System.Web.DynamicData.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\9d9bca1a8993c427984aa1bc9c165a33\System.Web.Abstractions.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a140e8da81b3af34c864ad851fe150fd\System.Runtime.Remoting.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\165bd290e518b9397ca55192985fdee3\System.Data.Entity.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\72d3aacfca2e1ce835c210f5a1decb36\ServiceModelReg.ni.exe
+ 2010-10-06 22:02 . 2010-10-06 22:02 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\af4a3ae6d5c1cafa57002beb487b8d7a\AspNetMMCExt.ni.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-10-13 07:19 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2008-04-14 08:00 . 2010-08-31 13:42 1852800 c:\windows\system32\win32k.sys
+ 2008-04-23 00:16 . 2010-09-10 05:58 1210880 c:\windows\system32\urlmon.dll
+ 2008-04-14 08:00 . 2010-07-16 12:05 1288192 c:\windows\system32\ole32.dll
+ 2008-04-23 22:16 . 2010-09-10 05:58 5957120 c:\windows\system32\mshtml.dll
+ 2008-04-23 00:16 . 2010-09-10 05:58 1986560 c:\windows\system32\iertutil.dll
- 2008-04-23 00:16 . 2010-06-24 12:21 1986560 c:\windows\system32\iertutil.dll
+ 2008-04-14 08:00 . 2010-08-31 13:42 1852800 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-23 00:16 . 2010-09-10 05:58 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 08:00 . 2010-07-16 12:05 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2008-04-23 22:16 . 2010-09-10 05:58 5957120 c:\windows\system32\dllcache\mshtml.dll
- 2009-04-20 01:20 . 2010-06-24 12:21 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2009-04-20 01:20 . 2010-09-10 05:58 1986560 c:\windows\system32\dllcache\iertutil.dll
- 2010-03-18 20:47 . 2010-03-18 20:47 1836904 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2010-09-22 09:55 . 2010-09-22 09:55 1836904 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2010-09-22 09:55 . 2010-09-22 09:55 5176144 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.dll
- 2010-03-23 09:32 . 2010-03-23 09:32 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-09-22 13:44 . 2010-09-22 13:44 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
- 2010-04-01 15:42 . 2010-04-01 15:42 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2010-09-23 19:55 . 2010-09-23 19:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-04-01 15:42 . 2010-04-01 15:42 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-23 19:55 . 2010-09-23 19:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-23 06:26 . 2010-09-23 06:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-03-31 18:50 . 2010-03-31 18:50 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2010-09-23 06:25 . 2010-09-23 06:25 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2010-04-01 15:42 . 2010-04-01 15:42 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2010-09-23 19:55 . 2010-09-23 19:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1587064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1587064 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1070960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1070960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1836904 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1836904 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1697144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1697144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 5078360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 5078360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1327968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1327968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 1064816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
- 2010-09-02 21:27 . 2010-09-02 21:27 1064816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
+ 2010-10-06 09:49 . 2010-10-06 09:49 5176144 c:\windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-08-13 22:01 . 2010-08-13 22:01 8993280 c:\windows\Installer\768b01f.msp
+ 2010-08-13 21:59 . 2010-08-13 21:59 8182272 c:\windows\Installer\768b009.msp
+ 2010-08-13 22:02 . 2010-08-13 22:02 2545664 c:\windows\Installer\768aff3.msp
+ 2010-08-13 22:00 . 2010-08-13 22:00 9404928 c:\windows\Installer\768afdd.msp
+ 2010-09-17 10:06 . 2010-09-17 10:06 3355648 c:\windows\Installer\768afc6.msp
+ 2010-09-22 19:02 . 2010-09-22 19:02 4076032 c:\windows\Installer\130e49.msp
+ 2010-09-23 11:39 . 2010-09-23 11:39 4265472 c:\windows\Installer\130e3a.msp
+ 2010-10-10 19:33 . 2010-10-10 19:33 9472000 c:\windows\Installer\10f5ad.msi
+ 2009-04-20 21:07 . 2010-10-13 19:57 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-04-20 21:07 . 2010-09-15 20:42 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-20 21:07 . 2010-10-13 19:57 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-10-13 19:56 . 2010-06-24 12:22 1210368 c:\windows\ie8updates\KB2360131-IE8\urlmon.dll
+ 2010-10-13 19:56 . 2010-06-24 12:22 5951488 c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
+ 2010-10-13 19:56 . 2010-06-24 12:21 1986560 c:\windows\ie8updates\KB2360131-IE8\iertutil.dll
+ 2010-10-09 13:13 . 2010-10-09 13:13 7786496 c:\windows\ERDNT\10-9-2010\Users\00000001\ntuser.dat
+ 2010-10-07 20:32 . 2010-10-07 20:32 7786496 c:\windows\ERDNT\10-7-2010\Users\00000001\ntuser.dat
+ 2010-10-18 13:39 . 2010-10-18 13:39 7811072 c:\windows\ERDNT\10-18-2010\Users\00000001\ntuser.dat
+ 2010-10-16 01:41 . 2010-10-16 01:41 7798784 c:\windows\ERDNT\10-15-2010\Users\00000001\ntuser.dat
+ 2010-10-11 21:17 . 2010-10-11 21:17 7798784 c:\windows\ERDNT\10-11-2010\Users\00000001\ntuser.dat
+ 2010-10-10 19:18 . 2010-10-10 19:18 7798784 c:\windows\ERDNT\10-10-2010\Users\00000001\ntuser.dat
+ 2010-08-12 01:38 . 2010-08-12 01:38 2933248 c:\windows\assembly\temp\WYUEMU2C74\System.Data.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_c0c6c68a\System.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b5328f71\System.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_2cf2d5a1\System.Xml.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_161ff49c\System.Xml.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b64493fb\System.Windows.Forms.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_82e9bb7d\System.Windows.Forms.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_f777d7c5\System.Drawing.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_885b175a\System.Design.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_366eca5e\System.Design.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_af13929e\mscorlib.dll
+ 2010-10-06 09:47 . 2010-10-06 09:47 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2c6e6f1b\mscorlib.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 1203712 c:\windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\86cd79a8f3b4991e6567336f72bafe8f\System.WorkflowServices.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 1956352 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\edb095b3941144f54611595814e5a00b\System.Workflow.Runtime.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 2839552 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\cddda284ac13b4781173e3683e311f78\System.Workflow.Activities.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 1864704 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\a3127da357e08b1231dc81b1cc1ca3e6\System.Web.Services.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 2324992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Mobile\8f4da4fb8ed932f1859dde85f3166401\System.Web.Mobile.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 3079168 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\d0739e461cfbacb33fcc425823d95cde\System.Web.Extensions.ni.dll
+ 2010-10-06 22:08 . 2010-10-06 22:08 4429312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\f9fd93051344ba6d8f917632d9279c46\System.Web.DataVisualization.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 1046528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\786c1e70a93b5b2b8f38fb2ad4986129\System.ServiceModel.Web.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 2008576 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\f2aa6c7df6b0aa0c834a8009c501e239\System.Data.Services.ni.dll
+ 2010-10-06 22:07 . 2010-10-06 22:07 1398272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity.#\35cffaf2cf00f5b124336d86cf311558\System.Data.Entity.Design.ni.dll
+ 2010-10-06 22:04 . 2010-10-06 22:04 1133056 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\d75dacd6d5dfbe603f76397bdcd7ce27\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2010-10-06 22:02 . 2010-10-06 22:02 2002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a195431bdc3af72a16ec93f83edf4461\WindowsLive.Writer.CoreServices.ni.dll
+ 2010-10-06 22:02 . 2010-10-06 22:02 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\76031ae8240c17333d5fef398ef2b550\WindowsLive.Writer.PostEditor.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bec60fe2e934a6284224ab45b0e981e2\System.WorkflowServices.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\09da139c48e2f5e76994a5c0f2e5b19e\System.Workflow.Runtime.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\6809417da74ff937e18b3034f1eac2f2\System.Workflow.ComponentModel.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\6c91ee82035d30efa8893e7b0396bbb0\System.Workflow.Activities.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\181254ba0cb690decedb950fd26d7bea\System.Web.Services.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4200f716e9a41cb91d17516ba864e586\System.Web.Mobile.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\da367bc2ecf2c9c5b4f858b6dba9e2ea\System.Web.Extensions.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\8e34e273d036b7468fc4e951a1fde437\System.ServiceModel.Web.ni.dll
+ 2010-10-06 22:02 . 2010-10-06 22:02 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\095bb4f033374647b6d66c51f16bb886\System.IdentityModel.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\b8c9267d87b7358e1a5f00bf1572c313\System.Data.Services.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\a27783547338dbebf84101a685ba641b\Microsoft.VisualBasic.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 1609728 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\adca7827958ca8958a599d82143dce51\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2009-04-20 22:12 . 2009-04-20 22:12 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-10-06 09:48 . 2010-10-06 09:48 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-08-12 01:38 . 2010-08-12 01:38 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-06-13 03:52 . 2010-06-13 03:52 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2010-10-06 09:46 . 2010-10-06 09:46 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-06-13 03:52 . 2010-06-13 03:52 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-07-12 19:25 . 2009-07-14 03:43 10841088 c:\windows\system32\wmp.dll
+ 2008-07-12 19:25 . 2010-08-26 03:36 10841088 c:\windows\system32\wmp.dll
+ 2009-04-20 21:36 . 2010-10-13 19:54 35385288 c:\windows\system32\MRT.exe
+ 2008-04-23 00:16 . 2010-09-10 05:58 11080192 c:\windows\system32\ieframe.dll
- 2008-07-12 19:25 . 2009-07-14 03:43 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2008-07-12 19:25 . 2010-08-26 03:36 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2009-04-20 01:20 . 2010-09-10 05:58 11080192 c:\windows\system32\dllcache\ieframe.dll
+ 2010-09-24 18:08 . 2010-09-24 18:08 11430400 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp
+ 2010-09-29 17:47 . 2010-09-29 17:47 20303872 c:\windows\Installer\1d3d318.msp
+ 2010-09-24 11:08 . 2010-09-24 11:08 17518080 c:\windows\Installer\130e31.msp
+ 2010-10-13 19:56 . 2010-06-24 21:51 11077120 c:\windows\ie8updates\KB2360131-IE8\ieframe.dll
+ 2010-10-06 22:04 . 2010-10-06 22:04 11917312 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web\8a400489077afe13c171674cd68850cb\System.Web.ni.dll
+ 2010-10-06 09:50 . 2010-10-06 09:50 10847744 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Design\0fedf245cd0239816f52fe60ee4e18b4\System.Design.ni.dll
+ 2010-10-06 22:03 . 2010-10-06 22:03 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\41f436dae3c8146752d06130f7331527\System.Web.ni.dll
+ 2010-10-06 22:02 . 2010-10-06 22:02 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\75aeb590008d6e166f7be18f935c52d2\System.ServiceModel.ni.dll
+ 2010-10-06 09:50 . 2010-10-06 09:50 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\fdc42078fd10e4dc8b05087900c63977\System.Design.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Soluto\\Soluto.exe"=
"c:\\Program Files\\Soluto\\SolutoService.exe"=
"c:\\Program Files\\Soluto\\SolutoConsole.exe"=
"c:\\Program Files\\Soluto\\SolutoUpdateService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [8/31/2009 9:02 AM 46080]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [6/17/2010 7:14 PM 338464]
R2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [11/8/2006 3:49 AM 16384]
R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [11/8/2006 3:50 AM 37888]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [8/31/2009 9:02 AM 56960]
R3 UBFWNet;Unibrain 1394 FireNet Adapter NT Driver;c:\windows\system32\drivers\ubfwnet.sys [12/5/2006 3:37 AM 24576]
R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [11/30/2006 4:25 AM 91648]
S0 PCGenFAM;PCGenFAM;c:\windows\system32\drivers\PCGenFAM.sys [6/21/2010 9:29 AM 179656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/2/2009 4:28 PM 1684736]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [12/26/2009 2:53 PM 18560]
S3 gupdate1ca29aea165fa46;Google Update Service (gupdate1ca29aea165fa46);c:\program files\Google\Update\GoogleUpdate.exe [8/30/2009 4:15 PM 133104]
S3 LSICIMProvider;LSICIMProvider;c:\program files\LSICim\javaserv.exe [8/31/2009 9:41 AM 69632]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/14/2008 4:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-08-16 17:43 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 20:15]

2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-30 20:15]

2010-10-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2010-10-18 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]

2010-10-18 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2010-09-07 20:45]

2010-10-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-492894223-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 07:02]

2010-10-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-492894223-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 07:02]

2010-10-17 c:\windows\Tasks\User_Feed_Synchronization-{10F31AF9-7D8F-44B2-935E-1AEE982D53D5}.job
- c:\windows\system32\msfeedssync.exe [2008-07-12 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
Trusted Zone: mbamupdates.com\data-cdn
FF - ProfilePath - c:\documents and settings\debra\Application Data\Mozilla\Firefox\Profiles\xycdoetz.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\debra\Application Data\Mozilla\Firefox\Profiles\xycdoetz.default\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}\components\billeotoolbar.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\debra\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\debra\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.01.06c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1606980848-492894223-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(660)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-10-18 09:55:42
ComboFix-quarantined-files.txt 2010-10-18 13:55
ComboFix2.txt 2010-10-02 21:29
ComboFix3.txt 2010-09-26 14:49
ComboFix4.txt 2010-09-26 12:14

Pre-Run: 190,344,409,088 bytes free
Post-Run: 190,390,812,672 bytes free

- - End Of File - - 76524AF72F1AEEA5E4632CDEEDF1D20D
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 18th, 2010, 7:29 pm

Hello sunny21b,

i got this "security check"(new screen) when i was checking out article in bing/msn.when i tried to close asked me if i was sure i wanted to navigate away from page. no prob with instructions, guess i still havae some things to work out,. screens normal,sound does work. thanks, sunny21b
This seems like a forced pop-up that asks for verification that you "really" want to leave the web page. These are normal type nuisance pop-ups and not necessarily malware. Your screens are normal. You have sound.These are all good signs. :) Some web sites have pop-ups to other products... these can be controlled by your browser's pop up blocker. The more strict the blocks, less pop ups.
You can set your pop-up blocker to a high level, to minimize the number of pop-ups.

Ever wondered what your IQ was?
Well heres your chance to find out once and for all how smart you REALLY are! Take our IQ test to find out!

Play Frogger Now
Play frogger with 1 click download of gamevance!
Play Bubble Boomers
What is this? Are these the pop-ups you saw or ???

Outside of these pop-ups ... how is the computer behaving?
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA

Re: help with malware removal just added uninstall list

Unread postby sunny21b » October 19th, 2010, 5:07 pm

wingman-
that quote was on a pop up page. when i navigated away from it "security check" started running a virus scan on the computer.
okay, this did not make me happy...someone not me in the house thooughfully installed drivermax and updated my drivers...now my hibernate screen does not want to wake up. i have to "nudge" my on/off button and the welcome screen is a little shimmery at first.
i already gave the don't touch speech again..but now what? also, if this bugger is clean, how do i keep it that way??i love all your help and attention, but i'm pretty sure others need your help too!!!
thanks
sunny21b
sunny21b
Regular Member
 
Posts: 42
Joined: September 21st, 2010, 3:02 pm

Re: help with malware removal just added uninstall list

Unread postby Wingman » October 19th, 2010, 6:03 pm

Hello sunny21b,

There should not be any additions or removals from the computer unless I direct you to do it. Trying to deal with malware removal is hard enough without trying to manage a moving target.
It's hard when others want to use the computer but it is necessary to keep changes at a minimum.
Let's run some scans to check if anything is lurking in the corners.

The steps presented in these posts are for this person and machine ONLY. Do not apply these steps to your own system, without the guidance of a trained malware removal helper. Doing so, may possibly damage your system, preventing it from starting.

Please do not make any changes to your system: do not add or remove any software, run any scans or "fix" programs and/or remove any files unless instructed to do so, by me. Please read these instructions carefully before executing and then perform the steps, in the order given. If you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.
Thank you for answering my questions. This machine is not used for business purposes or connected to a business network is it?
When you tried to access the manual update site... did you try using both IE and Firefox? If you did, let me know, if you only tried IE, please try FF and see what happens, letting me know the results.

Step 1.
ERUNT - Emergency Recovery Utility NT
Please run this again, as changes may have occurred between the last run and now. Better to be safe than to be sorry.
Modifying the Registry can create unforeseen problems, so it's always wise to create a backup before doing so.
Run:
  1. Please navigate to Start >> All Programs >> ERUNT... double-click ERUNT from the menu.
  2. Click on OK within the pop-up menu.
  3. In the next menu under C:\WINDOWS\ERDNT\DD-MM-YYYY under Backup options make sure both the following are selected:
    • System registry.
    • Current user registry.
  4. Next click on "OK"... at the prompt... reply "Yes".
    After a short duration the Registry backup is complete! pop-up message will appear.
  5. Now click on "OK". A registry backup has now been created.
< STOP > If you did not successfully complete this step. < STOP > Do not continue with any other steps, post back and let me know!

Step 2.
Malwarebytes' Anti-Malware
  1. Please start MBAM (Malwarebytes' Anti-Malware) again.
  2. Press the Update tab.. then press the Check for Updates...button. <<---Important!
    Once any updates are installed or you get the message that you are up-to-date
  3. Press the Scanner tab...
  4. Select FULL SCAN this time... then press the Scan...button. This scan will take a while, so please be patient.
    When the scan finishes...
  5. Check all items except any items (if present) in the C:\System Volume Information folder... then click on Remove Selected.
  6. Let MBAM remove what it can... if there are files to be deleted on reboot... please reboot the machine so MBAM can finish the removal.
    If you rebooted, then you'll need to start MBAM again.
  7. Press the LOG... tab. Locate the most current log file.
    Please copy and paste the most recent log (from this new run) in your next reply.

Step 3.
Kaspersky Online Scanner.
Please go to Kaspersky Online Virus Scanner © Kaspersky Lab to perform an online antivirus scan.
  1. Read the "Advantages - Requirements and Limitations" then press... the ACCEPT...button.
    The latest program and definition files will be downloaded. It takes time, please be patient, let it finish.
  2. Once the files have been downloaded, click on the SETTINGS...button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the SAVE...button, if you made any changes.
  3. Now under the Scan section on the left:
      Select My Computer
    The program will start scanning your system. This takes a while, be patient... let it run.
    Once the scan is complete it will display if your system has been infected.
  4. Save the scan results as a Text file ... save it to your desktop.
  5. Copy and paste the saved scan results file in your next reply.

Step 4.
RSIT (Random's System Information Tool)
You need to be connected to the Internet, so RSIT can download HijackThis, if needed.
  1. Double click on RSIT.exe to run it... read the disc
    You should still have this program on your desktop. If so, just ignore the download instructions.
    Please download RSIT by random/random... save it to your desktop.

    Attention!
    In order for both info and log files to be produced again, I need you to delete the existing RSIT folder:
  2. C:\RSIT <-- delete this entire folder , then...

  3. Double click on RSIT.exe to run it.
  4. Please read the disclaimer... click on Continue.
    RSIT will start running. When done... 2 (Notepad) text files...will be produced.
    The first one, "log.txt", <<will be maximized... the second one, "info.txt", <<will be minimized.
    These log files can be found in the C:\RSIT folder
  5. Please post both... "log.txt" and "info.txt", file contents in your next reply.

Step 5.
Please include in your next reply:
  1. Any problem executing the instructions?
  2. MBAM scan results.
  3. KAS online scan results.
  4. How is the computer behaving?
Thanks,
Wingman
User avatar
Wingman
Admin/Teacher
Admin/Teacher
 
Posts: 14347
Joined: July 1st, 2008, 1:34 pm
Location: East Coast, USA
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 329 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware