Question

About:blank- a new twist?

Asked by: pforbin

I have been unable to find this particular variation of the about:blank issue posted anywhere.
1) Small "about:blank" window opens when opening a new web page.
2) After closing the window, another pops up saying: "this page has an unspecified security risk, would you like to continue?" This can be closed with several clicks on either yes or no.
3)After tha window closes, a script error wndow pops up.

I can still browse the web and use the computer, but it's slow for sure. The other issue that may or may not be related to this is after searching with Google and clicking on one of the search results, it re-directs me to a scam virus page, or search page. If I cut and paste the link, however, it will take me there just fine.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-10-10 at 08:04:15ID24801669
Tags

XP- adware issue

Topics

Windows XP Operating System

,

Anti-Spyware

Participating Experts
4
Points
500
Comments
28

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Unspecified error
    hi, i dont get it: Microsoft JET Database Engine error '80004005' Unspecified error /neo33/test/header.asp, line 3 when i run this: <%Dim Conn1, RS1 set conn1=Server.CreateObject("ADODB.Connection") conn1.open "Provider=Microsoft.Jet.OLEDB.4.0;Data ...
  2. unspecified error
    I am using the following code, Set cn = Server.CreateObject("ADODB.Connection") cn.Open "DBQ=" & Server.MapPath(exceldb) & ";" & _ "DRIVER={Microsoft Excel Driver (*.xls)};" and get the following error; Error Type: Prov...
  3. Vigenere Cipher - variation
    I need a variation of the Vigenere Cipher http://delphi.about.com/od/fullcodeprojects/a/vigenere-cipher-delphi-implementation-fdac-49.htm which will take flags that turn on and off options I would like it to default to just the original Vigenere Cipher using the capital c...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: optomaPosted on 2009-10-10 at 08:37:57ID: 25542642

Could you download this live cd and run its scan.
It is in iso/image format so you will have to burn it to a cd and then let your machine boot to that cd
Kaspersky live cd http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/

 

by: akahanPosted on 2009-10-10 at 10:17:39ID: 25542920

You are infected with malware.  The suggestion from optoma was good; if you're unable to burn an ISO, try downloading and running Malwarebytes, from www.malwarebytes.org   Let it do a COMPLETE scan, and then follow the directions it provides when it's done.

 

by: pforbinPosted on 2009-10-10 at 10:44:09ID: 25543029

I am downloading what optoma suggested, wil I have o bn it to a disk, or will it scan from the file?

FYI: I have tried the following already with no luck..

Spybot, Malware Bytes, Ad-aware

 

by: pforbinPosted on 2009-10-10 at 10:45:26ID: 25543034

Sorry, I didn't read thoroughly. I will try downloaing and burning now.

 

by: pforbinPosted on 2009-10-10 at 20:04:12ID: 25544742

Okay, I got the disk burned successfully. You said to boot from the disk, which I assume means hit F12 at start-up? If this is the case, for some reason I can't get that boot menu to load. I hit F12 repeatedly, but it boots normally and loads windows. What next? Thanks.

 

by: rpggamergirlPosted on 2009-10-11 at 00:17:40ID: 25545141

"after searching with Google and clicking on one of the search results, it re-directs me to a scam virus page,"

Search redirects when clicking on links, isn't necessarily mean the system is infected as the case below:

"The ads served by Bing and Google along with your search results are linking  more and more often to sites trying to infect your machine."

Sponsored search results lead to malware:
http://windowssecrets.com/2009/10/08/01-Sponsored-search-results-lead-to-malware




BUT, It's also possible that the system is infected, so use Combofix if you already tried MalwareBytes:
Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
(If it doesn't run, re-download and rename before saving to your desktop)

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: optomaPosted on 2009-10-11 at 03:06:01ID: 25545405

If it wont respond to "f12" try cold booting the machine:
Unplug the machine from the mains for roughly three minutes (when machine is powered down). Plug it back in and try again.

 

by: rpggamergirlPosted on 2009-10-11 at 05:23:14ID: 25545689

I would suggest that before you head for a LiveCD or slaving the drive(if the pc is infected) try running scans while windows is active.
One of the cons when slaving or using LiveCD is IF the bad file is removed and the loading point is left behind it can sometimes render the pc unbootable depending on how the nasties hook themselves.

Slaving and or using LIveCD is a very good idea when the pc is already unbootable or if no scanners are able to run. You haven't try other tools that are more effective like Combofix.

 

by: pforbinPosted on 2009-10-11 at 09:06:11ID: 25546361

Here's the combofix results...

ComboFix 09-10-10.02 - Pete 2009-10-11  8:46.3.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1022.613 [GMT -7:00]
Running from: c:\documents and settings\Pete\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
c:\documents and settings\All Users\Application Data\peqec.bat
c:\documents and settings\All Users\Documents\aquqinix.bat
c:\documents and settings\All Users\Documents\ytywu.inf
c:\documents and settings\Pete\Application Data\qepoty.inf
c:\documents and settings\Pete\Local Settings\Application Data\edeg.inf
c:\documents and settings\Pete\Local Settings\Application Data\qage.reg
c:\windows\adaway.lic
c:\windows\ihuvig.scr
c:\windows\kb913800.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\oqydyl.bat
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tlcwkbxi.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
 
c:\windows\system32\ws2_32.dll . . . is infected!!
 
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
-------\Legacy_TDSSSERV
-------\Service_TDSSserv
 
 
(((((((((((((((((((((((((   Files Created from 2009-09-11 to 2009-10-11  )))))))))))))))))))))))))))))))
.
 
2009-10-10 14:55 . 2009-10-10 14:47	15688	----a-w-	c:\windows\system32\lsdelete.exe
2009-10-10 14:47 . 2009-07-03 14:49	64160	----a-w-	c:\windows\system32\drivers\Lbd.sys
2009-10-10 14:46 . 2009-10-10 14:46	--------	dc-h--w-	c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-10-10 14:29 . 2008-10-16 21:06	268648	----a-w-	c:\windows\system32\mucltui.dll
2009-10-10 14:29 . 2008-10-16 21:06	208744	----a-w-	c:\windows\system32\muweb.dll
2009-10-10 05:35 . 2008-11-08 01:55	16928	------w-	c:\windows\system32\spmsgXP_2k3.dll
2009-10-10 05:34 . 2009-10-10 05:35	--------	d-----w-	c:\program files\Zune
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\dllcache\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 10:49	62976	------w-	c:\windows\system32\dllcache\cdrom.sys
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\imapi2.dll
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\dllcache\imapi2.dll
2009-10-10 05:28 . 2009-10-10 05:28	--------	d-----w-	c:\program files\Microsoft Silverlight
2009-10-10 05:15 . 2009-10-10 14:39	--------	d-----w-	c:\program files\Adware Away
2009-10-10 05:15 . 2009-03-14 13:48	5120	----a-w-	c:\windows\system32\drivers\Start1Driver.SYS
2009-10-10 05:10 . 2009-10-10 14:27	--------	d-----w-	c:\program files\XoftSpySE6
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf
2009-10-10 05:57 . 2009-10-10 05:57	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2009-10-09 14:29 . 2007-05-19 12:06	--------	d-----w-	c:\documents and settings\Pete\Application Data\U3
2009-10-06 05:26 . 2006-03-13 14:04	--------	d-----w-	c:\program files\Trend Micro
2009-10-02 14:15 . 2008-07-04 18:49	--------	d-----w-	c:\program files\Spybot - Search & Destroy
2009-10-02 14:14 . 2008-10-24 05:37	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2009-09-30 15:07 . 2007-03-31 13:28	--------	d-----w-	c:\program files\dl_Cats
2009-09-28 19:22 . 2008-07-06 20:13	--------	d-----w-	c:\program files\Lavasoft
2009-09-28 19:22 . 2008-07-06 20:13	--------	d-----w-	c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-10 21:54 . 2008-10-24 05:37	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2008-10-24 05:37	19160	----a-w-	c:\windows\system32\drivers\mbam.sys
2009-09-04 20:17 . 2009-09-04 20:17	447216	----a-w-	c:\windows\system32\ZuneWlanCfgSvc.exe
2009-09-04 20:16 . 2009-09-04 20:16	58592	----a-w-	c:\windows\system32\ZuneBusEnum.exe
2009-09-04 02:39 . 2009-03-15 17:36	--------	d-----w-	c:\program files\MediaMonkey
2009-09-02 07:29 . 2009-09-02 07:29	74240	----a-w-	c:\windows\system32\ZuneUsbTransport.dll
2009-09-02 07:29 . 2009-09-02 07:29	57344	----a-w-	c:\windows\system32\ZuneRegUtil.dll
2009-09-02 07:29 . 2009-09-02 07:29	18944	----a-w-	c:\windows\system32\ZuneTcp2Udp.dll
2009-09-02 07:29 . 2009-09-02 07:29	12800	----a-w-	c:\windows\system32\ZunePTDNS.dll
2009-09-02 07:29 . 2009-09-02 07:29	310784	----a-w-	c:\windows\system32\ZuneNetProxy.dll
2009-09-02 07:29 . 2009-09-02 07:29	147456	----a-w-	c:\windows\system32\ZuneMTPZ.dll
2009-09-02 07:28 . 2009-09-02 07:28	40832	----a-w-	c:\windows\system32\drivers\zumbus.sys
2009-08-28 01:15 . 2009-08-28 00:30	--------	d-----w-	c:\program files\meryse
2009-08-27 17:31 . 2009-08-27 17:31	16384	----a-w-	c:\windows\system32\drivers\DiagnosticScan.SYS
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\program files\Avira
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\documents and settings\All Users\Application Data\Avira
2009-08-24 05:26 . 2008-10-22 01:24	48152	----a-w-	c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-24 03:08 . 2009-08-23 23:10	--------	d-----w-	c:\documents and settings\All Users\Application Data\NOS
2009-08-23 20:20 . 2008-07-04 15:22	--------	d-----w-	c:\program files\a-squared Anti-Dialer
2009-08-23 17:46 . 2006-03-17 01:52	48152	----a-w-	c:\documents and settings\Pete\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\MSBuild
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\Reference Assemblies
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\Pete\Application Data\Comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\All Users\Application Data\comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\program files\COMODO
2009-08-22 01:09 . 2009-08-22 01:09	--------	d-----w-	c:\documents and settings\Ashley\Application Data\Comodo
2009-08-18 05:08 . 2008-08-16 20:07	--------	d-----w-	c:\program files\aTunes
2009-08-18 04:54 . 2009-08-18 04:46	--------	d-----w-	c:\program files\TidySongs
2009-08-18 04:47 . 2009-08-18 04:47	--------	d-----w-	c:\documents and settings\Pete\Application Data\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
2009-08-17 19:37 . 2009-08-17 19:37	1837296	----a-w-	c:\windows\system32\WUDFUpdate_01009.dll
2009-08-17 19:37 . 2009-08-17 19:37	1461992	----a-w-	c:\windows\system32\WdfCoInstaller01009.dll
2009-08-17 04:24 . 2006-04-09 20:44	7520	--sha-w-	c:\windows\system32\KGyGaAvL.sys
2009-08-17 04:24 . 2006-03-26 18:42	152	--sh--r-	c:\windows\system32\BF6708BE1C.sys
2009-08-15 20:36 . 2006-03-17 01:28	--------	d-----w-	c:\documents and settings\Pete\Application Data\Corel
2009-08-14 18:35 . 2009-08-28 02:07	23096	----a-w-	c:\windows\system32\drivers\MusCAudio.sys
2009-08-11 01:15 . 2009-08-11 01:15	0	----a-w-	c:\windows\system32\3C1.tmp
2009-08-05 09:01 . 2005-08-16 10:18	204800	----a-w-	c:\windows\system32\mswebdvd.dll
2009-07-31 17:33 . 2009-07-31 17:33	581192	----a-w-	c:\windows\system32\WinUSBCoInstaller.dll
2009-07-28 23:33 . 2009-08-26 01:37	55656	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2009-07-17 19:01 . 2005-08-16 10:18	58880	----a-w-	c:\windows\system32\atl.dll
2009-07-14 17:35 . 2009-07-14 17:35	444136	------w-	c:\windows\system32\drivers\wdf01000.sys
2009-07-14 17:35 . 2009-07-14 17:35	37608	------w-	c:\windows\system32\drivers\wdfldr.sys
2009-07-14 01:16 . 2006-09-29 00:13	39936	----a-w-	c:\windows\system32\WUDFCoinstaller.dll
2009-07-14 01:16 . 2006-09-28 22:56	567808	----a-w-	c:\windows\system32\WUDFx.dll
2009-07-14 01:16 . 2006-09-28 22:56	64512	----a-w-	c:\windows\system32\WudfSvc.dll
2009-07-14 01:14 . 2006-09-28 22:56	195584	----a-w-	c:\windows\system32\WudfHost.exe
2009-07-13 23:50 . 2006-09-28 23:00	132224	------w-	c:\windows\system32\drivers\WudfRd.sys
2009-07-13 23:50 . 2006-09-28 22:56	148480	----a-w-	c:\windows\system32\WudfPlatform.dll
2009-07-13 23:50 . 2006-09-28 22:55	91904	------w-	c:\windows\system32\drivers\WudfPf.sys
2009-07-13 17:08 . 2005-08-16 10:19	286720	----a-w-	c:\windows\system32\wmpdxm.dll
2008-10-21 02:13 . 2008-10-21 02:13	13634	----a-w-	c:\program files\Common Files\asoticy.com
2008-10-21 02:13 . 2008-10-21 02:13	12975	----a-w-	c:\program files\Common Files\etuxo.bin
2008-10-21 02:13 . 2008-10-21 02:13	10412	----a-w-	c:\program files\Common Files\vomufysutu.exe
2008-10-21 02:13 . 2008-10-21 02:13	19089	----a-w-	c:\program files\Common Files\rytinuno.lib
2008-07-07 05:18 . 2008-07-07 05:18	1292818	----a-w-	c:\program files\smartpopupblocker110.exe
2008-05-11 22:56 . 2008-05-11 22:56	241360	----a-w-	c:\program files\SmileboxInstaller.exe
2008-05-11 22:27 . 2008-05-11 22:27	550636	----a-w-	c:\program files\baku.zip
2008-05-11 22:26 . 2008-05-11 22:25	3005408	----a-w-	c:\program files\AWCSetup_Major.exe
2008-02-04 21:04 . 2008-02-04 21:03	43423968	----a-w-	c:\program files\PalmDesktopWin414e.zip
2007-06-11 20:45 . 2007-06-11 20:43	1467392	----a-w-	c:\program files\Netflix_Movie_Viewer_Installer.msi
2006-10-25 21:00 . 2006-10-25 21:00	35475296	----a-w-	c:\program files\Anonymizer_Software.exe
2006-08-05 14:26 . 2006-08-05 14:26	774144	----a-w-	c:\program files\RngInterstitial.dll
2006-08-04 03:02 . 2006-08-04 03:01	1379085	----a-w-	c:\program files\LSuperPacman.zip
2006-07-25 19:41 . 2006-07-25 19:41	524709	----a-w-	c:\program files\flac112a.exe
2006-04-14 15:12 . 2006-04-14 15:12	12754672	----a-w-	c:\program files\MP10Setup.exe
2006-04-13 01:16 . 2006-04-13 01:16	1221515	----a-w-	c:\program files\trackeraser.exe
2006-04-13 01:01 . 2006-04-13 01:01	3494992	----a-w-	c:\program files\pginstall.exe
2006-03-17 01:52 . 2006-03-17 01:52	251	----a-w-	c:\program files\wt3d.ini
.
 
------- Sigcheck -------
 
[-] 2008-04-14 . CCB61AEA9FFFD31F534528B7090B42DE . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 . CCB61AEA9FFFD31F534528B7090B42DE . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-10 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\Pete\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-14 79872]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2006-10-20 73728]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2005-03-10 28160]
 
c:\documents and settings\Pete\Start Menu\Programs\Startup\
AbsoluteShield Track Eraser.lnk - c:\program files\SysShield Tools\Track Eraser\cseraser.exe [2003-12-10 555520]
 
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-3-13 24576]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
 
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{731AC7F0-7344-4FBE-9B2E-6C5146845A04}"= "c:\windows\system32\ehmeruli.dll" [2007-03-31 319488]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
 
R0 DiagnosticScan;DiagnosticScan;c:\windows\system32\drivers\DiagnosticScan.SYS [2009-08-27 16384]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-10 64160]
R1 Start1Driver;Start1Driver;c:\windows\system32\drivers\Start1Driver.SYS [2009-10-09 5120]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-08-25 108289]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-07-03 1028432]
S2 jzcsxdjuxvkg;jzcsxdjuxvkg; [x]
S2 rdykzow;rdykzow; [x]
S3 3xHybrid;Pinnacle PCTV 110i service;c:\windows\system32\drivers\3xHybrid.sys [2006-03-28 827008]
S3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-08-27 23096]
S3 ZD1211BU(Linksys A Division of Cisco Systems Inc.);Linksys Wireless-G USB Network Adapter Driver(Linksys A Division of Cisco Systems Inc.);c:\windows\system32\drivers\ZD1211BU.sys [2008-05-11 402432]
 
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
 
2009-10-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:47]
 
2009-10-11 c:\windows\Tasks\USBCoinstallerTaskUserS-1-5-21-2875547054-3911223903-918033636-1005.job
- c:\windows\system32\USBComp4.exe [2009-06-11 14:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.live.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: plaxo.com\www
DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} - hxxps://register.creative.com/register/OCXs/CtORWebClientNoMFC.cab
.
- - - - ORPHANS REMOVED - - - -
 
SafeBoot-TDSSqaxc.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
 
 
 
**************************************************************************
 
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-11 08:58
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ... 
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
- - - - - - - > 'explorer.exe'(3572)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\ehmeruli.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\NettutBv.dll
c:\program files\Siber Systems\AI RoboForm\RoboForm.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\dlcfcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2009-10-11  9:01 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-11 16:01
ComboFix2.txt  2008-07-07 04:48
 
Pre-Run: 35,682,955,264 bytes free
Post-Run: 36,038,594,560 bytes free
 
281	--- E O F ---	2009-09-13 19:03
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
207:
208:
209:
210:
211:
212:
213:
214:
215:
216:
217:
218:
219:
220:
221:
222:
223:
224:
225:
226:
227:
228:
229:
230:
231:
232:
233:
234:
235:
236:
237:
238:
239:
240:
241:
242:
243:
244:
245:
246:
247:
248:
249:
250:
251:
252:
253:
254:
255:
256:
257:
258:
259:
260:
261:
262:
263:
264:
265:
266:
267:
268:
269:
270:
271:
272:
273:
274:
275:
276:
277:
278:
279:
280:
281:
282:
283:
284:
285:
286:
287:
288:
289:
290:
291:
292:
293:
294:
295:
296:
297:
298:
299:
300:
301:
302:
303:
304:
305:
306:
307:
308:
309:
310:
311:
312:
313:
314:
315:
316:
317:
318:
319:
320:
321:
322:
323:
324:
325:

Select allOpen in new window

 

by: rpggamergirlPosted on 2009-10-11 at 22:51:24ID: 25548805

Thanks for the log.

c:\windows\system32\ws2_32.dll . . . is infected!!

ws2_32.dll is infected and CF didn't replace it probably because the clean one found in the system is a different version:(BELOW)
[-] 2004-08-10 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll


Here's a clean copy, same version as your infected ones, SP3, ver. 5.1.2600.5512
Download   and extract it to C:\



Then run the script below:
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
------------------------------------------------------------------------
Fcopy::
C:\ws2_32.dll | c:\windows\system32\ws2_32.dll
C:\ws2_32.dll | c:\windows\ServicePackFiles\i386\ws2_32.dll


File::
c:\program files\Common Files\asoticy.com
c:\program files\Common Files\etuxo.bin
c:\program files\Common Files\vomufysutu.exe
c:\program files\Common Files\rytinuno.lib

Driver::
jzcsxdjuxvkg
rdykzow
------------------------------------------------------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.


I also suggest uninstalling Adware Away. Do you recognize all of the programs showing in the log? I haven't thoroughly checked all of them.

 

by: pforbinPosted on 2009-10-12 at 21:03:03ID: 25556864

When I click on the download link, I get a window that says "cannot display the webpage", wth a tab to diagnose the connection problem. When  I do this, it finds nothng wrong with the connection. Allother websites are displaying just fine. I also tried copying the shortcut into the address bar...same thing. I cannot get to that link.

I will uninstall ad-aware in the meantime.

 

by: rpggamergirlPosted on 2009-10-13 at 05:22:01ID: 25559132

I uploaded the zip file( ws2_32.dll) at EE-Stuff.com
http://www.ee-stuff.com/Expert/Upload/getFile.php?fid=7756

 

by: pforbinPosted on 2009-10-13 at 07:24:04ID: 25560231

Same thing, cannot display the web page. All other internet applications run fine. I am runnig a Malware Bytes scan...maye this is caused by another infection??

 

by: JonveePosted on 2009-10-13 at 09:55:31ID: 25561860

pforbin,
The E_E web page did not appear available to me either.  But it's ok now, and 'failure' was probably not due to Malware.  
However, if you try again by logging in, you should be able to download rpggamergirl's file without a problem .. i just did.

Try this >
Click on her link.
Select "Expert Area" tab.
Select "Find files for a question".
Paste the number of your thread in the box, in this case it's:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/Q_24801669.html?cid=1572#a25560231
Click "submit" button, & you can access the file for download.

Time Zone differences is the probable reason that rpggamergirl has not been able to reply to you.

 

by: rpggamergirlPosted on 2009-10-13 at 17:39:50ID: 25566213

Sorry, for the missing instructions.

Excellent work Jonvee, thanks for that, :)

 

by: pforbinPosted on 2009-10-13 at 19:03:48ID: 25566690

No worries, I appreciate everyone's help with this. I was able to download the file. I think I extracted it to the C drive, but it didn't really do anything when I extracted it. I ran the cf as instructed, and no luck. The window still pops up. Here's the log frommy latest attempt. Maybe I need to try it again?

ComboFix 09-10-10.02 - Pete 2009-10-13 17:34.4.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1022.628 [GMT -7:00]
Running from: c:\documents and settings\Pete\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Pete\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
 
FILE ::
"c:\program files\Common Files\asoticy.com"
"c:\program files\Common Files\etuxo.bin"
"c:\program files\Common Files\rytinuno.lib"
"c:\program files\Common Files\vomufysutu.exe"
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
c:\program files\Common Files\asoticy.com
c:\program files\Common Files\etuxo.bin
c:\program files\Common Files\rytinuno.lib
c:\program files\Common Files\vomufysutu.exe
 
.
--------------- FCopy ---------------
 
c:\ws2_32.dll --> c:\windows\system32\ws2_32.dll
c:\ws2_32.dll --> c:\windows\ServicePackFiles\i386\ws2_32.dll
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
-------\Service_jzcsxdjuxvkg
-------\Service_rdykzow
 
 
(((((((((((((((((((((((((   Files Created from 2009-09-14 to 2009-10-14  )))))))))))))))))))))))))))))))
.
 
2009-10-14 00:26 . 2008-04-14 12:42	82432	------w-	C:\ws2_32.dll
2009-10-12 14:47 . 2009-10-12 14:47	--------	d-sh--w-	c:\documents and settings\NetworkService\IETldCache
2009-10-10 14:29 . 2008-10-16 21:06	268648	----a-w-	c:\windows\system32\mucltui.dll
2009-10-10 14:29 . 2008-10-16 21:06	208744	----a-w-	c:\windows\system32\muweb.dll
2009-10-10 05:35 . 2008-11-08 01:55	16928	------w-	c:\windows\system32\spmsgXP_2k3.dll
2009-10-10 05:34 . 2009-10-10 05:35	--------	d-----w-	c:\program files\Zune
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\dllcache\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 10:49	62976	------w-	c:\windows\system32\dllcache\cdrom.sys
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\imapi2.dll
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\dllcache\imapi2.dll
2009-10-10 05:28 . 2009-10-10 05:28	--------	d-----w-	c:\program files\Microsoft Silverlight
2009-10-10 05:15 . 2009-10-10 14:39	--------	d-----w-	c:\program files\Adware Away
2009-10-10 05:15 . 2009-03-14 13:48	5120	----a-w-	c:\windows\system32\drivers\Start1Driver.SYS
2009-10-10 05:10 . 2009-10-10 14:27	--------	d-----w-	c:\program files\XoftSpySE6
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-14 00:30 . 2009-10-14 00:41	1610612736	----a-w-	C:\SSF3.tmp
2009-10-13 04:05 . 2008-07-06 20:13	--------	d-----w-	c:\program files\Lavasoft
2009-10-13 04:05 . 2008-07-06 20:13	--------	d-----w-	c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-11 18:34 . 2009-10-11 18:34	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf
2009-10-10 05:57 . 2009-10-10 05:57	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2009-10-09 14:29 . 2007-05-19 12:06	--------	d-----w-	c:\documents and settings\Pete\Application Data\U3
2009-10-06 05:26 . 2006-03-13 14:04	--------	d-----w-	c:\program files\Trend Micro
2009-10-02 14:15 . 2008-07-04 18:49	--------	d-----w-	c:\program files\Spybot - Search & Destroy
2009-10-02 14:14 . 2008-10-24 05:37	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2009-09-30 15:07 . 2007-03-31 13:28	--------	d-----w-	c:\program files\dl_Cats
2009-09-10 21:54 . 2008-10-24 05:37	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2008-10-24 05:37	19160	----a-w-	c:\windows\system32\drivers\mbam.sys
2009-09-04 20:17 . 2009-09-04 20:17	447216	----a-w-	c:\windows\system32\ZuneWlanCfgSvc.exe
2009-09-04 20:16 . 2009-09-04 20:16	58592	----a-w-	c:\windows\system32\ZuneBusEnum.exe
2009-09-04 02:39 . 2009-03-15 17:36	--------	d-----w-	c:\program files\MediaMonkey
2009-09-02 07:29 . 2009-09-02 07:29	74240	----a-w-	c:\windows\system32\ZuneUsbTransport.dll
2009-09-02 07:29 . 2009-09-02 07:29	57344	----a-w-	c:\windows\system32\ZuneRegUtil.dll
2009-09-02 07:29 . 2009-09-02 07:29	18944	----a-w-	c:\windows\system32\ZuneTcp2Udp.dll
2009-09-02 07:29 . 2009-09-02 07:29	12800	----a-w-	c:\windows\system32\ZunePTDNS.dll
2009-09-02 07:29 . 2009-09-02 07:29	310784	----a-w-	c:\windows\system32\ZuneNetProxy.dll
2009-09-02 07:29 . 2009-09-02 07:29	147456	----a-w-	c:\windows\system32\ZuneMTPZ.dll
2009-09-02 07:28 . 2009-09-02 07:28	40832	----a-w-	c:\windows\system32\drivers\zumbus.sys
2009-08-28 01:15 . 2009-08-28 00:30	--------	d-----w-	c:\program files\meryse
2009-08-27 17:31 . 2009-08-27 17:31	16384	----a-w-	c:\windows\system32\drivers\DiagnosticScan.SYS
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\program files\Avira
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\documents and settings\All Users\Application Data\Avira
2009-08-24 05:26 . 2008-10-22 01:24	48152	----a-w-	c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-24 03:08 . 2009-08-23 23:10	--------	d-----w-	c:\documents and settings\All Users\Application Data\NOS
2009-08-23 20:20 . 2008-07-04 15:22	--------	d-----w-	c:\program files\a-squared Anti-Dialer
2009-08-23 17:46 . 2006-03-17 01:52	48152	----a-w-	c:\documents and settings\Pete\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\MSBuild
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\Reference Assemblies
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\Pete\Application Data\Comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\All Users\Application Data\comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\program files\COMODO
2009-08-22 01:09 . 2009-08-22 01:09	--------	d-----w-	c:\documents and settings\Ashley\Application Data\Comodo
2009-08-18 05:08 . 2008-08-16 20:07	--------	d-----w-	c:\program files\aTunes
2009-08-18 04:54 . 2009-08-18 04:46	--------	d-----w-	c:\program files\TidySongs
2009-08-18 04:47 . 2009-08-18 04:47	--------	d-----w-	c:\documents and settings\Pete\Application Data\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
2009-08-17 19:37 . 2009-08-17 19:37	1837296	----a-w-	c:\windows\system32\WUDFUpdate_01009.dll
2009-08-17 19:37 . 2009-08-17 19:37	1461992	----a-w-	c:\windows\system32\WdfCoInstaller01009.dll
2009-08-17 04:24 . 2006-04-09 20:44	7520	--sha-w-	c:\windows\system32\KGyGaAvL.sys
2009-08-17 04:24 . 2006-03-26 18:42	152	--sh--r-	c:\windows\system32\BF6708BE1C.sys
2009-08-15 20:36 . 2006-03-17 01:28	--------	d-----w-	c:\documents and settings\Pete\Application Data\Corel
2009-08-14 18:35 . 2009-08-28 02:07	23096	----a-w-	c:\windows\system32\drivers\MusCAudio.sys
2009-08-11 01:15 . 2009-08-11 01:15	0	----a-w-	c:\windows\system32\3C1.tmp
2009-08-05 09:01 . 2005-08-16 10:18	204800	----a-w-	c:\windows\system32\mswebdvd.dll
2009-07-31 17:33 . 2009-07-31 17:33	581192	----a-w-	c:\windows\system32\WinUSBCoInstaller.dll
2009-07-28 23:33 . 2009-08-26 01:37	55656	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2009-07-17 19:01 . 2005-08-16 10:18	58880	----a-w-	c:\windows\system32\atl.dll
2008-07-07 05:18 . 2008-07-07 05:18	1292818	----a-w-	c:\program files\smartpopupblocker110.exe
2008-05-11 22:56 . 2008-05-11 22:56	241360	----a-w-	c:\program files\SmileboxInstaller.exe
2008-05-11 22:27 . 2008-05-11 22:27	550636	----a-w-	c:\program files\baku.zip
2008-05-11 22:26 . 2008-05-11 22:25	3005408	----a-w-	c:\program files\AWCSetup_Major.exe
2008-02-04 21:04 . 2008-02-04 21:03	43423968	----a-w-	c:\program files\PalmDesktopWin414e.zip
2007-06-11 20:45 . 2007-06-11 20:43	1467392	----a-w-	c:\program files\Netflix_Movie_Viewer_Installer.msi
2006-10-25 21:00 . 2006-10-25 21:00	35475296	----a-w-	c:\program files\Anonymizer_Software.exe
2006-08-05 14:26 . 2006-08-05 14:26	774144	----a-w-	c:\program files\RngInterstitial.dll
2006-08-04 03:02 . 2006-08-04 03:01	1379085	----a-w-	c:\program files\LSuperPacman.zip
2006-07-25 19:41 . 2006-07-25 19:41	524709	----a-w-	c:\program files\flac112a.exe
2006-04-14 15:12 . 2006-04-14 15:12	12754672	----a-w-	c:\program files\MP10Setup.exe
2006-04-13 01:16 . 2006-04-13 01:16	1221515	----a-w-	c:\program files\trackeraser.exe
2006-04-13 01:01 . 2006-04-13 01:01	3494992	----a-w-	c:\program files\pginstall.exe
2006-03-17 01:52 . 2006-03-17 01:52	251	----a-w-	c:\program files\wt3d.ini
.
 
(((((((((((((((((((((((((((((   SnapShot@2009-10-11_15.58.09   )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-08-16 10:18 . 2008-04-14 12:42	82432              c:\windows\system32\dllcache\ws2_32.dll
+ 2009-07-12 07:02 . 2009-07-12 07:02	159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2005-08-16 10:19 . 2008-06-18 12:03	938496              c:\windows\system32\WMNetmgr.dll
+ 2005-08-16 10:19 . 2007-10-28 00:40	222720              c:\windows\system32\wmasf.dll
+ 2005-08-16 10:19 . 2006-12-04 23:21	414720              c:\windows\system32\msscp.dll
- 2005-08-16 10:19 . 2006-10-19 03:03	100864              c:\windows\system32\logagent.exe
+ 2005-08-16 10:19 . 2008-06-18 08:09	100864              c:\windows\system32\logagent.exe
+ 2007-10-27 22:40 . 2007-10-28 00:40	222720              c:\windows\system32\dllcache\wmasf.dll
+ 2009-10-11 19:00 . 2009-10-11 19:00	195584              c:\windows\Installer\aa6c70.msi
+ 2005-08-16 10:19 . 2009-05-20 11:56	2458112              c:\windows\system32\WMVCore.dll
+ 2005-08-16 10:19 . 2009-05-20 11:56	2458112              c:\windows\system32\dllcache\WMVCore.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\Pete\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-14 79872]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2006-10-20 73728]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2005-03-10 28160]
 
c:\documents and settings\Pete\Start Menu\Programs\Startup\
AbsoluteShield Track Eraser.lnk - c:\program files\SysShield Tools\Track Eraser\cseraser.exe [2003-12-10 555520]
 
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-3-13 24576]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
 
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{731AC7F0-7344-4FBE-9B2E-6C5146845A04}"= "c:\windows\system32\ehmeruli.dll" [2007-03-31 319488]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
 
R0 DiagnosticScan;DiagnosticScan;c:\windows\system32\drivers\DiagnosticScan.SYS [2009-08-27 16384]
R1 Start1Driver;Start1Driver;c:\windows\system32\drivers\Start1Driver.SYS [2009-10-09 5120]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-08-25 108289]
S3 3xHybrid;Pinnacle PCTV 110i service;c:\windows\system32\drivers\3xHybrid.sys [2006-03-28 827008]
S3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-08-27 23096]
S3 ZD1211BU(Linksys A Division of Cisco Systems Inc.);Linksys Wireless-G USB Network Adapter Driver(Linksys A Division of Cisco Systems Inc.);c:\windows\system32\drivers\ZD1211BU.sys [2008-05-11 402432]
 
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
 
2009-10-14 c:\windows\Tasks\USBCoinstallerTaskUserS-1-5-21-2875547054-3911223903-918033636-1005.job
- c:\windows\system32\USBComp4.exe [2009-06-11 14:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.live.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: plaxo.com\www
DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} - hxxps://register.creative.com/register/OCXs/CtORWebClientNoMFC.cab
.
 
**************************************************************************
 
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-13 17:41
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ... 
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
- - - - - - - > 'explorer.exe'(3984)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\ehmeruli.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\NettutBv.dll
c:\program files\Siber Systems\AI RoboForm\RoboForm.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\dlcfcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2009-10-14 17:45 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-14 00:45
ComboFix2.txt  2009-10-11 16:01
ComboFix3.txt  2008-07-07 04:48
 
Pre-Run: 36,164,755,456 bytes free
Post-Run: 36,057,927,680 bytes free
 
257	--- E O F ---	2009-10-11 19:02
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
207:
208:
209:
210:
211:
212:
213:
214:
215:
216:
217:
218:
219:
220:
221:
222:
223:
224:
225:
226:
227:
228:
229:
230:
231:
232:
233:
234:
235:
236:
237:
238:
239:
240:
241:
242:
243:
244:
245:
246:
247:
248:
249:
250:
251:
252:
253:
254:
255:
256:
257:
258:
259:
260:
261:
262:
263:
264:
265:
266:
267:
268:
269:
270:
271:
272:
273:
274:
275:
276:
277:
278:
279:
280:
281:
282:
283:
284:
285:
286:
287:
288:
289:
290:
291:
292:
293:
294:
295:
296:

Select allOpen in new window

 

by: rpggamergirlPosted on 2009-10-14 at 00:35:16ID: 25568036

It extracted okay and CF replaced the infected ones.

The Adware Away is still there too.

Try running an online scan with Kaspersky and save the log, if Kaspersky doesn't find any threats then try rootkit scanners.
Kaspersky Online Scanner
http://www.kaspersky.com/virusscanner


 

by: pforbinPosted on 2009-10-14 at 07:21:52ID: 25570800

I did it again, just in case and everything seems okay. No pop-ups yet. Hmmmm, I did uninstall Adware Away, and it does not show in the list of current programs?

I will give it a day or so and make sure it's gone before awarding points...thanks so much.

 

by: rpggamergirlPosted on 2009-10-14 at 16:50:22ID: 25576281

No popups yet, that sounds good then.


<<<"I did uninstall Adware Away, and it does not show in the list of current programs?">>>

Maybe it's just the folder left then, as the line below is showing in the Combofix log.

<<< 51:  2009-10-10 05:15 . 2009-10-10 14:39      --------      d-----w-      c:\program files\Adware Away >>>



 

by: pforbinPosted on 2009-10-14 at 20:50:43ID: 25577065

You guys rock. Things are running smooth....

Points to follow.

 

by: JonveePosted on 2009-10-15 at 00:19:49ID: 25578039

No popups is good & it seems you're ok once again  .. but it was rpggamergirl that did all the work  ; )

 

by: rpggamergirlPosted on 2009-10-15 at 22:04:34ID: 25587134

<<<"but it was rpggamergirl that did all the work  ; )">>>

No, it was teamwork! :)
And there's that nice "Accept Multiple Solutions" button.

 

by: pforbinPosted on 2009-10-20 at 17:30:11ID: 25619905

Okay, sorry I was away for a few days. "blank page" is back, but not doing the same thing exactly.  It actually happens much less frequently, but still happening just the same. Occasionally windows completely freezes up and I need to re-start.

Here's the CF snippet

ComboFix 09-10-19.04 - Pete 10/20/2009 17:15.6.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1022.569 [GMT -7:00]
Running from: c:\documents and settings\Pete\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
 
(((((((((((((((((((((((((   Files Created from 2009-09-21 to 2009-10-21  )))))))))))))))))))))))))))))))
.
 
2009-10-16 22:13 . 2009-10-17 08:15	--------	d-----w-	c:\program files\Active Security
2009-10-14 00:26 . 2008-04-14 12:42	82432	------w-	C:\ws2_32.dll
2009-10-12 14:47 . 2009-10-12 14:47	--------	d-sh--w-	c:\documents and settings\NetworkService\IETldCache
2009-10-10 14:29 . 2008-10-16 21:06	268648	----a-w-	c:\windows\system32\mucltui.dll
2009-10-10 14:29 . 2008-10-16 21:06	208744	----a-w-	c:\windows\system32\muweb.dll
2009-10-10 05:35 . 2008-11-08 01:55	16928	------w-	c:\windows\system32\spmsgXP_2k3.dll
2009-10-10 05:34 . 2009-10-10 05:35	--------	d-----w-	c:\program files\Zune
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 13:25	465920	------w-	c:\windows\system32\dllcache\imapi2fs.dll
2009-10-10 05:34 . 2008-05-02 10:49	62976	------w-	c:\windows\system32\dllcache\cdrom.sys
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\imapi2.dll
2009-10-10 05:34 . 2008-05-02 13:25	317952	------w-	c:\windows\system32\dllcache\imapi2.dll
2009-10-10 05:28 . 2009-10-10 05:28	--------	d-----w-	c:\program files\Microsoft Silverlight
2009-10-10 05:15 . 2009-10-10 14:39	--------	d-----w-	c:\program files\Adware Away
2009-10-10 05:15 . 2009-03-14 13:48	5120	----a-w-	c:\windows\system32\drivers\Start1Driver.SYS
2009-10-10 05:10 . 2009-10-10 14:27	--------	d-----w-	c:\program files\XoftSpySE6
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 04:05 . 2008-07-06 20:13	--------	d-----w-	c:\program files\Lavasoft
2009-10-13 04:05 . 2008-07-06 20:13	--------	d-----w-	c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-11 18:34 . 2009-10-11 18:34	0	---ha-w-	c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
2009-10-10 05:58 . 2009-10-10 05:58	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf
2009-10-10 05:57 . 2009-10-10 05:57	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2009-10-10 05:35 . 2009-10-10 05:35	0	---ha-w-	c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2009-10-09 14:29 . 2007-05-19 12:06	--------	d-----w-	c:\documents and settings\Pete\Application Data\U3
2009-10-06 05:26 . 2006-03-13 14:04	--------	d-----w-	c:\program files\Trend Micro
2009-10-02 14:15 . 2008-07-04 18:49	--------	d-----w-	c:\program files\Spybot - Search & Destroy
2009-10-02 14:14 . 2008-10-24 05:37	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2009-09-30 15:07 . 2007-03-31 13:28	--------	d-----w-	c:\program files\dl_Cats
2009-09-11 14:18 . 2005-08-16 10:18	136192	----a-w-	c:\windows\system32\msv1_0.dll
2009-09-10 21:54 . 2008-10-24 05:37	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2008-10-24 05:37	19160	----a-w-	c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2005-08-16 10:18	58880	----a-w-	c:\windows\system32\msasn1.dll
2009-09-04 20:17 . 2009-09-04 20:17	447216	----a-w-	c:\windows\system32\ZuneWlanCfgSvc.exe
2009-09-04 20:16 . 2009-09-04 20:16	58592	----a-w-	c:\windows\system32\ZuneBusEnum.exe
2009-09-04 02:39 . 2009-03-15 17:36	--------	d-----w-	c:\program files\MediaMonkey
2009-09-02 07:29 . 2009-09-02 07:29	74240	----a-w-	c:\windows\system32\ZuneUsbTransport.dll
2009-09-02 07:29 . 2009-09-02 07:29	57344	----a-w-	c:\windows\system32\ZuneRegUtil.dll
2009-09-02 07:29 . 2009-09-02 07:29	18944	----a-w-	c:\windows\system32\ZuneTcp2Udp.dll
2009-09-02 07:29 . 2009-09-02 07:29	12800	----a-w-	c:\windows\system32\ZunePTDNS.dll
2009-09-02 07:29 . 2009-09-02 07:29	310784	----a-w-	c:\windows\system32\ZuneNetProxy.dll
2009-09-02 07:28 . 2009-09-02 07:28	40832	----a-w-	c:\windows\system32\drivers\zumbus.sys
2009-08-29 08:08 . 2005-08-16 10:18	916480	----a-w-	c:\windows\system32\wininet.dll
2009-08-28 01:15 . 2009-08-28 00:30	--------	d-----w-	c:\program files\meryse
2009-08-27 17:31 . 2009-08-27 17:31	16384	----a-w-	c:\windows\system32\drivers\DiagnosticScan.SYS
2009-08-26 08:00 . 2005-08-16 10:19	247326	----a-w-	c:\windows\system32\strmdll.dll
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\program files\Avira
2009-08-26 01:37 . 2009-08-26 01:37	--------	d-----w-	c:\documents and settings\All Users\Application Data\Avira
2009-08-24 05:26 . 2008-10-22 01:24	48152	----a-w-	c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-24 03:08 . 2009-08-23 23:10	--------	d-----w-	c:\documents and settings\All Users\Application Data\NOS
2009-08-23 20:20 . 2008-07-04 15:22	--------	d-----w-	c:\program files\a-squared Anti-Dialer
2009-08-23 17:46 . 2006-03-17 01:52	48152	----a-w-	c:\documents and settings\Pete\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\MSBuild
2009-08-23 17:27 . 2009-08-23 17:27	--------	d-----w-	c:\program files\Reference Assemblies
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\Pete\Application Data\Comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\documents and settings\All Users\Application Data\comodo
2009-08-23 17:02 . 2009-08-18 05:12	--------	d-----w-	c:\program files\COMODO
2009-08-22 01:09 . 2009-08-22 01:09	--------	d-----w-	c:\documents and settings\Ashley\Application Data\Comodo
2009-08-17 19:37 . 2009-08-17 19:37	1837296	----a-w-	c:\windows\system32\WUDFUpdate_01009.dll
2009-08-17 19:37 . 2009-08-17 19:37	1461992	----a-w-	c:\windows\system32\WdfCoInstaller01009.dll
2009-08-17 04:24 . 2006-04-09 20:44	7520	--sha-w-	c:\windows\system32\KGyGaAvL.sys
2009-08-17 04:24 . 2006-03-26 18:42	152	--sh--r-	c:\windows\system32\BF6708BE1C.sys
2009-08-14 18:35 . 2009-08-28 02:07	23096	----a-w-	c:\windows\system32\drivers\MusCAudio.sys
2009-08-11 01:15 . 2009-08-11 01:15	0	----a-w-	c:\windows\system32\3C1.tmp
2009-08-05 09:01 . 2005-08-16 10:18	204800	----a-w-	c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2005-08-16 10:18	2145280	------w-	c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 04:59	2023936	------w-	c:\windows\system32\ntkrnlpa.exe
2009-07-31 17:33 . 2009-07-31 17:33	581192	----a-w-	c:\windows\system32\WinUSBCoInstaller.dll
2009-07-28 23:33 . 2009-08-26 01:37	55656	----a-w-	c:\windows\system32\drivers\avgntflt.sys
2008-07-07 05:18 . 2008-07-07 05:18	1292818	----a-w-	c:\program files\smartpopupblocker110.exe
2008-05-11 22:56 . 2008-05-11 22:56	241360	----a-w-	c:\program files\SmileboxInstaller.exe
2008-05-11 22:27 . 2008-05-11 22:27	550636	----a-w-	c:\program files\baku.zip
2008-05-11 22:26 . 2008-05-11 22:25	3005408	----a-w-	c:\program files\AWCSetup_Major.exe
2008-02-04 21:04 . 2008-02-04 21:03	43423968	----a-w-	c:\program files\PalmDesktopWin414e.zip
2007-06-11 20:45 . 2007-06-11 20:43	1467392	----a-w-	c:\program files\Netflix_Movie_Viewer_Installer.msi
2006-10-25 21:00 . 2006-10-25 21:00	35475296	----a-w-	c:\program files\Anonymizer_Software.exe
2006-08-05 14:26 . 2006-08-05 14:26	774144	----a-w-	c:\program files\RngInterstitial.dll
2006-08-04 03:02 . 2006-08-04 03:01	1379085	----a-w-	c:\program files\LSuperPacman.zip
2006-07-25 19:41 . 2006-07-25 19:41	524709	----a-w-	c:\program files\flac112a.exe
2006-04-14 15:12 . 2006-04-14 15:12	12754672	----a-w-	c:\program files\MP10Setup.exe
2006-04-13 01:16 . 2006-04-13 01:16	1221515	----a-w-	c:\program files\trackeraser.exe
2006-04-13 01:01 . 2006-04-13 01:01	3494992	----a-w-	c:\program files\pginstall.exe
2006-03-17 01:52 . 2006-03-17 01:52	251	----a-w-	c:\program files\wt3d.ini
.
 
(((((((((((((((((((((((((((((   SnapShot@2009-10-11_15.58.09   )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-08-16 10:18 . 2008-04-14 12:42	82432              c:\windows\system32\ws2_32.dll
- 2005-08-16 10:18 . 2008-04-14 00:12	82432              c:\windows\system32\ws2_32.dll
- 2005-08-16 10:18 . 2009-08-23 17:33	73962              c:\windows\system32\perfc009.dat
+ 2005-08-16 10:18 . 2009-10-18 19:09	73962              c:\windows\system32\perfc009.dat
+ 2007-08-13 23:54 . 2009-08-29 08:08	55296              c:\windows\system32\msfeedsbs.dll
- 2007-08-13 23:54 . 2009-07-03 17:09	55296              c:\windows\system32\msfeedsbs.dll
- 2005-08-16 10:18 . 2009-07-03 17:09	25600              c:\windows\system32\jsproxy.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08	25600              c:\windows\system32\jsproxy.dll
+ 2009-08-23 16:55 . 2009-08-29 08:08	12800              c:\windows\system32\dllcache\xpshims.dll
- 2009-08-23 16:55 . 2009-07-03 17:09	12800              c:\windows\system32\dllcache\xpshims.dll
+ 2005-08-16 10:18 . 2008-04-14 12:42	82432              c:\windows\system32\dllcache\ws2_32.dll
- 2007-12-22 02:18 . 2009-07-03 17:09	55296              c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-12-22 02:18 . 2009-08-29 08:08	55296              c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-09-04 21:03 . 2009-09-04 21:03	58880              c:\windows\system32\dllcache\msasn1.dll
- 2006-05-10 05:25 . 2009-07-03 17:09	25600              c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08	25600              c:\windows\system32\dllcache\jsproxy.dll
- 2008-08-26 05:41 . 2008-04-14 00:12	82432              c:\windows\ServicePackFiles\i386\ws2_32.dll
+ 2008-08-26 05:41 . 2008-04-14 12:42	82432              c:\windows\ServicePackFiles\i386\ws2_32.dll
+ 2009-06-25 02:56 . 2009-06-25 02:56	73728              c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2008-05-28 07:49 . 2008-05-28 07:49	77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2007-04-14 00:58 . 2007-04-14 00:58	77824              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2008-05-28 07:49 . 2008-05-28 07:49	86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2007-04-14 00:57 . 2007-04-14 00:57	86016              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2008-05-28 07:49 . 2008-05-28 07:49	81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2007-04-14 00:57 . 2007-04-14 00:57	81920              c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2007-04-14 01:30 . 2007-04-14 01:30	32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2008-05-28 08:30 . 2008-05-28 08:30	32768              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2004-09-29 23:11 . 2009-06-24 19:56	86016              c:\windows\Microsoft.NET\Framework\v1.0.3705\ToGac.exe
+ 2004-10-07 22:36 . 2009-06-24 19:56	73728              c:\windows\Microsoft.NET\Framework\v1.0.3705\SetRegNI.exe
- 2005-08-16 10:38 . 2007-01-02 20:29	86016              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
+ 2005-08-16 10:38 . 2009-06-24 05:01	86016              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
- 2005-08-16 10:38 . 2007-01-02 20:29	73728              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
+ 2005-08-16 10:38 . 2009-06-24 05:01	73728              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
+ 2005-08-16 10:38 . 2009-06-24 05:12	32768              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
- 2005-08-16 10:38 . 2008-04-13 16:10	32768              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
+ 2005-08-16 10:38 . 2009-06-24 05:12	32768              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
- 2005-08-16 10:38 . 2008-04-13 16:10	32768              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2009-10-18 19:05 . 2009-07-03 17:09	12800              c:\windows\ie8updates\KB974455-IE8\xpshims.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	55296              c:\windows\ie8updates\KB974455-IE8\msfeedsbs.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	25600              c:\windows\ie8updates\KB974455-IE8\jsproxy.dll
+ 2009-10-18 19:02 . 2009-10-18 19:02	90112              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_d8bc129f\System.Drawing.Design.dll
+ 2009-10-18 19:02 . 2009-10-18 19:02	61440              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_17e22cb8\CustomMarshalers.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	90112              c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_58aad780\System.Drawing.Design.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	61440              c:\windows\assembly\NativeImages1_v1.0.3705\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a_1738b4b1\CustomMarshalers.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	45056              c:\windows\assembly\NativeImages_v2.0.50727_32\UIXControls\20007071fb3ea7c6687f93788a94b34a\UIXControls.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	60928              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\b4a9e413d5cd6d6ec2d50aa05381e293\UIAutomationProvider.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	37888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\8acb476a0d4ee17a12881e17ae74a6af\System.Windows.Presentation.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	36864              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\4b87ca3482a3c0ee733e028ecee7de65\System.Web.DynamicData.Design.ni.dll
+ 2009-10-18 19:21 . 2009-10-18 19:21	94208              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\a0c71055364bd356971791284c3fb910\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-10-18 19:21 . 2009-10-18 19:21	82944              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f9a75bbdc2ce7db578b5977766a09b99\System.AddIn.Contract.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	47104              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\3dd0f86c966c75755d62eab8ddf0634c\PresentationFontCache.ni.exe
+ 2009-10-18 19:10 . 2009-10-18 19:10	39424              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\034d081fe294bab1ee1ecc98c1181424\PresentationCFFRasterizer.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	55296              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2673aec397c52796aef05bb9d2668df\Microsoft.Vsa.ni.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	15872              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\1ded203bd27031c3a5e3441f94b528c0\Microsoft.VisualC.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	65024              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d513fe1a81c441e7656a9b062cff4e9f\Microsoft.Build.Framework.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	74752              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\c5d504724d7f351b1d034615dbb72a2a\Microsoft.Build.Framework.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	14336              c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a664ccab020f93f1d533919f57131190\dfsvc.ni.exe
+ 2009-10-18 19:13 . 2009-10-18 19:13	25600              c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	77824              c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	81920              c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	81920              c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	32768              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	12800              c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	28672              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	77824              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	36864              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	77824              c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	13312              c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	10752              c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	72192              c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	69120              c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	8192              c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2005-08-16 10:38 . 2007-01-02 20:29	8192              c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2005-08-16 10:38 . 2009-06-29 18:57	8192              c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2009-10-18 19:09 . 2009-10-18 19:09	7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	7168              c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2009-08-23 17:33 . 2009-08-23 17:33	5632              c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2009-08-23 17:33 . 2009-08-23 17:33	6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	6656              c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	8192              c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	113664              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	258048              c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2009-07-12 07:02 . 2009-07-12 07:02	159032              c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2005-08-16 10:19 . 2009-04-02 06:02	604160              c:\windows\system32\wmspdmod.dll
+ 2005-08-16 10:19 . 2008-06-18 12:03	938496              c:\windows\system32\WMNetmgr.dll
+ 2005-08-16 10:19 . 2007-10-28 00:40	222720              c:\windows\system32\wmasf.dll
- 2005-08-16 10:18 . 2009-08-23 17:33	448188              c:\windows\system32\perfh009.dat
+ 2005-08-16 10:18 . 2009-10-18 19:09	448188              c:\windows\system32\perfh009.dat
+ 2005-08-16 10:18 . 2009-08-29 08:08	206848              c:\windows\system32\occache.dll
- 2005-08-16 10:18 . 2009-07-03 17:09	206848              c:\windows\system32\occache.dll
+ 2005-08-16 10:19 . 2006-12-04 23:21	414720              c:\windows\system32\msscp.dll
+ 2007-08-13 23:54 . 2009-08-29 08:08	594432              c:\windows\system32\msfeeds.dll
- 2007-08-13 23:54 . 2009-07-03 17:09	594432              c:\windows\system32\msfeeds.dll
+ 2005-08-16 10:19 . 2008-06-18 08:09	100864              c:\windows\system32\logagent.exe
- 2005-08-16 10:19 . 2006-10-19 03:03	100864              c:\windows\system32\logagent.exe
+ 2005-08-16 10:18 . 2009-08-29 08:08	184320              c:\windows\system32\iepeers.dll
- 2005-08-16 10:18 . 2009-07-03 17:09	184320              c:\windows\system32\iepeers.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08	387584              c:\windows\system32\iedkcs32.dll
+ 2005-08-16 10:18 . 2009-08-28 10:35	173056              c:\windows\system32\ie4uinit.exe
- 2005-08-16 10:18 . 2009-07-03 11:01	173056              c:\windows\system32\ie4uinit.exe
+ 2009-04-02 06:02 . 2009-04-02 06:02	604160              c:\windows\system32\dllcache\wmspdmod.dll
+ 2007-10-27 22:40 . 2007-10-28 00:40	222720              c:\windows\system32\dllcache\wmasf.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08	916480              c:\windows\system32\dllcache\wininet.dll
+ 2006-08-21 14:52 . 2009-08-26 08:00	247326              c:\windows\system32\dllcache\strmdll.dll
- 2006-08-21 14:52 . 2008-10-03 10:02	247326              c:\windows\system32\dllcache\strmdll.dll
- 2007-08-13 23:44 . 2009-07-03 17:09	206848              c:\windows\system32\dllcache\occache.dll
+ 2007-08-13 23:44 . 2009-08-29 08:08	206848              c:\windows\system32\dllcache\occache.dll
- 2009-06-25 08:25 . 2009-06-25 08:25	136192              c:\windows\system32\dllcache\msv1_0.dll
+ 2009-06-25 08:25 . 2009-09-11 14:18	136192              c:\windows\system32\dllcache\msv1_0.dll
- 2007-12-22 02:18 . 2009-07-03 17:09	594432              c:\windows\system32\dllcache\msfeeds.dll
+ 2007-12-22 02:18 . 2009-08-29 08:08	594432              c:\windows\system32\dllcache\msfeeds.dll
- 2009-08-23 16:55 . 2009-07-03 17:09	246272              c:\windows\system32\dllcache\ieproxy.dll
+ 2009-08-23 16:55 . 2009-08-29 08:08	246272              c:\windows\system32\dllcache\ieproxy.dll
- 2006-05-10 05:25 . 2009-07-03 17:09	184320              c:\windows\system32\dllcache\iepeers.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08	184320              c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 23:39 . 2009-08-29 08:08	387584              c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 23:39 . 2009-08-28 10:35	173056              c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-13 23:39 . 2009-07-03 11:01	173056              c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-08-08 06:51 . 2009-08-08 06:51	989016              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2008-05-28 07:49 . 2008-05-28 07:49	102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2007-04-14 00:58 . 2007-04-14 00:58	102400              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2008-05-28 07:48 . 2008-05-28 07:48	315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2007-04-14 00:56 . 2007-04-14 00:56	315392              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2008-05-28 08:30 . 2008-05-28 08:30	258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2007-04-14 01:30 . 2007-04-14 01:30	258048              c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2005-08-16 10:38 . 2004-07-20 00:54	303104              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
+ 2005-08-16 10:38 . 2009-06-24 04:59	303104              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
+ 2005-08-16 10:38 . 2009-06-24 05:12	200704              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
- 2005-08-16 10:38 . 2008-04-13 16:09	200704              c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2009-10-11 19:00 . 2009-10-11 19:00	195584              c:\windows\Installer\aa6c70.msi
+ 2009-10-18 19:05 . 2009-07-03 17:09	915456              c:\windows\ie8updates\KB974455-IE8\wininet.dll
+ 2009-10-18 19:05 . 2009-05-26 11:40	382840              c:\windows\ie8updates\KB974455-IE8\spuninst\updspapi.dll
+ 2009-10-18 19:05 . 2008-07-08 13:02	231288              c:\windows\ie8updates\KB974455-IE8\spuninst\spuninst.exe
+ 2009-10-18 19:05 . 2009-07-03 17:09	206848              c:\windows\ie8updates\KB974455-IE8\occache.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	594432              c:\windows\ie8updates\KB974455-IE8\msfeeds.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	246272              c:\windows\ie8updates\KB974455-IE8\ieproxy.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	184320              c:\windows\ie8updates\KB974455-IE8\iepeers.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	386048              c:\windows\ie8updates\KB974455-IE8\iedkcs32.dll
+ 2009-10-18 19:05 . 2009-07-03 11:01	173056              c:\windows\ie8updates\KB974455-IE8\ie4uinit.exe
+ 2006-11-20 18:04 . 2006-11-20 18:04	117088              c:\windows\Downloaded Program Files\CONFLICT.1\PURen-us.dll
+ 2009-08-19 18:55 . 2009-08-19 18:55	829288              c:\windows\Downloaded Program Files\CONFLICT.1\MsnPUpld.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	835584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_ab365968\System.Drawing.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	192512              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_98db13b4\System.Drawing.Design.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	118784              c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_cf7e0a5c\CustomMarshalers.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	847872              c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_f43a4705\System.Drawing.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	321536              c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\e2098e43d115155d6ba91ba3a7e577cf\WsatConfig.ni.exe
+ 2009-10-18 19:12 . 2009-10-18 19:12	240128              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bf92bc207f927cbbd6dfc9dc0c3eae68\WindowsFormsIntegration.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	187904              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\6f488b7644dc50a083868e91a4014466\UIAutomationTypes.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	447488              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\c2fbf25609b704061a93500efa6f241d\UIAutomationClient.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	400896              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\eb23b78564687badff1bd1f1d0a0ec97\System.Xml.Linq.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\e7666364bf9f3ba5f4833c9efedd8218\System.Web.Routing.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	202240              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5f1b8791e6c47e5bd5e7018c346c586\System.Web.RegularExpressions.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	859648              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\884eacddf339b8b342f66aedff5f8ef9\System.Web.Extensions.Design.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	328704              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\9e199645bd26f1afe58ebe185d1e7f0f\System.Web.Entity.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	301056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\652017ebe962ab2eb271c2524f31cd61\System.Web.Entity.Design.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\d0070c1c1a642ae30394e00bc0d82336\System.Web.DynamicData.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\1896753d02d146be1988d32241300f51\System.Web.Abstractions.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	627200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\408e637346ef628a3f54fb1b9b83ac9f\System.Transactions.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	676352              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\a9e9b885a6601469c4058375cc74d856\System.Security.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	311296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9bc34a79af9c3ed2cf17a0226c769b4c\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	621056              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\5f74a84e9d28c2332c51f6e30da0e125\System.Net.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	998400              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	330752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\818b20a7c6f3b2fe97bf008ca24080c1\System.Management.Instrumentation.ni.dll
+ 2009-10-18 19:13 . 2009-10-18 19:13	381440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\6c273eb9d1ee8b66b5ecb073de4b785d\System.IO.Log.ni.dll
+ 2009-10-18 19:13 . 2009-10-18 19:13	212992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\7222db518afb4eaaa138824278249bc7\System.IdentityModel.Selectors.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	280064              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.Wrapper.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	627712              c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	208384              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\ca6d7208c0fb72ff97429f2636ced321\System.Drawing.Design.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	881152              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c92fc19800e701c90f90ab7a2ab44c47\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	455680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\a601f47a98ee67df424685c9a66ea449\System.DirectoryServices.Protocols.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	939008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\b91b44015859163646f210d284f7166a\System.Data.Services.Client.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	354816              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1b35297e07b85071daecdb06f96750a1\System.Data.Services.Design.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	756736              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\cf906bf9146d1f0013451ec63b58e064\System.Data.Entity.Design.ni.dll
+ 2009-10-18 19:21 . 2009-10-18 19:21	135680              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4ff4134b0d490c090e03d74e104517c4\System.Data.DataSetExtensions.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	971264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\443e3a85c491b2de4a2ac654cb957484\System.Configuration.Install.ni.dll
+ 2009-10-18 19:15 . 2009-10-18 19:15	633856              c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\cba35f47925431a54d0e6ae147a292f1\System.AddIn.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	366080              c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6af32fe5cbec0aa54e2efa6910c73651\SMSvcHost.ni.exe
+ 2009-10-18 19:14 . 2009-10-18 19:14	256000              c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	320512              c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a23dc25782df04533a13e348203e4dc5\ServiceModelReg.ni.exe
+ 2009-10-18 19:11 . 2009-10-18 19:11	258048              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\96f74da5fc40b92f09069230bc0df4f0\PresentationFramework.Royale.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	539648              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bb4d16b042b72c2c85a0f8ac9d48f28\PresentationFramework.Luna.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	368128              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\30c5c2682d3c5bdaa83bb9a36ee48afa\PresentationFramework.Aero.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	224768              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07e952efd70f5608e221a008e6231ace\PresentationFramework.Classic.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	133632              c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\eade8c1c9c1e8e5ffb50e6c9b9af0f6a\MSBuild.ni.exe
+ 2009-10-18 19:14 . 2009-10-18 19:14	386560              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fc4d66e0a92b3767006a84f2519d2457\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-10-18 19:15 . 2009-10-18 19:15	144384              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\58ca3ecc52b7246b448c109817198a0b\Microsoft.Build.Utilities.ni.dll
+ 2009-10-18 19:15 . 2009-10-18 19:15	175104              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4dd43724dd92026577c6f588270137a0\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	839680              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8c651f75bb741330370986dcad8e9e5b\Microsoft.Build.Engine.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	222720              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a6dcbae619ccd938bfe808c54d6d3ae0\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	220672              c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\77688ce14f221ed94a9f442ae4736123\CustomMarshalers.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	410112              c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a17c65f0cffaa4f792dd38d50df9d526\ComSvcConfig.ni.exe
+ 2009-10-18 19:13 . 2009-10-18 19:13	842240              c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\85d7c111956b478766d90625b35d963f\AspNetMMCExt.ni.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	839680              c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	835584              c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	114688              c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	258048              c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	131072              c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	303104              c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	258048              c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	372736              c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	626688              c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	401408              c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	188416              c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	970752              c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	745472              c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	425984              c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	110592              c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	659456              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	372736              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	110592              c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	749568              c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	655360              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	348160              c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	507904              c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	261632              c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	113664              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	258048              c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	486400              c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-10-14 00:47 . 2009-08-13 13:55	1748992              c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
+ 2005-08-16 10:19 . 2009-05-20 11:56	2458112              c:\windows\system32\WMVCore.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08	1208832              c:\windows\system32\urlmon.dll
- 2005-08-16 10:18 . 2009-07-03 17:09	1208832              c:\windows\system32\urlmon.dll
- 2005-08-16 10:18 . 2008-04-14 00:12	1435648              c:\windows\system32\query.dll
+ 2005-08-16 10:18 . 2009-07-17 16:22	1435648              c:\windows\system32\query.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08	5940224              c:\windows\system32\mshtml.dll
- 2007-08-13 23:34 . 2009-07-03 17:09	1985536              c:\windows\system32\iertutil.dll
+ 2007-08-13 23:34 . 2009-08-29 08:08	1985536              c:\windows\system32\iertutil.dll
+ 2005-08-16 10:19 . 2009-05-20 11:56	2458112              c:\windows\system32\dllcache\WMVCore.dll
- 2006-05-10 05:25 . 2009-07-03 17:09	1208832              c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08	1208832              c:\windows\system32\dllcache\urlmon.dll
+ 2009-07-17 16:22 . 2009-07-17 16:22	1435648              c:\windows\system32\dllcache\query.dll
+ 2008-10-14 21:20 . 2009-08-05 03:44	2189184              c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-14 21:20 . 2009-02-06 10:32	2023936              c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-14 21:20 . 2009-08-04 14:20	2023936              c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-14 21:20 . 2009-08-04 14:20	2066048              c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-14 21:20 . 2009-02-08 02:02	2066048              c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-14 21:20 . 2009-08-04 15:13	2145280              c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-10-14 21:20 . 2009-02-06 11:06	2145280              c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:06 . 2009-08-29 08:08	5940224              c:\windows\system32\dllcache\mshtml.dll
+ 2007-12-22 02:18 . 2009-08-29 08:08	1985536              c:\windows\system32\dllcache\iertutil.dll
- 2007-12-22 02:18 . 2009-07-03 17:09	1985536              c:\windows\system32\dllcache\iertutil.dll
+ 2009-08-08 06:51 . 2009-08-08 06:51	5812560              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2008-11-25 11:59 . 2008-11-25 11:59	4546560              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2009-08-08 06:51 . 2009-08-08 06:51	4546560              c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2007-04-14 01:35 . 2007-04-14 01:35	1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2008-05-28 08:35 . 2008-05-28 08:35	1265664              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2008-05-28 08:35 . 2008-05-28 08:35	1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2007-04-14 01:35 . 2007-04-14 01:35	1232896              c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2007-04-14 00:57 . 2007-04-14 00:57	2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 07:48 . 2008-05-28 07:48	2514944              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 07:48 . 2008-05-28 07:48	2523136              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2007-04-14 00:57 . 2007-04-14 00:57	2523136              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2008-05-28 07:43 . 2008-05-28 07:43	2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2007-04-14 00:50 . 2007-04-14 00:50	2142208              c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2005-08-16 10:38 . 2007-01-02 20:40	1200128              c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
+ 2005-08-16 10:38 . 2009-06-29 18:58	1200128              c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
+ 2005-08-16 10:38 . 2009-06-24 05:00	2281472              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- 2005-08-16 10:38 . 2007-12-17 11:59	2281472              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- 2005-08-16 10:38 . 2007-12-17 11:58	2273280              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
+ 2005-08-16 10:38 . 2009-06-24 05:00	2273280              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
- 2005-08-16 10:38 . 2007-01-02 20:21	1998848              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
+ 2005-08-16 10:38 . 2009-06-29 18:58	1998848              c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	1208832              c:\windows\ie8updates\KB974455-IE8\urlmon.dll
+ 2009-10-18 19:05 . 2009-07-19 13:18	5937152              c:\windows\ie8updates\KB974455-IE8\mshtml.dll
+ 2009-10-18 19:05 . 2009-07-03 17:09	1985536              c:\windows\ie8updates\KB974455-IE8\iertutil.dll
+ 2008-10-14 21:20 . 2009-08-05 03:44	2189184              c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-10-14 21:20 . 2009-02-06 10:32	2023936              c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-14 21:20 . 2009-08-04 14:20	2023936              c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-14 21:20 . 2009-02-08 02:02	2066048              c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-14 21:20 . 2009-08-04 14:20	2066048              c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-14 21:20 . 2009-08-04 15:13	2145280              c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-14 21:20 . 2009-02-06 11:06	2145280              c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-10-18 19:02 . 2009-10-18 19:02	1966080              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_9d3bcedb\System.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	4792320              c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_6f233cfd\System.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	2088960              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_25865afd\System.Xml.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	5513216              c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_247cb74e\System.Xml.dll
+ 2009-10-18 19:02 . 2009-10-18 19:02	3018752              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a9818067\System.Windows.Forms.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	7884800              c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_886f5961\System.Windows.Forms.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	2244608              c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_51100848\System.Drawing.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	1470464              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_9d71fe59\System.Design.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	3395584              c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_4d91eea7\System.Design.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	3391488              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7edd17e2\mscorlib.dll
+ 2009-10-18 19:03 . 2009-10-18 19:03	8908800              c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_3a23e135\mscorlib.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	1855488              c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_b576fb9e\System.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	2027520              c:\windows\assembly\NativeImages1_v1.0.3705\System.Xml\1.0.3300.0__b77a5c561934e089_a1518628\System.Xml.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	2953216              c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_159248f0\System.Windows.Forms.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	1454080              c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_e27a1f70\System.Design.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	3301376              c:\windows\assembly\NativeImages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_16806cc0\mscorlib.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	3593728              c:\windows\assembly\NativeImages_v2.0.50727_32\ZuneShell\9792317c1b3342eb5e70dfbaf18fc333\ZuneShell.ni.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	2132992              c:\windows\assembly\NativeImages_v2.0.50727_32\ZuneDBApi\d9c37d5af0dddcdae7b48b3c580c0d0d\ZuneDBApi.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	3313664              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\204d6e5b335134f23ca37638b9227ecf\WindowsBase.ni.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	4542976              c:\windows\assembly\NativeImages_v2.0.50727_32\UIX\04e11461e48e7b13c44b2d9d61a7fb9a\UIX.ni.dll
+ 2009-10-18 19:24 . 2009-10-18 19:24	1831424              c:\windows\assembly\NativeImages_v2.0.50727_32\UIX.RenderApi\46de7088426da0a0a2370d1c58c15dbd\UIX.RenderApi.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	1049600              c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\0f2ed6a204eb13841e99b77025464afc\UIAutomationClientsideProviders.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	7868416              c:\windows\assembly\NativeImages_v2.0.50727_32\System\3de5bd01124463d7862bd173af90bc83\System.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	5450752              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5913d3f81e77194ec833991b1047a532\System.Xml.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	1356288              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\fa48917b13629d8effa80dd4a2f2973d\System.WorkflowServices.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	1908224              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6fe66ee6f3c81996bc148f1ebe7ec030\System.Workflow.Runtime.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	4514304              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\9d0b61f2f1ebdc300bd970f594c422ef\System.Workflow.ComponentModel.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	2992640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\65328898148a720d394f802f192fc2a0\System.Workflow.Activities.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\ea07ac791bb5cb9f83679e3dd1a0c0cc\System.Web.Services.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	2209280              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\29e2f8b1fb691ced973acf49fcee6ec1\System.Web.Mobile.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	2403328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\981dea02bc63c0c083e335adf9018788\System.Web.Extensions.ni.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	1917440              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\99594bae1d022502925f5b9dfcdaae9a\System.Speech.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	1706496              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll
+ 2009-10-18 19:13 . 2009-10-18 19:13	2338304              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\67ad55827f2542552b576170f0a7dc56\System.Runtime.Serialization.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	1035264              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\e5313735a40c0800f116e27fba4754db\System.Printing.ni.dll
+ 2009-10-18 19:13 . 2009-10-18 19:13	1056768              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c3b18fef5c6dc3bcdbe5df699fd21a55\System.IdentityModel.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	1587200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\abb2ac7e08bee026f857d8fa36f9fe6f\System.Drawing.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	1116672              c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f47ebb9db460874b1bcbfc391dc970b1\System.DirectoryServices.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	1801216              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c94a427baa7683f4221b91f90c18461b\System.Deployment.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	6616576              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\694c07365e0fd6bba0bc304d4d2404a7\System.Data.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	2510336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\272152f0cc139490729e215611a4b244\System.Data.SqlXml.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	1328128              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\112a48e34620a0210eb850040da8a31b\System.Data.Services.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	2516480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\32788c58ff9f8324460604cf1fe7681b\System.Data.Linq.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	9924096              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\9012cac7819660f61f1c69cf8e4f2ccf\System.Data.Entity.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	2295296              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\c0a42d2ad8a4078040b334f6770ea11f\System.Core.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	2128896              c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\954685c29689d2a6126ceca1fd55e904\ReachFramework.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	1657856              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\a3a6f52ce1d09a7bdccc8e7fc664792d\PresentationUI.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	1451008              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\f906701365083c1473db31519147e263\PresentationBuildTasks.ni.dll
+ 2009-10-18 19:15 . 2009-10-18 19:15	1712128              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6eee9b772b6d12d3dbd82f118c2ab2e5\Microsoft.VisualBasic.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	1093120              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f19e9b439636d0744597fff1331cad04\Microsoft.Transactions.Bridge.ni.dll
+ 2009-10-18 19:22 . 2009-10-18 19:22	2332160              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\5b1af7b5be24c7ace065fe1c81c2b650\Microsoft.JScript.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	1620992              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9eec1cc7ac37e0c7f3205e8156149c5a\Microsoft.Build.Tasks.ni.dll
+ 2009-10-18 19:15 . 2009-10-18 19:15	1966080              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\28c0730288453d57d5dcd62903c4d31b\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	1888768              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5dd4f58999eed37c12aee7ea9f9863ac\Microsoft.Build.Engine.ni.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	3149824              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	3149824              c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	2048000              c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	5025792              c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	5062656              c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	5242880              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	2933248              c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2009-08-23 17:33 . 2009-08-23 17:33	4546560              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2009-10-18 19:09 . 2009-10-18 19:09	4546560              c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2007-07-12 02:47 . 2007-07-12 02:47	1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-10-18 19:02 . 2009-10-18 19:02	1232896              c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2007-07-12 02:47 . 2007-07-12 02:47	1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-10-18 19:02 . 2009-10-18 19:02	1265664              c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-10-23 01:55 . 2008-10-23 01:55	1200128              c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-10-18 19:01 . 2009-10-18 19:01	1200128              c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2006-04-03 20:34 . 2009-10-02 18:01	25198016              c:\windows\system32\MRT.exe
+ 2007-08-13 23:54 . 2009-08-29 08:08	11069440              c:\windows\system32\ieframe.dll
+ 2007-12-22 02:18 . 2009-08-29 08:08	11069440              c:\windows\system32\dllcache\ieframe.dll
+ 2009-08-11 04:08 . 2009-08-11 04:08	11315712              c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp
+ 2009-08-15 03:32 . 2009-08-15 03:32	11110912              c:\windows\Installer\2cd802c.msp
+ 2009-08-10 21:09 . 2009-08-10 21:09	17254912              c:\windows\Installer\2cd8023.msp
+ 2009-10-18 19:05 . 2009-07-20 01:48	11067392              c:\windows\ie8updates\KB974455-IE8\ieframe.dll
+ 2009-10-18 19:12 . 2009-10-18 19:12	12430848              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d2ea8d76f015817db1607075812b555f\System.Windows.Forms.ni.dll
+ 2009-10-18 19:23 . 2009-10-18 19:23	11796992              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5cea03cfb008f2eac1439a9905467f37\System.Web.ni.dll
+ 2009-10-18 19:14 . 2009-10-18 19:14	17317888              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	10683392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\8b82e08c008924d51833cb0884bcbfc5\System.Design.ni.dll
+ 2009-10-18 19:11 . 2009-10-18 19:11	14327808              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\58c7ac6b6054038dc9346d7ec8e32b4c\PresentationFramework.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	12216320              c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\94badbd64df59de7da249f71da38b1c2\PresentationCore.ni.dll
+ 2009-10-18 19:10 . 2009-10-18 19:10	11486720              c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\Pete\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-14 79872]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2006-10-20 73728]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2005-03-10 28160]
 
c:\documents and settings\Pete\Start Menu\Programs\Startup\
AbsoluteShield Track Eraser.lnk - c:\program files\SysShield Tools\Track Eraser\cseraser.exe [2003-12-10 555520]
 
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-3-13 24576]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
 
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{731AC7F0-7344-4FBE-9B2E-6C5146845A04}"= "c:\windows\system32\ehmeruli.dll" [2007-03-31 319488]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
 
R0 DiagnosticScan;DiagnosticScan;c:\windows\system32\drivers\DiagnosticScan.SYS [8/27/2009 10:31 AM 16384]
R1 Start1Driver;Start1Driver;c:\windows\system32\drivers\Start1Driver.SYS [10/9/2009 10:15 PM 5120]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/25/2009 6:37 PM 108289]
S3 3xHybrid;Pinnacle PCTV 110i service;c:\windows\system32\drivers\3xHybrid.sys [3/28/2006 6:59 PM 827008]
S3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [8/27/2009 7:07 PM 23096]
S3 ZD1211BU(Linksys A Division of Cisco Systems Inc.);Linksys Wireless-G USB Network Adapter Driver(Linksys A Division of Cisco Systems Inc.);c:\windows\system32\drivers\ZD1211BU.sys [5/11/2008 2:59 PM 402432]
.
Contents of the 'Scheduled Tasks' folder
 
2009-10-21 c:\windows\Tasks\USBCoinstallerTaskUserS-1-5-21-2875547054-3911223903-918033636-1005.job
- c:\windows\system32\USBComp4.exe [2009-06-11 14:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://home.live.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: plaxo.com\www
DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} - hxxps://register.creative.com/register/OCXs/CtORWebClientNoMFC.cab
.
- - - - ORPHANS REMOVED - - - -
 
AddRemove-Active Security - c:\program files\Active Security\Uninstall.exe
 
 
 
**************************************************************************
 
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-20 17:21
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ... 
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
- - - - - - - > 'explorer.exe'(492)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\ehmeruli.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\NettutBv.dll
c:\program files\Siber Systems\AI RoboForm\RoboForm.DLL
.
Completion time: 2009-10-21 17:23
ComboFix-quarantined-files.txt  2009-10-21 00:23
ComboFix2.txt  2009-10-14 04:43
ComboFix3.txt  2009-10-14 00:45
ComboFix4.txt  2009-10-11 16:01
ComboFix5.txt  2009-10-21 00:14
 
Pre-Run: 35,097,710,592 bytes free
Post-Run: 35,069,681,664 bytes free
 
- - End Of File - - FD615F2BEEB563EFD17CB7DCFF975A30
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
207:
208:
209:
210:
211:
212:
213:
214:
215:
216:
217:
218:
219:
220:
221:
222:
223:
224:
225:
226:
227:
228:
229:
230:
231:
232:
233:
234:
235:
236:
237:
238:
239:
240:
241:
242:
243:
244:
245:
246:
247:
248:
249:
250:
251:
252:
253:
254:
255:
256:
257:
258:
259:
260:
261:
262:
263:
264:
265:
266:
267:
268:
269:
270:
271:
272:
273:
274:
275:
276:
277:
278:
279:
280:
281:
282:
283:
284:
285:
286:
287:
288:
289:
290:
291:
292:
293:
294:
295:
296:
297:
298:
299:
300:
301:
302:
303:
304:
305:
306:
307:
308:
309:
310:
311:
312:
313:
314:
315:
316:
317:
318:
319:
320:
321:
322:
323:
324:
325:
326:
327:
328:
329:
330:
331:
332:
333:
334:
335:
336:
337:
338:
339:
340:
341:
342:
343:
344:
345:
346:
347:
348:
349:
350:
351:
352:
353:
354:
355:
356:
357:
358:
359:
360:
361:
362:
363:
364:
365:
366:
367:
368:
369:
370:
371:
372:
373:
374:
375:
376:
377:
378:
379:
380:
381:
382:
383:
384:
385:
386:
387:
388:
389:
390:
391:
392:
393:
394:
395:
396:
397:
398:
399:
400:
401:
402:
403:
404:
405:
406:
407:
408:
409:
410:
411:
412:
413:
414:
415:
416:
417:
418:
419:
420:
421:
422:
423:
424:
425:
426:
427:
428:
429:
430:
431:
432:
433:
434:
435:
436:
437:
438:
439:
440:
441:
442:
443:
444:
445:
446:
447:
448:
449:
450:
451:
452:
453:
454:
455:
456:
457:
458:
459:
460:
461:
462:
463:
464:
465:
466:
467:
468:
469:
470:
471:
472:
473:
474:
475:
476:
477:
478:
479:
480:
481:
482:
483:
484:
485:
486:
487:
488:
489:
490:
491:
492:
493:
494:
495:
496:
497:
498:
499:
500:
501:
502:
503:
504:
505:
506:
507:
508:
509:
510:
511:
512:
513:
514:
515:
516:
517:
518:
519:
520:
521:
522:
523:
524:
525:
526:
527:
528:
529:
530:
531:
532:
533:
534:
535:
536:
537:
538:
539:
540:
541:
542:
543:
544:
545:
546:
547:
548:
549:
550:
551:
552:
553:
554:
555:
556:
557:
558:
559:
560:
561:
562:
563:
564:
565:
566:
567:
568:
569:
570:
571:
572:
573:
574:
575:
576:
577:
578:
579:
580:
581:
582:
583:
584:
585:
586:
587:
588:
589:
590:
591:
592:
593:
594:
595:
596:
597:
598:
599:
600:
601:
602:
603:
604:
605:
606:
607:
608:
609:
610:
611:
612:
613:
614:
615:
616:
617:
618:
619:
620:
621:
622:
623:
624:
625:
626:
627:
628:
629:
630:
631:
632:
633:
634:
635:
636:
637:

Select allOpen in new window

 

by: optomaPosted on 2009-10-20 at 17:58:42ID: 25620009

 

by: pforbinPosted on 2009-10-20 at 19:19:27ID: 25620383

I ran Malware bytes and cleared a lot of junk...

 

by: pforbinPosted on 2009-10-22 at 07:22:17ID: 31639633

Still kinda screwy, but gonna try a new post and new code snippet. My issues were addressed, thanks everyone.

 

by: rpggamergirlPosted on 2009-10-23 at 04:44:20ID: 25643399

Try this script and let Combofix remove that Adware Away folder which is still showing there.

Run combofix again using this script.

1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
------------------------------------------------------------------------

Folder::
c:\program files\Adware Away

------------------------------------------------------------------------
3. Save the above as CFScript.txt in the same location as Combofix.exe.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.


I hope the issue is now resolved?
Thanks!

 

by: JonveePosted on 2009-10-23 at 13:17:09ID: 25648142

pforbin:
When you've definitely finished using ComboFix and do not require it again, you can uninstall it as follows >
Start > Run > then type "ComboFix /u" (with no quotes, and space between x and / )
Then hit enter.  This will uninstall ComboFix, reset your clock settings, re-hide system hidden files, re-hide the file extensions and reset System Restore.

Sorry i didn't get back to you between 21st and 23rd, somehow i misplaced your return e-mail.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...