Ga naar inhoud

YayYay

Lid
  • Items

    91
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door YayYay

  1. Hoi, 

     

    Mijn laptop crasht op regelmatige basis, en ik krijg Een Foutmelding ontmoette Een Droevig Gezicht:-(

    "Kernelgegevens Inpage ERROR".

     

    Scan ontmoette HD Tune GAF Enkele riet blokjes aan. 

    Bijgevoegd ook Mijn RSIT Logje. 

     

    Valt hier IETS aan te doen? Of is deze laptop zijn Einde Nabij (max. 2 jaar oud).

     

    Alvast bedankt voor de hulp. 

     

     

     

     

    log.txt

  2.  

    Zoek.exe v5.0.0.0 Updated 08-December-2014

    Tool run by Jelle on wo 10/12/2014 at  0:42:58,44.

    Microsoft Windows 8.1 6.3.9600  x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Jelle\Desktop\zoek.exe [scan all users] [script inserted] 

     

    ==== System Restore Info ======================

     

    10/12/2014 0:43:46 Zoek.exe System Restore Point Created Succesfully.

     

    ==== Deleting Files \ Folders ======================

     

    C:\Program Files\Common Files\ShopperPro not found

    C:\ProgramData\WindowsMangerProtect not found

    "C:\Windows\tasks\AVGNOJW.job" deleted

     

    ==== Reset Google Chrome ======================

     

    C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

    C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

     

    ==== Deleting CLSID Registry Keys ======================

     

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== C:\zoek_backup content ======================

     

    C:\zoek_backup (files=31 folders=25 8332667 bytes)

     

    ==== EOF on wo 10/12/2014 at  0:44:08,83 ======================
  3. Heb de indruk dat de programma's weg zijn. Zie geen onbekende icoontjes meer, en startpagina is opnieuw hersteld. 

    Hieronder mijn logje:

     

     

    Zoek.exe v5.0.0.0 Updated 08-December-2014

    Tool run by Jelle on di 09/12/2014 at 22:27:49,78.

    Microsoft Windows 8.1 6.3.9600  x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Jelle\Desktop\zoek.exe [scan all users] [script inserted] [Checkboxes used]

     

    ==== System Restore Info ======================

     

    9/12/2014 22:29:40 Zoek.exe System Restore Point Created Succesfully.

     

    ==== Empty Folders Check ======================

     

    C:\PROGRA~2\Universal Updater deleted successfully

    C:\PROGRA~2\COMMON~1\Intel deleted successfully

    C:\Program Files\log deleted successfully

    C:\PROGRA~3\CLSK deleted successfully

    C:\Users\Jelle\AppData\Local\VirtualStore deleted successfully

     

    ==== Deleting CLSID Registry Keys ======================

     

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{22D321B5-7CF-48FC-8179-67A79BE4EA11} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39FA9E88-F00E-49A8-9C67-A01D92CEE011} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44AB86E1-4631-428B-801F-B4708CA9914} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{579C25EB-48C-43CF-99E6-585E4B7C8F53} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{654770E8-9C9D-4EBC-9DC1-B27267FC13E1} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7630F2EA-528A-4EC0-91FE-82ECE308FC1} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFAC6354-DCCB-4553-AA83-9AF1CEB53138} deleted successfully

    HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F7135541-FE19-4C72-AC27-DA119EB1DFB5} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== Running Processes ======================

     

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe

    C:\ProgramData\IePluginServices\PluginService.exe

    C:\Program Files (x86)\0ca45c95134d\cf3e08d747e4.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

    C:\Users\Jelle\Desktop\zoek.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\cmd.exe

     

    ==== Deleting Services ======================

     

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UniversalUpdater deleted successfully

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\b786bdb3c67d deleted successfully

     

    ==== Registry Fix Code x64 ======================

     

    Windows Registry Editor Version 5.00

     

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] 

    "YTDownloader"=- 

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] 

    "YTDownloader"=- 

    "Salus"=- 

     

    ==== Deleting Files \ Folders ======================

     

    C:\Program Files (x86)\YTDownloader not found

    C:\Program Files (x86)\SupTab not found

    C:\Program Files (x86)\Universal Updater not found

    C:\Program Files (x86)\f552dd4c52e3 not found

    C:\Program Files (x86)\ShopperPro not found

    "C:\Program Files (x86)\f552dd4c52e3\b786bdb3c67d.exe" not found

    C:\Program Files (x86)\0ca45c95134d deleted

    C:\Program Files (x86)\fb9c456e-c6d8-4567-b255-31f106c1ca11 deleted

    C:\Program Files (x86)\globalUpdate deleted

    C:\PROGRA~3\ShopperPro deleted

    C:\PROGRA~3\Package Cache deleted

    C:\Users\Jelle\AppData\Local\globalUpdate deleted

    C:\Users\Jelle\AppData\Local\CrashRpt deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted

    C:\Users\Public\Documents\ShopperPro deleted

    C:\Windows\SysNative\config\systemprofile\Searches deleted

    C:\Windows\Syswow64\RegistryHelperLM.ocx deleted

    "C:\Program Files\Common Files\ShopperPro\spbiu.exe" not deleted

    "C:\ProgramData\IePluginServices\PluginService.exe" deleted

    "C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe" deleted

    "C:\PROGRA~3\IePluginServices\PluginService.exe" deleted

    "C:\PROGRA~3\IePluginServices\PluginService.exe" deleted

    "C:\PROGRA~3\WindowsMangerProtect\ProtectWindowsManager.exe" deleted

    "C:\Program Files\Common Files\ShopperPro" not deleted

    "C:\ProgramData\IePluginServices" not deleted

    "C:\ProgramData\WindowsMangerProtect" not deleted

    "C:\PROGRA~3\IePluginServices" not deleted

    "C:\PROGRA~3\IePluginServices" not deleted

    "C:\PROGRA~3\WindowsMangerProtect" not deleted

     

    ==== System Specs ======================

     

    Windows: Windows Version 6.2 (Build 9200)

    Memory (RAM): 4052 MB

    CPU Info: Intel® Pentium® CPU G3220 @ 3.00GHz

    CPU Speed: 3080,7 MHz

    Sound Card: Speakers (Realtek High Definiti | 

    Display Adapters: NVIDIA GeForce GTX 745 | NVIDIA GeForce GTX 745

    Monitors: 1x; Generic PnP Monitor | 

    Screen Resolution: 1920 X 1080 - 32 bit

    Network: Network Present

    Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Realtek RTL8188CU Wireless LAN 802.11n USB 2.0 Network Adapter | Realtek PCIe GBE Family Controller

    CD / DVD Drives: 1x (F: | ) F: TSSTcorpCDDVDW SH-216DB

    Ports: COM Ports NOT Present. LPT Port NOT Present. 

    Mouse: 3 Button Wheel Mouse Present

    Hard Disks: C:  869,8GB | D:  60,0GB

    Hard Disks - Free: C:  667,5GB | D:  43,4GB

    Manufacturer *: American Megatrends Inc.

    BIOS Info: AT/AT COMPATIBLE |  | ALASKA - 1072009

    Time Zone: Romance (standaardtijd)

    Motherboard *: MEDION H81H3-EM2

    Country: Belgi‰ 

    Language: NLB 

     

    ==== System Specs (Software) ======================

     

    Anti-Virus: Windows Defender On-access scanning disabled (Outdated)

    Anti-Spyware: Windows Defender disabled (Outdated)

    Default Browser: Google Chrome 39.0.2171.71

    Internet Explorer Version: 11.0.9600.17416 

    Google Chrome version: 39.0.2171.71

    Adobe Reader version: 11.0.9.29

     

    ==== Files Recently Created / Modified ======================

     

    ====== C:\Windows ====

    ====== C:\Users\Jelle\AppData\Local\Temp ====

    2014-12-09 21:26:27 EB4686F6F4BE2B00AA40978D551F66C4 43008 ----a-w- C:\Users\Jelle\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxy42vl.dll

    2014-12-09 20:56:06 2B6C7D88053EDF95221D30BC048D9EEB 9728 ----a-w- C:\Users\mieke_000\AppData\Local\Temp\nsu3E7E.tmp\System.dll

    2014-12-09 15:05:29 EB4686F6F4BE2B00AA40978D551F66C4 43008 ----a-w- C:\Users\mieke_000\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpucc6i8.dll

    2014-12-08 18:35:46 717E87D8F33D1AA7BC647828C2E178C8 222704 ----a-w- C:\Users\Jelle\AppData\Local\Temp\tu17p84.exe

    2014-12-08 15:50:49 E8B8EE3DF018745083CD3E1A0180B84B 6866769 ----a-w- C:\Users\Jelle\AppData\Local\Temp\Install_4738\ins_ytd.exe

    2014-12-08 15:50:49 5FB507803B530B46A26506956A81E9E4 4689355 ----a-w- C:\Users\Jelle\AppData\Local\Temp\Install_4738\ins_shopperpro.exe

    2014-12-08 00:05:32 11AD7B667A17D37C66BFABC966750613 762136 ----a-w- C:\Users\Jelle\AppData\Local\Temp\uobnyv04ydl6.exe

    ====== Java Cache =====

    ====== C:\Windows\SysWOW64 =====

    ====== C:\Windows\SysWOW64\drivers =====

    ====== C:\Windows\Sysnative =====

    ====== C:\Windows\Sysnative\drivers =====

    2014-12-08 19:22:11 95B3CEAF06A2DF96FE28CD0755D319C4 79064 ----a-w- C:\Windows\Sysnative\drivers\qvbfgexw.sys

    2014-12-08 18:35:31 95B3CEAF06A2DF96FE28CD0755D319C4 79064 ----a-w- C:\Windows\Sysnative\drivers\cembn.sys

    2014-11-12 08:07:28 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys

    2014-11-12 08:07:28 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys

    2014-11-12 08:07:28 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\Sysnative\drivers\cng.sys

    2014-11-12 08:06:48 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\Sysnative\drivers\WdFilter.sys

    2014-11-12 08:06:47 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\Sysnative\drivers\WdNisDrv.sys

    2014-11-12 08:06:46 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\Sysnative\drivers\WdBoot.sys

    2014-11-12 08:05:48 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys

    2014-11-12 08:05:46 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\Sysnative\drivers\netio.sys

    2014-11-12 08:05:45 66732C13628BDB1AB0D6FD46027327C2 148800 -c--a-w- C:\Windows\Sysnative\drivers\USBSTOR.SYS

    2014-11-12 08:05:44 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS

    ====== C:\Windows\Tasks ======

    2014-12-08 15:52:28 FE19A729142DB2429CC66C8CD074CD9F 1360 ----a-w- C:\Windows\Tasks\DMHMP.job

    2014-12-08 15:52:28 C5FCDE79D26D673A2519B2F7F5931A23 4364 ----a-w- C:\Windows\Sysnative\Tasks\DMHMP

    2014-12-08 15:51:51 420C090AB1B130115143343193A1E7E9 1708 ----a-w- C:\Windows\Tasks\AVGNOJW.job

    2014-12-08 15:51:51 3767A5CED00EF87B8EF1869D614F177F 4714 ----a-w- C:\Windows\Sysnative\Tasks\AVGNOJW

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    2014-12-08 18:41:54 -------- d-----w- C:\Program Files\trend micro

    2014-12-08 15:52:22 -------- d-----w- C:\Program Files\Common Files\ShopperPro

    ======= C:\PROGRA~2 =====

    ======= C: =====

    ====== C:\Users\Jelle\AppData\Roaming ======

    2014-12-09 20:57:53 -------- d-----w- C:\Users\mieke_000\AppData\Local\Adobe_Systems_Incorporate

    2014-12-09 15:39:27 -------- d-sh--w- C:\Users\mieke_000\AppData\Locallow\EmieBrowserModeList

    ====== C:\Users\Jelle ======

    2014-12-09 20:57:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe

    2014-12-09 20:56:20 A1BBAA630BAB9F763FB8F01D061E528C 6144272 ----a-w- C:\Users\mieke_000\Downloads\ADE_3.0_Installer (1).exe

    2014-12-09 20:55:56 A1BBAA630BAB9F763FB8F01D061E528C 6144272 ----a-w- C:\Users\mieke_000\Downloads\ADE_3.0_Installer.exe

    2014-12-08 18:54:57 038B75662205880BE56A8FFA9930F830 5162080 ----a-w- C:\Users\Jelle\Downloads\ccsetup500.exe

    2014-12-08 18:40:52 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jelle\Desktop\RSITx64.exe

    2014-12-08 15:50:58 -------- d-----w- C:\ProgramData\IePluginServices

    2014-12-08 15:50:42 -------- d-----w- C:\ProgramData\WindowsMangerProtect

     

    ====== C: exe-files ==

    2014-12-09 20:56:20 A1BBAA630BAB9F763FB8F01D061E528C 6144272 ----a-w- C:\Users\mieke_000\Downloads\ADE_3.0_Installer (1).exe

    2014-12-09 20:55:56 A1BBAA630BAB9F763FB8F01D061E528C 6144272 ----a-w- C:\Users\mieke_000\Downloads\ADE_3.0_Installer.exe

    2014-12-08 18:54:57 038B75662205880BE56A8FFA9930F830 5162080 ----a-w- C:\Users\Jelle\Downloads\ccsetup500.exe

    2014-12-08 18:41:55 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Jelle.exe

    2014-12-08 18:40:52 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jelle\Desktop\RSITx64.exe

    2014-12-08 18:35:46 717E87D8F33D1AA7BC647828C2E178C8 222704 ----a-w- C:\Users\Jelle\AppData\Local\Temp\tu17p84.exe

    2014-12-08 15:50:49 E8B8EE3DF018745083CD3E1A0180B84B 6866769 ----a-w- C:\Users\Jelle\AppData\Local\Temp\Install_4738\ins_ytd.exe

    2014-12-08 15:50:49 5FB507803B530B46A26506956A81E9E4 4689355 ----a-w- C:\Users\Jelle\AppData\Local\Temp\Install_4738\ins_shopperpro.exe

    2014-12-08 09:30:00 179EF0D01F01A8D3AA1CB4D7D1C88796 2346880 ----a-w- C:\Program Files\Common Files\ShopperPro\spbiu.exe

    2014-12-08 00:05:32 11AD7B667A17D37C66BFABC966750613 762136 ----a-w- C:\Users\Jelle\AppData\Local\Temp\uobnyv04ydl6.exe

    === C: other files ==

    2014-12-08 19:22:11 95B3CEAF06A2DF96FE28CD0755D319C4 79064 ----a-w- C:\Windows\System32\drivers\qvbfgexw.sys

    2014-12-08 18:35:31 95B3CEAF06A2DF96FE28CD0755D319C4 79064 ----a-w- C:\Windows\System32\drivers\cembn.sys

     

    ==== Startup Registry Enabled ======================

     

    [HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1001\Software\Microsoft\Windows\CurrentVersion\Run]

    "AppLauncher"="C:\Program Files (x86)\Medion MediaPack 3\Ashampoo AppLauncher (Medion)\AppLauncher.exe"

     

    [HKEY_USERS\S-1-5-21-40242581-377180158-3296479076-1002\Software\Microsoft\Windows\CurrentVersion\Run]

    "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

     

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"

     

    ==== Startup Registry Enabled x64 ======================

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IAStorIcon"="C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe 60"

    "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"

    "BoxSync"="C:\Program Files\Box\Box Sync\BoxSync.exe -m"

     

    ==== Startup Folders ======================

     

    2014-04-18 06:32:09 1102 ----a-w- C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    2014-05-19 06:23:49 1106 ----a-w- C:\Users\mieke_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

     

    ==== Task Scheduler Jobs ======================

     

    C:\Windows\tasks\AVGNOJW.job --a-------- C:\Users\mieke_000\AppData\Roaming\AVGNOJW.exe []

    C:\Windows\tasks\DMHMP.job --a-------- C:\Users\mieke_000\AppData\Roaming\DMHMP.exe []

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/03/2014 07:33]

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/03/2014 07:33]

     

    ==== Other Scheduled Tasks ======================

     

    "C:\Windows\SysNative\tasks\AVGNOJW" [C:\Users\mieke_000\AppData\Roaming\AVGNOJW.exe]

    "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]

    "C:\Windows\SysNative\tasks\DMHMP" [C:\Users\mieke_000\AppData\Roaming\DMHMP.exe]

    "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

    "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

    "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{64BAB2E2-20A5-409C-AEAA-2C0491862C20}" [C:\Windows\system32\msfeedssync.exe]

    "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{F2C56A42-47A5-4083-9491-7A4F73EF528A}" [C:\Windows\system32\msfeedssync.exe]

    "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

     

    ==== Firefox Extensions Registry ======================

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]

    "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" []

     

    ==== Chromium Look ======================

     

    Google Docs - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    selector is not a valid CSS selector - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb

    Google Search - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Google Wallet - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    Google Docs - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Google Wallet - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - mieke_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

     

    ==== Chromium Fix ======================

     

    C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully

    C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully

     

    ==== Set IE to Default ======================

     

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

    "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found

     

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

    "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

     

    ==== All HKCU SearchScopes ======================

     

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    {012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"

    {D48D43D9-DF6C-4B39-BE6F-C8A0B2253078} Bing  Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB"

     

    ==== Deleting CLSID Registry Keys ======================

     

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== shortcuts on Users Desktops ======================

     

    C:\Users\Default\Desktop\ALDI Foto Service.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.aldifoto.be/nl

    C:\Users\Default\Desktop\ALDI Startpagina.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://aldi-bn.aldi.be/

    C:\Users\Default\Desktop\ALDI Talk.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medionmobile.be/

    C:\Users\Default\Desktop\LIFESTORE.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medion.com/lifestore

    C:\Users\Default\Desktop\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medion.com/be/nl

    C:\Users\Default User\Desktop\ALDI Foto Service.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.aldifoto.be/nl

    C:\Users\Default User\Desktop\ALDI Startpagina.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://aldi-bn.aldi.be/

    C:\Users\Default User\Desktop\ALDI Talk.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medionmobile.be/

    C:\Users\Default User\Desktop\LIFESTORE.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medion.com/lifestore

    C:\Users\Default User\Desktop\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.medion.com/be/nl

    C:\Users\Jelle\Desktop\Box Sync.lnk - C:\Users\Jelle\Box Sync 

    C:\Users\Jelle\Desktop\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /home

    C:\Users\mieke_000\Desktop\Box Sync.lnk - C:\Users\Jelle\Box Sync 

    C:\Users\mieke_000\Desktop\DOCTORAAT 13aug2014 - Snelkoppeling.lnk - C:\Users\mieke_000\Dropbox\DOCTORAAT 13aug2014 

    C:\Users\mieke_000\Desktop\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /home

    C:\Users\mieke_000\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\mieke_000\Desktop\Theoretische Dringende ReadingList dec2014 - Snelkoppeling.lnk - C:\Users\mieke_000\Dropbox\DOCTORAAT 13aug2014\BIBLIOGRAPHY\Theoretische Dringende ReadingList dec2014.docx 

     

    ==== shortcuts on All Users Desktop ======================

     

    C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe 

    C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe 

    C:\Users\Public\Desktop\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe 

    C:\Users\Public\Desktop\ePainter.lnk - C:\Program Files (x86)\AkzoNobel\OwnRooms\OwnRooms.exe 

    C:\Users\Public\Desktop\Kruidvat fotoservice.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\Kruidvat fotoservice.exe 

    C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 

     

    ==== shortcuts in Users Start Menu ======================

     

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /home

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Uninstall Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DOCTORAAT 13aug2014.lnk - C:\Users\mieke_000\Dropbox\DOCTORAAT 13aug2014 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /home

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Uninstall Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup

     

    ==== shortcuts in All Users Start Menu ======================

     

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AB0000000001}\SC_Reader.ico 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Help.lnk -  

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Home Page.lnk -  

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Uninstall.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\uninstall.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync\Box Sync.lnk - C:\Windows\Installer\{09C53B19-C578-4803-95EF-DDEDF89D080C}\BoxSync.ico 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Verwijder Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm 

     

    ==== shortcuts in Quick Launch ======================

     

    C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  

    C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  

    C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  

    C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -  

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -  

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1418053832&from=amt&uid=TOSHIBAXDT01ACA100_14KJM2NNSXX14KJM2NNSX

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\iTunes (2).lnk - C:\Program Files (x86)\iTunes\iTunes.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Excel 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office PowerPoint 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office15\FIRSTRUN.EXE /OEM

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\µTorrent.lnk -  

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -  

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office PowerPoint 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office15\FIRSTRUN.EXE /OEM

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Paint.lnk - C:\Windows\system32\mspaint.exe 

    C:\Users\mieke_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1

    C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -  

    C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -  

     

    ==== shortcuts After Repair ======================

     

    C:\Users\Default\Desktop\ALDI Foto Service.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default\Desktop\ALDI Startpagina.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default\Desktop\ALDI Talk.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default\Desktop\LIFESTORE.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default\Desktop\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default User\Desktop\ALDI Foto Service.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default User\Desktop\ALDI Startpagina.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default User\Desktop\ALDI Talk.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default User\Desktop\LIFESTORE.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Default User\Desktop\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe 

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

    C:\Users\Jelle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe 

     

    ==== HijackThis Entries ======================

     

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR

    O4 - HKUS\S-1-5-21-40242581-377180158-3296479076-1001\..\Run: [AppLauncher] C:\Program Files (x86)\Medion MediaPack 3\Ashampoo AppLauncher (Medion)\AppLauncher.exe (User 'UpdatusUser')

    O4 - Startup: Dropbox.lnk = Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU)

    O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU)

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Box Sync Update Service (BoxSyncUpdateService) - Box, Inc. - C:\Program Files\Box\Box Sync\SyncUpdaterService.exe

    O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

     

    ==== Empty IE Cache ======================

     

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Jelle\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Jelle\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Users\mieke_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\mieke_000\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Jelle\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Jelle\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully

    C:\Users\mieke_000\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\mieke_000\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

     

    ==== Empty FireFox Cache ======================

     

    No FireFox Profiles found

     

    ==== Empty Chrome Cache ======================

     

    C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    C:\Users\mieke_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

     

    ==== Empty All Flash Cache ======================

     

    Flash Cache Emptied Successfully

     

    ==== Empty All Java Cache ======================

     

    No Java Cache Found

     

    ==== C:\zoek_backup content ======================

     

    C:\zoek_backup (files=30 folders=25 8330888 bytes)

     

    ==== Empty Temp Folders ======================

     

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\Jelle\AppData\Local\Temp will be emptied at reboot

    C:\Users\mieke_000\AppData\Local\Temp emptied successfully

    C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\Windows\Temp will be emptied at reboot

     

    ==== After Reboot ======================

     

    ==== Empty Temp Folders ======================

     

    C:\Windows\Temp successfully emptied

    C:\Users\Jelle\AppData\Local\Temp successfully emptied

     

    ==== Empty Recycle Bin ======================

     

    C:\$RECYCLE.BIN successfully emptied

     

    ==== Deleting Files / Folders ======================

     

    "C:\Program Files\Common Files\ShopperPro\spbiu.exe"  not found

    "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

    "C:\Program Files\Common Files\ShopperPro"  not found

    "C:\ProgramData\IePluginServices"  not found

    "C:\ProgramData\WindowsMangerProtect"  not found

    "C:\PROGRA~3\IePluginServices"  not found

    "C:\PROGRA~3\IePluginServices"  not found

    "C:\PROGRA~3\WindowsMangerProtect"  not found

     

    ==== EOF on di 09/12/2014 at 22:44:18,91 ======================
  4.  

    Hi, 

     

    Mijn vriendin heeft per ongeluk een bestandje aangeklikt op internet, dat allerlei malware programma's heeft geinstalleerd op m'n pc. 

    De meeste hiervan heb ik kunnen verwijderen via Configuratiescherm & heb Anti-malware bytes al eens laten lopen. 

     

    Momenteel wordt mijn startpagina van Chrome echter nog altijd opnieuw gewijzigd naar een "startmysearch" pagina, en heb ik nog een icoontje van "Searchprotect" staan bij mijn systeemicoontje. Voorspelt weinig goeds dus.

     

    Vandaar even mijn logje. 

     

    Alvast bedankt voor de hulp.

    Groeten.

     

     

     

    Logfile of random's system information tool 1.10 (written by random/random)

    Run by Jelle at 2014-12-08 19:41:54

    Microsoft Windows 8.1 

    System drive C: has 681 GB (76%) free of 891 GB

    Total RAM: 4051 MB (50% free)

     

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 19:41:58, on 8/12/2014

    Platform: Unknown Windows (WinNT 6.02.1008)

    MSIE: Internet Explorer v11.0 (11.00.9600.17416)

    Boot mode: Normal

     

    Running processes:

    C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1434\jsdrv.exe

    C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Program Files (x86)\SupTab\HpUI.exe

    C:\Program Files (x86)\SupTab\Loader32.exe

    C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Windows\syswow64\wwahost.exe

    C:\Program Files\trend micro\Jelle.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot

    O4 - HKLM\..\Run: [salus] C:\Program Files (x86)\f552dd4c52e3\b786bdb3c67d.exe

    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe" "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware"

    O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot

    O4 - HKUS\S-1-5-21-40242581-377180158-3296479076-1001\..\Run: [AppLauncher] C:\Program Files (x86)\Medion MediaPack 3\Ashampoo AppLauncher (Medion)\AppLauncher.exe (User 'UpdatusUser')

    O4 - Startup: Dropbox.lnk = Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU)

    O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU)

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Box Sync Update Service (BoxSyncUpdateService) - Box, Inc. - C:\Program Files\Box\Box Sync\SyncUpdaterService.exe

    O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Universal Updater Service (UniversalUpdater) - Unknown owner - C:\Program Files (x86)\0ca45c95134d\cf3e08d747e4.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

     

    --

    End of file - 8897 bytes

     

    ======Listing Processes======

     

     

     

     

     

    wininit.exe

     

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    "C:\Windows\system32\nvvsvc.exe"

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"

    "C:\Program Files\Bonjour\mDNSResponder.exe"

    dashost.exe {4249051b-0712-42f3-acc8e4537dcfc56e}

    C:\Windows\system32\svchost.exe -k imgsvc

     

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalServicePeerNet

     

    C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}

    C:\Windows\system32\SearchIndexer.exe /Embedding

    "C:\Program Files\iPod\bin\iPodService.exe"

    "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe"

    "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"

    "C:\Program Files\Windows Media Player\wmpnetwk.exe"

    C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service

    C:\ProgramData\IePluginServices\PluginService.exe -service

    "C:\Program Files\Common Files\ShopperPro\spbiu.exe" /service

    "C:\Program Files (x86)\0ca45c95134d\cf3e08d747e4.exe"

    "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7cae713e-21a3-4622-b504-ee19b70a5c0d -SystemEventPortName:HostProcess-6a1909b7-8a6f-45ad-95f2-83af79e6ffed -IoCancelEventPortName:HostProcess-ca42f200-233c-4a52-9100-f7988f71222f -NonStateChangingEventPortName:HostProcess-d57548be-b80b-4daa-af8c-f4be5a70f14e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:014e737c-7f7e-49b4-b423-0ba818c4af4a -DeviceGroupId:

     

    winlogon.exe

    "dwm.exe"

    "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"

    C:\Windows\system32\nvvsvc.exe -session

    taskhostex.exe 

    C:\Windows\Explorer.EXE

    C:\Windows\System32\skydrive.exe -Embedding

    "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1

    "C:\Windows\System32\SettingSyncHost.exe" -Embedding

    "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s

    "C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1434\jsdrv.exe" 

    "C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup

    "C:\Program Files (x86)\iTunes\iTunesHelper.exe" 

    "C:\Program Files (x86)\SupTab\HpUI.exe" -run

    "C:\Program Files (x86)\SupTab\Loader64.exe" 

    "C:\Program Files (x86)\SupTab\Loader32.exe" 

    "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe"

    taskhost.exe 

    taskhost.exe $(Arg0)

    "C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 65E746BB-0829-19CC-E3A2-AD1E7C4C3C97 -Reinvoke


    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5252.0.1201249762\1401067872" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38,46 --gpu-vendor-id=0x10de --gpu-device-id=0x1382 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3235 --ignored=" --type=renderer " /prefetch:822062411

    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_38/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5252.1.293524107\912204902" /prefetch:673131151

    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_38/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5252.2.445022969\924216113" /prefetch:673131151

    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Disabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_38/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5252.8.1027542747\1687234586" /prefetch:673131151

    "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5252.9.925639626\1325423877" --ppapi-flash-args=enable_hw_video_decode=1 --lang=nl --ignored=" --type=renderer " /prefetch:-632637702

    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe168_ Global\UsGthrCtrlFltPipeMssGthrPipe168 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 

    "C:\Windows\system32\SearchFilterHost.exe" 0 576 580 588 65536 584 

     

    "C:\Users\Jelle\Desktop\RSITx64.exe" 

    "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server

    "C:\Windows\syswow64\wwahost.exe" -ServerName:App.wwa

    C:\Windows\System32\RuntimeBroker.exe -Embedding

    C:\Windows\system32\wbem\wmiprvse.exe

     

    ======Scheduled tasks folder======

     

    C:\Windows\tasks\AVGNOJW.job - C:\Users\mieke_000\AppData\Roaming\AVGNOJW.exe  /infocmdline=EVbq3I6mFN8RARhFcw2Ed740Jnzs1c1ks5fbtMKCNy8Z5ezYD+0MgioHxryPyJ/bqHTHnK+OqWtWoo9D5yWhb/YnXm5I1B1cbz//OZmYBUX1inxHTJsaHvn+mX2x9CNg7tCqYl0NO1vgWST7R9PmFJPDu2KLkDj96arAg0hczeVEpqW3eaULQfO2trZ/LTXA1oS/QXTN2sE3ucRKlLPphvviL3CHRK4L4MNedWE8KUoJGo1o/GYuXNIesunGJdjOkdh8wjzTxD3UXr8kg5jIaRJuyVds5z1Hb5G7dCU3Y7fo7VI9ERCDcqqpbn9xLkEz5Yz2oB6G9AcC9tlojRs3orX5908p1TVUoFQKKcff9zuoCG9tPOsJ0vlR2HGfiMEfxXsZFM1MM086vySRW2f8tR9b+KYVM/EHjdQPbMCLySLKGgDJRjh82CkLnonKC3gIJvHkAd3MpceiIkfi/tHvL1QzZalkmhWP7XDcs6WAeMzJWj8Ut5XdsKv3RtrkgD3oqA5POcZgiGcz88A0D/owDv2EW28VYmjIYUpcNAfwwBd8A7nOqSIXtDw3Vqe0JeZHQr6Yp/Ves+OqMM8587Ryv2iCkwpevi6rrr9x9A4crcJfU6S+2xTNAyYBSdpWy9qW1vh9vSUNyhCrdLSjq0PfHww9PoW/hIZdMw4hjfXxM70= 

    C:\Windows\tasks\DMHMP.job - C:\Users\mieke_000\AppData\Roaming\DMHMP.exe  /infocmdline=wslPuO13l2Qejgzfagyoi050OI3njiwYAuR0e5lgrpbq90ofs8vYE3KNDIVyBJVvsXYQAC3CZCGQyCHvFh4wxrL1hwSa655WctosEy+sWsPE3otPFeptjzuJmyh0+LYGtSWg9OrXJiSKEEQ3Yi67WUtO5LsKii+eLkeXU4aZiTacQLM36L76kmSIAZ3QSlDlJZK7PF/wbVZ9dZUu95N0MMpThoNSCaWksm1+zXxovKcGQ73+WpGpxQxnL7wGeOELhKFILN7ffpYSnGw2TMQQVEhj1uIy0WzU/qhAtUknhTRwRZ9WQQ7KhLn0j7pfwGuPCnSgxKqKyP9DSgIZqVsnGL5DfwQ3OIw0Xlux2oTFoxHlN+fEYx4MRCp0m0tMvmpMALOMQv7wmduJj4+C5uv1mBOAHYOVaY7vmYcXp4uZzdsw8497sUc9IXxlJWmGBaC186A9psN4D29Drw3jZlCtxKIHTJGyiGepVCer+9y/vRHkq/0+12s7GtKkLwu0mmK3 

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

     

    ======Registry dump======

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

    Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

     

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

    "IAStorIcon"=C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]

    "RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]

    "BoxSync"=C:\Program Files\Box\Box Sync\BoxSync.exe [2014-11-13 5609176]

     

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []

     

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

    "iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-02-21 152392]

    "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]

    "GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

    "beid"=C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup []

    "YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []

    "Salus"=C:\Program Files (x86)\f552dd4c52e3\b786bdb3c67d.exe [2014-12-08 1114624]

     

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]

    "Malwarebytes Anti-Malware (cleanup)"=C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [2014-11-21 54072]

     

    C:\Users\Jelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

    Dropbox.lnk - C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]

    C:\Windows\system32\igfxdev.dll [2014-01-08 624640]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

     

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

    "ConfirmFileDelete"=1

     

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

     

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm

    "VIDC.YUY2"=msyuv.dll

    "vidc.i420"=iyuv_32.dll

    "msacm.msgsm610"=msgsm32.acm

    "msacm.msg711"=msg711.acm

    "VIDC.YVYU"=msyuv.dll

    "VIDC.YVU9"=tsbyuv.dll

    "wavemapper"=msacm32.drv

    "midimapper"=midimap.dll

    "VIDC.UYVY"=msyuv.dll

    "VIDC.IYUV"=iyuv_32.dll

    "vidc.mrle"=msrle32.dll

    "msacm.imaadpcm"=imaadp32.acm

    "msacm.msadpcm"=msadp32.acm

    "vidc.msvc"=msvidc32.dll

    "wave"=wdmaud.drv

    "midi"=wdmaud.drv

    "mixer"=wdmaud.drv

    "aux"=wdmaud.drv

    "wave1"=wdmaud.drv

    "midi1"=wdmaud.drv

    "mixer1"=wdmaud.drv

    "MSVideo8"=VfWWDM32.dll

    "wave2"=wdmaud.drv

    "midi2"=wdmaud.drv

    "mixer2"=wdmaud.drv

    "aux1"=wdmaud.drv

    "wave3"=wdmaud.drv

    "midi3"=wdmaud.drv

    "mixer3"=wdmaud.drv

    "aux2"=wdmaud.drv

     

    ======File associations======

     

    .js - edit - C:\Windows\System32\Notepad.exe %1

    .js - open - C:\Windows\System32\WScript.exe "%1" %*

     

    ======List of files/folders created in the last 1 month======

     

    2014-12-08 19:41:54 ----D---- C:\rsit

    2014-12-08 19:41:54 ----D---- C:\Program Files\trend micro

    2014-12-08 19:35:31 ----A---- C:\Windows\system32\drivers\cembn.sys

    2014-12-08 16:53:04 ----D---- C:\Program Files (x86)\Universal Updater

    2014-12-08 16:53:04 ----D---- C:\Program Files (x86)\0ca45c95134d

    2014-12-08 16:53:03 ----D---- C:\Program Files (x86)\f552dd4c52e3

    2014-12-08 16:52:22 ----D---- C:\Program Files\Common Files\ShopperPro

    2014-12-08 16:51:52 ----D---- C:\Program Files (x86)\fb9c456e-c6d8-4567-b255-31f106c1ca11

    2014-12-08 16:51:46 ----D---- C:\Program Files (x86)\globalUpdate

    2014-12-08 16:51:09 ----D---- C:\Program Files (x86)\ShopperPro

    2014-12-08 16:50:58 ----D---- C:\ProgramData\IePluginServices

    2014-12-08 16:50:48 ----D---- C:\Program Files (x86)\SupTab

    2014-12-08 16:50:42 ----D---- C:\ProgramData\WindowsMangerProtect

    2014-12-08 01:08:08 ----A---- C:\Windows\system32\drivers\b786bdb3c67d.sys

    2014-11-19 08:49:09 ----A---- C:\Windows\SYSWOW64\pku2u.dll

    2014-11-19 08:49:09 ----A---- C:\Windows\SYSWOW64\kerberos.dll

    2014-11-19 08:49:09 ----A---- C:\Windows\system32\pku2u.dll

    2014-11-19 08:49:09 ----A---- C:\Windows\system32\kerberos.dll

    2014-11-12 09:08:40 ----A---- C:\Windows\SYSWOW64\msxml3.dll

    2014-11-12 09:08:39 ----A---- C:\Windows\system32\msxml3.dll

    2014-11-12 09:08:33 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll

    2014-11-12 09:08:33 ----A---- C:\Windows\system32\audiosrv.dll

    2014-11-12 09:08:33 ----A---- C:\Windows\system32\AudioSes.dll

    2014-11-12 09:08:33 ----A---- C:\Windows\system32\AUDIOKSE.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\SYSWOW64\AudioSes.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\SYSWOW64\AudioEng.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\system32\EncDump.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\system32\AudioEng.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll

    2014-11-12 09:08:32 ----A---- C:\Windows\system32\audiodg.exe

    2014-11-12 09:08:29 ----A---- C:\Windows\system32\mshtml.dll

    2014-11-12 09:08:27 ----A---- C:\Windows\SYSWOW64\mshtml.dll

    2014-11-12 09:08:05 ----A---- C:\Windows\system32\ieframe.dll

    2014-11-12 09:08:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll

    2014-11-12 09:07:57 ----A---- C:\Windows\system32\jscript9.dll

    2014-11-12 09:07:56 ----A---- C:\Windows\SYSWOW64\jscript9.dll

    2014-11-12 09:07:55 ----A---- C:\Windows\system32\wininet.dll

    2014-11-12 09:07:54 ----A---- C:\Windows\SYSWOW64\wininet.dll

    2014-11-12 09:07:54 ----A---- C:\Windows\SYSWOW64\urlmon.dll

    2014-11-12 09:07:54 ----A---- C:\Windows\system32\urlmon.dll

    2014-11-12 09:07:53 ----A---- C:\Windows\SYSWOW64\inetcomm.dll

    2014-11-12 09:07:53 ----A---- C:\Windows\system32\inetcomm.dll

    2014-11-12 09:07:53 ----A---- C:\Windows\system32\iertutil.dll

    2014-11-12 09:07:53 ----A---- C:\Windows\system32\actxprxy.dll

    2014-11-12 09:07:52 ----A---- C:\Windows\SYSWOW64\jscript.dll

    2014-11-12 09:07:52 ----A---- C:\Windows\SYSWOW64\iertutil.dll

    2014-11-12 09:07:52 ----A---- C:\Windows\system32\jscript9diag.dll

    2014-11-12 09:07:52 ----A---- C:\Windows\system32\jscript.dll

    2014-11-12 09:07:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

    2014-11-12 09:07:51 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll

    2014-11-12 09:07:51 ----A---- C:\Windows\system32\msfeeds.dll

    2014-11-12 09:07:51 ----A---- C:\Windows\system32\ieui.dll

    2014-11-12 09:07:50 ----A---- C:\Windows\SYSWOW64\vbscript.dll

    2014-11-12 09:07:50 ----A---- C:\Windows\SYSWOW64\ieui.dll

    2014-11-12 09:07:50 ----A---- C:\Windows\system32\vbscript.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\SYSWOW64\dxtrans.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\system32\ieapfltr.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\system32\dxtrans.dll

    2014-11-12 09:07:47 ----A---- C:\Windows\system32\dxtmsft.dll

    2014-11-12 09:07:46 ----A---- C:\Windows\SYSWOW64\webcheck.dll

    2014-11-12 09:07:46 ----A---- C:\Windows\system32\webcheck.dll

    2014-11-12 09:07:46 ----A---- C:\Windows\system32\ieetwproxystub.dll

    2014-11-12 09:07:45 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll

    2014-11-12 09:07:45 ----A---- C:\Windows\SYSWOW64\hlink.dll

    2014-11-12 09:07:45 ----A---- C:\Windows\system32\iedkcs32.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\msrating.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\inseng.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\iesysprep.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\iepeers.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\SYSWOW64\actxprxy.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\inseng.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\ieUnatt.exe

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\iesysprep.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\iepeers.dll

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\ieetwcollector.exe

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\ie4uinit.exe

    2014-11-12 09:07:44 ----A---- C:\Windows\system32\hlink.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\occache.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\mshtmled.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\iexpress.exe

    2014-11-12 09:07:43 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\msrating.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\mshtmled.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\MshtmlDac.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\msfeedsbs.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\jsproxy.dll

    2014-11-12 09:07:43 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\wextract.exe

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\url.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\pngfilt.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\licmgr10.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\imgutil.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\iesetup.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\url.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\pngfilt.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\occache.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\licmgr10.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\imgutil.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\iernonce.dll

    2014-11-12 09:07:42 ----A---- C:\Windows\system32\IEAdvpack.dll

    2014-11-12 09:07:41 ----A---- C:\Windows\SYSWOW64\mshta.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\system32\wextract.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\system32\mshta.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\system32\msfeedssync.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\system32\iexpress.exe

    2014-11-12 09:07:41 ----A---- C:\Windows\system32\iesetup.dll

    2014-11-12 09:07:33 ----A---- C:\Windows\SYSWOW64\schannel.dll

    2014-11-12 09:07:33 ----A---- C:\Windows\SYSWOW64\ncryptsslp.dll

    2014-11-12 09:07:33 ----A---- C:\Windows\system32\schannel.dll

    2014-11-12 09:07:33 ----A---- C:\Windows\system32\ncryptsslp.dll

    2014-11-12 09:07:33 ----A---- C:\Windows\system32\dpapisrv.dll

    2014-11-12 09:07:32 ----A---- C:\Windows\system32\win32k.sys

    2014-11-12 09:07:31 ----A---- C:\Windows\SYSWOW64\packager.dll

    2014-11-12 09:07:31 ----A---- C:\Windows\system32\packager.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\SYSWOW64\msaudite.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\SYSWOW64\certcli.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\SYSWOW64\adtschema.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\rfxvmt.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\rdpudd.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\rdpcorets.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\msaudite.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\lsasrv.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\drivers\ksecpkg.sys

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\drivers\cng.sys

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\certcli.dll

    2014-11-12 09:07:28 ----A---- C:\Windows\system32\adtschema.dll

    2014-11-12 09:07:21 ----A---- C:\Windows\SYSWOW64\oleaut32.dll

    2014-11-12 09:07:21 ----A---- C:\Windows\system32\oleaut32.dll

    2014-11-12 09:07:19 ----A---- C:\Windows\system32\devinv.dll

    2014-11-12 09:07:19 ----A---- C:\Windows\system32\aepdu.dll

    2014-11-12 09:07:18 ----A---- C:\Windows\system32\generaltel.dll

    2014-11-12 09:07:18 ----A---- C:\Windows\system32\aeinv.dll

    2014-11-12 09:07:16 ----A---- C:\Windows\system32\aepic.dll

    2014-11-12 09:07:15 ----A---- C:\Windows\SYSWOW64\msi.dll

    2014-11-12 09:07:15 ----A---- C:\Windows\system32\msi.dll

    2014-11-12 09:07:15 ----A---- C:\Windows\system32\authui.dll

    2014-11-12 09:07:14 ----A---- C:\Windows\SYSWOW64\msihnd.dll

    2014-11-12 09:07:14 ----A---- C:\Windows\SYSWOW64\authui.dll

    2014-11-12 09:07:14 ----A---- C:\Windows\system32\msihnd.dll

    2014-11-12 09:07:13 ----A---- C:\Windows\system32\consent.exe

    2014-11-12 09:07:13 ----A---- C:\Windows\system32\appinfo.dll

    2014-11-12 09:07:08 ----A---- C:\Windows\system32\wuaueng.dll

    2014-11-12 09:07:08 ----A---- C:\Windows\system32\wuapi.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\SYSWOW64\wuwebv.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\SYSWOW64\wudriver.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\SYSWOW64\wuapi.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\system32\wuwebv.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\system32\WUSettingsProvider.dll

    2014-11-12 09:07:07 ----A---- C:\Windows\system32\wucltux.dll

    2014-11-12 09:07:06 ----A---- C:\Windows\SYSWOW64\wups.dll

    2014-11-12 09:07:06 ----A---- C:\Windows\SYSWOW64\wuapp.exe

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wups2.dll

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wups.dll

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wudriver.dll

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wuauclt.exe

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wuapp.exe

    2014-11-12 09:07:06 ----A---- C:\Windows\system32\wuaext.dll

    2014-11-12 09:06:52 ----A---- C:\Windows\system32\user32.dll

    2014-11-12 09:06:49 ----A---- C:\Windows\SYSWOW64\user32.dll

    2014-11-12 09:06:48 ----A---- C:\Windows\system32\drivers\WdFilter.sys

    2014-11-12 09:06:47 ----A---- C:\Windows\system32\drivers\WdNisDrv.sys

    2014-11-12 09:06:46 ----A---- C:\Windows\system32\drivers\WdBoot.sys

    2014-11-12 09:06:45 ----A---- C:\Windows\SYSWOW64\winshfhc.dll

    2014-11-12 09:06:45 ----A---- C:\Windows\system32\winshfhc.dll

    2014-11-12 09:05:54 ----A---- C:\Windows\system32\shell32.dll

    2014-11-12 09:05:53 ----A---- C:\Windows\system32\ntoskrnl.exe

    2014-11-12 09:05:52 ----A---- C:\Windows\SYSWOW64\shell32.dll

    2014-11-12 09:05:49 ----A---- C:\Windows\system32\SettingsHandlers.dll

    2014-11-12 09:05:48 ----A---- C:\Windows\system32\twinui.dll

    2014-11-12 09:05:48 ----A---- C:\Windows\system32\localspl.dll

    2014-11-12 09:05:48 ----A---- C:\Windows\system32\drivers\tcpip.sys

    2014-11-12 09:05:47 ----A---- C:\Windows\system32\mfmp4srcsnk.dll

    2014-11-12 09:05:47 ----A---- C:\Windows\system32\MFMediaEngine.dll

    2014-11-12 09:05:46 ----A---- C:\Windows\SYSWOW64\twinui.dll

    2014-11-12 09:05:46 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll

    2014-11-12 09:05:46 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll

    2014-11-12 09:05:46 ----A---- C:\Windows\system32\win32spl.dll

    2014-11-12 09:05:46 ----A---- C:\Windows\system32\drivers\netio.sys

    2014-11-12 09:05:45 ----AC---- C:\Windows\system32\drivers\USBSTOR.SYS

    2014-11-12 09:05:45 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll

    2014-11-12 09:05:45 ----A---- C:\Windows\SYSWOW64\puiobj.dll

    2014-11-12 09:05:45 ----A---- C:\Windows\system32\WsmSvc.dll

    2014-11-12 09:05:45 ----A---- C:\Windows\system32\puiobj.dll

    2014-11-12 09:05:44 ----A---- C:\Windows\SYSWOW64\untfs.dll

    2014-11-12 09:05:44 ----A---- C:\Windows\system32\untfs.dll

    2014-11-12 09:05:44 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS

    2014-11-12 09:05:43 ----A---- C:\Windows\system32\FXSCOMEX.dll

    2014-11-12 09:05:41 ----A---- C:\Windows\system32\FXSAPI.dll

    2014-11-12 09:05:36 ----A---- C:\Windows\SYSWOW64\FXSAPI.dll

     

    ======List of files/folders modified in the last 1 month======

     

    2014-12-08 19:41:54 ----RD---- C:\Program Files

    2014-12-08 19:41:31 ----D---- C:\Windows\Prefetch

    2014-12-08 19:36:31 ----RD---- C:\Program Files (x86)

    2014-12-08 19:36:30 ----HD---- C:\ProgramData

    2014-12-08 19:36:22 ----D---- C:\Windows\Temp

    2014-12-08 19:36:08 ----D---- C:\Windows\system32\Tasks

    2014-12-08 19:36:08 ----D---- C:\Program Files\Common Files\System

    2014-12-08 19:35:31 ----D---- C:\Windows\system32\drivers

    2014-12-08 19:35:31 ----D---- C:\Windows\da

    2014-12-08 19:35:08 ----D---- C:\Windows\Tasks

    2014-12-08 19:35:08 ----D---- C:\Program Files (x86)\AGEIA Technologies

    2014-12-08 19:19:56 ----HD---- C:\Program Files\WindowsApps

    2014-12-08 19:19:54 ----D---- C:\Windows\AppReadiness

    2014-12-08 19:12:07 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware

    2014-12-08 19:10:19 ----D---- C:\Users\Jelle\AppData\Roaming\Dropbox

    2014-12-08 19:00:19 ----D---- C:\Windows\system32\sru

    2014-12-08 17:19:20 ----D---- C:\Windows\Microsoft.NET

    2014-12-08 16:53:25 ----D---- C:\Windows\SysWOW64

    2014-12-08 16:52:22 ----D---- C:\Program Files\Common Files

    2014-12-08 16:52:04 ----SHD---- C:\Windows\Installer

    2014-12-08 13:46:25 ----D---- C:\Windows\system32\config

    2014-12-03 23:50:27 ----RD---- C:\Windows\System32

    2014-12-03 23:50:27 ----D---- C:\Windows\Inf

    2014-12-03 23:50:27 ----A---- C:\Windows\system32\PerfStringBackup.INI

    2014-12-03 11:48:37 ----SHD---- C:\System Volume Information

    2014-12-01 12:13:53 ----D---- C:\ProgramData\CanonIJPLM

    2014-11-26 07:58:01 ----D---- C:\Windows\CbsTemp

    2014-11-26 07:57:59 ----D---- C:\Windows\WinSxS

    2014-11-20 21:51:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

    2014-11-18 09:32:42 ----D---- C:\Windows\system32\catroot2

    2014-11-17 21:17:09 ----D---- C:\Program Files (x86)\Microsoft Office

    2014-11-17 12:51:58 ----D---- C:\Windows\rescache

    2014-11-17 12:28:19 ----D---- C:\Windows\system32\DriverStore

    2014-11-15 09:43:00 ----D---- C:\Windows\system32\MRT

    2014-11-15 09:40:34 ----A---- C:\Windows\system32\MRT.exe

    2014-11-15 08:46:53 ----D---- C:\Windows\system32\catroot

    2014-11-14 21:50:16 ----SD---- C:\Windows\system32\CompatTel

    2014-11-14 21:50:12 ----D---- C:\Program Files\Windows Defender

    2014-11-14 21:50:11 ----D---- C:\Program Files (x86)\Windows Defender

    2014-11-14 21:50:07 ----D---- C:\Windows\system32\wbem

    2014-11-14 21:50:04 ----D---- C:\Windows\SYSWOW64\nl-NL

    2014-11-14 21:50:04 ----D---- C:\Windows\system32\nl-NL

    2014-11-14 21:50:00 ----D---- C:\Program Files (x86)\Internet Explorer

    2014-11-14 21:49:58 ----D---- C:\Windows\SYSWOW64\migration

    2014-11-14 21:49:56 ----D---- C:\Windows\system32\migration

    2014-11-14 21:49:53 ----D---- C:\Program Files\Internet Explorer

    2014-11-14 15:55:13 ----D---- C:\ProgramData\Microsoft Help

    2014-11-12 16:41:02 ----RD---- C:\Windows\ToastData

    2014-11-12 16:40:59 ----RD---- C:\Windows\ImmersiveControlPanel

    2014-11-12 16:40:58 ----D---- C:\Windows\apppatch

    2014-11-12 11:22:05 ----RD---- C:\Windows\assembly

    2014-11-09 09:58:05 ----D---- C:\Users\Jelle\AppData\Roaming\uTorrent

     

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

     

    R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-21 632168]

    R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-03-13 157016]

    R1 b786bdb3c67d;b786bdb3c67d; C:\Windows\system32\drivers\b786bdb3c67d.sys [2014-12-08 51528]

    R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]

    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]

    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-10-29 3698904]

    R3 MEIx64;@oem16.inf,%TEE_SvcDesc%;Intel® Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-04 99288]

    R3 NVHDA;@oem14.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]

    R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-01-08 12652320]

    R3 RTL8168;@oem15.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-08-15 830680]

    R3 RtlWlanu;@oem2.inf,%RtlWlanu.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtwlanu.sys [2014-01-15 2968280]

    R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]

    R3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2013-08-22 78848]

    S0 ubbtcuot;ubbtcuot; C:\Windows\System32\drivers\cembn.sys [2014-12-08 79064]

    S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-08 4220416]

    S3 intaud_WaveExtensible;@oem11.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys []

    S3 IntcDAud;@oem9.inf,%IntcDAud.SvcDesc%;Intel® Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-01-08 450520]

    S3 iwdbus;@oem12.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys []

    S3 USBAAPL64;@oem12.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2013-03-18 54784]

    S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088]

    S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]

    S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\Windows\System32\drivers\WSDPrint.sys [2013-08-22 20992]

    S3 WSDScan;@sti.inf,%WSDScan.SvcDesc%;Ondersteuning voor WSD-scan; C:\Windows\System32\drivers\WSDScan.sys [2013-08-22 23040]

     

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

     

    R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]

    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-02-12 43336]

    R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]

    R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]

    R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-01-08 922912]

    R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2014-01-08 1364256]

    R2 UniversalUpdater;Universal Updater Service; C:\Program Files (x86)\0ca45c95134d\cf3e08d747e4.exe [2014-12-08 697344]

    R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2014-02-21 641352]

    S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 116648]

    S3 BoxSyncUpdateService;Box Sync Update Service; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [2014-09-18 28184]

    S3 cphs;Intel® Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-01-08 279024]

    S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-22 43696]

    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 116648]

    S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]

    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

    S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

     

    -----------------EOF-----------------

     

  5. Heb een quick scan moeten doen, aangezien de volledige scan vroeg of laat werd onderbroken door een crash, steeds weer met dezelfde error (KERNEL...).

    Ondertussen werkt Google chrome én Internet Explorer niet meer. Moet opnieuw posten via andere pc.

    Hieronder screenshot van de quick scan:

    post-5622-1417705883,8344_thumb.jpg

    - - - Updated - - -

    Wel opmerkelijk, tijdens de volledige scan had ik 1 rood blokje (toen ongeveer 25% gescand was).

  6. Hallo,

    Van de ene dag op de andere start mijn pc niet meer op.

    Deed regelmatig opkuis van spyware/virussen, en hij werkte nog perfect.

    - Medion PC, gekocht enkele jaren geleden (promotie Aldi).

    - Blijft hangen op het zwarte opstartscherm met "Windows starten". Heb hem zo al eens 45min laten staan, start niet verder op.

    - Foutherstel / opstarten in veilige modus / ... werkt allemaal niet, hij blijft ook steeds opnieuw hangen.

    - Ik hoor mijn harde schijf niet werken tijdens de opstart, er gebeurt dus blijkbaar niets meer.

    - Belangrijkste data heb ik back-up, maar toch nog veel data dat ik zou willen recupereren.

    - Opstarten vanop Windows 7 cd lijkt ook niet te lukken.

    Any ideas wat ik kan doen?

    Bedankt voor de hulp.

  7. Zoek.exe Version 4.0.0.4 Updated 27-September-2013

    Tool run by Mieke on do 03/10/2013 at 19:28:20,17.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Mieke\Desktop\zoek.exe [script inserted] [Checkboxes used]

    ==== System Restore Info ======================

    3/10/2013 19:45:44 Zoek.exe System Restore Point Created Succesfully.

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2705919615-782462397-452831582-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} deleted successfully

    HKEY_USERS\S-1-5-21-2705919615-782462397-452831582-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Services ======================

    ==== Registry Fix Code x64 ======================

    Windows Registry Editor Version 5.00

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]

    ==== Deleting Files \ Folders ======================

    "C:\Users\Mieke\AppData\Local\{487592A1-E555-4E0F-8518-E116F526BD0E}" deleted

    "C:\Users\Mieke\AppData\Local\{79706236-7E85-40EF-95D5-93E300181FBF}" deleted

    "C:\Users\Mieke\AppData\Local\{EBFB1EE2-75D6-4784-A703-D1C6B3225979}" deleted

    "C:\ProgramData\35982d799fc288ea0c0160235d26d1ae_c" deleted

    "C:\Windows\SysNative\roboot64.exe" deleted

    "C:\Users\Public\Desktop\iLivid.lnk" deleted

    "C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml" deleted

    "C:\Program Files (x86)\iLivid" deleted

    "C:\ProgramData\boost_interprocess" deleted

    "C:\Users\Mieke\AppData\Local\iLivid" deleted

    "C:\Users\Mieke\AppData\Local\Ilivid Player" deleted

    "C:\Users\Mieke\AppData\LocalLow\DataMngr" deleted

    "C:\Users\Mieke\AppData\LocalLow\PriceGong" deleted

    "C:\Users\Mieke\AppData\LocalLow\searchqutoolbar" deleted

    "C:\Users\Mieke\AppData\LocalLow\Conduit" deleted

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    2013-10-02 20:32:49 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe

    2013-10-02 20:32:49 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe

    2013-10-02 20:32:49 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe

    2013-10-02 20:32:49 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe

    2013-10-02 20:32:49 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe

    ====== C:\Users\Mieke\AppData\Local\Temp ====

    ====== Java Cache =====

    ====== C:\Windows\SysWOW64 =====

    2013-10-02 19:19:36 ACA17F8E1F9E8891DE15E2527D8D74D0 264616 ----a-w- C:\Windows\SysWOW64\javaws.exe

    2013-10-02 19:19:28 EC94122E6DCB6E731D8513A89AC9CF12 175016 ----a-w- C:\Windows\SysWOW64\javaw.exe

    2013-10-02 19:19:28 EC2A0F271C0FD4AD57B137845577F539 175016 ----a-w- C:\Windows\SysWOW64\java.exe

    2013-10-02 19:19:28 6BEE003DB3FEF04151F614303EBB1E7B 96168 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

    ====== C:\Windows\SysWOW64\drivers =====

    ====== C:\Windows\Sysnative =====

    ====== C:\Windows\Sysnative\drivers =====

    2013-09-13 14:52:57 059F00DEF82BF41E433B7ED465847726 155584 ----a-w- C:\Windows\Sysnative\drivers\ataport.sys

    ====== C:\Windows\Tasks ======

    2013-09-14 12:11:22 -------- d-----w- C:\Windows\Sysnative\Tasks\OfficeSoftwareProtectionPlatform

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    2013-10-02 20:56:54 -------- d-----w- C:\Program Files\trend micro

    ======= C:\Program Files (x86) =====

    2013-10-02 19:19:49 -------- d-----w- C:\Program Files (x86)\Common Files\Java

    2013-09-14 12:17:27 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services

    2013-09-14 12:17:26 -------- d-----w- C:\Program Files (x86)\Common Files\DESIGNER

    2013-09-14 12:17:00 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition

    2013-09-14 12:10:13 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8

    2013-09-14 12:09:03 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services

    ======= C: =====

    ====== C:\Users\Mieke\AppData\Roaming ======

    2013-10-02 20:47:36 -------- d-----w- C:\Users\Public\AppData\Local\temp

    2013-10-02 20:47:36 -------- d-----w- C:\Users\Default\AppData\Local\temp

    2013-10-02 20:47:36 -------- d-----w- C:\Users\Default User\AppData\Local\temp

    2013-10-02 20:47:36 -------- d-----w- C:\Users\Administrator\AppData\Local\temp

    ====== C:\Users\Mieke ======

    2013-10-03 17:24:33 122A32A068A76C220AD47B3C2780407C 1263104 ----a-w- C:\Users\Mieke\Desktop\Z-Analyse.exe

    2013-10-02 20:56:25 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Mieke\Downloads\RSITx64.exe

    2013-10-02 20:50:11 AB66C4C6486B1B05B3732726E4B430FA 486768 ----a-w- C:\Users\Mieke\Downloads\ccsetup405-aoc-jd.exe

    2013-10-02 20:47:36 -------- d-----w- C:\Users\Public\AppData

    2013-10-02 19:20:10 -------- d-----w- C:\ProgramData\Oracle

    2013-10-02 19:19:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    2013-09-14 12:19:47 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint

    ====== C: exe-files ==

    2013-10-03 17:24:33 122A32A068A76C220AD47B3C2780407C 1263104 ----a-w- C:\Users\Mieke\Desktop\Z-Analyse.exe

    2013-10-02 20:56:54 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Mieke.exe

    2013-10-02 20:56:25 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Mieke\Downloads\RSITx64.exe

    2013-10-02 20:50:11 AB66C4C6486B1B05B3732726E4B430FA 486768 ----a-w- C:\Users\Mieke\Downloads\ccsetup405-aoc-jd.exe

    2013-10-02 20:32:49 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe

    2013-10-02 20:32:49 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe

    2013-10-02 20:32:49 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe

    2013-10-02 20:32:49 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe

    2013-10-02 20:32:49 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe

    2013-10-02 19:19:36 ACA17F8E1F9E8891DE15E2527D8D74D0 264616 ----a-w- C:\Windows\SysWOW64\javaws.exe

    2013-10-02 19:19:28 EC94122E6DCB6E731D8513A89AC9CF12 175016 ----a-w- C:\Windows\SysWOW64\javaw.exe

    2013-10-02 19:19:28 EC2A0F271C0FD4AD57B137845577F539 175016 ----a-w- C:\Windows\SysWOW64\java.exe

    2013-10-02 19:19:22 FE62A080B6B3846FB18F04B488BF686F 66984 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javacpl.exe

    2013-10-02 19:19:22 FB81754A3C79379C3882128875C8C948 48552 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jabswitch.exe

    2013-10-02 19:19:22 F744671F237351A00580DEBDA7B13C58 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\servertool.exe

    2013-10-02 19:19:22 F07B981F68160C8932BD7E2A056E3542 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\kinit.exe

    2013-10-02 19:19:22 ED2542D50B46FACB647E9ACE15376F71 52648 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe

    2013-10-02 19:19:22 EC94122E6DCB6E731D8513A89AC9CF12 175016 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaw.exe

    2013-10-02 19:19:22 EC2A0F271C0FD4AD57B137845577F539 175016 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java.exe

    2013-10-02 19:19:22 DE16D31DDE767A35C4727D4F5C4F5165 49064 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ssvagent.exe

    2013-10-02 19:19:22 ACA17F8E1F9E8891DE15E2527D8D74D0 264616 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaws.exe

    2013-10-02 19:19:22 A5937B2A94424CF1B13A4AD503AF6B2E 182696 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jqs.exe

    2013-10-02 19:19:22 8BAE06DA395B81D5BB9D335719B4C71F 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\keytool.exe

    2013-10-02 19:19:22 8B060210811F4C88280BB1FE097C8D18 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\policytool.exe

    2013-10-02 19:19:22 879FBD4327A0411AD856CD256E05ACC8 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\pack200.exe

    2013-10-02 19:19:22 85369335B06BA3EF80DBB2463BD75FC6 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmid.exe

    2013-10-02 19:19:22 79E6E98DD340052FB62E85FC5C0F40B9 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmiregistry.exe

    2013-10-02 19:19:22 46D4A740A9CD31274B372AB31FDAB767 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\orbd.exe

    2013-10-02 19:19:22 3F17C8C96551E1DFADAD909282D7A53B 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ktab.exe

    2013-10-02 19:19:22 33329EE40961C9F75753135EEFEE5215 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\tnameserv.exe

    2013-10-02 19:19:22 20238A6FE9CA82DB6AA17CB08F4906CF 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java-rmi.exe

    2013-10-02 19:19:22 20121F1F03EA62AE7DBE20A5C065E62B 146344 ----a-w- C:\Program Files (x86)\Java\jre7\bin\unpack200.exe

    2013-10-02 19:19:22 14478E73336D593E396FEE603118DF73 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\klist.exe

    === C: other files ==

    2013-10-02 19:19:22 8C636C988365FC3E61F1B5C5ACECCB55 18675 ----a-w- C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip

    ==== Startup Registry Enabled ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    "CanonSolutionMenuEx"="C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon"

    "IJNetworkScannerSelectorEX"="C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE"

    "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices"

    "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    ==== Startup Registry Enabled x64 ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="C:\Windows\system32\igfxtray.exe"

    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe"

    "Persistence"="C:\Windows\system32\igfxpers.exe"

    "CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon"

    "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch"

    ==== Startup Folders ======================

    2013-04-04 06:14:30 1049 ----a-w- C:\Users\Mieke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [21/09/2013 18:37]

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [undetermined Task]

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [07/02/2011 12:56]

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000Core.job --a------ C:\Users\Mieke\AppData\LoC:al\Google\Update\GoogleUpdate.exe []

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000UA.job --a------ C:\Users\Mieke\AppData\Local\Google\Update\GoogleUpdate.exe [01/02/2012 22:19]

    ==== Chrome Look ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    jfmjfhklogoienhpfnppmbcbjfjnkonk - No path found[]

    lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[10/10/2011 11:09]

    Google Docs - Mieke - Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Mieke - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Mieke - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Mieke - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Skype Click to Call - Mieke - Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

    Chrome In-App Payments service - Mieke - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Mieke - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    ==== Set IE to Default ======================

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="http://www.google.be/"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]

    "SearchAssistant"="http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4"

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]

    "SearchAssistant"="http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4"

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="http://www.google.be/"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]

    "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]

    "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR"

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

    ==== Reset Google Chrome ======================

    C:\Users\Mieke\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

    C:\Users\Mieke\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

    ==== Deleting Registry Keys ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Mieke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Mieke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    ==== Empty FireFox Cache ======================

    No FireFox Profiles found

    ==== Empty Chrome Cache ======================

    C:\Users\Mieke\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache is not empty, a reboot is needed

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Mieke\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Users\Mieke\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2EGVRJXB\folder.blokker.be" not found

    "C:\Users\Mieke\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2EGVRJXB\static.tijd.be" not found

    ==== EOF on do 03/10/2013 at 21:19:16,81 ======================

  8. Hallo,

    Net een scan gedaan met Malwarebytes Anti Malware op de laptop van mijn vriendin -- 588 items gedetecteerd, die ik vervolgens verwijderd heb.

    Ook combofix al even laten lopen. Zie logje hieronder.

    Ook een RSIT logje bijgevoegd. Zie onder het combofix logje.

    Alvast bedankt voor de hulp.

    ComboFix 13-10-01.03 - Mieke 02/10/2013 22:34:59.1.2 - x64

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.3032.2083 [GMT 2:00]

    Gestart vanuit: c:\users\Mieke\Downloads\ComboFix.exe

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    C:\prefs.js

    c:\program files (x86)\BasicScan

    c:\program files (x86)\BasicScan\uninstall.exe

    c:\users\Mieke\AppData\Local\Google\Chrome\User Data\Default\Preferences

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2013-09-02 to 2013-10-02 ))))))))))))))))))))))))))))))

    .

    .

    2013-10-02 20:43 . 2013-10-02 20:43 -------- d-----w- c:\users\Default\AppData\Local\temp

    2013-10-02 19:23 . 2013-10-02 20:31 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{403A9794-2ACA-4F2F-B99D-5D8B34BC4973}\offreg.dll

    2013-10-02 19:20 . 2013-10-02 19:20 -------- d-----w- c:\programdata\Oracle

    2013-10-02 19:19 . 2013-10-02 19:19 -------- d-----w- c:\program files (x86)\Common Files\Java

    2013-10-02 19:19 . 2013-10-02 19:19 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

    2013-10-01 15:42 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{403A9794-2ACA-4F2F-B99D-5D8B34BC4973}\mpengine.dll

    2013-09-14 12:17 . 2013-09-14 12:17 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services

    2013-09-14 12:17 . 2013-09-14 12:17 -------- d-----w- c:\windows\PCHEALTH

    2013-09-14 12:17 . 2013-09-14 12:17 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework

    2013-09-14 12:17 . 2013-09-14 12:17 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition

    2013-09-14 12:10 . 2013-09-14 12:10 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8

    2013-09-14 12:09 . 2013-09-14 12:09 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services

    2013-09-13 14:52 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys

    2013-09-13 00:02 . 2013-08-02 02:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

    2013-09-12 18:02 . 2013-08-02 01:48 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll

    2013-09-12 18:01 . 2013-08-02 01:48 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2013-10-02 19:19 . 2012-10-15 16:21 868264 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

    2013-10-02 19:19 . 2011-04-28 15:58 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll

    2013-09-21 16:37 . 2013-03-16 07:42 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2013-09-21 16:37 . 2011-12-23 14:36 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2013-09-13 14:59 . 2011-02-07 15:53 79143768 ----a-w- c:\windows\system32\MRT.exe

    2013-08-07 02:22 . 2011-02-06 17:45 278800 ------w- c:\windows\system32\MpSigStub.exe

    2013-08-02 01:48 . 2013-09-13 14:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll

    2013-07-25 09:25 . 2013-08-15 08:20 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL

    2013-07-25 08:57 . 2013-08-15 08:20 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL

    2013-07-19 01:58 . 2013-08-15 08:20 2048 ----a-w- c:\windows\system32\tzres.dll

    2013-07-19 01:41 . 2013-08-15 08:20 2048 ----a-w- c:\windows\SysWow64\tzres.dll

    2013-07-09 05:52 . 2013-08-15 08:20 224256 ----a-w- c:\windows\system32\wintrust.dll

    2013-07-09 05:51 . 2013-08-15 08:20 1217024 ----a-w- c:\windows\system32\rpcrt4.dll

    2013-07-09 05:46 . 2013-08-15 08:20 184320 ----a-w- c:\windows\system32\cryptsvc.dll

    2013-07-09 05:46 . 2013-08-15 08:20 1472512 ----a-w- c:\windows\system32\crypt32.dll

    2013-07-09 05:46 . 2013-08-15 08:20 139776 ----a-w- c:\windows\system32\cryptnet.dll

    2013-07-09 04:52 . 2013-08-15 08:20 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll

    2013-07-09 04:52 . 2013-08-15 08:20 175104 ----a-w- c:\windows\SysWow64\wintrust.dll

    2013-07-09 04:46 . 2013-08-15 08:20 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll

    2013-07-09 04:46 . 2013-08-15 08:20 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll

    2013-07-09 04:46 . 2013-08-15 08:20 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll

    2013-07-06 06:03 . 2013-08-15 08:20 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 130736 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 130736 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 130736 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]

    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-12 421736]

    "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]

    "IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]

    "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]

    .

    c:\users\Mieke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    Dropbox.lnk - c:\users\Mieke\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

    "LoadAppInit_DLLs"=1 (0x1)

    .

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

    R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbdev.sys [x]

    R3 hxctlflt;hxctlflt;c:\windows\system32\Drivers\hxctlflt.sys;c:\windows\SYSNATIVE\Drivers\hxctlflt.sys [x]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

    S3 yukonw7;NDIS6.2 Minipoortstuurprogramma voor Marvell Yukon Ethernet-controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]

    .

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2013-10-02 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-16 16:37]

    .

    2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-07 10:56]

    .

    2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-07 10:56]

    .

    2013-10-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000Core.job

    - c:\users\Mieke\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-17 20:19]

    .

    2013-10-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000UA.job

    - c:\users\Mieke\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-17 20:19]

    .

    .

    --------- X64 Entries -----------

    .

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 164016 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 164016 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 164016 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

    2013-04-04 22:12 164016 ----a-w- c:\users\Mieke\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 161304]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 386584]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 415256]

    "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2779024]

    "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]

    .

    ------- Bijkomende Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    uStart Page = hxxp://www.google.be/

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uInternet Settings,ProxyOverride = *.local

    mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4

    IE: &Verzenden naar OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

    IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

    TCP: DhcpNameServer = 195.130.131.1 195.130.130.129

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    URLSearchHooks-{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)

    Toolbar-10 - (no file)

    Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe

    HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

    BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL

    Toolbar-10 - (no file)

    WebBrowser-{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - (no file)

    WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

    AddRemove-Any Video Converter 5_is1 - c:\program files (x86)\AnvSoft\Any Video Converter 5\unins000.exe

    AddRemove-AVS Video Editor_is1 - c:\program files (x86)\AVS4YOU\AVSVideoEditor\unins000.exe

    AddRemove-AVS4YOU Video Converter 7_is1 - c:\program files (x86)\AVS4YOU\AVSVideoConverter\unins000.exe

    AddRemove-Movavi Video Converter 12 - c:\program files (x86)\Movavi Video Converter 12\uninst.exe

    AddRemove-qt7lite_is1 - c:\program files (x86)\QT Lite\unins000.exe

    .

    .

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.11"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

    @Denied: (A) (Everyone)

    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

    .

    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

    @Denied: (A) (Everyone)

    .

    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

    "Key"="ActionsPane3"

    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

    .

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    "BlindDial"=dword:00000000

    .

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    Voltooingstijd: 2013-10-02 22:47:33

    ComboFix-quarantined-files.txt 2013-10-02 20:47

    .

    Pre-Run: 6.431.027.200 bytes beschikbaar

    Post-Run: 12.728.324.096 bytes beschikbaar

    .

    - - End Of File - - 9A6CAC0E8BA8D8E3A75D094C5E3CF4E5

    A36C5E4F47E84449FF07ED3517B43A31

    Logfile of random's system information tool 1.09 (written by random/random)

    Run by Mieke at 2013-10-02 22:56:54

    Microsoft Windows 7 Home Premium Service Pack 1

    System drive C: has 12 GB (5%) free of 223 GB

    Total RAM: 3032 MB (68% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:56:58, on 2/10/2013

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v10.0 (10.00.9200.16686)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

    C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\trend micro\Mieke.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon

    O4 - HKLM\..\Run: [iJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE

    O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - Startup: Dropbox.lnk = Mieke\AppData\Roaming\Dropbox\bin\Dropbox.exe

    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 8858 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    wininit.exe

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    C:\Windows\system32\services.exe

    winlogon.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

    "taskhost.exe"

    "C:\Windows\system32\Dwm.exe"

    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"

    "C:\Program Files\Bonjour\mDNSResponder.exe"

    "C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"

    C:\Windows\system32\svchost.exe -k imgsvc

    "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-49e9aa2a-1782-40a0-83d6-a379b1fae747 -SystemEventPortName:HostProcess-d0bef995-f63b-48d8-b709-62661f4614d2 -IoCancelEventPortName:HostProcess-ba2d3619-0742-48ce-995b-c7a29e3ddb18 -NonStateChangingEventPortName:HostProcess-b254c06b-9f18-4f39-8c20-53c2b827bcf0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6a661294-ddf5-43a5-90ed-7b442350d006 -DeviceGroupId:WpdFsGroup

    C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding

    C:\Windows\system32\SearchIndexer.exe /Embedding

    "C:\Windows\System32\igfxtray.exe"

    "C:\Windows\System32\hkcmd.exe"

    "C:\Windows\System32\igfxpers.exe"

    "C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon

    "C:\Windows\System32\StikyNot.exe"

    "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    "C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon

    "C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" /FORCE

    "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    "C:\Program Files\iPod\bin\iPodService.exe"

    C:\Windows\splwow64.exe 8192

    C:\Windows\System32\svchost.exe -k secsvcs

    "C:\Program Files\Windows Media Player\wmpnetwk.exe"

    C:\Windows\explorer.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\system32\sppsvc.exe

    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

    "C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516

    "C:\Users\Mieke\Downloads\RSITx64.exe"

    C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000Core.job

    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705919615-782462397-452831582-1000UA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

    Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]

    DataMngr - C:\PROGRA~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

    Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

    Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

    Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-02 462248]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

    Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

    Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

    Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-02 171944]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 161304]

    "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 386584]

    "Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 415256]

    "CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2779024]

    "Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 1832760]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

    "QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

    "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

    "APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]

    "iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-11-13 421736]

    "CanonSolutionMenuEx"=C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [2011-08-04 1612920]

    "IJNetworkScannerSelectorEX"=C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2011-01-15 452016]

    "BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

    "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

    C:\Users\Mieke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

    Dropbox.lnk - C:\Users\Mieke\AppData\Roaming\Dropbox\bin\Dropbox.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]

    C:\Windows\system32\igfxdev.dll [2010-08-25 271360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

    "ConsentPromptBehaviorAdmin"=5

    "ConsentPromptBehaviorUser"=3

    "EnableUIADesktopToggle"=0

    "dontdisplaylastusername"=0

    "legalnoticecaption"=

    "legalnoticetext"=

    "shutdownwithoutlogon"=1

    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

    "vidc.mrle"=msrle32.dll

    "vidc.msvc"=msvidc32.dll

    "msacm.imaadpcm"=imaadp32.acm

    "msacm.msg711"=msg711.acm

    "msacm.msgsm610"=msgsm32.acm

    "msacm.msadpcm"=msadp32.acm

    "midimapper"=midimap.dll

    "wavemapper"=msacm32.drv

    "VIDC.UYVY"=msyuv.dll

    "VIDC.YUY2"=msyuv.dll

    "VIDC.YVYU"=msyuv.dll

    "VIDC.IYUV"=iyuv_32.dll

    "vidc.i420"=iyuv_32.dll

    "VIDC.YVU9"=tsbyuv.dll

    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm

    "wave"=wdmaud.drv

    "midi"=wdmaud.drv

    "mixer"=wdmaud.drv

    "aux"=wdmaud.drv

    "wave1"=wdmaud.drv

    "midi1"=wdmaud.drv

    "mixer1"=wdmaud.drv

    "aux1"=wdmaud.drv

    "wave2"=wdmaud.drv

    "midi2"=wdmaud.drv

    "mixer2"=wdmaud.drv

    "aux2"=wdmaud.drv

    "MSVideo8"=VfWWDM32.dll

    "wave3"=wdmaud.drv

    "midi3"=wdmaud.drv

    "mixer3"=wdmaud.drv

    "aux3"=wdmaud.drv

    "wave4"=wdmaud.drv

    "midi4"=wdmaud.drv

    "mixer4"=wdmaud.drv

    "aux4"=wdmaud.drv

    "wave5"=wdmaud.drv

    "midi5"=wdmaud.drv

    "mixer5"=wdmaud.drv

    "aux5"=wdmaud.drv

    "wave6"=wdmaud.drv

    "midi6"=wdmaud.drv

    "mixer6"=wdmaud.drv

    "aux6"=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    ======List of files/folders created in the last 1 month======

    2013-10-02 22:56:54 ----D---- C:\rsit

    2013-10-02 22:56:54 ----D---- C:\Program Files\trend micro

    2013-10-02 22:47:40 ----SHD---- C:\$RECYCLE.BIN

    2013-10-02 22:47:36 ----D---- C:\Windows\temp

    2013-10-02 22:47:34 ----A---- C:\ComboFix.txt

    2013-10-02 22:32:49 ----A---- C:\Windows\zip.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\SWSC.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\SWREG.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\sed.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\PEV.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\NIRCMD.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\MBR.exe

    2013-10-02 22:32:49 ----A---- C:\Windows\grep.exe

    2013-10-02 22:31:41 ----D---- C:\Qoobox

    2013-10-02 22:31:11 ----D---- C:\Windows\erdnt

    2013-10-02 21:20:10 ----D---- C:\ProgramData\Oracle

    2013-10-02 21:19:36 ----A---- C:\Windows\SYSWOW64\javaws.exe

    2013-10-02 21:19:28 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll

    2013-10-02 21:19:28 ----A---- C:\Windows\SYSWOW64\javaw.exe

    2013-10-02 21:19:28 ----A---- C:\Windows\SYSWOW64\java.exe

    2013-09-14 14:17:27 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services

    2013-09-14 14:17:00 ----D---- C:\Windows\PCHEALTH

    2013-09-14 14:17:00 ----D---- C:\Program Files (x86)\Microsoft Sync Framework

    2013-09-14 14:17:00 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition

    2013-09-14 14:10:13 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8

    2013-09-14 14:09:03 ----D---- C:\Program Files (x86)\Microsoft Analysis Services

    2013-09-13 17:02:19 ----A---- C:\Windows\SYSWOW64\ieui.dll

    2013-09-13 17:02:19 ----A---- C:\Windows\system32\ieui.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe

    2013-09-13 17:02:17 ----A---- C:\Windows\SYSWOW64\iesysprep.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\SYSWOW64\iesetup.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\SYSWOW64\iernonce.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\iesysprep.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\iesetup.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\iertutil.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\iernonce.dll

    2013-09-13 17:02:17 ----A---- C:\Windows\system32\ie4uinit.exe

    2013-09-13 17:02:15 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

    2013-09-13 17:02:15 ----A---- C:\Windows\system32\msfeeds.dll

    2013-09-13 17:02:14 ----A---- C:\Windows\SYSWOW64\jscript.dll

    2013-09-13 17:02:14 ----A---- C:\Windows\system32\jscript.dll

    2013-09-13 17:02:13 ----A---- C:\Windows\system32\jscript9.dll

    2013-09-13 17:02:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll

    2013-09-13 17:02:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll

    2013-09-13 17:02:11 ----A---- C:\Windows\system32\urlmon.dll

    2013-09-13 17:02:10 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

    2013-09-13 17:02:10 ----A---- C:\Windows\system32\jsproxy.dll

    2013-09-13 17:02:09 ----A---- C:\Windows\SYSWOW64\wininet.dll

    2013-09-13 17:02:09 ----A---- C:\Windows\system32\wininet.dll

    2013-09-13 17:02:07 ----A---- C:\Windows\SYSWOW64\ieframe.dll

    2013-09-13 17:02:06 ----A---- C:\Windows\system32\ieframe.dll

    2013-09-13 17:02:04 ----A---- C:\Windows\system32\mshtml.dll

    2013-09-13 17:02:01 ----A---- C:\Windows\SYSWOW64\mshtml.dll

    2013-09-13 16:52:57 ----A---- C:\Windows\system32\drivers\ataport.sys

    2013-09-13 16:52:49 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe

    2013-09-13 16:52:49 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe

    2013-09-13 16:52:49 ----A---- C:\Windows\system32\ntoskrnl.exe

    2013-09-13 16:52:48 ----A---- C:\Windows\system32\ntdll.dll

    2013-09-13 16:52:47 ----A---- C:\Windows\system32\KernelBase.dll

    2013-09-13 16:52:45 ----A---- C:\Windows\SYSWOW64\ntdll.dll

    2013-09-13 16:52:44 ----A---- C:\Windows\SYSWOW64\kernel32.dll

    2013-09-13 16:52:44 ----A---- C:\Windows\system32\wow64.dll

    2013-09-13 16:52:44 ----A---- C:\Windows\system32\kernel32.dll

    2013-09-13 16:52:43 ----A---- C:\Windows\SYSWOW64\KernelBase.dll

    2013-09-13 16:52:43 ----A---- C:\Windows\system32\winsrv.dll

    2013-09-13 16:52:43 ----A---- C:\Windows\system32\smss.exe

    2013-09-13 16:52:42 ----A---- C:\Windows\system32\csrsrv.dll

    2013-09-13 16:52:42 ----A---- C:\Windows\system32\conhost.exe

    2013-09-13 16:52:41 ----A---- C:\Windows\system32\wow64win.dll

    2013-09-13 16:52:38 ----A---- C:\Windows\system32\wow64cpu.dll

    2013-09-13 16:52:36 ----A---- C:\Windows\system32\ntvdm64.dll

    2013-09-13 16:52:35 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll

    2013-09-13 16:52:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll

    2013-09-13 16:52:34 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll

    2013-09-13 02:02:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll

    2013-09-13 02:02:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll

    2013-09-13 02:02:25 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll

    2013-09-13 02:02:25 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll

    2013-09-13 02:02:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll

    2013-09-13 02:02:25 ----A---- C:\Windows\SYSWOW64\wow32.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll

    2013-09-13 02:02:24 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

    2013-09-13 02:02:23 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

    2013-09-13 02:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll

    2013-09-13 02:02:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll

    2013-09-13 02:02:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

    2013-09-13 02:02:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll

    2013-09-13 02:02:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

    2013-09-13 02:02:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll

    2013-09-13 02:02:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll

    2013-09-13 02:02:14 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll

    2013-09-13 02:02:14 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

    2013-09-13 02:02:12 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll

    2013-09-13 02:02:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll

    2013-09-13 02:02:10 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll

    2013-09-13 02:02:10 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll

    2013-09-12 20:02:07 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll

    2013-09-12 20:02:06 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll

    2013-09-12 20:02:06 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll

    2013-09-12 20:02:06 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

    2013-09-12 20:02:06 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll

    2013-09-12 20:02:05 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll

    2013-09-12 20:02:05 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll

    2013-09-12 20:02:04 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll

    2013-09-12 20:02:04 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll

    2013-09-12 20:02:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll

    2013-09-12 20:02:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll

    2013-09-12 20:02:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll

    2013-09-12 20:02:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll

    2013-09-12 20:02:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll

    2013-09-12 20:01:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll

    2013-09-12 20:01:56 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll

    2013-09-12 20:01:56 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll

    2013-09-12 20:01:55 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll

    2013-09-12 20:01:55 ----A---- C:\Windows\SYSWOW64\user.exe

    2013-09-12 20:01:55 ----A---- C:\Windows\SYSWOW64\setup16.exe

    2013-09-12 20:01:55 ----A---- C:\Windows\SYSWOW64\instnm.exe

    2013-09-12 20:01:55 ----A---- C:\Windows\SYSWOW64\apisetschema.dll

    2013-09-12 20:01:55 ----A---- C:\Windows\system32\apisetschema.dll

    2013-09-12 20:01:48 ----A---- C:\Windows\system32\win32k.sys

    2013-09-12 20:01:44 ----A---- C:\Windows\system32\shell32.dll

    2013-09-12 20:01:43 ----A---- C:\Windows\SYSWOW64\shell32.dll

    2013-09-12 20:01:42 ----A---- C:\Windows\SYSWOW64\shdocvw.dll

    2013-09-12 20:01:42 ----A---- C:\Windows\system32\shdocvw.dll

    ======List of files/folders modified in the last 1 month======

    2013-10-02 22:56:54 ----RD---- C:\Program Files

    2013-10-02 22:47:36 ----D---- C:\Windows

    2013-10-02 22:43:53 ----A---- C:\Windows\system.ini

    2013-10-02 22:43:49 ----D---- C:\Windows\system32\drivers\etc

    2013-10-02 22:42:44 ----RD---- C:\Program Files (x86)

    2013-10-02 22:39:20 ----D---- C:\Windows\SYSWOW64\drivers

    2013-10-02 22:39:20 ----D---- C:\Windows\SysWOW64

    2013-10-02 22:39:20 ----D---- C:\Windows\AppPatch

    2013-10-02 22:39:19 ----D---- C:\Program Files (x86)\Common Files

    2013-10-02 22:32:41 ----D---- C:\Windows\system32\config

    2013-10-02 22:31:41 ----D---- C:\Windows\system32\drivers

    2013-10-02 22:31:27 ----D---- C:\Windows\Prefetch

    2013-10-02 22:19:15 ----D---- C:\Users\Mieke\AppData\Roaming\Dropbox

    2013-10-02 22:17:22 ----D---- C:\Windows\system32\catroot2

    2013-10-02 22:17:08 ----D---- C:\ProgramData\CanonIJPLM

    2013-10-02 21:43:56 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware

    2013-10-02 21:20:10 ----D---- C:\ProgramData

    2013-10-02 21:19:50 ----SHD---- C:\Windows\Installer

    2013-10-02 21:19:22 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll

    2013-10-02 21:19:22 ----A---- C:\Windows\SYSWOW64\deployJava1.dll

    2013-10-02 21:19:21 ----D---- C:\Program Files (x86)\Java

    2013-10-02 21:18:47 ----SHD---- C:\System Volume Information

    2013-09-24 21:28:12 ----D---- C:\Windows\rescache

    2013-09-24 17:50:14 ----D---- C:\Windows\system32\NDF

    2013-09-23 22:20:16 ----SD---- C:\Users\Mieke\AppData\Roaming\Microsoft

    2013-09-22 13:21:50 ----D---- C:\ProgramData\tmp

    2013-09-21 18:37:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

    2013-09-21 09:12:02 ----D---- C:\Windows\System32

    2013-09-21 09:12:02 ----D---- C:\Windows\inf

    2013-09-21 09:12:02 ----A---- C:\Windows\system32\PerfStringBackup.INI

    2013-09-15 10:52:34 ----D---- C:\Windows\Microsoft.NET

    2013-09-15 10:52:17 ----RSD---- C:\Windows\assembly

    2013-09-15 10:12:16 ----D---- C:\ProgramData\Microsoft Help

    2013-09-15 09:57:44 ----A---- C:\Windows\win.ini

    2013-09-14 14:36:07 ----D---- C:\Windows\winsxs

    2013-09-14 14:29:26 ----D---- C:\Windows\ShellNew

    2013-09-14 14:19:19 ----RSD---- C:\Windows\Fonts

    2013-09-14 14:18:38 ----D---- C:\Program Files (x86)\MSBuild

    2013-09-14 14:17:01 ----D---- C:\Program Files (x86)\Microsoft Office

    2013-09-14 14:17:00 ----SD---- C:\ProgramData\Microsoft

    2013-09-14 14:17:00 ----D---- C:\Program Files (x86)\Microsoft.NET

    2013-09-14 14:11:22 ----D---- C:\Windows\system32\Tasks

    2013-09-14 14:10:45 ----D---- C:\Program Files\Common Files\Microsoft Shared

    2013-09-14 14:09:16 ----D---- C:\Program Files\Microsoft Office

    2013-09-14 13:38:37 ----D---- C:\Program Files\Internet Explorer

    2013-09-14 13:38:37 ----D---- C:\Program Files (x86)\Internet Explorer

    2013-09-14 13:38:34 ----D---- C:\Windows\SYSWOW64\nl-NL

    2013-09-14 13:38:34 ----D---- C:\Windows\system32\nl-NL

    2013-09-14 13:38:32 ----D---- C:\Windows\system32\DriverStore

    2013-09-13 17:02:58 ----D---- C:\Windows\system32\catroot

    2013-09-13 17:01:58 ----D---- C:\Windows\system32\MRT

    2013-09-13 16:59:34 ----A---- C:\Windows\system32\MRT.exe

    2013-09-08 13:17:53 ----D---- C:\Windows\Minidump

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]

    R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

    R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-07-08 2769400]

    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]

    R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-08-25 10611552]

    S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]

    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []

    S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-07 117504]

    S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 114304]

    S3 hxctlflt;hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [2009-02-08 111104]

    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]

    S3 SNP2UVC;Hercules Webcam; C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-04-22 3552384]

    S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]

    S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

    S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-09-03 65640]

    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-24 55144]

    R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]

    R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2011-02-07 138192]

    R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2011-11-13 934760]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    S2 gupdate;Google Updateservice (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-07 136176]

    S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-21 257416]

    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-07 136176]

    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]

    S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

    S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

    S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-07 1255736]

    -----------------EOF-----------------

  9. Heb snel even naar aantal websites gesurfd en de popups lijken verdwenen.

    Ook de reclame in mijn browser is weg.

    Hieronder het logje.

    # AdwCleaner v2.303 - Verslag gemaakt op 25/06/2013 om 11:57:21

    # Geactualiseerd op 08/06/2013 door Xplode

    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (32 bits)

    # Gebruiker : Jelle - JELLE-PC

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : C:\Users\Jelle\Desktop\adwcleaner.exe

    # Optie [Verwijderen]

    ***** [Diensten] *****

    ***** [Files / Mappen] *****

    File Verwijderd : C:\Windows\system32\roboot.exe

    Map Verwijderd : C:\Program Files\continuetosave

    Map Verwijderd : C:\Program Files\WebSearch

    Map Verwijderd : C:\Program Files\WinZip Registry Optimizer

    Map Verwijderd : C:\ProgramData\contionuetosave

    Map Verwijderd : C:\ProgramData\InstallMate

    Map Verwijderd : C:\ProgramData\SearchNewTab

    Map Verwijderd : C:\Users\Jelle\AppData\Local\Conduit

    Map Verwijderd : C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbpcodiioacjpmndonendolggkjeap

    Map Verwijderd : C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlpdeblpkfhfbofammonfjeljaammfhp

    Map Verwijderd : C:\Users\Jelle\AppData\LocalLow\Conduit

    Map Verwijderd : C:\Users\Jelle\AppData\LocalLow\PriceGong

    ***** [Register] *****

    Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\PriceGong

    Sleutel Verwijderd : HKCU\Software\AppDataLow\SProtector

    Sleutel Verwijderd : HKCU\Software\Ask&Record

    Sleutel Verwijderd : HKCU\Software\Conduit

    Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Conduit.Engine

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Toolbar.CT1060933

    Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}

    Sleutel Verwijderd : HKLM\Software\Conduit

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

    Sleutel Verwijderd : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966

    Sleutel Verwijderd : HKLM\Software\SProtector

    ***** [browsers] *****

    -\\ Internet Explorer v10.0.9200.16611

    [OK] Het register bevat geen enkele ongeoorloofde invoer.

    -\\ Google Chrome v27.0.1453.116

    File : C:\Users\Jelle\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] De file bevat geen enkele ongeoorloofde invoer.

    *************************

    AdwCleaner[s1].txt - [2506 octets] - [25/06/2013 11:57:21]

    ########## EOF - C:\AdwCleaner[s1].txt - [2566 octets] ##########

  10. Heb in alle haast verkeerd bestandje aangeklikt en geopend, weet niet meer precies wat het was.

    Heb nu vervelende popups en reclameblokken in mijn browser.

    Dus bij deze een Hijackthis logje.

    Heb met CCleaner alles al eens opgeschoond, maar zonder resultaat.

    Dank bij voorbaat!

    (windows 7)

    Logfile of Trend Micro HijackThis v2.0.2Scan saved at 22:15:36, on 24/06/2013

    Platform: Unknown Windows (WinNT 6.01.3505 SP1)

    MSIE: Internet Explorer v10.0 (10.00.9200.16576)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE

    C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Program Files\DAEMON Tools Pro\DTAgent.exe

    C:\Users\Jelle\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

    C:\Program Files\TP-LINK\COMMON\TWCU.exe

    C:\Program Files\Canon\Solution Menu EX\CNSEUPDT.EXE

    C:\Users\Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon

    O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon

    O4 - HKLM\..\Run: [iJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKCU\..\Run: [Google Update] "C:\Users\Jelle\AppData\Local\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun

    O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Jelle\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

    O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Jelle\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - Startup: Dropbox.lnk = Jelle\AppData\Roaming\Dropbox\bin\Dropbox.exe

    O4 - Global Startup: TP-LINK Wireless Client Utility.lnk = C:\Program Files\TP-LINK\COMMON\TWCU.exe

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O13 - Gopher Prefix:

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\TP-LINK\COMMON\RaRegistry.exe

    O23 - Service: TpMediaServer - Unknown owner - C:\Program Files\TP-LINK\COMMON\RaMediaServer.exe

    --

    End of file - 7326 bytes

  11. Hieronder mijn logje van Combofix.

    Ik kreeg tijdens de scan, wel steeds de volgende error:

    post-5622-1417705026,2936_thumb.jpg

    ComboFix 12-07-31.03 - Walter 01/08/2012 18:31:29.2.2 - x64

    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.32.1043.18.4056.2938 [GMT 2:00]

    Gestart vanuit: c:\users\Walter\Desktop\ComboFix.exe

    AV: McAfeeAntivirus en antispyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

    FW: McAfeeFirewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

    SP: McAfeeAntivirus en antispyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-07-01 to 2012-08-01 ))))))))))))))))))))))))))))))

    .

    .

    2012-08-01 16:39 . 2012-08-01 16:39 -------- d-----w- c:\users\Public\AppData\Local\temp

    2012-08-01 16:39 . 2012-08-01 16:39 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-07-31 20:58 . 2012-07-31 20:58 -------- d-----w- c:\program files (x86)\Apple Software Update

    2012-07-31 20:57 . 2012-07-31 20:57 -------- d-----w- c:\program files\Common Files\Apple

    2012-07-31 20:57 . 2012-07-31 20:57 -------- d-----w- c:\program files\Bonjour

    2012-07-31 20:57 . 2012-07-31 20:57 -------- d-----w- c:\program files (x86)\Bonjour

    2012-07-12 01:08 . 2012-06-12 03:02 3147264 ----a-w- c:\windows\system32\win32k.sys

    2012-07-10 17:50 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll

    2012-07-10 17:50 . 2012-06-06 05:09 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-07-30 15:10 . 2012-06-03 10:43 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2012-07-30 15:10 . 2012-01-08 13:09 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-07-12 01:04 . 2010-05-20 21:13 59701280 ----a-w- c:\windows\system32\MRT.exe

    2012-07-03 11:46 . 2010-09-19 15:21 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-06-02 22:19 . 2012-06-29 13:49 38424 ----a-w- c:\windows\system32\wups.dll

    2012-06-02 22:19 . 2012-06-29 13:49 2428952 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-02 22:19 . 2012-06-29 13:49 57880 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-02 22:19 . 2012-06-29 13:49 44056 ----a-w- c:\windows\system32\wups2.dll

    2012-06-02 22:19 . 2012-06-29 13:49 701976 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-02 22:15 . 2012-06-29 13:49 2622464 ----a-w- c:\windows\system32\wucltux.dll

    2012-06-02 22:15 . 2012-06-29 13:49 99840 ----a-w- c:\windows\system32\wudriver.dll

    2012-06-02 13:19 . 2012-06-29 13:49 186752 ----a-w- c:\windows\system32\wuwebv.dll

    2012-06-02 13:15 . 2012-06-29 13:49 36864 ----a-w- c:\windows\system32\wuapp.exe

    2012-05-15 03:56 . 2012-06-14 12:32 1197568 ----a-w- c:\windows\system32\wininet.dll

    2012-05-15 03:52 . 2012-06-14 12:32 64512 ----a-w- c:\windows\system32\jsproxy.dll

    2012-05-15 03:08 . 2012-06-14 12:32 981504 ----a-w- c:\windows\SysWow64\wininet.dll

    2012-05-04 17:29 . 2012-05-31 19:14 772504 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

    2012-05-04 17:29 . 2010-04-22 18:57 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll

    2012-05-04 10:52 . 2012-06-14 12:32 5505392 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-05-04 10:08 . 2012-06-14 12:32 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

    2012-05-04 10:08 . 2012-06-14 12:32 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

    .

    .

    ((((((((((((((((((((((((((((( SnapShot@2012-02-09_23.05.02 )))))))))))))))))))))))))))))))))))))))))

    .

    + 2012-07-10 17:51 . 2012-06-02 04:42 96768 c:\windows\SysWOW64\sspicli.dll

    - 2012-01-27 20:15 . 2011-11-17 05:35 96768 c:\windows\SysWOW64\sspicli.dll

    - 2012-01-27 20:15 . 2011-11-17 05:39 22016 c:\windows\SysWOW64\secur32.dll

    + 2012-07-10 17:51 . 2012-06-02 04:48 22016 c:\windows\SysWOW64\secur32.dll

    + 2012-06-14 12:32 . 2012-04-20 05:06 67584 c:\windows\SysWOW64\mshtmled.dll

    + 2012-06-14 12:32 . 2012-04-20 05:03 12800 c:\windows\SysWOW64\msfeedssync.exe

    - 2011-12-14 17:36 . 2011-11-05 04:32 12800 c:\windows\SysWOW64\msfeedssync.exe

    - 2011-12-14 17:36 . 2011-11-05 04:34 64512 c:\windows\SysWOW64\msfeedsbs.dll

    + 2012-06-14 12:32 . 2012-04-20 05:06 64512 c:\windows\SysWOW64\msfeedsbs.dll

    - 2011-12-14 17:36 . 2011-11-05 04:35 68608 c:\windows\SysWOW64\migration\WininetPlugin.dll

    + 2012-06-14 12:32 . 2012-05-15 03:08 68608 c:\windows\SysWOW64\migration\WininetPlugin.dll

    - 2011-12-14 17:36 . 2011-11-05 04:34 44544 c:\windows\SysWOW64\licmgr10.dll

    + 2012-06-14 12:32 . 2012-04-20 05:05 44544 c:\windows\SysWOW64\licmgr10.dll

    + 2012-06-14 12:32 . 2012-05-15 03:06 48128 c:\windows\SysWOW64\jsproxy.dll

    - 2011-12-14 17:36 . 2011-11-05 04:34 48128 c:\windows\SysWOW64\jsproxy.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 50536 c:\windows\SysWOW64\jdns_sd.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 73064 c:\windows\SysWOW64\dnssd.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 83816 c:\windows\SysWOW64\dns-sd.exe

    + 2009-07-14 04:54 . 2012-08-01 16:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    - 2009-07-14 04:54 . 2012-02-09 23:08 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    - 2009-07-14 04:54 . 2012-02-09 23:08 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2009-07-14 04:54 . 2012-08-01 16:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2009-07-14 04:54 . 2012-08-01 16:21 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    - 2009-07-14 04:54 . 2012-02-09 23:08 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    + 2010-03-11 06:08 . 2012-08-01 16:42 38910 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

    + 2009-07-14 05:10 . 2012-08-01 16:42 39312 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

    + 2010-03-17 18:43 . 2012-08-01 16:42 14610 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-538217755-3608469558-711902680-1001_UserData.bin

    + 2010-03-17 18:00 . 2009-02-27 01:42 66440 c:\windows\system32\spool\drivers\x64\msonpui.dll

    + 2012-06-14 12:33 . 2012-04-26 05:34 76288 c:\windows\system32\rdpwsx.dll

    - 2009-07-14 00:17 . 2009-07-14 01:41 76288 c:\windows\system32\rdpwsx.dll

    + 2012-06-14 12:32 . 2012-04-20 06:22 97792 c:\windows\system32\mshtmled.dll

    + 2012-06-14 12:32 . 2012-04-20 06:18 12288 c:\windows\system32\msfeedssync.exe

    - 2011-12-14 17:36 . 2011-11-05 05:19 12288 c:\windows\system32\msfeedssync.exe

    + 2012-06-14 12:32 . 2012-04-20 06:22 82944 c:\windows\system32\msfeedsbs.dll

    - 2011-12-14 17:36 . 2011-11-05 05:23 82944 c:\windows\system32\msfeedsbs.dll

    - 2011-12-14 17:36 . 2011-11-05 05:26 95232 c:\windows\system32\migration\WininetPlugin.dll

    + 2012-06-14 12:32 . 2012-05-15 03:56 95232 c:\windows\system32\migration\WininetPlugin.dll

    + 2012-04-03 22:39 . 2012-04-03 14:58 67584 c:\windows\system32\LogFiles\Srt\bootstat.dat

    + 2012-06-14 12:32 . 2012-04-20 06:22 57856 c:\windows\system32\licmgr10.dll

    - 2011-12-14 17:36 . 2011-11-05 05:23 57856 c:\windows\system32\licmgr10.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 61288 c:\windows\system32\jdns_sd.dll

    + 2012-05-09 01:01 . 2012-03-01 06:40 80896 c:\windows\system32\imagehlp.dll

    + 2009-07-14 05:30 . 2012-07-31 20:58 86016 c:\windows\system32\DriverStore\infpub.dat

    - 2009-07-14 05:30 . 2011-07-15 02:05 86016 c:\windows\system32\DriverStore\infpub.dat

    + 2012-04-25 10:11 . 2012-04-25 10:11 52736 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_509d7a31d0ee45f2\usbaapl64.sys

    + 2012-03-26 12:50 . 2012-03-26 12:50 22528 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_bf785db627c6d127\netaapl64.sys

    + 2009-07-14 00:09 . 2009-07-14 00:09 19968 c:\windows\system32\drivers\usb8023x.sys

    - 2009-07-14 00:16 . 2009-07-14 00:16 23552 c:\windows\system32\drivers\tdtcp.sys

    + 2012-03-13 20:48 . 2012-02-15 04:46 23552 c:\windows\system32\drivers\tdtcp.sys

    + 2009-07-14 00:09 . 2009-07-14 00:09 41472 c:\windows\system32\drivers\rndismpx.sys

    + 2012-05-09 17:54 . 2012-03-17 07:55 75632 c:\windows\system32\drivers\partmgr.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 75936 c:\windows\system32\drivers\mfenlfk.sys

    - 2011-07-02 19:20 . 2011-10-15 12:16 10248 c:\windows\system32\drivers\mfeclnk.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 10248 c:\windows\system32\drivers\mfeclnk.sys

    - 2012-01-27 20:15 . 2011-11-17 07:17 95088 c:\windows\system32\drivers\ksecdd.sys

    + 2012-07-10 17:51 . 2012-06-02 05:38 95088 c:\windows\system32\drivers\ksecdd.sys

    + 2012-05-09 01:01 . 2012-03-01 06:54 22896 c:\windows\system32\drivers\fs_rec.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 65264 c:\windows\system32\drivers\cfwids.sys

    - 2011-07-02 19:20 . 2011-10-15 12:16 65264 c:\windows\system32\drivers\cfwids.sys

    + 2011-08-30 21:05 . 2011-08-30 21:05 85864 c:\windows\system32\dnssd.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 96104 c:\windows\system32\dns-sd.exe

    + 2010-03-16 10:04 . 2012-08-01 16:23 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    - 2010-03-16 10:04 . 2012-02-09 23:04 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    + 2010-03-16 10:04 . 2012-08-01 16:23 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2009-07-14 04:54 . 2012-08-01 16:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    - 2009-07-14 04:54 . 2012-02-09 23:04 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    + 2010-03-16 10:16 . 2012-08-01 16:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    - 2010-03-16 10:16 . 2012-02-09 23:08 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    + 2009-07-14 04:46 . 2012-08-01 16:22 80144 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat

    - 2010-03-16 10:16 . 2012-02-09 23:08 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2010-03-16 10:16 . 2012-08-01 16:42 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2010-03-16 10:16 . 2012-08-01 16:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    - 2010-03-16 10:16 . 2012-02-09 23:08 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    - 2010-03-16 10:16 . 2012-02-09 23:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    + 2010-03-16 10:16 . 2012-08-01 16:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    + 2010-03-16 10:16 . 2012-08-01 16:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    - 2010-03-16 10:16 . 2012-02-09 23:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    + 2011-12-15 12:01 . 2011-12-15 12:01 68880 c:\windows\Microsoft.NET\Framework64\v4.0.30319\nlssorting.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 57616 c:\windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 87408 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 93024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 35688 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 11120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 17784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Presentation.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 58240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 44920 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 37240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 64352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 51032 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\System.Device.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 50552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 81784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 81800 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 39784 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 68952 c:\windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 62880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.ApplicationServer.Applications\v4.0_4.0.0.0__31bf3856ad364e35\Microsoft.Windows.ApplicationServer.Applications.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 12128 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 97680 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 17240 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 94552 c:\windows\Microsoft.NET\assembly\GAC_64\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 91488 c:\windows\Microsoft.NET\assembly\GAC_64\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

    - 2012-01-14 16:56 . 2012-01-14 16:56 78168 c:\windows\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

    - 2012-01-14 16:56 . 2012-01-14 16:56 81248 c:\windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

    + 2012-05-10 01:05 . 2012-05-10 01:05 49936 c:\windows\Installer\{95120000-00AF-0413-0000-0000000FF1CE}\ppvwicon.exe

    - 2011-12-16 02:07 . 2011-12-16 02:07 49936 c:\windows\Installer\{95120000-00AF-0413-0000-0000000FF1CE}\ppvwicon.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

    - 2011-12-16 02:07 . 2011-12-16 02:07 35600 c:\windows\Installer\{90120000-0020-0413-0000-0000000FF1CE}\O12ConvIcon.exe

    + 2012-05-10 01:17 . 2012-05-10 01:17 35600 c:\windows\Installer\{90120000-0020-0413-0000-0000000FF1CE}\O12ConvIcon.exe

    + 2010-06-06 01:01 . 2012-05-10 01:03 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll

    - 2010-06-06 01:01 . 2011-10-16 01:13 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll

    + 2012-07-31 20:58 . 2012-07-31 20:58 27136 c:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 25214 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\MSWorks.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 25214 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\MSWorks.exe

    + 2009-02-26 12:06 . 2009-02-26 12:06 16712 c:\windows\Installer\$PatchCache$\Managed\00002159FA0031400000000000F01FEC\12.0.6612\PXBPROXY.DLL

    + 2009-02-26 12:06 . 2009-02-26 12:06 68488 c:\windows\Installer\$PatchCache$\Managed\00002159FA0031400000000000F01FEC\12.0.6612\PXBCOM.EXE

    + 2009-02-26 12:09 . 2009-02-26 12:09 10120 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\XLCALL32.DLL

    + 2009-02-26 17:43 . 2009-02-26 17:43 71520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\XL12CNVP.DLL

    + 2009-02-26 16:45 . 2009-02-26 16:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WRD12EXE.EXE

    + 2006-07-24 09:50 . 2006-07-24 09:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBAME.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 54104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCANOST.EXE

    + 2011-07-20 04:28 . 2011-07-20 04:28 75624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RM.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 38248 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RECALL.DLL

    + 2011-05-26 18:18 . 2011-05-26 18:18 52088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLVBA.DLL

    + 2009-02-26 11:09 . 2009-02-26 11:09 43352 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLRPC.DLL

    + 2009-02-26 13:24 . 2009-02-26 13:24 71536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONFILTER.DLL

    + 2009-02-26 13:24 . 2009-02-26 13:24 97680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONENOTEM.EXE

    + 2006-07-24 09:50 . 2006-07-24 09:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSADDNDR.DLL

    + 2009-02-26 11:09 . 2009-02-26 11:09 20352 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MLSHEXT.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 34208 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\DUMPSTER.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 87408 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\DLGSETP.DLL

    + 2010-03-17 17:56 . 2010-03-17 17:56 35648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLCTLPIA.DLL

    + 2009-04-02 11:01 . 2009-04-02 11:01 56680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXP_XPS.DLL

    + 2009-04-03 17:46 . 2009-04-03 17:46 97640 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXP_PDF.DLL

    + 2006-10-26 19:13 . 2006-10-26 19:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNFLT.EXE

    + 2009-02-26 17:43 . 2009-02-26 17:43 71520 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\XL12CNVP.DLL

    + 2009-02-26 16:45 . 2009-02-26 16:45 20808 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\WRD12EXE.EXE

    + 2009-02-26 12:06 . 2009-02-26 12:06 16712 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\PXBPROXY.DLL

    + 2009-02-26 12:06 . 2009-02-26 12:06 68488 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\PXBCOM.EXE

    + 2012-05-10 01:26 . 2012-05-10 01:26 10240 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\7fa267d10b2df6dbd00d00d130715f0a\System.Xml.Serialization.ni.dll

    + 2012-05-10 01:26 . 2012-05-10 01:26 43520 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Pres#\054fce9466c6cef615b2f7cc9ff4e7f8\System.Windows.Presentation.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 86016 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\ff78ec1b5bf38a8fb74c2d4f41bb308a\System.Web.ApplicationServices.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 97792 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn.Contra#\e144d0028365c62178eb0662911ac910\System.AddIn.Contract.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 14336 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualC\93295f3771dc9e5be2d49d5f5d76a7a6\Microsoft.VisualC.ni.dll

    + 2012-05-10 01:17 . 2012-05-10 01:17 10752 c:\windows\assembly\NativeImages_v4.0.30319_64\dfsvc\5ea625ce2d6c08687f70cb81a003a28b\dfsvc.ni.exe

    + 2012-05-10 01:17 . 2012-05-10 01:17 58368 c:\windows\assembly\NativeImages_v4.0.30319_64\Accessibility\061cbee19075e086d675a9e1f65725d7\Accessibility.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 96768 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\4add87007e0864467659e6a248a7fe06\UIAutomationProvider.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 35328 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Pres#\28caa2ab8a4999900321b653e8b6ddc1\System.Windows.Presentation.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 71680 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\4967f3e8b106851802f212e963bb8735\System.Web.ApplicationServices.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 82432 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\7f49661d0e79763b30e9e99e714409a3\System.ServiceModel.Channels.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 78848 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn.Contra#\a5c37bc9caf315df294f8b680a1ccd6f\System.AddIn.Contract.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 11776 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\5ccc57bb582bf753166610089f204601\Microsoft.VisualC.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 44544 c:\windows\assembly\NativeImages_v4.0.30319_32\Accessibility\414da765b5d5bb7fde97c0ea22de7d74\Accessibility.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 60416 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Pres#\cf409e6576e3acec611838a755293418\System.Windows.Presentation.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 54784 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\0e8a192d6df9aa905653ddce81fa3895\System.Web.DynamicData.Design.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 90624 c:\windows\assembly\NativeImages_v2.0.50727_64\stdole\ef1f41de2634a23063369e7eb1cac97b\stdole.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 72192 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\ecc5750e8d62675bf59eb202eeeeacbe\PresentationFontCache.ni.exe

    + 2012-05-10 01:46 . 2012-05-10 01:46 61952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCFFRast#\cc29df25d166ceed89d259b00e2bba9e\PresentationCFFRasterizer.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 33792 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Run#\dd71ed714dc374e3d85824c17795e706\Microsoft.WSMan.Runtime.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 45056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\b8dac004fdabbb2dc12830dcd22fed29\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 70144 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\6b86a80d8cb8fb51252e0cd8fe697f9f\Microsoft.Windows.Diagnosis.SDEngine.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 43520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\64c811070a4d05e238e27d2a6e9bed25\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 40448 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\4eaff8355f942bb1a95300aeb2882602\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 59904 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\3453bb2216048726659887ecaf5cce4a\Microsoft.Windows.Diagnosis.SDHost.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 36864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\12abdc966e63bcb3077c71c6483762c3\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll

    + 2012-05-10 01:44 . 2012-05-10 01:44 32256 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualC\e0e2b0cdfa700bc21e09ddac3a9b46cc\Microsoft.VisualC.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 65536 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\c341c5df5ab35bb87765f39688c1e7ec\Microsoft.MediaCenter.iTv.Hosting.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 40960 c:\windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\62299472064bb88c63cdfa740cc34f1d\LoadMxf.ni.exe

    + 2012-05-10 01:52 . 2012-05-10 01:52 49664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUPnP\4ba55ae7274a85c8ae32a36aa8bcbfc5\ehiUPnP.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 93184 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiTVMSMusic\f9bd420501d5877ff7dd7fe308663935\ehiTVMSMusic.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 28672 c:\windows\assembly\NativeImages_v2.0.50727_64\dfsvc\c1ba413fc8eb57b417a2de4cf678e4f6\dfsvc.ni.exe

    + 2012-05-10 01:45 . 2012-05-10 01:45 78848 c:\windows\assembly\NativeImages_v2.0.50727_64\Accessibility\0bc383bf9841cca7654fe938399b3a07\Accessibility.ni.dll

    + 2012-06-16 01:46 . 2012-06-16 01:46 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\fcf327dc3b81cd97af7059f4522b72a6\WindowsLiveWriter.ni.exe

    + 2012-05-11 10:08 . 2012-05-11 10:08 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\fa1af6d87dd8e448467ad76f37d379d2\WindowsLiveWriter.ni.exe

    + 2012-05-11 10:09 . 2012-05-11 10:09 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c7c46b73c1637040083a7ae4fb976a9a\WindowsLive.Writer.Passport.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\68b5806af0df6ce86027bacb7dc37233\UIAutomationProvider.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\b0b664ed5c18ac51259abb7902671370\System.Windows.Presentation.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\f5c5517bf252bf6c4d8de833d2111309\System.Web.DynamicData.Design.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\bdf3aabfa0a15d557aec32505a5eaaee\System.ComponentModel.DataAnnotations.ni.dll

    + 2012-05-10 01:49 . 2012-05-10 01:49 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\99bb6d93ce5daed24761530fa32ed5f4\System.AddIn.Contract.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\5357cca887f53e1007fc9cf4c0c9a412\stdole.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\b0cdc419b6f2b0ddf0cda5f157e67516\PresentationFontCache.ni.exe

    + 2012-05-10 01:42 . 2012-05-10 01:42 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\8ac4be1ad8f1aae0c23366c9ce0724e0\PresentationCFFRasterizer.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 79872 c:\windows\assembly\NativeImages_v2.0.50727_32\napcrypt\1af767233028c3165de880775391c53f\napcrypt.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 17920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Run#\b9935982ad038d7a02f7931a8ee2977b\Microsoft.WSMan.Runtime.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 21504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ea54c98d0fa82cdb0bf5ec9b50463d75\Microsoft.Windows.Diagnosis.SDEngine.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 32256 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\ddf3add57c84af5d63b3a2398ed5e1a4\Microsoft.Windows.Diagnosis.SDHost.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 27136 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\bd26bb6b78c6c02df886f26342b5e76a\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 25088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\6a491bf821cc13223f288eb72176ffc7\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 86016 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\6a1cb87d9cb795b53eab2c57e2d7db48\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 19968 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\62e634be25913db13e84a26296cee020\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 23040 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\5c234eea7e7d54a466ad00d9ac238e6a\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\dc44431123bc3e6b39dbea49ac1f1963\Microsoft.Vsa.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\b69ac98f94e80b659eac618c6142ea9b\Microsoft.VisualC.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\6ddfa12f22ada63da088e98223858b69\Microsoft.Build.Framework.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2f7754efa196f832b12b4133f0eae060\Microsoft.Build.Framework.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 60416 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiUserXp\094c7076aed91bda969c01f72d4bb63a\ehiUserXp.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\3c44431071abcaba099902fb72392688\dfsvc.ni.exe

    + 2012-05-10 01:41 . 2012-05-10 01:41 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\34f340b0c113f7216a55dd7c82a69cc2\Accessibility.ni.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll

    - 2010-03-22 02:04 . 2010-03-22 02:04 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 34696 c:\windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll

    - 2009-07-14 00:19 . 2009-07-14 01:11 5120 c:\windows\SysWOW64\wmi.dll

    + 2012-05-09 01:01 . 2012-03-01 05:40 5120 c:\windows\SysWOW64\wmi.dll

    + 2012-05-09 01:01 . 2012-03-01 06:35 5120 c:\windows\system32\wmi.dll

    - 2009-07-14 00:41 . 2009-07-14 01:33 5120 c:\windows\system32\wmi.dll

    + 2012-06-14 12:33 . 2012-04-26 05:28 9216 c:\windows\system32\rdrmemptylst.exe

    + 2012-07-31 18:30 . 2012-07-31 18:30 9560 c:\windows\system32\NetworkList\Icons\{99B90EBA-B331-4B5E-99BB-B10F23DB2A76}_48.bin

    + 2012-07-31 18:30 . 2012-07-31 18:30 4280 c:\windows\system32\NetworkList\Icons\{99B90EBA-B331-4B5E-99BB-B10F23DB2A76}_32.bin

    + 2012-07-31 18:30 . 2012-07-31 18:30 2456 c:\windows\system32\NetworkList\Icons\{99B90EBA-B331-4B5E-99BB-B10F23DB2A76}_24.bin

    - 2012-02-09 23:04 . 2012-02-09 23:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    + 2012-08-01 16:40 . 2012-08-01 16:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2012-02-09 23:04 . 2012-02-09 23:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-08-01 16:40 . 2012-08-01 16:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-05-10 01:30 . 2012-05-10 01:30 9216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\5d0529cca67ada47749f5373ae050a4a\System.Xml.Serialization.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 9728 c:\windows\assembly\NativeImages_v4.0.30319_32\dfsvc\1361a05238cfe45d7da6cb4b367a986c\dfsvc.ni.exe

    + 2012-05-09 01:01 . 2012-03-01 05:49 172544 c:\windows\SysWOW64\wintrust.dll

    - 2011-12-14 17:36 . 2011-11-05 04:35 132096 c:\windows\SysWOW64\url.dll

    + 2012-06-14 12:32 . 2012-04-20 05:07 132096 c:\windows\SysWOW64\url.dll

    + 2012-07-10 17:51 . 2012-06-02 04:48 225280 c:\windows\SysWOW64\schannel.dll

    - 2009-07-14 00:01 . 2009-07-14 01:16 826368 c:\windows\SysWOW64\rdpcore.dll

    + 2012-03-13 20:48 . 2012-02-15 05:44 826368 c:\windows\SysWOW64\rdpcore.dll

    + 2012-02-16 19:47 . 2012-01-04 09:03 442880 c:\windows\SysWOW64\ntshrui.dll

    - 2009-07-13 23:41 . 2009-07-14 01:16 442880 c:\windows\SysWOW64\ntshrui.dll

    + 2012-07-10 17:51 . 2012-06-02 04:47 219136 c:\windows\SysWOW64\ncrypt.dll

    - 2009-07-13 23:33 . 2009-07-14 01:16 219136 c:\windows\SysWOW64\ncrypt.dll

    - 2009-07-13 23:12 . 2009-07-14 01:15 690688 c:\windows\SysWOW64\msvcrt.dll

    + 2012-02-16 19:47 . 2011-12-16 07:59 690688 c:\windows\SysWOW64\msvcrt.dll

    + 2011-06-07 16:51 . 2011-06-07 16:51 770384 c:\windows\SysWOW64\msvcr100.dll

    + 2010-03-18 07:15 . 2010-03-18 07:15 421200 c:\windows\SysWOW64\msvcp100.dll

    - 2011-12-14 17:36 . 2011-11-05 04:34 606208 c:\windows\SysWOW64\mstime.dll

    + 2012-06-14 12:32 . 2012-04-20 05:06 606208 c:\windows\SysWOW64\mstime.dll

    + 2012-06-14 12:32 . 2012-04-20 05:06 627200 c:\windows\SysWOW64\msfeeds.dll

    + 2012-07-30 15:10 . 2012-07-30 15:10 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.exe

    + 2012-07-30 15:10 . 2012-07-30 15:10 466632 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.dll

    + 2012-06-03 10:43 . 2012-07-30 15:10 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    + 2012-06-14 12:33 . 2012-04-17 04:45 716800 c:\windows\SysWOW64\jscript.dll

    - 2012-01-11 21:27 . 2011-10-14 04:42 716800 c:\windows\SysWOW64\jscript.dll

    + 2012-06-29 14:33 . 2012-05-04 17:29 227720 c:\windows\SysWOW64\javaws.exe

    + 2012-06-29 14:32 . 2012-05-15 17:06 174064 c:\windows\SysWOW64\javaw.exe

    + 2012-06-29 14:32 . 2012-05-15 17:06 174064 c:\windows\SysWOW64\java.exe

    + 2012-05-09 01:01 . 2012-03-01 05:45 158720 c:\windows\SysWOW64\imagehlp.dll

    + 2012-06-14 12:32 . 2012-04-20 05:05 176640 c:\windows\SysWOW64\ieui.dll

    - 2011-12-14 17:36 . 2011-11-11 05:50 176640 c:\windows\SysWOW64\ieui.dll

    - 2011-12-14 17:36 . 2011-11-05 04:34 185856 c:\windows\SysWOW64\iepeers.dll

    + 2012-06-14 12:32 . 2012-04-20 05:05 185856 c:\windows\SysWOW64\iepeers.dll

    - 2011-12-14 17:36 . 2011-11-05 04:33 381440 c:\windows\SysWOW64\iedkcs32.dll

    + 2012-06-14 12:32 . 2012-04-20 05:05 381440 c:\windows\SysWOW64\iedkcs32.dll

    + 2011-08-30 21:05 . 2011-08-30 21:05 178536 c:\windows\SysWOW64\dnssdX.dll

    + 2012-05-09 17:56 . 2012-03-03 05:40 218624 c:\windows\SysWOW64\d3d10_1core.dll

    - 2011-01-12 07:13 . 2010-11-02 04:35 218624 c:\windows\SysWOW64\d3d10_1core.dll

    - 2011-06-25 16:13 . 2011-01-17 05:38 161792 c:\windows\SysWOW64\d3d10_1.dll

    + 2012-05-09 17:56 . 2012-03-03 05:40 161792 c:\windows\SysWOW64\d3d10_1.dll

    - 2011-03-09 16:02 . 2011-02-19 05:32 739840 c:\windows\SysWOW64\d2d1.dll

    + 2012-05-09 17:56 . 2012-03-03 05:40 739840 c:\windows\SysWOW64\d2d1.dll

    + 2012-06-14 12:31 . 2012-04-24 04:47 139264 c:\windows\SysWOW64\cryptsvc.dll

    + 2012-06-14 12:31 . 2012-04-24 04:47 103936 c:\windows\SysWOW64\cryptnet.dll

    - 2010-03-19 02:27 . 2011-04-15 01:39 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    + 2010-03-19 02:27 . 2012-02-18 02:33 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    + 2012-05-09 01:01 . 2012-03-01 06:45 220672 c:\windows\system32\wintrust.dll

    - 2010-04-14 15:38 . 2009-12-29 08:03 220672 c:\windows\system32\wintrust.dll

    + 2010-03-17 10:41 . 2012-07-31 16:05 252102 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin

    + 2010-03-17 00:16 . 2012-07-31 18:14 239270 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin

    - 2011-12-14 17:36 . 2011-11-05 05:26 134144 c:\windows\system32\url.dll

    + 2012-06-14 12:32 . 2012-04-20 06:25 134144 c:\windows\system32\url.dll

    + 2012-05-27 09:58 . 2012-05-27 09:38 263168 c:\windows\system32\SPReview\spwizui.dll

    - 2011-07-14 19:50 . 2011-07-14 19:49 263168 c:\windows\system32\SPReview\spwizui.dll

    + 2012-05-27 09:58 . 2012-05-27 09:38 301568 c:\windows\system32\SPReview\spreview.exe

    - 2011-07-14 19:50 . 2011-07-14 19:49 301568 c:\windows\system32\SPReview\spreview.exe

    + 2012-05-27 09:58 . 2012-05-27 09:38 238592 c:\windows\system32\SPReview\sperror.dll

    - 2011-07-14 19:50 . 2011-07-14 19:49 238592 c:\windows\system32\SPReview\sperror.dll

    + 2010-03-17 18:00 . 2009-02-27 01:42 863128 c:\windows\system32\spool\drivers\x64\msonpdrv.dll

    - 2012-01-27 20:15 . 2011-11-17 07:10 340992 c:\windows\system32\schannel.dll

    + 2012-07-10 17:51 . 2012-06-02 05:27 340992 c:\windows\system32\schannel.dll

    - 2009-07-14 00:17 . 2009-07-14 01:41 149504 c:\windows\system32\rdpcorekmts.dll

    + 2012-06-14 12:33 . 2012-04-26 05:34 149504 c:\windows\system32\rdpcorekmts.dll

    + 2012-06-14 12:33 . 2012-05-02 05:32 208896 c:\windows\system32\profsvc.dll

    + 2009-07-14 09:16 . 2012-07-31 17:44 701798 c:\windows\system32\perfh013.dat

    - 2009-07-14 09:16 . 2012-01-19 19:48 701798 c:\windows\system32\perfh013.dat

    + 2009-07-14 02:36 . 2012-07-31 17:44 616242 c:\windows\system32\perfh009.dat

    - 2009-07-14 02:36 . 2012-01-19 19:48 616242 c:\windows\system32\perfh009.dat

    + 2009-07-14 09:16 . 2012-07-31 17:44 133798 c:\windows\system32\perfc013.dat

    - 2009-07-14 09:16 . 2012-01-19 19:48 133798 c:\windows\system32\perfc013.dat

    - 2009-07-14 02:36 . 2012-01-19 19:48 106622 c:\windows\system32\perfc009.dat

    + 2009-07-14 02:36 . 2012-07-31 17:44 106622 c:\windows\system32\perfc009.dat

    - 2009-07-13 23:57 . 2009-07-14 01:41 509952 c:\windows\system32\ntshrui.dll

    + 2012-02-16 19:47 . 2012-01-04 09:58 509952 c:\windows\system32\ntshrui.dll

    - 2009-07-13 23:49 . 2009-07-14 01:41 307200 c:\windows\system32\ncrypt.dll

    + 2012-07-10 17:51 . 2012-06-02 05:27 307200 c:\windows\system32\ncrypt.dll

    + 2012-02-16 19:47 . 2011-12-16 08:42 634368 c:\windows\system32\msvcrt.dll

    + 2012-06-14 12:32 . 2012-04-20 06:22 736256 c:\windows\system32\msfeeds.dll

    + 2011-07-02 18:38 . 2012-03-20 11:11 162192 c:\windows\system32\mfevtps.exe

    + 2012-07-30 15:10 . 2012-07-30 15:10 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_ActiveX.exe

    + 2012-07-30 15:10 . 2012-07-30 15:10 513224 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_ActiveX.dll

    + 2012-06-14 12:33 . 2012-04-17 05:38 851968 c:\windows\system32\jscript.dll

    - 2011-12-14 17:36 . 2011-11-11 06:41 247808 c:\windows\system32\ieui.dll

    + 2012-06-14 12:32 . 2012-04-20 06:21 247808 c:\windows\system32\ieui.dll

    + 2012-06-14 12:32 . 2012-04-20 06:21 256000 c:\windows\system32\iepeers.dll

    - 2011-12-14 17:36 . 2011-11-05 05:22 256000 c:\windows\system32\iepeers.dll

    - 2011-12-14 17:36 . 2011-11-05 05:22 445952 c:\windows\system32\iedkcs32.dll

    + 2012-06-14 12:32 . 2012-04-20 06:21 445952 c:\windows\system32\iedkcs32.dll

    - 2009-07-14 04:45 . 2011-12-16 02:24 421128 c:\windows\system32\FNTCACHE.DAT

    + 2009-07-14 04:45 . 2012-07-12 01:27 421128 c:\windows\system32\FNTCACHE.DAT

    - 2009-07-14 05:30 . 2011-07-15 02:05 143360 c:\windows\system32\DriverStore\infstrng.dat

    + 2009-07-14 05:30 . 2012-07-31 20:58 143360 c:\windows\system32\DriverStore\infstrng.dat

    - 2009-07-14 05:30 . 2011-07-15 02:05 143360 c:\windows\system32\DriverStore\infstor.dat

    + 2009-07-14 05:30 . 2012-07-31 20:58 143360 c:\windows\system32\DriverStore\infstor.dat

    - 2009-07-14 00:16 . 2009-07-14 00:16 204800 c:\windows\system32\drivers\rdpwd.sys

    + 2012-06-14 12:32 . 2012-04-28 03:50 204800 c:\windows\system32\drivers\rdpwd.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 289664 c:\windows\system32\drivers\mfewfpk.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 100912 c:\windows\system32\drivers\mferkdet.sys

    - 2011-07-02 19:20 . 2011-10-15 12:16 100912 c:\windows\system32\drivers\mferkdet.sys

    + 2011-03-13 09:20 . 2012-02-22 11:29 647208 c:\windows\system32\drivers\mfehidk.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 487296 c:\windows\system32\drivers\mfefirek.sys

    - 2011-07-02 19:20 . 2011-10-15 12:16 229528 c:\windows\system32\drivers\mfeavfk.sys

    + 2011-07-02 19:20 . 2012-02-22 11:29 229528 c:\windows\system32\drivers\mfeavfk.sys

    + 2011-03-13 09:20 . 2012-02-22 11:29 160792 c:\windows\system32\drivers\mfeapfk.sys

    - 2012-01-27 20:15 . 2011-11-17 07:17 152432 c:\windows\system32\drivers\ksecpkg.sys

    + 2012-07-10 17:51 . 2012-06-02 05:38 152432 c:\windows\system32\drivers\ksecpkg.sys

    + 2012-07-10 17:51 . 2012-06-02 05:37 459216 c:\windows\system32\drivers\cng.sys

    + 2012-02-16 19:47 . 2011-12-28 03:59 499200 c:\windows\system32\drivers\afd.sys

    + 2011-08-30 21:05 . 2011-08-30 21:05 212840 c:\windows\system32\dnssdX.dll

    + 2012-05-09 17:56 . 2012-03-03 06:29 320512 c:\windows\system32\d3d10_1core.dll

    - 2011-01-12 07:13 . 2010-11-02 05:12 320512 c:\windows\system32\d3d10_1core.dll

    - 2011-06-25 16:13 . 2011-01-17 06:17 197120 c:\windows\system32\d3d10_1.dll

    + 2012-05-09 17:56 . 2012-03-03 06:29 197120 c:\windows\system32\d3d10_1.dll

    + 2012-05-09 17:56 . 2012-03-03 06:29 902656 c:\windows\system32\d2d1.dll

    - 2011-03-09 16:02 . 2011-02-19 06:36 902656 c:\windows\system32\d2d1.dll

    + 2012-06-14 12:31 . 2012-04-24 05:59 182272 c:\windows\system32\cryptsvc.dll

    + 2012-06-14 12:31 . 2012-04-24 05:59 140288 c:\windows\system32\cryptnet.dll

    + 2009-07-14 05:38 . 2012-05-08 09:38 262144 c:\windows\system32\config\systemprofile\ntuser.dat

    - 2009-07-14 05:38 . 2011-06-22 20:32 262144 c:\windows\system32\config\systemprofile\ntuser.dat

    - 2009-07-14 05:12 . 2012-02-04 18:09 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    + 2009-07-14 05:12 . 2012-07-12 01:44 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    - 2010-03-16 10:16 . 2011-04-15 01:38 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    + 2010-03-16 10:16 . 2012-02-18 02:32 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

    - 2009-07-14 05:01 . 2012-02-09 23:02 394268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    + 2009-07-14 05:01 . 2012-08-01 16:39 394268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    + 2011-12-15 12:01 . 2011-12-15 12:01 226600 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationHost_v0400.dll

    + 2012-04-21 09:03 . 2012-04-21 09:03 616024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 156440 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.AddIn.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 598784 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SOS.dll

    + 2012-05-09 17:55 . 2012-04-06 00:45 172128 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll

    + 2012-06-14 12:33 . 2012-04-23 22:38 630784 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 486144 c:\windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 182056 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll

    + 2012-04-21 09:03 . 2012-04-21 09:03 616024 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 156440 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.AddIn.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 518400 c:\windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 957200 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 386824 c:\windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 131168 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll

    + 2012-06-14 12:33 . 2012-04-23 22:37 630784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 389888 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 364816 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 996112 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 350592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 163168 c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 138592 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 699224 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 857960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 675672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 113512 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 129912 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 390008 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 505208 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 261472 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 122264 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 291184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 349568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 236880 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 253280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 378720 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 134528 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 123736 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 392552 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 125816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 120152 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 616024 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 395120 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 182144 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 285072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 829280 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 747360 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 436600 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 683872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 409448 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 210816 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 156440 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 122248 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 525704 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 112976 c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 581464 c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 832856 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 194424 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 478576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 167288 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 232304 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 661352 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 349576 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 387960 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 746336 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 505184 c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 288616 c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 335712 c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 125440 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 237424 c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 187776 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 269672 c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 334688 c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll

    - 2012-01-14 16:56 . 2012-01-14 16:56 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 109568 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

    - 2012-01-14 16:56 . 2012-01-14 16:56 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 246128 c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 170368 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll

    + 2012-06-29 14:32 . 2012-06-29 14:32 461312 c:\windows\Installer\2c7cd.msi

    + 2012-05-18 09:01 . 2012-05-18 09:01 751616 c:\windows\Installer\18d07dbd.msi

    + 2012-05-31 19:15 . 2012-05-31 19:15 179200 c:\windows\Installer\1309f6c9.msi

    + 2012-04-03 01:03 . 2012-04-03 01:03 217864 c:\windows\Installer\{90120000-006E-0413-0000-0000000FF1CE}\misc.exe

    - 2010-03-22 02:02 . 2010-03-22 02:02 217864 c:\windows\Installer\{90120000-006E-0413-0000-0000000FF1CE}\misc.exe

    + 2012-04-03 01:03 . 2012-04-03 01:03 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe

    - 2010-03-22 02:02 . 2010-03-22 02:02 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 693600 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksWP.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 693600 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksWP.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 947552 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\wksss.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 947552 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\wksss.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 709984 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksCal.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 709984 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksCal.exe

    + 2010-03-18 11:16 . 2010-03-18 11:16 181096 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_X86.dll

    + 2010-03-18 12:27 . 2010-03-18 12:27 225640 c:\windows\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\PresentationHostDLL_AMD64.dll

    + 2011-09-15 18:41 . 2011-09-15 18:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WINWORD.EXE

    + 2007-06-07 18:51 . 2007-06-07 18:51 125320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SSGEN.DLL

    + 2011-07-27 02:58 . 2011-07-27 02:58 439160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SETUP.EXE

    + 2011-07-20 04:28 . 2011-07-20 04:28 282032 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCNPST64.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 273832 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCNPST32.DLL

    + 2011-07-27 02:55 . 2011-07-27 02:55 410992 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RTFHTML.DLL

    + 2011-07-20 05:06 . 2011-07-20 05:06 770480 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\REGFORM.EXE

    + 2011-07-20 04:28 . 2011-07-20 04:28 421736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PSTPRX32.DLL

    + 2011-05-31 14:15 . 2011-05-31 14:15 177040 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLPH.DLL

    + 2011-07-27 02:55 . 2011-07-27 02:55 596888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLMIME.DLL

    + 2007-06-07 18:51 . 2007-06-07 18:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL

    + 2011-05-26 18:18 . 2011-05-26 18:18 136536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLCTL.DLL

    + 2011-07-27 04:03 . 2011-07-27 04:03 194448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OMSXP32.DLL

    + 2011-07-27 04:03 . 2011-07-27 04:03 661888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OMSMAIN.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 253824 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OLKFSTUB.DLL

    + 2008-03-19 05:27 . 2008-03-19 05:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGALEGIT.DLL

    + 2009-02-26 13:24 . 2009-02-26 13:24 231864 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ODEPLOY.EXE

    + 2006-07-24 09:50 . 2006-07-24 09:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 340320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MIMEDIR.DLL

    + 2012-04-03 01:05 . 2012-04-03 01:05 117160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPOMINT.DLL

    + 2011-07-20 05:06 . 2011-07-20 05:06 176024 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPOLK.DLL

    + 2011-07-20 04:28 . 2011-07-20 04:28 138088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IMPMAIL.DLL

    + 2008-10-25 05:18 . 2008-10-25 05:18 172880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IEAWSDC.DLL

    + 2009-02-26 11:09 . 2009-02-26 11:09 154000 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ENVELOPE.DLL

    + 2011-05-26 18:18 . 2011-05-26 18:18 115584 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\EMABLT32.DLL

    + 2011-07-27 02:55 . 2011-07-27 02:55 128376 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\CONTAB32.DLL

    + 2006-10-27 14:35 . 2006-10-27 14:35 436512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL

    + 2006-10-26 19:13 . 2006-10-26 19:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNF.DLL

    + 2009-02-26 15:45 . 2009-02-26 15:45 509256 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\WRD12CVR.DLL

    + 2008-10-24 23:51 . 2008-10-24 23:51 844696 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.4518\OICE.EXE

    + 2012-05-10 01:26 . 2012-05-10 01:26 336896 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\342472450a587d22afebf6e7ecbbca5c\WindowsFormsIntegration.ni.dll

    + 2012-06-16 01:57 . 2012-06-16 01:57 337408 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsFormsIntegra#\08becdcc9bd647c4e4d07ceea7fe4895\WindowsFormsIntegration.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 231424 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationTypes\fb43d84bc59b21e8a7f3e36d616eea90\UIAutomationTypes.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 122368 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationProvider\26f12a0a3baed2a227cf30aaeae03913\UIAutomationProvider.ni.dll

    + 2012-05-10 01:26 . 2012-05-10 01:26 645120 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClient\1c3c298326e9ac14796516ac1da09a16\UIAutomationClient.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 528896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml.Linq\307eea660f877dc40ae90882ce554757\System.Xml.Linq.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 256000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Inpu#\b4afa252d0f0e27b0b5e8fcb2cc5b3a7\System.Windows.Input.Manipulations.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 903168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Transactions\8c0ee7b970cc4e8c2986c7898af71661\System.Transactions.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\f67f5d2f51eecc45b68bf86d65a1624d\System.ServiceProcess.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 281088 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceProce#\ca5505a49a075ee7ad2535f89d9ea992\System.ServiceProcess.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 108032 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\eb4fb369926faaffede7aaf317fd6532\System.ServiceModel.Channels.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 517120 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\e5ab3c37897bb578bdbfe6b7e0558ad8\System.ServiceModel.Routing.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 946688 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Security\e48b6a8c491a96d1bc601795532af605\System.Security.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 376832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\7590828d50338d512b11a4d3f87d69a2\System.Runtime.Serialization.Formatters.Soap.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 987648 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\21d5b44ef01ccfa69e79674a51707de0\System.Runtime.Remoting.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 176640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Numerics\5f2bfb0585061dc256ee9587d430959f\System.Numerics.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 933376 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Net\6996a415485a84fef2d2556b0462336f\System.Net.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\6e886c2e732ff69ae9eb1dc121b767d8\System.Messaging.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 781824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Messaging\0d8257087be3e57b071d1d5ccd705c2f\System.Messaging.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 521728 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management.I#\92d266f677605e5475b7f39c063c4a9d\System.Management.Instrumentation.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 531456 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IO.Log\07a0e1efc063042be3e8faf62b413a12\System.IO.Log.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 290816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityMode#\7fd39b9a208214e6e5eba4e9396409f1\System.IdentityModel.Selectors.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 348672 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.Wrapper.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 512000 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Dynamic\521f5bccf74318a4777597b0c01fda1e\System.Dynamic.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 632832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6a8bd7d373c988a585e90bb61c5ec8cc\System.DirectoryServices.Protocols.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 141824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Device\78dd02d104bb15bc3820c06bd2876239\System.Device.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 176128 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.DataSet#\97d1aaf3733b107ecdbecb9d21050ff4\System.Data.DataSetExtensions.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\c3d7a7ff58ff502887d8f1b77e61adbc\System.Configuration.Install.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 181760 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuratio#\52792a7ce63196551c29f5201562c1ae\System.Configuration.Install.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 255488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\a4f91f2dfd1656ef2e42917963f6bf50\System.ComponentModel.DataAnnotations.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 871936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.AddIn\b1c67ee2e0e6e78c31985069fbc82596\System.AddIn.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 560640 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.D#\c69fb0f955adc7ca80cd5f2fd730edea\System.Activities.DurableInstancing.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 432128 c:\windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\11fc863fa4f5092fca4f2ce25a9ac361\SMSvcHost.ni.exe

    + 2012-05-10 01:21 . 2012-05-10 01:21 185344 c:\windows\assembly\NativeImages_v4.0.30319_64\SMDiagnostics\50e8e826488639e549589ba34666933e\SMDiagnostics.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 428032 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\722c0236432dd5ccc047481d3ebbd49e\PresentationFramework.Royale.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 622592 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\6739c3715c9e38dbdfbfd57b424a3094\PresentationFramework.Aero.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 802304 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\3e7359f5f0fb68565314f88f6ec2d67a\PresentationFramework.Luna.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 349184 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\263748f3d18955b9e467710da1e8546f\PresentationFramework.Classic.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 422400 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\634a00569f0fe8693873f42039aca35f\Microsoft.VisualBasic.Compatibility.Data.ni.dll

    + 2012-06-16 01:54 . 2012-06-16 01:54 422912 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\097137b03ff37196b4b8ba62db34d64a\Microsoft.VisualBasic.Compatibility.Data.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 600064 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\6480551111832c83ee88bcf756a72533\Microsoft.Transactions.Bridge.Dtc.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 279552 c:\windows\assembly\NativeImages_v4.0.30319_64\CustomMarshalers\0e81a3996f7cbff23fc01bea4185a918\CustomMarshalers.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 253952 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\db6668b547e7504d74c3f345e2519b65\WindowsFormsIntegration.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 196096 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\6823effdbb0434f96511748697349862\UIAutomationTypes.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 484352 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClient\021651282dda157fbe5a1f3575c67534\UIAutomationClient.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 393216 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8f0cf05d2b1e46a772312143227cb6ed\System.Xml.Linq.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 189440 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Inpu#\5fc7ab2af170ab1217c5e1a7328b999b\System.Windows.Input.Manipulations.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 649728 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\6cb2089f1eaf08c3d94a54031cf1313a\System.Transactions.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 221696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\9ae3a257c347602d42ab80bb7a5ca3bb\System.ServiceProcess.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 369664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\8e3ba21dc083837fdc1c8b9f98c5f4bf\System.ServiceModel.Routing.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 736768 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Security\4278bedb3086448c94c1e7f563325052\System.Security.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 311296 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\490f9ea2b1a2e738d203af00c5c9b735\System.Runtime.Serialization.Formatters.Soap.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 762880 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\e5f1db35163684e821bca4a2fb0311b1\System.Runtime.Remoting.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 145408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\360e9c00572679f437fff0ae719a5886\System.Numerics.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 657408 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Net\62a6ed6942237e009110ffa55adbb77a\System.Net.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 626176 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Messaging\7a5371c272b4008457a3af780bf65ae5\System.Messaging.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 395264 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management.I#\0eb2dedcc5b7f32e7886b83635d22dbc\System.Management.Instrumentation.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 413696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IO.Log\54f78c72dbc55f90983ee1a887b27547\System.IO.Log.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 229888 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityMode#\7cfdedf408ac80e153d7988e308c7caa\System.IdentityModel.Selectors.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 236032 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\058fc53adeb7f06708bb4fa9f92fab5c\System.EnterpriseServices.Wrapper.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 787456 c:\windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\058fc53adeb7f06708bb4fa9f92fab5c\System.EnterpriseServices.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 377856 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Dynamic\559594e862b578f3040446d7d4498cb7\System.Dynamic.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 913920 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\41173dd435cb9e35b406e5ee17894cd1\System.DirectoryServices.AccountManagement.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 470528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\40466b947e5932c0c96529915fef0c45\System.DirectoryServices.Protocols.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 112640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Device\e38e62fe185dbc8344fc242b2093aee2\System.Device.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 134656 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.DataSet#\bc5bf4e71af4c7689ffed22f5187d922\System.Data.DataSetExtensions.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 982528 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\6711765f90c0082ec393943b924ed277\System.Configuration.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 148480 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\0a0d6610975706aee94ec9f44191bab8\System.Configuration.Install.ni.dll

    + 2012-05-10 01:10 . 2012-05-10 01:10 693760 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\dcf415181fba99d99ec87eefdf082864\System.ComponentModel.Composition.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ComponentMod#\41a21613a657cc7d9ea10386f271d388\System.ComponentModel.DataAnnotations.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 624128 c:\windows\assembly\NativeImages_v4.0.30319_32\System.AddIn\cdd87ceeb66eb0db86b02c27372cc31c\System.AddIn.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 411136 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.D#\139ec162dfa0903f5b00d623d2e944be\System.Activities.DurableInstancing.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 317952 c:\windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\01c8de400571afc3469fb99c6b7edecc\SMSvcHost.ni.exe

    + 2012-05-10 01:28 . 2012-05-10 01:28 143360 c:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4dd48e938a8834fe950cf0cd11603c71\SMDiagnostics.ni.dll

    + 2012-05-10 01:13 . 2012-05-10 01:13 309760 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a6b504e505c1c4bc6204136a957a4e30\PresentationFramework.Classic.ni.dll

    + 2012-05-10 01:14 . 2012-05-10 01:14 755712 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\71bcb2ec4fe3e7edb47397dfc1687576\PresentationFramework.Luna.ni.dll

    + 2012-05-10 01:13 . 2012-05-10 01:13 387072 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\453c2355cf76a74cc01226680cca4a01\PresentationFramework.Royale.ni.dll

    + 2012-05-10 01:13 . 2012-05-10 01:13 595968 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3263fe38362543170c1682381eeac25a\PresentationFramework.Aero.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 303104 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\26599cf02308adfabdc81eff4b322a01\Microsoft.VisualBasic.Compatibility.Data.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 418816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\dd47533d2837e1d78400f759f5f05e41\Microsoft.Transactions.Bridge.Dtc.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 194048 c:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\8f0e78c2aa12e929ecf3b0c912ac8406\CustomMarshalers.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 468992 c:\windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\3fbaee209e13d65183d2d802cf053f10\WsatConfig.ni.exe

    + 2012-05-11 10:14 . 2012-05-11 10:14 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\e1802bf7db5b95c2f6ba666ce3b9467b\WindowsFormsIntegration.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 329216 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsFormsIntegra#\0599e722d086c85c54a6dc71de5781f5\WindowsFormsIntegration.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 472576 c:\windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\56e8549d117a444a1b18305babe029c8\VistaBridgeLibrary.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 472576 c:\windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\4a8b7b0901e06a1931b9dfc0749dbf9a\VistaBridgeLibrary.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 736768 c:\windows\assembly\NativeImages_v2.0.50727_64\VDialog\94b71ba6396716a5e6d61699208c2b75\VDialog.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 736768 c:\windows\assembly\NativeImages_v2.0.50727_64\VDialog\14f98c714b48919e8349db11670c1919\VDialog.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 253952 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationTypes\f0e602dd94327e6eea126e72cb24c4a3\UIAutomationTypes.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationProvider\ef1cc397129c81ecb60431633b7d6f94\UIAutomationProvider.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 653312 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClient\2adb36011c54ef24dff70bef5e31a71a\UIAutomationClient.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\ecf332ee723fd33a408a00e926935c4a\TaskScheduler.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 304128 c:\windows\assembly\NativeImages_v2.0.50727_64\TaskScheduler\556067accb285eb0a304f8a9d90310b9\TaskScheduler.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 529920 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml.Linq\b0bc5a1ed5648bbe61d4ceb1b4bde03d\System.Xml.Linq.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 187392 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\2c66bb8492ad0ccd7c86eb204a86f16a\System.Web.Routing.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 261120 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.RegularE#\9a541383d78143dc386512b092cb58a9\System.Web.RegularExpressions.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\e3ca70a436f9c8a0cb178f3fe0d15ce6\System.Web.Entity.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 449024 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\6dd24af608fc5a3f68159984c3cf147e\System.Web.Entity.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 398848 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\4a722f8a9668af77c08a921ec5d249f2\System.Web.Entity.Design.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 753664 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\5e3e171d6b46739a8f89e2a589de1062\System.Web.DynamicData.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 204800 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\8f8685c0362ccfae34c1c958fc43bf40\System.Web.Abstractions.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 921600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\348482b8eb60eb9595a313ed706fa074\System.Transactions.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\d97a2e8d3ec212c982cd2923d5ca28a2\System.ServiceProcess.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 295424 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\993018172a83c2431adeb6a309aa27cf\System.ServiceProcess.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 928768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Security\3fbac653667adb06ac98561f57049751\System.Security.ni.dll

    + 2012-05-10 01:46 . 2012-05-10 01:46 396288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\3805923cd6a0d7c9c4c872c1ede4619d\System.Runtime.Serialization.Formatters.Soap.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 916480 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Net\c944f6d1355c8e02be1b6adb9022efd8\System.Net.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\984398a06970ec18178ddf072de6167e\System.Messaging.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 783360 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Messaging\3d63e73c95641bdc6cb4addc20059763\System.Messaging.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 534016 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.I#\27bb4472bb5e4fe714126010e7c615ca\System.Management.Instrumentation.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 569344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IO.Log\beb72e4d0964165386096323e4494003\System.IO.Log.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 294400 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityMode#\0e83d3c8f7e6295055548caa2a1a3743\System.IdentityModel.Selectors.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 446464 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\b48bd4bfbc25e5fb2b6bbc0627bb7aad\System.EnterpriseServices.Wrapper.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\a99929dc0a4fc6ac6081fc08e00ab34f\System.Drawing.Design.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 288768 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing.Desi#\a650d1b1ee920b0fecfe5e8342217265\System.Drawing.Design.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 649728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\3d2da45f50b57ab5871ff32fa9a0fa71\System.DirectoryServices.Protocols.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 493056 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\c1999d1e18a7c62be8765f97398c1b7c\System.Data.Services.Design.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 194560 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.DataSet#\2e18ba464979573aa3dcf04e07e79d87\System.Data.DataSetExtensions.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 192000 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\58d7e28f550aa89ebc5046b960525b46\System.Configuration.Install.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 132096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ComponentMod#\3de11837ee6fc7bda6f50bdc8eed68ce\System.ComponentModel.DataAnnotations.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 890880 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn\eb850c90fad10f90fa495be2efa5d8ec\System.AddIn.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\System.AddIn.Contra#\236fe667af3ca016ae66a5b08fb94bd8\System.AddIn.Contract.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 297984 c:\windows\assembly\NativeImages_v2.0.50727_64\sysglobl\9cf7f4430b8c379ca9bfe4428932af5e\sysglobl.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 525824 c:\windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\510283052ba3df05080787d71eb6fa31\SMSvcHost.ni.exe

    + 2012-05-10 01:51 . 2012-05-10 01:51 349184 c:\windows\assembly\NativeImages_v2.0.50727_64\SMDiagnostics\97ef3ca694f50f101c0b369e3c3528cc\SMDiagnostics.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 279040 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\dc82ea5f368056cb5340c270bb75becb\PresentationFramework.Classic.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 620544 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\76933856fb4dd9f9cf17136aac2ca38c\PresentationFramework.Luna.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 463360 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\5a95213214431ffa96c6e4dbfa36345e\PresentationFramework.Aero.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 317440 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\57138d0d992b152869c9bb250e9d3735\PresentationFramework.Royale.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\87dd0dd5e57819b99ce598d4bc6ffcdf\napsnap.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 855040 c:\windows\assembly\NativeImages_v2.0.50727_64\napsnap\33ae5cf0b1603f19a9c66e376b4cdcda\napsnap.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\e572a3bc2b5f0a4911450b62725de831\napinit.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 162816 c:\windows\assembly\NativeImages_v2.0.50727_64\napinit\5c28e1b5ec388ca1b62f229a068b9842\napinit.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 175104 c:\windows\assembly\NativeImages_v2.0.50727_64\naphlpr\4a034fcf374482db0b2cb8a7f661608c\naphlpr.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 127488 c:\windows\assembly\NativeImages_v2.0.50727_64\napcrypt\41854d8487d49fad7f177425b6c781f7\napcrypt.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 407552 c:\windows\assembly\NativeImages_v2.0.50727_64\MyDock.Util\8212b8fca5c8723f56159a61e4be89dd\MyDock.Util.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 407552 c:\windows\assembly\NativeImages_v2.0.50727_64\MyDock.Util\20e3b33b087f805d20dca97484a09ee9\MyDock.Util.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 184320 c:\windows\assembly\NativeImages_v2.0.50727_64\MSBuild\02fa94543dd6ba737d98562e9a42e519\MSBuild.ni.exe

    + 2012-06-16 01:51 . 2012-06-16 01:51 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\bf084532afc235bb8947191850be2dbd\MMCFxCommon.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 417792 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCFxCommon\a5fc9e3531c669fb457a7a9d9e384dae\MMCFxCommon.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 681472 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.WSMan.Man#\d4a321be6b1775b27e878d5866ac9b6d\Microsoft.WSMan.Management.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 122368 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Windows.D#\bdfc36a270290eeff2dfa72949ff20ca\Microsoft.Windows.Diagnosis.TroubleshootingPack.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 105984 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Vsa\915c41bb932618c4abf94b123df9ceae\Microsoft.Vsa.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 584192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\b90d3fa08fb2f482ec06283b20bf4525\Microsoft.Transactions.Bridge.Dtc.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 237056 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f50a903783750e4c093cbf105f334ead\Microsoft.PowerShell.Security.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 999936 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\65d6ad0aa6d85a25d2840ab5f7d7405c\Microsoft.PowerShell.GraphicalHost.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 713216 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\3acefb890be23403069123754db8a8d1\Microsoft.PowerShell.ConsoleHost.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 416768 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\2708d6ea3f3db7891db1a609018064d8\Microsoft.PowerShell.Commands.Diagnostics.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 965632 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\fe529847ae6fd62b1ef4e0ce5ab14569\Microsoft.MediaCenter.Sports.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\e05deb3d1be914eed8fb389fef425d3b\Microsoft.MediaCenter.ITVVM.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\6b6188faa076a68d083ae9e6d43338f4\Microsoft.MediaCenter.iTv.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 152576 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\611f809f625bafde88d989c624f5fd0f\Microsoft.MediaCenter.ITVVM.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 522240 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\4817b5f63709e4dbf02cfa2f1fbf68dd\Microsoft.MediaCenter.Interop.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 312320 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\390ab84a69a72771f8c15596c3918ca3\Microsoft.MediaCenter.iTv.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 370176 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\29c42a85dce9c813e64c8c7e7c1a713c\Microsoft.MediaCenter.Playback.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 164864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\10492ed390f72165b7701b0b209f41b1\Microsoft.MediaCenter.Mheg.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 219648 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\0e7cbd0361f32288ba6d9010608fffb9\Microsoft.MediaCenter.iTv.Media.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 797696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\e357bfb6a7358070a31cfb315e1094b8\Microsoft.ManagementConsole.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 797696 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Managemen#\812fede589a0d9f14eac827ca7472c04\Microsoft.ManagementConsole.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 198656 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\6f1c7692333bbe4aba03d4c68cd56210\Microsoft.Build.Utilities.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 244224 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Uti#\05ab0f916af911347d5b7fda20fab3e3\Microsoft.Build.Utilities.v3.5.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 120832 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\a92742de12c5358a722d9b81f4c93f8b\Microsoft.Build.Framework.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 142336 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Fra#\4d843288146d5c6ddcd942e1d68b510b\Microsoft.Build.Framework.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 294912 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Con#\9435c4788924ed688417b3087ff5cdd2\Microsoft.Build.Conversion.v3.5.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 107520 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft-Windows-H#\1302272bd95a6d5bbeaf3e1a832f2552\Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 380928 c:\windows\assembly\NativeImages_v2.0.50727_64\Mcx2Dvcs\d0c9c13cbeb5e9d29c3300c7dc6ad18f\Mcx2Dvcs.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 547328 c:\windows\assembly\NativeImages_v2.0.50727_64\mcupdate\b65913a9eb492b4ec40363f59badb1cb\mcupdate.ni.exe

    + 2012-05-10 01:52 . 2012-05-10 01:52 533504 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\6de88da68ff92581d1bce3deaa25d9c0\mcstoredb.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\c87d2b065618a0c752ed206a5b93f8ce\mcplayerinterop.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 549376 c:\windows\assembly\NativeImages_v2.0.50727_64\mcplayerinterop\3cbc899f004a3144820b162f339cc299\mcplayerinterop.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\cd46c89d7c48abf9fd348d2ffb03c9cd\mcGlidHostObj.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 696320 c:\windows\assembly\NativeImages_v2.0.50727_64\mcGlidHostObj\1ee690ef6472178228e84214d7f136ad\mcGlidHostObj.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 156672 c:\windows\assembly\NativeImages_v2.0.50727_64\MCESidebarCtrl\07d8613ab03648bcfed976e469523541\MCESidebarCtrl.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\bef11fb4617a18e0cdb5c7673308f0d8\EventViewer.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 659456 c:\windows\assembly\NativeImages_v2.0.50727_64\EventViewer\a186fab8a650e22bf361c6e9e1112e1c\EventViewer.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 969216 c:\windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\80ae3deb3ce5b39e8134838689f5e616\ehRecObj.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 661504 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiWUapi\81a510ea5fd14aa30ff41d4fc7f74161\ehiWUapi.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 933888 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiwmp\608233581ceee7892045ebae25b48248\ehiwmp.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 145408 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiUserXp\0ff5bc978a9279d484cdf59d919e60df\ehiUserXp.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 196096 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiiTv\75957f1e4c465eb8053fb9f235c5c696\ehiiTv.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 397824 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiExtens\165c31078ab64ffe338512b778f3a645\ehiExtens.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 110080 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiBmlDataCarousel\097208918b41f71a55e52cf2e8a14b9e\ehiBmlDataCarousel.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 126976 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiActivScp\e59e98a748cfb940f1ec7032d0d634c9\ehiActivScp.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\4265533205276b32dad388c62a10e7f9\ehExtHost.ni.exe

    + 2012-06-16 01:50 . 2012-06-16 01:50 389120 c:\windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\3266ef1067584da5503061cb4c694b82\ehExtHost.ni.exe

    + 2012-05-10 01:52 . 2012-05-10 01:52 313856 c:\windows\assembly\NativeImages_v2.0.50727_64\ehCIR\f5cd36f9696a44997ffb61cc38067006\ehCIR.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 348672 c:\windows\assembly\NativeImages_v2.0.50727_64\CustomMarshalers\e7e8991e9dfce879c22b2647edb72287\CustomMarshalers.ni.dll

    + 2012-05-10 01:51 . 2012-05-10 01:51 640000 c:\windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\bad60d21de09740f3c2a498fa4aaa7b0\ComSvcConfig.ni.exe

    + 2012-05-10 01:50 . 2012-05-10 01:50 971264 c:\windows\assembly\NativeImages_v2.0.50727_64\BDATunePIA\a7fd2038556fca7f411cf6f0a62c1671\BDATunePIA.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\2aac794e7890acc1a1430e065e16b31a\WsatConfig.ni.exe

    + 2012-05-11 10:09 . 2012-05-11 10:09 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\ab0cf48866599dee9641aee4fd49dc94\WindowsLiveLocal.WriterPlugin.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\1d3ec9f47ef24f4ae3b7011364e7302d\WindowsLiveLocal.WriterPlugin.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 890880 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f0d9085f20fdb46072827a4b9d985d7c\WindowsLive.Writer.HtmlEditor.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 313856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e040c9e32d2b6ec6aab2e0d55df8642a\WindowsLive.Writer.Interop.SHDocVw.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dc21028ea0278bb81422504ac5521a68\WindowsLive.Writer.FileDestinations.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d4c1f2000a4d608a6f51515c7a07c949\WindowsLive.Writer.Instrumentation.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d462248e3a0350baa187530cf4e4ce99\WindowsLive.Writer.Extensibility.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cc342bf1c12b23bc300c1d3a48ae6b79\WindowsLive.Writer.SpellChecker.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c8cedcdec782ac3920baba7492a0f7d3\WindowsLive.Writer.Interop.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 890880 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ac59de7ee325c77f0f4e3a8aa007bf3a\WindowsLive.Writer.HtmlEditor.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\9c4035d0ba3427580fb4a1a899d080f1\WindowsLive.Writer.Mshtml.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\88f3a75e834ec610a2509c4bed12eb6b\WindowsLive.Writer.BlogClient.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\80cb75b9cb19bd962f69cf656dc7dc42\WindowsLive.Writer.BlogClient.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\71e51665f298326d8a4f0e8d330c2383\WindowsLive.Writer.Interop.Mshtml.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\705633f2fc844c232fd7fa61a95e6f62\WindowsLive.Writer.Extensibility.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\675adec4605ffbcceb8b61cefc62eb6b\WindowsLive.Writer.Mshtml.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\63860a12f7243faaf363e7376d25e82c\WindowsLive.Writer.Api.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\583ae66517e0b45d32abc1388a828f6d\WindowsLive.Writer.FileDestinations.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5777ff5662a5e279cba17faf62269aca\WindowsLive.Writer.BrowserControl.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4ab1c5bf195bf6e5e178f5c0dd3faf34\WindowsLive.Writer.Controls.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4667ae25f407693144273d3e1ef3c0b7\WindowsLive.Writer.Interop.ni.dll

    + 2012-05-11 10:08 . 2012-05-11 10:08 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\453fa7a479c8f6c0f51146bed90dc2df\WindowsLive.Writer.Controls.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3ba14b5ac42bc2209115221377e2b280\WindowsLive.Writer.Api.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2a9c5429127d84552f2efd2fde385c35\WindowsLive.Writer.SpellChecker.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1dcdbe3a82d2a1ee2305109fa3a36de0\WindowsLive.Writer.HtmlParser.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\015233b500974ea4ff8ed7a927c2729a\WindowsLive.Writer.BrowserControl.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\2ccfa5153f9a4d514ef61c0558f73831\WindowsLive.Client.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\1272c3020fb51506b4a3ecdf67a8d28d\WindowsLive.Client.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\961b28b18dc304d4434ca9938abd1d60\WindowsFormsIntegration.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\66e4d742316d29e9b28ef39c0aca5c6e\WindowsFormsIntegration.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 185344 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\5e398c245811fe932ce6bcf68664e307\UIAutomationTypes.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 452096 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\42378a09ba2a003848de7d2cfeb1c56a\UIAutomationClient.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\6dca7d279b5977956d040e52814dbd31\TaskScheduler.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 245248 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\58b6523c5167dd748a679e8a46330c32\TaskScheduler.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 401408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\496033ebd93c3381e4ba09486bf23cc3\System.Xml.Linq.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\e8583c3f80cd2a94f552a64b4953dde2\System.Web.Routing.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\e6a25bb61babf2ad6d6fa3256a2ea41a\System.Web.RegularExpressions.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\394765924d5b924fe87103c943abc69c\System.Web.Extensions.Design.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\4b72a66912627a66c65ebc8ce8d82e91\System.Web.Entity.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\0ae0da95dc4b6b0175496e3909522ca0\System.Web.Entity.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 301568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\973d534cb631a5c9c7ea74842056332d\System.Web.Entity.Design.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c80448d686095317e9019f48572b03e0\System.Web.DynamicData.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\a5f548d874a19f075ca408ac46e57d72\System.Web.Abstractions.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\61fbbd8bc7d76972115b292b132ff2d1\System.Transactions.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\c06efd2e3e05e4e3231904d543240c20\System.ServiceProcess.ni.dll

    + 2012-06-16 01:40 . 2012-06-16 01:40 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b7a7f9c607e09bfa03c07b5ff3a8ae3\System.ServiceProcess.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 680960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\61af058c2bc079f28397a29ed145fbc7\System.Security.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 310784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\35fcbda2532ece23d09a044aa2ef62a4\System.Runtime.Serialization.Formatters.Soap.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 624128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\cd8ad97063680071342f13d12376fd17\System.Net.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\9023843c5179d58bd814b64f440679a1\System.Messaging.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\817e1d01a48cec4f9ef66528d479f18b\System.Messaging.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 997888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\3f9dee1ce0ccb42145293a5bfcbe7205\System.Management.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 330240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\c9986072b91eb63728d4843ae798e121\System.Management.Instrumentation.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\870427539c6829f750490719470bfa22\System.IO.Log.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\f93d41cf41160cc660aea5eb8be181d6\System.IdentityModel.Selectors.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\558fa6c6131f14af258f94291a5d19d6\System.EnterpriseServices.Wrapper.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 628224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\558fa6c6131f14af258f94291a5d19d6\System.EnterpriseServices.ni.dll

    + 2012-06-16 01:40 . 2012-06-16 01:40 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\4e3449df387e6a0680d25969da6f965a\System.Drawing.Design.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\3cf93ee533ca0e7e02c7ca3fff5a4bb2\System.Drawing.Design.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 887808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\bbede691e8386ac49379edad37eb7e3c\System.DirectoryServices.AccountManagement.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\77fb2ee5038b95bb20353a305918df9e\System.DirectoryServices.Protocols.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 946176 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\4c7d1e5492f79ac7217577e45a06f559\System.Data.Services.Client.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 356864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\35dfab6426c2a64cae53944e19623dca\System.Data.Services.Design.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 762880 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\71d6318c39c6ee8abb7c3ae61cf2fd4f\System.Data.Entity.Design.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4f1cef2fd7b12da72654f2522f169d2e\System.Data.DataSetExtensions.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f96bc91c85c7aafc6cc0f04742359564\System.Configuration.Install.ni.dll

    + 2012-05-10 01:49 . 2012-05-10 01:49 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\db477bc003958f524c72bc30040f0899\System.AddIn.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\51f227c6d989cd851b46ac157df263a3\sysglobl.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\4bc345ee664ca736a30a7fafd8c5a16c\SMSvcHost.ni.exe

    + 2012-05-11 10:09 . 2012-05-11 10:09 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\26a852935ab27c328a148effb43a76bf\SMDiagnostics.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fcdfda3443709bbe8d0a44cf2e0e1660\PresentationFramework.Classic.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fc626095c194be137bceb219934b06a7\PresentationFramework.Aero.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d85fc1508cff1e635f87b4afb4f4cc9a\PresentationFramework.Luna.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\056f7ed4e914569f97b47631c0ade534\PresentationFramework.Royale.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\faf43d33ee30d43a83f121e83deb9926\napsnap.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 723456 c:\windows\assembly\NativeImages_v2.0.50727_32\napsnap\0e9f88f220b048e2b0d2c8e3801e1fbd\napsnap.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\a15f912411789bcc3129435b4402a70d\napinit.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\napinit\821bb293acac9e6fbb0dc69087e2a172\napinit.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 114176 c:\windows\assembly\NativeImages_v2.0.50727_32\naphlpr\5de0fa9a3f84bad3c0827c3f77387c25\naphlpr.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\b31fec98f29b3530a72c044d36c88cfa\MSBuild.ni.exe

    + 2012-05-11 10:09 . 2012-05-11 10:09 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\3c971ed76268f5cac1d9da788fad447d\MMCFxCommon.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 287232 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCFxCommon\1f10581674c9eb08c896e21fc1f43be4\MMCFxCommon.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 531456 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\530aebd2f4fb78e463e4622b53fa1d29\Microsoft.WSMan.Management.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\0329bf8cfafd687cee2b2d682d182ce9\Microsoft.Transactions.Bridge.Dtc.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 291328 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ec25dcf853949dc1b1055f0a8d3d3817\Microsoft.PowerShell.Commands.Diagnostics.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 167424 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d664a2c965541177d610a2deffd28a29\Microsoft.PowerShell.Security.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 785920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d3719732987a18c70428002240fa0271\Microsoft.PowerShell.Commands.Management.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\83032d78b29cd09caf0ef69d05d33cd3\Microsoft.PowerShell.GraphicalHost.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 515584 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6140e4423431468afff328b69276bd43\Microsoft.PowerShell.ConsoleHost.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\d2168b059e77078ac012ca6e0e1942db\Microsoft.ManagementConsole.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 561664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Managemen#\49af28b21e53bc36f58c371995dfae1a\Microsoft.ManagementConsole.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a3163f28829b22e3ae962dbaa9216028\Microsoft.Build.Utilities.v3.5.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4e130bab9541f548007f649552225772\Microsoft.Build.Utilities.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c617adec91d29b55d0690ace389d1b46\Microsoft.Build.Engine.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\aa7fe29b3123fc147df14c38b18aed9d\Microsoft.Build.Conversion.v3.5.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 364032 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstoredb\6b3830a6c3f619389a49d05164a9306f\mcstoredb.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\81137abf8d8f82270722c4ad14991295\EventViewer.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 553472 c:\windows\assembly\NativeImages_v2.0.50727_32\EventViewer\491bfb35b47079843c7faecb5b67787d\EventViewer.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\44cb15eb402bd0ca508daca85020225a\ehRecObj.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 875520 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiVidCtl\ae72fa5ad8bbb6651ebe2c56dabbd193\ehiVidCtl.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 442880 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiProxy\f627a0274101e3dae80ddcde40885795\ehiProxy.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 161280 c:\windows\assembly\NativeImages_v2.0.50727_32\ehiExtens\b052b90444da59b2ebd1d6485cf49605\ehiExtens.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\c1c5c5288e37abcaa45cfd4e8aa0116d\ehExtHost32.ni.exe

    + 2012-06-16 01:47 . 2012-06-16 01:47 254464 c:\windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\97a8bea875e2f88da466cfa59340a528\ehExtHost32.ni.exe

    + 2012-05-11 10:09 . 2012-05-11 10:09 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\1435db5dea878f59191dc112a40e2185\CustomMarshalers.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\1d948af5bf966ad1277936a6e30f91e3\ComSvcConfig.ni.exe

    + 2012-05-11 08:00 . 2012-05-11 08:00 621568 c:\windows\assembly\NativeImages_v2.0.50727_32\BDATunePIA\7ac2fa31914eca722b63ebd994550211\BDATunePIA.ni.dll

    + 2012-06-14 12:33 . 2012-04-23 22:37 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

    - 2009-07-13 21:10 . 2009-06-10 21:14 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll

    - 2009-07-14 00:35 . 2009-06-10 21:14 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 532480 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 608136 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll

    + 2012-05-09 17:55 . 2012-04-06 00:45 357376 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll

    - 2009-07-14 01:01 . 2009-06-10 20:30 357376 c:\windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll

    - 2009-07-14 00:35 . 2009-06-10 21:14 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll

    + 2012-07-12 01:04 . 2012-07-12 01:04 117160 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll

    - 2010-03-22 02:04 . 2010-03-22 02:04 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 149368 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll

    - 2011-12-14 17:36 . 2011-11-05 04:35 1230336 c:\windows\SysWOW64\urlmon.dll

    + 2012-06-14 12:32 . 2012-04-20 05:07 1230336 c:\windows\SysWOW64\urlmon.dll

    - 2011-02-10 07:08 . 2010-12-21 05:36 1389568 c:\windows\SysWOW64\msxml6.dll

    + 2012-07-10 17:51 . 2012-06-06 05:09 1389568 c:\windows\SysWOW64\msxml6.dll

    + 2012-07-10 17:51 . 2012-06-06 05:09 1236992 c:\windows\SysWOW64\msxml3.dll

    - 2011-02-10 07:07 . 2010-12-21 05:36 1236992 c:\windows\SysWOW64\msxml3.dll

    + 2012-06-14 12:32 . 2012-04-07 11:34 2342400 c:\windows\SysWOW64\msi.dll

    + 2012-06-14 12:32 . 2012-04-20 05:06 6028288 c:\windows\SysWOW64\mshtml.dll

    + 2012-06-14 12:32 . 2012-04-20 05:05 2072576 c:\windows\SysWOW64\iertutil.dll

    - 2011-12-14 17:36 . 2011-11-05 04:34 2072576 c:\windows\SysWOW64\iertutil.dll

    + 2011-07-07 00:28 . 2011-07-07 00:28 1193320 c:\windows\SysWOW64\FM20.DLL

    + 2012-05-09 17:56 . 2012-03-03 05:40 1074176 c:\windows\SysWOW64\DWrite.dll

    - 2011-03-09 16:02 . 2011-02-19 05:32 1074176 c:\windows\SysWOW64\DWrite.dll

    - 2011-01-12 07:13 . 2010-11-02 04:35 1170944 c:\windows\SysWOW64\d3d10warp.dll

    + 2012-05-09 17:56 . 2012-03-03 05:40 1170944 c:\windows\SysWOW64\d3d10warp.dll

    + 2012-06-14 12:31 . 2012-04-24 04:47 1156608 c:\windows\SysWOW64\crypt32.dll

    - 2011-12-14 17:36 . 2011-11-05 05:26 1501184 c:\windows\system32\urlmon.dll

    + 2012-06-14 12:32 . 2012-04-20 06:25 1501184 c:\windows\system32\urlmon.dll

    - 2009-07-14 00:03 . 2009-07-14 01:41 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll

    + 2012-05-09 17:54 . 2012-04-02 05:24 1402880 c:\windows\system32\spool\drivers\x64\3\JNWDRV.dll

    + 2012-03-13 20:48 . 2012-02-15 06:27 1031680 c:\windows\system32\rdpcore.dll

    - 2009-07-14 00:16 . 2009-07-14 01:41 1031680 c:\windows\system32\rdpcore.dll

    + 2012-07-10 17:51 . 2012-06-06 05:50 2003968 c:\windows\system32\msxml6.dll

    - 2011-02-10 07:08 . 2010-12-21 06:13 2003968 c:\windows\system32\msxml6.dll

    + 2012-07-10 17:51 . 2012-06-06 05:50 1880064 c:\windows\system32\msxml3.dll

    + 2012-06-14 12:32 . 2012-04-20 06:23 1026560 c:\windows\system32\mstime.dll

    - 2011-12-14 17:36 . 2011-11-05 05:23 1026560 c:\windows\system32\mstime.dll

    + 2012-06-14 12:32 . 2012-04-07 12:18 3213824 c:\windows\system32\msi.dll

    + 2012-06-14 12:33 . 2012-04-20 06:22 9373696 c:\windows\system32\mshtml.dll

    + 2012-06-14 12:32 . 2012-04-20 06:21 2458624 c:\windows\system32\iertutil.dll

    - 2011-12-14 17:36 . 2011-11-05 05:22 2458624 c:\windows\system32\iertutil.dll

    + 2012-05-09 17:56 . 2012-03-03 06:29 1541120 c:\windows\system32\DWrite.dll

    + 2012-04-25 10:11 . 2012-04-25 10:11 4547944 c:\windows\system32\DriverStore\FileRepository\usbaapl64.inf_amd64_neutral_509d7a31d0ee45f2\usbaaplrc.dll

    + 2012-03-26 12:51 . 2012-03-26 12:51 1721576 c:\windows\system32\DriverStore\FileRepository\netaapl64.inf_amd64_neutral_bf785db627c6d127\wdfcoinstaller01009.dll

    + 2012-05-09 17:54 . 2012-03-30 11:09 1895280 c:\windows\system32\drivers\tcpip.sys

    + 2012-05-09 17:56 . 2012-03-03 06:29 1837568 c:\windows\system32\d3d10warp.dll

    - 2011-01-12 07:13 . 2010-11-02 05:12 1837568 c:\windows\system32\d3d10warp.dll

    + 2012-06-14 12:31 . 2012-04-24 05:59 1460224 c:\windows\system32\crypt32.dll

    - 2009-07-14 04:45 . 2012-01-30 02:21 3802522 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat

    + 2009-07-14 04:45 . 2012-08-01 16:21 3802522 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat

    - 2011-02-27 17:55 . 2012-02-09 23:03 1327681 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-538217755-3608469558-711902680-1001-8192.dat

    + 2011-02-27 17:55 . 2012-07-25 15:25 1327681 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-538217755-3608469558-711902680-1001-8192.dat

    + 2012-01-19 11:08 . 2012-01-19 11:08 1369872 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WindowsBase.dll

    + 2012-01-19 11:08 . 2012-01-19 11:08 6429992 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationFramework.dll

    + 2012-01-19 11:52 . 2012-01-19 11:52 3825952 c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\PresentationCore.dll

    + 2012-03-15 11:17 . 2012-03-15 11:17 5029672 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 3512072 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 4970768 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 1455376 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordbi.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 1515792 c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscordacwks.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 1512712 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll

    + 2011-12-15 12:01 . 2011-12-15 12:01 9793280 c:\windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll

    + 2012-05-09 17:55 . 2012-04-06 00:45 2255952 c:\windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll

    - 2011-06-14 20:19 . 2011-03-29 22:26 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll

    + 2012-05-09 17:55 . 2012-03-21 22:28 5025792 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 3182592 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.dll

    + 2012-06-14 12:31 . 2012-03-21 22:28 4927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll

    - 2009-07-13 20:37 . 2009-06-10 20:40 4927488 c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll

    - 2011-10-12 20:07 . 2011-07-08 22:32 4567040 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 1577744 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 1765136 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll

    + 2012-01-19 11:08 . 2012-01-19 11:08 1369872 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll

    + 2012-01-19 11:08 . 2012-01-19 11:08 6429992 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll

    + 2012-01-19 11:08 . 2012-01-19 11:08 3790112 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll

    + 2012-03-15 11:17 . 2012-03-15 11:17 5029672 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Windows.Forms.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 3512072 c:\windows\Microsoft.NET\Framework\v4.0.30319\System.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 5201168 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 1143568 c:\windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll

    + 2011-12-15 11:08 . 2011-12-15 11:08 6727424 c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 1737296 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll

    + 2012-05-09 17:55 . 2012-03-21 22:29 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll

    - 2011-06-14 20:19 . 2011-03-29 22:31 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll

    + 2012-06-14 12:31 . 2012-03-21 22:29 4927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll

    - 2009-07-13 20:46 . 2009-06-10 21:23 4927488 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 5917456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

    - 2011-10-12 20:07 . 2011-07-08 22:35 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1369872 c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 3512072 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 2207568 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 5029672 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 1711496 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 6097256 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1026936 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 4464480 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1354584 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1199968 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 1462648 c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 6429992 c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 3116376 c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 3825952 c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 4970768 c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 3563408 c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll

    - 2012-01-14 16:56 . 2012-01-14 16:56 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 2975064 c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 3790112 c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 5201168 c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll

    + 2012-06-16 01:14 . 2012-06-16 01:14 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll

    - 2012-01-14 16:57 . 2012-01-14 16:57 2989456 c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll

    + 2012-04-05 15:27 . 2012-04-05 15:27 2323456 c:\windows\Installer\b818f1.msi

    + 2012-04-05 15:23 . 2012-04-05 15:23 2682368 c:\windows\Installer\b818be.msi

    + 2012-04-04 20:38 . 2012-04-04 20:38 2831360 c:\windows\Installer\513f63a.msp

    + 2012-04-28 19:44 . 2012-04-28 19:44 9101824 c:\windows\Installer\513f632.msp

    + 2012-04-28 19:44 . 2012-04-28 19:44 9586176 c:\windows\Installer\513f61c.msp

    + 2012-04-30 12:38 . 2012-04-30 12:38 5011456 c:\windows\Installer\513f5f9.msp

    + 2012-04-04 20:38 . 2012-04-04 20:38 3620864 c:\windows\Installer\513f5a7.msp

    + 2012-03-15 00:24 . 2012-03-15 00:24 1795584 c:\windows\Installer\513f59f.msp

    + 2012-04-28 19:43 . 2012-04-28 19:43 8459264 c:\windows\Installer\513f575.msp

    + 2012-02-17 06:45 . 2012-02-17 06:45 2299392 c:\windows\Installer\513f56d.msp

    + 2012-03-26 22:28 . 2012-03-26 22:28 5009920 c:\windows\Installer\30ac677.msp

    + 2012-02-22 13:19 . 2012-02-22 13:19 2221568 c:\windows\Installer\30ac663.msp

    + 2012-03-23 12:59 . 2012-03-23 12:59 7899648 c:\windows\Installer\30ac655.msp

    + 2011-11-01 11:34 . 2011-11-01 11:34 1169920 c:\windows\Installer\30ac63f.msp

    + 2011-10-26 15:36 . 2011-10-26 15:36 2829312 c:\windows\Installer\29d969ae.msp

    + 2012-02-03 14:13 . 2012-02-03 14:13 4988928 c:\windows\Installer\29d9699b.msp

    + 2012-05-30 05:17 . 2012-05-30 05:17 5010432 c:\windows\Installer\1c69de37.msp

    + 2012-04-22 20:46 . 2012-04-22 20:46 1187328 c:\windows\Installer\1c69de22.msp

    + 2012-03-15 12:26 . 2012-03-15 12:26 4212736 c:\windows\Installer\1c69de1a.msp

    + 2011-09-15 16:42 . 2011-09-15 16:42 1095680 c:\windows\Installer\1af0c659.msp

    + 2011-09-15 16:40 . 2011-09-15 16:40 4760064 c:\windows\Installer\1af0c652.msp

    + 2011-09-15 16:40 . 2011-09-15 16:40 7959552 c:\windows\Installer\1af0c64c.msp

    + 2011-09-15 16:34 . 2011-09-15 16:34 8499712 c:\windows\Installer\1af0c623.msp

    + 2011-09-15 16:35 . 2011-09-15 16:35 1411072 c:\windows\Installer\1af0c357.msp

    + 2012-04-20 05:39 . 2012-04-20 05:39 1948160 c:\windows\Installer\191d68f7.msi

    + 2012-05-30 05:19 . 2012-05-30 05:19 1732608 c:\windows\Installer\106f6ce7.msp

    + 2012-05-30 05:18 . 2012-05-30 05:18 1739264 c:\windows\Installer\106f6cde.msp

    + 2012-06-19 10:54 . 2012-06-19 10:54 2239488 c:\windows\Installer\106f6cd5.msp

    + 2012-06-19 10:54 . 2012-06-19 10:54 5009920 c:\windows\Installer\106f6cbf.msp

    + 2012-04-04 20:37 . 2012-04-04 20:37 2540544 c:\windows\Installer\106f6ca9.msp

    + 2012-04-04 20:37 . 2012-04-04 20:37 3149824 c:\windows\Installer\106f6c85.msp

    + 2012-02-29 21:45 . 2012-02-29 21:45 4989440 c:\windows\Installer\102b4b1b.msp

    - 2010-03-17 18:00 . 2012-01-14 16:54 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

    + 2010-03-17 18:00 . 2012-07-12 01:08 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

    - 2010-03-17 18:00 . 2012-01-14 16:54 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 1099104 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksSb.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 1099104 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\WksSb.exe

    + 2010-03-11 05:56 . 2012-05-09 01:06 1242464 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\wksdb.exe

    - 2010-03-11 05:56 . 2010-12-19 02:05 1242464 c:\windows\Installer\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}\wksdb.exe

    + 2011-06-06 10:55 . 2011-06-06 10:55 1189004 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73401B744AA0100000010\10.1.0\JSByteCodeWin.bin

    + 2009-10-09 21:10 . 2009-10-09 21:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL

    + 2011-07-27 02:59 . 2011-07-27 02:59 6540136 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OSETUP.DLL

    + 2011-07-27 02:55 . 2011-07-27 02:55 3004800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OLMAPI32.DLL

    + 2011-07-07 00:58 . 2011-07-07 00:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGL.DLL

    + 2011-08-02 22:14 . 2011-08-02 22:14 8579448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OARTCONV.DLL

    + 2011-07-27 03:09 . 2011-07-27 03:09 5310848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPEDITOR.DLL

    + 2011-07-27 03:09 . 2011-07-27 03:09 5484416 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPDESIGN.DLL

    + 2011-07-27 03:09 . 2011-07-27 03:09 1460088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\INFOPATH.EXE

    + 2006-10-26 19:25 . 2006-10-26 19:25 2172688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL

    + 2011-08-17 07:49 . 2011-08-17 07:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\WRD12CNV.DLL

    + 2011-07-07 00:58 . 2011-07-07 00:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\OGL.DLL

    + 2011-08-02 22:14 . 2011-08-02 22:14 8579448 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\OARTCONV.DLL

    + 2012-06-16 01:54 . 2012-06-16 01:54 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\e286701acf74012d3aa4a21953f03b6b\WindowsBase.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 5237248 c:\windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\4e962b1751cd3b039c5186963ad5f130\WindowsBase.ni.dll

    + 2012-05-10 01:26 . 2012-05-10 01:26 1430016 c:\windows\assembly\NativeImages_v4.0.30319_64\UIAutomationClients#\6ee9d76d9f1e618cd6fb94b13355bcc9\UIAutomationClientsideProviders.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 7037952 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xml\28ca4f076264ab07f1d00a6c9623dc49\System.Xml.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 2449408 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Xaml\df013cbfec0defc7e9997cdaa90b89bc\System.Xaml.ni.dll

    + 2012-06-16 01:57 . 2012-06-16 01:57 5645824 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\950f64ba9fb22ca06c5b2b9cf6f5f4b4\System.Windows.Forms.DataVisualization.ni.dll

    + 2012-05-10 01:26 . 2012-05-10 01:26 5627904 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Form#\6003f51e67a2ae938571bf999135a05a\System.Windows.Forms.DataVisualization.ni.dll

    + 2012-05-10 01:26 . 2012-05-10 01:26 2236416 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\bc6df78c506c89659ab7be738179b2ba\System.Web.Services.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 2735616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Speech\cd7c3aed4408c3554c30a8f0236b90e1\System.Speech.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 1918976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\94289b88c5b494f572cd7114fa995487\System.ServiceModel.Activities.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 1579008 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\2dbc7aabd92cc0d470acb455c498d919\System.ServiceModel.Discovery.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 3412992 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\affb28e2d9cc3c19de0758e7e8c68e8f\System.Runtime.Serialization.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 1348096 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Dura#\b37e6f4b1d742031f328504eb99d0f6c\System.Runtime.DurableInstancing.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\e29ea726977686cc14c3a57e351e8661\System.Printing.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 1467392 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Printing\d2de16284459454472a6875185c64d08\System.Printing.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 1470464 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Management\b83f2453b4538b2e80fe09cfd94dce00\System.Management.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 1416192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.IdentityModel\60bf6251873ef465abcebeb9a24b7932\System.IdentityModel.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 1098752 c:\windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 2290176 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\97b0b093e73d3a40aa4fd72f38bd5070\System.Drawing.ni.dll

    + 2012-06-16 01:55 . 2012-06-16 01:55 2305024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\1225ef41527a975de83f22328d0a3b93\System.Drawing.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 1217024 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 1622528 c:\windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 2402816 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\c66de888fa426d24e6ff4c4725aef1b0\System.Deployment.ni.dll

    + 2012-06-16 01:55 . 2012-06-16 01:55 2403328 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Deployment\ad9ff5d55f7ea22e80c39e0ff0240984\System.Deployment.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 8601600 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data\0ec8effb7b9d03ae69d37922813bc880\System.Data.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 3390976 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.SqlXml\0eb72df497fad5c273ff16f88b0fb950\System.Data.SqlXml.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 1799168 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 3386368 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Linq\86553c1d7f3e66c17fc3e0274de7a2de\System.Data.Linq.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 1257472 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\6aea67f24827961ce1d48356715389d8\System.Configuration.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 1007616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ComponentMod#\eac19ca5a18a6d08cd247e68b618ba68\System.ComponentModel.Composition.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 5695488 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities\3869077874ba987242c791b3a18b2f8b\System.Activities.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\cffc381c37033e26f6aecc9de6f4f793\System.Activities.Presentation.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 5048832 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.P#\707f90689caf41ad429bf3ad373503cb\System.Activities.Presentation.ni.dll

    + 2012-05-10 01:23 . 2012-05-10 01:23 2064896 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Activities.C#\96083298999a677341c98fc2bf01b248\System.Activities.Core.Presentation.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 4233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\36d8641ebc8601162adae65242087d85\ReachFramework.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 4233216 c:\windows\assembly\NativeImages_v4.0.30319_64\ReachFramework\16c9569b75a9f47c38b60ba733936e1a\ReachFramework.ni.dll

    + 2012-06-16 01:55 . 2012-06-16 01:55 2056704 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\9c3d6b3ddef66cac069b6ab1fec514f8\PresentationUI.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 2056192 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationUI\45b96dd6ea9eb2c7f16ea7b5a1ce6a94\PresentationUI.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e8180bc4b9fe2cfc2c4378fc1b24ccd0\Microsoft.VisualBasic.ni.dll

    + 2012-06-16 01:54 . 2012-06-16 01:54 1843712 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\e4d308f69077903e24de92fe4fc06d29\Microsoft.VisualBasic.Compatibility.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 2317312 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\70e2694fe050bd480b9f61f935ca2da5\Microsoft.VisualBasic.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 1843200 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\5f6c79d821e57c78ceeb90006382f5ff\Microsoft.VisualBasic.Compatibility.ni.dll

    + 2012-05-10 01:19 . 2012-05-10 01:19 1623040 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\16425c121db8083cbaa51f619c9e51e7\Microsoft.VisualBasic.Activities.Compiler.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 1526784 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Transacti#\5284682fcf04815a86233bcaf696da66\Microsoft.Transactions.Bridge.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 3313664 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.JScript\4b1d24a96b3882f9e77445e48a7c59ee\Microsoft.JScript.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 2009600 c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.CSharp\1ff62486cdefbfc2dab41b686a9aa4e2\Microsoft.CSharp.ni.dll

    + 2012-06-16 01:15 . 2012-06-16 01:15 3858432 c:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\1d3c2d83da69c30ba8edf5cfea3c0057\WindowsBase.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 1063424 c:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationClients#\551f143f078d91ce131d3007f16d0b19\UIAutomationClientsideProviders.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 9091584 c:\windows\assembly\NativeImages_v4.0.30319_32\System\9cf67ed1b743fbc3dd6b78fbc0595236\System.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 5617664 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bd2433e160ce2f19acc8ebe10babae8d\System.Xml.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 1782272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\a181199f8dec15116e1c2eb4a79ec22b\System.Xaml.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 4587008 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Form#\0927d75b05e9d3bfdae478155e8c0742\System.Windows.Forms.DataVisualization.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 1885696 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\9c2da5bc8e93845d80dc6768efa78de7\System.Web.Services.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 2012160 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Speech\6f608e64178e985270abbf3b5776fcca\System.Speech.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 1140736 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\a4345e4ff74ec912a5219576049df7fe\System.ServiceModel.Discovery.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 1393152 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\509dab10fd00e66d750ac92101fa3d7b\System.ServiceModel.Activities.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 2647040 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\3fe3910474b3e2a08fca9b09330a74f7\System.Runtime.Serialization.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 1021952 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\ac5d04fd61df57da0f9976440a8c6c58\System.Runtime.DurableInstancing.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 1060864 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Printing\71e3d9751ca6679c5ce2d707ca173373\System.Printing.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 1218560 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\e72d56a0f58bcf95890614700f925609\System.Management.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 1072640 c:\windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\2f4ce144f88caf780421d66027355f77\System.IdentityModel.ni.dll

    + 2012-06-16 01:15 . 2012-06-16 01:15 1666048 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\29e48cb144e24a7b4335d1360cc06642\System.Drawing.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 1172992 c:\windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\6cd7a0ee3583e91326c73ca8e934a99c\System.DirectoryServices.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 1880064 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\e642f8e9415d53aa2bc08fc3af938236\System.Deployment.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 6815232 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data\67065dc691dbf9574b3c8e5ac6ec5246\System.Data.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 2550272 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.SqlXml\e26c8064282712b32d529e521eabde5d\System.Data.SqlXml.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 1343488 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\743d8f183ebfb457d773fc178bdf450d\System.Data.Services.Client.ni.dll

    + 2012-05-10 01:10 . 2012-05-10 01:10 2517504 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\dd5b1a261ce2d2206cdd187666ff0246\System.Data.Linq.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 7069184 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\3e4f9b3b78f0f13b7469a14e69d756ef\System.Core.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 4129280 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities\5efc7ead86507fe65d83cde64c1f659d\System.Activities.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 3757568 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.P#\4ff694358b3796883fea64e500c27169\System.Activities.Presentation.ni.dll

    + 2012-05-10 01:28 . 2012-05-10 01:28 1546752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Activities.C#\3dc813516761fde757cba8adfbe86bd7\System.Activities.Core.Presentation.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 2906624 c:\windows\assembly\NativeImages_v4.0.30319_32\ReachFramework\47f8023bf6e24604f908ebc472dbe3b6\ReachFramework.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 1641984 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationUI\de8350e990fc1123d26665588c7d68c7\PresentationUI.ni.dll

    + 2012-06-16 01:49 . 2012-06-16 01:49 1139712 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\e3be750f68ac84f84240e86a5e1020af\Microsoft.VisualBasic.Compatibility.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 1172480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\8b670069b8d6cd402bef08a90b42b0be\Microsoft.VisualBasic.Activities.Compiler.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 1838080 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\4cd09961cd45c4c3d3a079f3e81686f5\Microsoft.VisualBasic.ni.dll

    + 2012-05-10 01:27 . 2012-05-10 01:27 1085952 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Transacti#\15e239f82d2be50ebf7b4ab8364d4320\Microsoft.Transactions.Bridge.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 2452480 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.JScript\d58c3dcfe00d95d9b397cd0d3d5db5a7\Microsoft.JScript.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 1616896 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\4bacbc23cd4c0841cf4c18399b30b63c\Microsoft.CSharp.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 4927488 c:\windows\assembly\NativeImages_v2.0.50727_64\WindowsBase\7cdb4f5d0ff25c672e52a333ee394bb8\WindowsBase.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 1458688 c:\windows\assembly\NativeImages_v2.0.50727_64\UIAutomationClients#\916d509de3e37ffe61381dc35ee84575\UIAutomationClientsideProviders.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 6948864 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Xml\c40cbbdf7af03daedb16f4d9ef1b6f5f\System.Xml.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 1817600 c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\5e8951a5428e1e760a668b48983988f8\System.WorkflowServices.ni.dll

    + 2012-06-16 01:06 . 2012-06-16 01:06 2707456 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\13dec2cd87ea433f1746027ccbaa3bc4\System.Workflow.Runtime.ni.dll

    + 2012-06-16 01:06 . 2012-06-16 01:06 5955072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\7387f5a454ec6fe605b4bb20b8163256\System.Workflow.ComponentModel.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 5955072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\1c1764b9120f6a73ebdfb58b8e4ab9df\System.Workflow.ComponentModel.ni.dll

    + 2012-06-16 01:03 . 2012-06-16 01:03 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\fc907e5185762726f4d70ad67cc78a22\System.Workflow.Activities.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 3895296 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\254e69d8d12742213f715fc860aad36f\System.Workflow.Activities.ni.dll

    + 2012-06-16 01:03 . 2012-06-16 01:03 2291712 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\35b994e63fbc2836f32326e9f5862a1b\System.Web.Services.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 3335680 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\991f0a84aef8729bde6ae7d9a5ee3eab\System.Web.Mobile.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 3043840 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\1c19687f7c7c4dc03e75c0d23646def6\System.Web.Extensions.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 1155072 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\116bbcff5d5ec37d4606353e4d79fb07\System.Web.Extensions.Design.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 2727936 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Speech\070cd8d59ce62cb6dc5d38b9fecd3858\System.Speech.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 2312704 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\f486134488aa17c44b14af6038a5c8cf\System.ServiceModel.Web.ni.dll

    + 2012-05-10 01:51 . 2012-05-10 01:51 3073536 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\f37d2ca916cafdabe1c4f6f9c6b2c518\System.Runtime.Serialization.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 1022976 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\17bf0932e5c6cb8ba59046456f13328d\System.Runtime.Remoting.ni.dll

    + 2012-06-16 01:43 . 2012-06-16 01:43 1453568 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\86a3611cdef98c49edd41c3cb52d5b81\System.Printing.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 1453568 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Printing\60dee738fe21bb0e9f09fb5a0a66f0e8\System.Printing.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 1408512 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management\bc4eb71543857d07a7401eab3a93d412\System.Management.ni.dll

    + 2012-05-10 01:51 . 2012-05-10 01:51 1433088 c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\8310af7cfed169c2e806347dfd31ed03\System.IdentityModel.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 1081344 c:\windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\b48bd4bfbc25e5fb2b6bbc0627bb7aad\System.EnterpriseServices.ni.dll

    + 2012-06-16 01:41 . 2012-06-16 01:41 2318336 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\6ea40f2da0e2321428a7bdd387e475fd\System.Drawing.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 2311168 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\532c0144e9fb0ed6359b347bcf23273b\System.Drawing.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 1229824 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d0f7e6fad3bf0b055fa9b1d0e5d43305\System.DirectoryServices.AccountManagement.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 1640448 c:\windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\09fa848feffe98e25571f12ba6533b71\System.DirectoryServices.ni.dll

    + 2012-06-16 01:41 . 2012-06-16 01:41 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\817485fd285d4ceca00b5a2f54127187\System.Deployment.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 2444288 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Deployment\3d26045e8d750ce8a49a459ef9b62eb8\System.Deployment.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 8692736 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data\d223792883556acb200a74d695a1c2c5\System.Data.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 3461632 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.SqlXml\e2bf05478288e42b7d5b3953303b43ea\System.Data.SqlXml.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 1846272 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\027818d739a4d16c6c6a6d3a3f97d5ed\System.Data.Services.ni.dll

    + 2012-05-11 10:14 . 2012-05-11 10:14 1289728 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\ce4bbe0a9167e14e22e97c188649ef95\System.Data.Services.Client.ni.dll

    + 2012-05-10 01:48 . 2012-05-10 01:48 1506816 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.OracleC#\a3f0cb65205bc8101de152a3049efa53\System.Data.OracleClient.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 3480576 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Linq\611d21d7fb315802ca1880a6f1c0b8b4\System.Data.Linq.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 1080320 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\4aeeafaf88950db2b1412aa9c1dfc542\System.Data.Entity.Design.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 3312128 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Core\fb0a7c597f43ec6c1fa7eb5c1404cac3\System.Core.ni.dll

    + 2012-05-10 01:44 . 2012-05-10 01:44 1308160 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\dcadcfb938ccdd3f70859fdcdd329ec5\System.Configuration.ni.dll

    + 2012-06-16 01:43 . 2012-06-16 01:43 3101696 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\ace65925339dc7a67f7d5801d305fea7\ReachFramework.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 3101696 c:\windows\assembly\NativeImages_v2.0.50727_64\ReachFramework\8ffee14a3b38799d0707712d4ba2d0e7\ReachFramework.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\f66de669bd9d7fc342118ae8858a0117\PresentationUI.ni.dll

    + 2012-06-16 01:43 . 2012-06-16 01:43 2109952 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationUI\bb6de6dc7e0983ff5d5eb50e4d303401\PresentationUI.ni.dll

    + 2012-05-11 10:12 . 2012-05-11 10:12 1881088 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationBuildTa#\42dad1fa286c2dfef840436e0117f195\PresentationBuildTasks.ni.dll

    + 2012-06-16 01:53 . 2012-06-16 01:53 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\fcfebf142d7794efa4d9f3442b4078b0\Narrator.ni.exe

    + 2012-05-11 10:12 . 2012-05-11 10:12 3601920 c:\windows\assembly\NativeImages_v2.0.50727_64\Narrator\84f71484d6cb38f05c4122e2b55c5ff3\Narrator.ni.exe

    + 2012-05-11 10:12 . 2012-05-11 10:12 2327040 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\93dae3170bf66c3a4a04760f49866351\MMCEx.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 2327040 c:\windows\assembly\NativeImages_v2.0.50727_64\MMCEx\53fc273e6830f8ed9f4a6861bd9e3259\MMCEx.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 7966208 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\cbd80a405506069dcbc40bcf9e35cdbe\MIGUIControls.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 7966208 c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\2979f0ab7db4f166c74e3f9424e32ae7\MIGUIControls.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\d0aece00fadd1a36540bcb49e6f61a81\Microsoft.VisualBasic.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 2131968 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\c43123085590686ee0fe2157c6cf78c8\Microsoft.VisualBasic.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 1598464 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Transacti#\f0d782756caeea9306a63de672c6da6e\Microsoft.Transactions.Bridge.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 1131008 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\f99d492441caaf40f1825b2fb1bb018d\Microsoft.PowerShell.Commands.Management.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 2175488 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\e67017ef44edf5abace08749ba07b3b8\Microsoft.PowerShell.Commands.Utility.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 5351424 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\c939db5fdcb48f5c0a5f1d729127404e\Microsoft.PowerShell.Editor.ni.dll

    + 2012-05-11 09:48 . 2012-05-11 09:48 2105344 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b2a90c6f1e99fd284159c30dfe2f34e8\Microsoft.PowerShell.GPowerShell.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 5351424 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\57340a7859df958d29fa5caa530dcf5f\Microsoft.PowerShell.Editor.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 2175488 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\300edef8229b51147187345b97a2e835\Microsoft.PowerShell.Commands.Utility.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 1142784 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\cc1a3125cc25ececf6bdd96313e1b43d\Microsoft.MediaCenter.Shell.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\cb5ff04ccae6b9da5dbe37a6ae0fa6c1\Microsoft.MediaCenter.Bml.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b6af7cba1817dc28bdcea3f0552b05f3\Microsoft.MediaCenter.UI.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 1516032 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\b193d6accb1cb9d66a6c8e11e163643d\Microsoft.MediaCenter.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 1516032 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\77cfbc9d38b1f0ba1dda1acbf8dc864e\Microsoft.MediaCenter.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 1508864 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\7105232597199587fe5e38441ca0e6f3\Microsoft.MediaCenter.Bml.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 1170432 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\5940bb2af41ce045c35a68977ce3d1f6\Microsoft.MediaCenter.TV.Tuners.Interop.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 8979456 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\366388fa50525598a68e5db0b612bf64\Microsoft.MediaCenter.UI.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 3208192 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.JScript\729baa115f5b270a3b161e72ef7f5351\Microsoft.JScript.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\a036f49088456b29078f9450be06443f\Microsoft.Ink.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 2365952 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Ink\6988ccc9fd7cb466bb763bfa386657d9\Microsoft.Ink.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 2218496 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\9293388abb9fd1c2e63ae6224b5f1631\Microsoft.Build.Tasks.ni.dll

    + 2012-06-16 01:52 . 2012-06-16 01:52 2677760 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Tas#\1f21383dca22c1a8cbe08f00f26150df\Microsoft.Build.Tasks.v3.5.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 1137152 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\dc5d8b624b01a2a1db10e4ed5be18b93\Microsoft.Build.Engine.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 2544640 c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Build.Eng#\3a40ad58fa2e38681f57c1f1e641e329\Microsoft.Build.Engine.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\dc68964376339f9b71d002094cb3f0ca\mcstore.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 2801664 c:\windows\assembly\NativeImages_v2.0.50727_64\mcstore\d38a39e2bd7f6edb06b4c3403b8c7000\mcstore.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 4086784 c:\windows\assembly\NativeImages_v2.0.50727_64\mcepg\c83d93208a390e05a61e34216be32d35\mcepg.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 2184192 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiVidCtl\5d36ff5947a27bcb6028b1341799f15d\ehiVidCtl.ni.dll

    + 2012-05-10 01:52 . 2012-05-10 01:52 1201664 c:\windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\2260f0ed059f4db1564c6015bb1a591d\ehiProxy.ni.dll

    + 2012-05-10 01:50 . 2012-05-10 01:50 3419648 c:\windows\assembly\NativeImages_v2.0.50727_64\DellDock\328df91cef0cb7ec75cdb563b2102777\DellDock.ni.exe

    + 2012-06-16 01:50 . 2012-06-16 01:50 3419648 c:\windows\assembly\NativeImages_v2.0.50727_64\DellDock\00b53b443e33093d91dee5cad638874c\DellDock.ni.exe

    + 2012-06-16 01:47 . 2012-06-16 01:47 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c7c747373d2499890b6f067356806369\WindowsLive.Writer.CoreServices.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\5fcd30e1c21f97ed8e1ae3f2fea1a4f5\WindowsLive.Writer.Localization.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4503e50885b276592f3f791000d3cf4b\WindowsLive.Writer.CoreServices.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 7023616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\44be79c1bc0e85d6ca5e68e54d7e733d\WindowsLive.Writer.PostEditor.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1284608 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\314a994cce75c7a3a203602199142cb8\WindowsLive.Writer.ApplicationFramework.ni.dll

    + 2012-05-11 10:08 . 2012-05-11 10:08 7023616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2cb22c23e24e179fd28ad575eda1d220\WindowsLive.Writer.PostEditor.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\14ebb337bad5a3d15b62b3a24080977c\WindowsLive.Writer.Localization.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 3325952 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b68fdf2c95b93fc5006a092c11eed07c\WindowsBase.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 1047552 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\7f102c92f212048da706c724d5809f12\UIAutomationClientsideProviders.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 7952384 c:\windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 5453312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 1358336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\b345f2895557e6ef39b94aebdeb4a57e\System.WorkflowServices.ni.dll

    + 2012-06-16 01:08 . 2012-06-16 01:08 1914880 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\fd5cec6034bba6b7c0c9b8429b6f2222\System.Workflow.Runtime.ni.dll

    + 2012-06-16 01:40 . 2012-06-16 01:40 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\7ad53a4ed45b577ddc8f80aa5c8e012d\System.Workflow.ComponentModel.ni.dll

    + 2012-06-16 01:08 . 2012-06-16 01:08 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0bda4723e21e411d2ef9fb41d423c1b9\System.Workflow.ComponentModel.ni.dll

    + 2012-06-16 01:08 . 2012-06-16 01:08 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\606d03a28b3dfd46e343a2fd1a9d8659\System.Workflow.Activities.ni.dll

    + 2012-06-16 01:40 . 2012-06-16 01:40 2994688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\5c617f481e72820be334a511ad7e0648\System.Workflow.Activities.ni.dll

    + 2012-06-16 01:07 . 2012-06-16 01:07 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\675c8bd801698993255d100c3b350d4b\System.Web.Services.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 2209792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\e950097b782a3726f9ec9a2662944e73\System.Web.Mobile.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 2403840 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\99d890cec9c7b5d0883d2d84ad98a457\System.Web.Extensions.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\f68d50b9cfb466c62939548433943b3f\System.Speech.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\b744ac6047519b7b186db4d77a78ca0c\System.ServiceModel.Web.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 2347008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3848d7865bda88a9e94e03480b5ada2f\System.Runtime.Serialization.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\fe45d275c0294f519c0967de19ee0aac\System.Printing.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\da97dedec4a2fd679a2c45b6e91b2481\System.Printing.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 8871936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\c9b40cfc4764cf4f9585897f6d2d6110\System.Management.Automation.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 1072128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\f77eb3dd20db5f2277636d4e700a2a2a\System.IdentityModel.ni.dll

    + 2012-06-16 01:38 . 2012-06-16 01:38 1591808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebefde27b0ef7f39bb49c493b34a602c\System.Drawing.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 1586688 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bbf2cf8dd0409f1ccc989406e2942dac\System.Drawing.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 1117184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\027d378a0f7111c18fb687d2948088a9\System.DirectoryServices.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\de5fff0e6854fd1e93f0a6807f46e284\System.Deployment.ni.dll

    + 2012-06-16 01:38 . 2012-06-16 01:38 1806848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\37aa8a6e1a69671c23eb916417629682\System.Deployment.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 6618624 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\294d439cfe959b5528ca81d37d3d502f\System.Data.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 2508288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e8dd334aba14a540d9ac95e372564310\System.Data.SqlXml.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 1328640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\30664d5f93b99eb6e51900ec8137909d\System.Data.Services.ni.dll

    + 2012-05-10 01:43 . 2012-05-10 01:43 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\e05825b235c398d3148bbac51abab75d\System.Data.OracleClient.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 2516992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\98bbe3c24de8dfbbfa6faa685fac7632\System.Data.Linq.ni.dll

    + 2012-05-11 10:11 . 2012-05-11 10:11 9921024 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\e7f8e31dd8f015e08388619be47e632c\System.Data.Entity.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\c366ebd7f33816762268154efc68176d\System.Core.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 2147328 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\937353a3b00a4f47d3c9f022d008936c\ReachFramework.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 2147328 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\4ddbf3609f6efff982c900440dcdb181\ReachFramework.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\8d025cd9dffe9c948a98203bf6a7f322\PresentationUI.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 1658368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\1b357b8f86096b51ac50f1d7c90fd9b9\PresentationUI.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 1449984 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\178be2ae406d87f35b4f22458af0d448\PresentationBuildTasks.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\edd366eb04c2fe0aaabba01c5a2105e0\Narrator.ni.exe

    + 2012-05-11 10:10 . 2012-05-11 10:10 2623488 c:\windows\assembly\NativeImages_v2.0.50727_32\Narrator\b18726a1a33db947e2b4d30b8762d750\Narrator.ni.exe

    + 2012-05-11 10:10 . 2012-05-11 10:10 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\f83e92995389f00559e3ada742fe0603\MMCEx.ni.dll

    + 2012-06-16 01:48 . 2012-06-16 01:48 1545216 c:\windows\assembly\NativeImages_v2.0.50727_32\MMCEx\e143c439fa3698366c4b2b1911a5f8f2\MMCEx.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 6434304 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\7c71cf8026b569ce25c4d1400db16d38\MIGUIControls.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 6434304 c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\66183b1d79527c54e9d5ffdd8f8fda69\MIGUIControls.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\d0abd59506a3ec2f78320912f990d8e8\Microsoft.VisualBasic.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1670144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\3eaec5bc57c67c3b24ca2bb281ca249d\Microsoft.VisualBasic.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 1092608 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7f5335e134e48d154c8cc8aa5d1d9cce\Microsoft.Transactions.Bridge.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f14d9c57454242469919427dd634210e\Microsoft.PowerShell.Commands.Utility.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\b02bdb4f1d9b1e3fb1c5b79838e371e4\Microsoft.PowerShell.Editor.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 1705472 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\6a81878ac094031e85d9b01001dee716\Microsoft.PowerShell.GPowerShell.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1681920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\4f309ae82c753663e09a9a4cdb8375e1\Microsoft.PowerShell.Commands.Utility.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 3724288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\05e23a75053b4659525f4060027ff47a\Microsoft.PowerShell.Editor.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\f606df7f73ca8fb4ad5fc8edf23c3a88\Microsoft.MediaCenter.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b2f1e0442b16e2a25c63b9479034f256\Microsoft.MediaCenter.UI.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 1009664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\80666fd699bdacea4b6b54b974c4d1c9\Microsoft.MediaCenter.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 6499840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\3e794c9f632eef8f63037605644b2385\Microsoft.MediaCenter.UI.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 2332672 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\45c2fc4880b3ea85ee32d106553d5484\Microsoft.JScript.ni.dll

    + 2012-05-11 10:10 . 2012-05-11 10:10 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\9fe034cf200b2ecfdd14226c93169a78\Microsoft.Ink.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1361408 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Ink\4c9b801dd450ef4344d43ba63cd8928f\Microsoft.Ink.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d7fe0033c89960de70477f3a3bf6f139\Microsoft.Build.Tasks.v3.5.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\608fbe1dfdc8d81dacec493fb0359ff4\Microsoft.Build.Tasks.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\cf8b29164df493cae5121e9da162150a\Microsoft.Build.Engine.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\e311a27b6b987b50cb2237d78131721b\mcstore.ni.dll

    + 2012-06-16 01:47 . 2012-06-16 01:47 2035712 c:\windows\assembly\NativeImages_v2.0.50727_32\mcstore\9118d768723cabeb71ee31c9ae817dd5\mcstore.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 3025920 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\9b8e2dfba66cb800d532e0f9596b336f\mcepg.ni.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll

    - 2010-06-23 06:52 . 2010-03-02 23:24 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

    + 2012-05-09 17:55 . 2012-03-21 22:29 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

    - 2011-06-14 20:19 . 2011-03-29 22:31 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

    + 2012-06-14 12:31 . 2012-03-21 22:29 4927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

    - 2009-07-13 20:46 . 2009-06-10 21:23 4927488 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll

    - 2010-06-23 06:52 . 2010-03-02 23:24 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll

    + 2012-05-09 17:55 . 2012-04-06 00:45 2255952 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll

    + 2012-05-09 17:55 . 2012-04-06 00:45 3997696 c:\windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

    - 2011-10-12 20:07 . 2011-07-08 22:32 4567040 c:\windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 1737296 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll

    - 2010-06-23 06:52 . 2010-03-02 23:24 4214784 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll

    + 2012-05-09 17:55 . 2012-04-06 00:49 4214784 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll

    - 2011-10-12 20:07 . 2011-07-08 22:35 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

    + 2012-05-09 17:55 . 2012-01-04 02:51 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

    + 2012-04-03 01:05 . 2012-04-03 01:05 1279864 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll

    + 2012-07-10 17:51 . 2012-06-09 04:46 12868608 c:\windows\SysWOW64\shell32.dll

    + 2012-06-14 12:33 . 2012-04-20 05:05 11019776 c:\windows\SysWOW64\ieframe.dll

    + 2009-07-14 02:34 . 2012-08-01 16:32 10747904 c:\windows\system32\SMI\Store\Machine\schema.dat

    + 2012-07-10 17:51 . 2012-06-09 05:30 14165504 c:\windows\system32\shell32.dll

    + 2012-06-14 12:33 . 2012-04-20 06:21 12405760 c:\windows\system32\ieframe.dll

    + 2012-05-09 17:55 . 2012-01-04 02:48 10005264 c:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll

    + 2012-04-04 13:32 . 2012-04-04 13:32 16613376 c:\windows\Installer\cfc5eae.msp

    + 2012-05-24 16:34 . 2012-05-24 16:34 11071488 c:\windows\Installer\b818c3.msi

    + 2012-05-30 23:47 . 2012-05-30 23:47 20403200 c:\windows\Installer\b81872.msi

    + 2012-01-19 12:20 . 2012-01-19 12:20 11997696 c:\windows\Installer\513f606.msp

    + 2011-12-15 12:54 . 2011-12-15 12:54 39732736 c:\windows\Installer\513f5e4.msp

    + 2012-05-10 01:02 . 2012-05-10 01:02 20343808 c:\windows\Installer\513f559.msp

    + 2012-02-18 02:06 . 2012-02-18 02:06 20333056 c:\windows\Installer\29d969a6.msp

    + 2011-09-15 16:42 . 2011-09-15 16:42 37952512 c:\windows\Installer\1af0c66b.msp

    + 2011-09-15 16:39 . 2011-09-15 16:39 11163136 c:\windows\Installer\1af0c643.msp

    + 2011-09-15 16:38 . 2011-09-15 16:38 10838528 c:\windows\Installer\1af0c638.msp

    + 2011-09-15 16:37 . 2011-09-15 16:37 14140416 c:\windows\Installer\1af0c62e.msp

    + 2011-09-15 16:42 . 2011-09-15 16:42 38326272 c:\windows\Installer\1af0c3f1.msp

    + 2011-09-15 16:42 . 2011-09-15 16:42 14895104 c:\windows\Installer\1af0c389.msp

    + 2011-09-15 16:37 . 2011-09-15 16:37 16691712 c:\windows\Installer\1af0c35e.msp

    + 2011-09-15 16:37 . 2011-09-15 16:37 34428416 c:\windows\Installer\1af0c358.msp

    + 2011-09-15 16:42 . 2011-09-15 16:42 37116416 c:\windows\Installer\1af0c34c.msp

    + 2012-05-31 19:12 . 2012-05-31 19:12 17379840 c:\windows\Installer\1309f6b7.msi

    + 2012-05-30 05:18 . 2012-05-30 05:18 11885056 c:\windows\Installer\106f6d16.msp

    + 2011-11-21 22:42 . 2011-11-21 22:42 33189888 c:\windows\Installer\102b4b30.msp

    + 2011-09-15 18:42 . 2011-09-15 18:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WWLIB.DLL

    + 2011-08-03 16:18 . 2011-08-03 16:18 12997488 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLOOK.EXE

    + 2011-08-17 08:01 . 2011-08-17 08:01 16149352 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OART.DLL

    + 2011-08-03 17:53 . 2011-08-03 17:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSO.DLL

    + 2011-08-03 17:53 . 2011-08-03 17:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002109020031400000000000F01FEC\12.0.6612\MSO.DLL

    + 2012-05-10 01:09 . 2012-05-10 01:09 11880448 c:\windows\assembly\NativeImages_v4.0.30319_64\System\935aea6e7eae16674abdd96a68ec97af\System.ni.dll

    + 2012-06-16 01:56 . 2012-06-16 01:56 17355264 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\e883d90a0210bf99ca88f3b4ade53a24\System.Windows.Forms.ni.dll

    + 2012-05-10 01:22 . 2012-05-10 01:22 17291264 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\3e1fa07a8e487acceef1c22275f08779\System.Windows.Forms.ni.dll

    + 2012-05-10 01:25 . 2012-05-10 01:25 24551936 c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel\c4cc7eb7733c4221c32caccfd66ae320\System.ServiceModel.ni.dll

    + 2012-05-10 01:24 . 2012-05-10 01:24 18479616 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity\9df4e7ae75baa7bbb1af30c8061a6e9b\System.Data.Entity.ni.dll

    + 2012-05-10 01:18 . 2012-05-10 01:18 10440192 c:\windows\assembly\NativeImages_v4.0.30319_64\System.Core\b64f213e823a591607c45fac4997801e\System.Core.ni.dll

    + 2012-06-16 01:55 . 2012-06-16 01:55 24407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\a3c3789d54894008501ce5891f1eeb40\PresentationFramework.ni.dll

    + 2012-05-10 01:21 . 2012-05-10 01:21 24407552 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationFramewo#\5eb97ad52c10035367b07021f1febe97\PresentationFramework.ni.dll

    + 2012-05-10 01:20 . 2012-05-10 01:20 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\c750a4d32ab6ff508c2a8825cc7c9e7d\PresentationCore.ni.dll

    + 2012-06-16 01:54 . 2012-06-16 01:54 15908864 c:\windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\9d69a7a407bbc43a1bcb2da603af5840\PresentationCore.ni.dll

    + 2012-05-10 01:08 . 2012-05-10 01:08 19353600 c:\windows\assembly\NativeImages_v4.0.30319_64\mscorlib\6087fce8f76d9af69af496cb10b7d1ee\mscorlib.ni.dll

    + 2012-06-16 01:15 . 2012-06-16 01:15 13198336 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c06946b464ae8dd22151e0a6f310c976\System.Windows.Forms.ni.dll

    + 2012-05-10 01:30 . 2012-05-10 01:30 18058752 c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\4f8ecf03aa4a4165e6850d1d67dc445f\System.ServiceModel.ni.dll

    + 2012-05-10 01:29 . 2012-05-10 01:29 13345792 c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity\31df9a0b86a3259cb02bbe741e501b85\System.Data.Entity.ni.dll

    + 2012-06-16 01:15 . 2012-06-16 01:15 18000896 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\bcec0e7db1d027328cc8cd702185fa66\PresentationFramework.ni.dll

    + 2012-06-16 01:15 . 2012-06-16 01:15 11451904 c:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b460188cf6862491550a006c3660e2e6\PresentationCore.ni.dll

    + 2012-05-10 01:09 . 2012-05-10 01:09 14413824 c:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\1bdf7de454340e0ea9fc455aeaec49d9\mscorlib.ni.dll

    + 2012-05-10 01:53 . 2012-05-10 01:53 25462272 c:\windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPFB01.tmp\ehshell.dll

    + 2012-05-10 01:44 . 2012-05-10 01:44 10605056 c:\windows\assembly\NativeImages_v2.0.50727_64\System\6ec488b702c100ad5d3e712db0e88554\System.ni.dll

    + 2012-06-16 01:42 . 2012-06-16 01:42 17382912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\ced1d3b0790804426463ad06a61f180e\System.Windows.Forms.ni.dll

    + 2012-05-10 01:46 . 2012-05-10 01:46 17382912 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\9e615199d107a0a6bce7b7a9abc9b0e6\System.Windows.Forms.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 15252992 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\f6514b690596d60ca9f4fa64e14a8355\System.Web.ni.dll

    + 2012-06-16 01:02 . 2012-06-16 01:02 15252992 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\be45e05cff9357affb382eb87c92396a\System.Web.ni.dll

    + 2012-05-10 01:51 . 2012-05-10 01:51 23812096 c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\de361406af8223de5eaa109782ea8272\System.ServiceModel.ni.dll

    + 2012-05-11 08:24 . 2012-05-11 08:24 11898880 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Management.A#\e8015a653e9913ada402b8361ced3d7e\System.Management.Automation.ni.dll

    + 2012-06-16 01:44 . 2012-06-16 01:44 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\dfb7152260d641e49ec1ecf0f2df0f37\System.Design.ni.dll

    + 2012-06-16 01:03 . 2012-06-16 01:03 13609472 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\a8fe0528a8ff08181473d7658f4031dc\System.Design.ni.dll

    + 2012-05-11 10:13 . 2012-05-11 10:13 13757952 c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity\b0920f4fb4f89400b383e2db88209bf5\System.Data.Entity.ni.dll

    + 2012-06-16 01:43 . 2012-06-16 01:43 19173376 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\916af5e5c39e1226e0b87a80e3a979f2\PresentationFramework.ni.dll

    + 2012-05-10 01:47 . 2012-05-10 01:47 19173376 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationFramewo#\52d8b5acd06ad5e97e910b216d297fd2\PresentationFramework.ni.dll

    + 2012-06-16 01:41 . 2012-06-16 01:41 16517120 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\ea90a194614680a484a25b6ccc4df754\PresentationCore.ni.dll

    + 2012-05-10 01:45 . 2012-05-10 01:45 16517120 c:\windows\assembly\NativeImages_v2.0.50727_64\PresentationCore\3b7ce3ed3cbbaa85258e792608c2a3a7\PresentationCore.ni.dll

    + 2012-05-10 01:44 . 2012-05-10 01:44 15568896 c:\windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a7b48ad2929bc93362ec42cd4573f87\mscorlib.ni.dll

    + 2012-06-16 01:50 . 2012-06-16 01:50 22171136 c:\windows\assembly\NativeImages_v2.0.50727_64\MenuSkinning\a90333d607423213be056665d422c19b\MenuSkinning.ni.dll

    + 2012-06-16 01:51 . 2012-06-16 01:51 25462272 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\a1484b74816bb58e5a5e59cc750fc3bd\ehshell.ni.dll

    + 2012-05-11 08:23 . 2012-05-11 08:23 25462272 c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\0a1c7232b18b52c6e3a98d8eb79977d9\ehshell.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 12433920 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9e953ea4e76b62ab1c4a1874abae2961\System.Windows.Forms.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 12433920 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\009c50fb69919b90fb233cb4c35d0ad7\System.Windows.Forms.ni.dll

    + 2012-06-16 01:07 . 2012-06-16 01:07 11824128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\98df3846663c7901dda205672cbdd65b\System.Web.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 11824128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\84fbf353f91385690a3e4e982aa6930e\System.Web.ni.dll

    + 2012-05-11 10:09 . 2012-05-11 10:09 17400320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\7900b4e8c860d8b4a3c1f98047c3c1a3\System.ServiceModel.ni.dll

    + 2012-06-16 01:08 . 2012-06-16 01:08 10578432 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\2d9fd93aa30a0f2b99ef3a684495ef82\System.Design.ni.dll

    + 2012-06-16 01:40 . 2012-06-16 01:40 10578432 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\1321319c8922886e520d2821b5a64dca\System.Design.ni.dll

    + 2012-05-10 01:42 . 2012-05-10 01:42 14325760 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\64e140108933b8090472da1a76b78c20\PresentationFramework.ni.dll

    + 2012-06-16 01:39 . 2012-06-16 01:39 14325760 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\517358eb2fd962a942dd1ea6afc5b93e\PresentationFramework.ni.dll

    + 2012-06-16 01:38 . 2012-06-16 01:38 12218880 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\e9d0ba41128f363f2390c7e630129c2b\PresentationCore.ni.dll

    + 2012-05-10 01:41 . 2012-05-10 01:41 12218880 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b6370d1903505abc171c968e357fe1bf\PresentationCore.ni.dll

    + 2012-05-10 01:40 . 2012-05-10 01:40 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll

    + 2011-09-15 16:34 . 2011-09-15 16:34 428804608 c:\windows\Installer\1af0c616.msp

    .

    -- Snapshot teruggezet naar huidige datum --

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 94208 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 94208 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 94208 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "MyTomTomSA.exe"="c:\program files (x86)\MyTomTom 3\MyTomTomSA.exe" [2012-05-18 434168]

    "TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2012-04-20 247728]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

    "DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]

    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160]

    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]

    .

    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

    "mixer"=wdmaud.drv

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

    @=""

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

    @=""

    .

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-30 250056]

    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]

    R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1255736]

    S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]

    S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

    S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]

    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]

    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]

    S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192]

    S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2012-04-20 92592]

    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]

    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]

    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]

    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552]

    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]

    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-05-20 393728]

    .

    .

    --- Andere Services/Drivers In Geheugen ---

    .

    *Deregistered* - mfeavfk01

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-08-01 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-03 15:10]

    .

    2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-538217755-3608469558-711902680-1001Core.job

    - c:\users\Walter\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-28 16:24]

    .

    2012-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-538217755-3608469558-711902680-1001UA.job

    - c:\users\Walter\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-28 16:24]

    .

    .

    --------- X64 Entries -----------

    .

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 97792 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 97792 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 97792 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

    2011-02-18 05:12 97792 ----a-w- c:\users\Walter\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]

    .

    ------- Bijkomende Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    uStart Page = hxxp://www.google.be/

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uInternet Settings,ProxyOverride = *.local

    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 195.130.130.129 195.130.131.129

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    Toolbar-Locked - (no file)

    .

    .

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.11"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker4"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    ------------------------ Andere Aktieve Processen ------------------------

    .

    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    c:\windows\SysWOW64\rundll32.exe

    c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe

    .

    **************************************************************************

    .

    Voltooingstijd: 2012-08-01 18:50:45 - machine werd herstart

    ComboFix-quarantined-files.txt 2012-08-01 16:50

    ComboFix2.txt 2012-02-09 23:12

    .

    Pre-Run: 86.172.315.648 bytes beschikbaar

    Post-Run: 85.720.289.280 bytes beschikbaar

    .

    - - End Of File - - 9D2A3D3428172BB8B0A27732EF5945C0

  12. Aangezien de laptop van m'n ouders enorm traag gaat, had ik graag een goeie opkuis gedaan.

    Hierbij alvast een MB-scan, alsook Hijackthis logje.

    Alvast bedankt voor de hulp.

    Malwarebytes Anti-Malware 1.62.0.1300

    Malwarebytes : Free anti-malware download

    Databaseversie: v2012.07.31.11

    Windows 7 x64 NTFS

    Internet Explorer 8.0.7600.16385

    Walter :: WALTER-PC [administrator]

    31/07/2012 20:43:14

    mbam-log-2012-07-31 (20-43-14).txt

    Scantype: Volledige scan (C:\|)

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 343651

    Verstreken tijd: 1 uur/uren, 48 minuut/minuten, 57 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:50:53, on 31/07/2012

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.17006)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe

    C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe

    C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120629144043.dll

    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

    O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

    O4 - HKCU\..\Run: [Google Update] "C:\Users\Walter\AppData\Local\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: [MyTomTomSA.exe] "C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe"

    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"

    O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe

    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe

    O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe

    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe

    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 10304 bytes

  13. Internet snelheid is drastisch gedaald.

    Provider ziet geen problemen bij aansluiting, en wijt het probleem aan mogelijke virussen / spyware.

    Mcafee virusscan leverde niets op, alsook een scan met Malwarebytes Anti Malware.

    Vandaar hieronder een hijackthis logje bijgevoegd.

    Alvast bedankt voor de hulp.

    Mvg.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:24:11, on 4/06/2012

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.16968)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Windows\SysWOW64\rundll32.exe

    C:\Users\Walter\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    C:\Windows\SysWOW64\DllHost.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120508184134.dll

    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

    O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKCU\..\Run: [Google Update] "C:\Users\Walter\AppData\Local\Google\Update\GoogleUpdate.exe" /c

    O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe

    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe

    O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe

    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe

    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 10314 bytes

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.