About: Blank(RESOLVED)

  1. #1
    donkeytime is offline Newbie

    About: Blank(RESOLVED)

    This computer is only several months old. I uninstalled Norton and installed AVG with upgrade before I went on the internet. About a week or two ago, I began noticing about:blank pop up on my URL. I started getting some blank pages when I was on internet. I run AVG every day on a schedule. All windows updated, etc... I realized something was wrong and googled about:blank and learned this is malware. I contacted AVG for help---no reply and it has been well over a week now. Finally, I did system restore all the way back so it was supposed to be just like when I first got the computer. It seemed to be fine until last night when I started seeing about:blank again and having some problems (EX: I was going through d.a.l. pages when it defaulted to about:blank and I had to start all over again.) I have also run Registry Mechanic today.

    I am also having quite a few problems with bluestreak, tribal fusion, and some other trackign cookies that I can not remove.

    I would like some recommendations for the right combination of paid programs to keep this from happening (as much as possible) in the future. Your help is greatly appreciated.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:50:53 PM, on 7/6/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\Registry Mechanic\RMTray.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\IEUser.exe
    C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
    C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\System32\wsqmcons.exe
    c:\Users\donkeytime\Downloads\HiJackThis.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /QS
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9502 bytes





    From scan log:
    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!

    Generated 07/06/2008 at 02:50 PM

    Application Version : 4.15.1000

    Core Rules Database Version : 3497
    Trace Rules Database Version: 1488

    Scan type : Complete Scan
    Total Scan Time : 00:30:18

    Memory items scanned : 588
    Memory threats detected : 0
    Registry items scanned : 6499
    Registry threats detected : 0
    File items scanned : 30404
    File threats detected : 38

    Adware.Tracking Cookie
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@toyota.112.2o7[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@avgtechnologies.112.2o7[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@media.adrevolver[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@imrworldwide[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@collective-media[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@apmebf[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@rotator.adjuggler[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@atwola[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@anat.tacoda[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@specificclick[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@interclick[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@cbs.112.2o7[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@anad.tacoda[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[3].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.revsci[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@edge.ru4[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@sales.liveperson[3].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ehg-space.hitbox[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.pointroll[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@tracking.dsmmadvantage[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ehg-dig.hitbox[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@sales.liveperson[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@iacas.adbureau[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@kontera[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@homeaway.112.2o7[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@adopt.specificclick[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@toplist[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@clickshift[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@aws.112.2o7[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@insightexpressai[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@dynamic.media.adrevolve r[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.bridgetrack[2].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@track.cbs[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.cnn[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.burstnet[1].txt
    C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@glb.adtechus[1].txt



    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!

    Generated 07/06/2008 at 02:20 PM

    Application Version : 4.15.1000

    Core Rules Database Version : 3497
    Trace Rules Database Version: 1488

    Scan type : Complete Scan
    Total Scan Time : 00:00:02

    Memory items scanned : 26
    Memory threats detected : 0
    Registry items scanned : 0
    Registry threats detected : 0
    File items scanned : 0
    File threats detected : 0


    Registry Mechanic
    ersion 7.0.0.1010
    ----------------------------------------------------------------------------------------------------
    Engine: 2.0.0.704
    ----------------------------------------------------------------------------------------------------
    Start of Scan
    7/6/2008 4:42:41 PM

    Your System Information :
    CPU: Intel Pentium
    IE: 7.0.6001.18000
    MEMORY FREE: 1914044
    MEMORY TOTAL: 2097152
    VIRTUAL FREE: 1972516
    VIRTUAL TOTAL: 2097024
    Windows Vista 6.0 (6001) Service Pack 1.0
    ----------------------------------------------------------------------------------------------------
    Running processes: Process ID
    ----------------------------------------------------------------------------------------------------
    [System Process] 0
    System 4
    smss.exe 432
    csrss.exe 548
    wininit.exe 600
    csrss.exe 612
    winlogon.exe 712
    services.exe 732
    lsass.exe 748
    lsm.exe 760
    svchost.exe 912
    svchost.exe 972
    svchost.exe 1008
    svchost.exe 1068
    svchost.exe 1096
    svchost.exe 1124
    audiodg.exe 1192
    SLsvc.exe 1232
    svchost.exe 1268
    svchost.exe 1376
    spoolsv.exe 1564
    svchost.exe 1588
    avgwdsvc.exe 1768
    avgfws8.exe 1784
    svchost.exe 1808
    LSSrvc.exe 1924
    svchost.exe 2028
    QPCapSvc.exe 188
    avgam.exe 1856
    avgrsx.exe 12
    avgnsx.exe 724
    RichVideo.exe 2088
    svchost.exe 2156
    XAudio.exe 2220
    hpqWmiEx.exe 2276
    QPSched.exe 2600
    avgemc.exe 2688
    taskeng.exe 2700
    dwm.exe 3388
    taskeng.exe 3424
    explorer.exe 3552
    rundll32.exe 3736
    SynTPEnh.exe 3752
    QPService.exe 3760
    QLBCTRL.exe 3768
    HPKBDAPP.exe 3780
    rundll32.exe 3788
    MSASCui.exe 3796
    HpqSRmon.exe 3804
    hpwuSchd2.exe 3840
    HPWAMain.exe 3896
    svchost.exe 3916
    WiFiMsg.exe 3980
    jusched.exe 4024
    WmiPrvSE.exe 4072
    avgtray.exe 4088
    RMTray.exe 2056
    sidebar.exe 2144
    LightScribeControlPanel.exe 804
    HPAdvisor.exe 2324
    GoogleToolbarNotifier.exe 2448
    SUPERAntiSpyware.exe 2428
    BTTray.exe 2748
    SearchIndexer.exe 3156
    SUPERAntiSpyware.exe 3336
    HpqToaster.exe 3720
    iexplore.exe 3464
    ieuser.exe 3020
    aAvgApi.exe 3692
    hpswp_clipbook.exe 2488
    BTStackServer.exe 2400
    PresentationFontCache.exe 4552
    iexplore.exe 4716
    SynTPHelper.exe 4760
    HPHC_Service.exe 5968
    FlashUtil9f.exe 4548
    wsqmcons.exe 3228
    notepad.exe 3340
    taskeng.exe 1288
    RegMech.exe 5656
    ----------------------------------------------------------------------------------------------------
    Sections Scanned:
    ----------------------------------------------------------------------------------------------------
    FX - 1
    Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\OpenWithList
    Value : default = OpenWithList
    Parsed :

    DEEP - 2
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Installer\UserData\S-1-5-18\Components\3FDE6B2B8B223B743885D491670F49D9
    Value : 1FBBCDDC3072CB6439B8CB8CA1E1AEAA = C:\Program Files\SUPERAntiSpyware\Quarantine\
    Parsed : c:\program files\superantispyware\quarantine

    DEEP - 3
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Installer\UserData\S-1-5-18\Components\4B18D8CB32BF75649BECD8ED5A5FD871
    Value : 1FBBCDDC3072CB6439B8CB8CA1E1AEAA = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Start Menu\Programs\SUPERAntiSpyware\
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\start menu\programs\superantispyware

    DEEP - 4
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
    Value : HistoryHashMapFile = C:\ProgramData\Microsoft\Search\Data\Applications\ Windows\Projects\SystemIndex\SystemIndex.Hash.gthr
    Parsed : c:\programdata\microsoft\search\data\applications\ windows\projects\systemindex\systemindex.hash.gthr

    DEEP - 5
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
    Value : DocIdMapFile = C:\ProgramData\Microsoft\Search\Data\Applications\ Windows\Projects\SystemIndex\SystemIndex.Idm.gthr
    Parsed : c:\programdata\microsoft\search\data\applications\ windows\projects\systemindex\systemindex.idm.gthr

    DEEP - 6
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File0 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@toyota.112.2o7[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@toyota.112.2o7[1].txt

    DEEP - 7
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File1 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@avgtechnologies.112.2o7[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@avgtechnologies.112.2o7[2].txt

    DEEP - 8
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File2 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@media.adrevolver[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@media.adrevolver[1].txt

    DEEP - 9
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File3 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@imrworldwide[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@imrworldwide[2].txt

    DEEP - 10
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File4 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@collective-media[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@collective-media[1].txt

    DEEP - 11
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File5 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@apmebf[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@apmebf[1].txt

    DEEP - 12
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File6 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@rotator.adjuggler[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@rotator.adjuggler[1].txt

    DEEP - 13
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File7 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@atwola[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@atwola[1].txt

    DEEP - 14
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File8 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@anat.tacoda[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@anat.tacoda[2].txt

    DEEP - 15
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File9 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@specificclick[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@specificclick[1].txt

    DEEP - 16
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File10 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@interclick[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@interclick[2].txt

    DEEP - 17
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File11 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@cbs.112.2o7[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@cbs.112.2o7[1].txt

    DEEP - 18
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File12 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@anad.tacoda[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@anad.tacoda[1].txt

    DEEP - 19
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File13 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[3].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@www.googleadservices[3].txt

    DEEP - 20
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File14 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@www.googleadservices[1].txt

    DEEP - 21
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File15 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.revsci[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ads.revsci[1].txt

    DEEP - 22
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File16 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.googleadservices[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@www.googleadservices[2].txt

    DEEP - 23
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File17 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@edge.ru4[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@edge.ru4[2].txt

    DEEP - 24
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File18 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@sales.liveperson[3].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@sales.liveperson[3].txt

    DEEP - 25
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File19 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ehg-space.hitbox[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ehg-space.hitbox[1].txt

    DEEP - 26
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File20 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.pointroll[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ads.pointroll[1].txt

    DEEP - 27
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File21 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@tracking.dsmmadvantage[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@tracking.dsmmadvantage[1].txt

    DEEP - 28
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File22 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ehg-dig.hitbox[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ehg-dig.hitbox[1].txt

    DEEP - 29
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File23 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@sales.liveperson[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@sales.liveperson[1].txt

    DEEP - 30
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File24 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@iacas.adbureau[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@iacas.adbureau[1].txt

    DEEP - 31
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File25 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@kontera[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@kontera[2].txt

    DEEP - 32
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File26 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@homeaway.112.2o7[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@homeaway.112.2o7[1].txt

    DEEP - 33
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File27 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@adopt.specificclick[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@adopt.specificclick[1].txt

    DEEP - 34
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File28 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@toplist[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@toplist[1].txt

    DEEP - 35
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File29 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@clickshift[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@clickshift[1].txt

    DEEP - 36
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File30 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@aws.112.2o7[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@aws.112.2o7[1].txt

    DEEP - 37
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File31 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@insightexpressai[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@insightexpressai[1].txt

    DEEP - 38
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File32 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@dynamic.media.adrevolve r[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@dynamic.media.adrevolve r[1].txt

    DEEP - 39
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File33 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.bridgetrack[2].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ads.bridgetrack[2].txt

    DEEP - 40
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File34 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@track.cbs[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@track.cbs[1].txt

    DEEP - 41
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File35 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@ads.cnn[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@ads.cnn[1].txt

    DEEP - 42
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File36 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@www.burstnet[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@www.burstnet[1].txt

    DEEP - 43
    Location: HKEY_LOCAL_MACHINE\SOFTWARE\SUPERAntiSpyware.com\S UPERAntiSpyware\InUseFiles
    Value : File37 = C:\Users\donkeytime\AppData\Roaming\Microsoft\Wind ows\Cookies\Low\donkeytime@glb.adtechus[1].txt
    Parsed : c:\users\donkeytime\appdata\roaming\microsoft\wind ows\cookies\low\donkeytime@glb.adtechus[1].txt

    ----------------------------------------------------------------------------------------------------
    Version 7.0.0.1010
    ----------------------------------------------------------------------------------------------------

    End of Scan
    7/6/2008 4:43:01 PM

    Your System Information :
    MEMORY FREE: 1906484
    MEMORY TOTAL: 2097152
    VIRTUAL FREE: 1957676
    VIRTUAL TOTAL: 2097024
    Last edited by donkeytime; 06-07-2008 at 09:47 PM.


  2. #2
    donkeytime is offline Newbie
    update: I purchased the SuperAnti-spyware Professional and ran it last night until it showed no problems. I shut down the computer, went to bed and started it this morning. I received another "about:blank" screen.

  3. #3
    Neal is offline Dedicated Member
    Visit this page below to familiarize yourself to the tool below:

    A guide and tutorial on using ComboFix




    If you have previously downloaded ComboFix,please delete that version now.

    Now download ComboFix and save to your desktop:

    Note:

    It is IMPORTANT that it is saved directly to your desktop

    Close any open browsers.

    Disconnect from the Internet.

    Please do not re-connect your machine back to the Internet until Combofix has completely finished.

    Disable your antivirus program and any realtime malware scanners and script blockers now


    How To Disable



    Double click on combofix.exe and follow the prompts.

    When it's finished it will produce a log.
    Post the entire contents of C:\ComboFix.txt into your next reply.

    Note:
    Do not mouseclick combofix's window while it's running.

    That may cause the program to freeze/hang.

    Do NOT post the ComboFix-quarantined-files.txt unless I ask.

    Re-enable your anti-virus and re-connect back to the internet and post the combofix log.



    *Note*
    In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
    Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.


    ComboFix SHOULD NOT be used unless requested by a forum helper.

  4. #4
    donkeytime is offline Newbie
    Thank you so much for the reply!

    I made sure there were no virus scanners or malware scanners on. I had some trouble downloading ComboFix and then realized I had some scripting to enable. I did this, and initially I got res://iefream.dll/dnserror.htm error. I had to try a couple of times. Then I did not get a traditional icon, but a blue box that had "adminstrator" in it, so I ran to disconnect the internet. It took me about 20-40 seconds to do this. this is the post:

    ComboFix 08-07-08.1 - donkeytime 2008-07-08 21:33:35.1 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2025 [GMT -4:00]
    Running from: c:\Users\donkeytime\Downloads\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Windows\system32\KBL.LOG

    .
    ((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
    .

    2008-07-07 09:40 . 2008-07-07 09:40 3,646 --a------ C:\WINDOWS\System32\ealregsnapshot1.reg
    2008-07-06 13:24 . 2008-07-06 13:24 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
    2008-07-06 13:24 . 2008-07-06 13:24 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
    2008-07-06 13:23 . 2008-07-06 13:23 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\SUPERAntiSpywa re.com
    2008-07-06 13:23 . 2008-07-06 13:23 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-07-06 11:06 . 2008-07-07 21:20 <DIR> d--h----- C:\$AVG8.VAULT$
    2008-07-06 10:49 . 2008-07-06 10:49 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\Yahoo!
    2008-07-06 10:49 . 2008-07-06 10:49 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
    2008-07-06 10:49 . 2008-07-06 10:49 <DIR> d-------- C:\ProgramData\Yahoo! Companion
    2008-07-06 09:51 . 2008-07-06 09:51 <DIR> d-------- C:\Users\All Users\Google
    2008-07-06 09:51 . 2008-07-06 12:35 <DIR> d-------- C:\Program Files\Google
    2008-07-03 11:45 . 2008-07-03 11:45 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\CyberLink
    2008-07-03 03:01 . 2008-07-03 03:01 <DIR> d-------- C:\Program Files\MSXML 4.0
    2008-07-02 23:13 . 2008-07-02 23:13 27,810 --a------ C:\Users\donkeytime\AppData\Roaming\nvModes.dat
    2008-07-02 23:02 . 2008-04-23 00:42 428,544 --a------ C:\WINDOWS\System32\EncDec.dll
    2008-07-02 23:02 . 2008-04-23 00:42 293,376 --a------ C:\WINDOWS\System32\psisdecd.dll
    2008-07-02 23:02 . 2008-04-23 00:41 218,624 --a------ C:\WINDOWS\System32\psisrndr.ax
    2008-07-02 23:02 . 2008-04-23 00:41 57,856 --a------ C:\WINDOWS\System32\MSDvbNP.ax
    2008-07-02 22:50 . 2008-04-24 22:12 1,383,424 --a------ C:\WINDOWS\System32\mshtml.tlb
    2008-07-02 22:50 . 2008-04-25 00:35 826,880 --a------ C:\WINDOWS\System32\wininet.dll
    2008-07-02 01:06 . 2008-07-02 01:06 <DIR> d-------- C:\Users\donkeytime\Bluetooth Software
    2008-07-02 01:06 . 2008-07-02 01:06 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\Symantec
    2008-07-02 01:05 . 2008-07-02 01:05 <DIR> dr------- C:\Users\donkeytime\Searches
    2008-07-02 01:05 . 2008-07-07 23:46 <DIR> dr------- C:\Users\donkeytime\Contacts
    2008-07-02 01:05 . 2008-07-02 01:05 81 --a------ C:\WINDOWS\System32\LOG
    2008-07-02 01:04 . 2008-07-02 01:04 44 --a------ C:\WINDOWS\system\hpsysdrv.dat
    2008-07-02 01:00 . 2008-07-02 01:07 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\Hewlett-Packard
    2008-07-02 00:59 . 2008-07-02 00:59 <DIR> d-------- C:\Program Files\Yahoo!
    2008-07-02 00:58 . 2008-07-02 00:58 <DIR> d-------- C:\Users\All Users\Electronic Arts
    2008-07-02 00:58 . 2008-07-02 00:58 <DIR> d-------- C:\ProgramData\Electronic Arts
    2008-07-02 00:54 . 2008-07-02 00:58 <DIR> d-------- C:\Program Files\Electronic Arts
    2008-07-02 00:54 . 2006-07-28 12:30 236,824 --a------ C:\WINDOWS\System32\xactengine2_3.dll
    2008-07-02 00:54 . 2006-07-28 12:30 62,744 --a------ C:\WINDOWS\System32\xinput1_2.dll
    2008-07-02 00:53 . 2005-05-26 18:34 2,297,552 --a------ C:\WINDOWS\System32\d3dx9_26.dll
    2008-07-02 00:52 . 2008-07-02 00:52 <DIR> d-------- C:\Program Files\Common Files\LightScribe
    2008-07-02 00:52 . 2008-07-02 00:52 0 -rahs---- C:\WINDOWS\System32\drivers\103C_HP_cNB_Pavilion dv6700 Notebook PC_Y5335KV_0U_QCNF81228BK_E480576-002_4A_I30CF_SQuanta_V85.24_F.2A_T080222_WV3-1_L409_M3007_J160_7AMD_8F82_92.00_#080701_N10DE054 C;168C001C_(KN828UA#ABA)_XMOBILE_CN10_Z.MRK
    2008-07-02 00:51 . 2008-07-02 01:05 <DIR> dr------- C:\Users\donkeytime\Videos
    2008-07-02 00:51 . 2008-07-02 01:05 <DIR> dr------- C:\Users\donkeytime\Saved Games
    2008-07-02 00:51 . 2008-07-02 13:40 <DIR> dr------- C:\Users\donkeytime\Pictures
    2008-07-02 00:51 . 2008-07-02 01:05 <DIR> dr------- C:\Users\donkeytime\Music
    2008-07-02 00:51 . 2008-07-02 01:05 <DIR> dr------- C:\Users\donkeytime\Links
    2008-07-02 00:51 . 2008-07-08 21:03 <DIR> dr------- C:\Users\donkeytime\Downloads
    2008-07-02 00:51 . 2008-07-06 14:18 <DIR> dr------- C:\Users\donkeytime\Documents
    2008-07-02 00:51 . 2006-11-02 08:37 <DIR> d-------- C:\Users\donkeytime\AppData\Roaming\Media Center Programs
    2008-07-02 00:51 . 2008-07-02 00:51 <DIR> d--h----- C:\Users\donkeytime\AppData
    2008-07-02 00:51 . 2008-07-08 04:06 <DIR> d-------- C:\Users\donkeytime
    2008-07-02 00:18 . 2008-07-08 20:53 <DIR> d-------- C:\Users\All Users\avg8
    2008-07-02 00:18 . 2008-07-08 20:53 <DIR> d-------- C:\ProgramData\avg8
    2008-07-02 00:18 . 2008-07-02 00:18 <DIR> d-------- C:\Program Files\AVG
    2008-07-02 00:18 . 2008-07-02 00:18 10,520 --a------ C:\WINDOWS\System32\avgrsstx.dll.old
    2008-07-01 23:01 . 2008-03-07 22:08 4,240,384 --a------ C:\WINDOWS\System32\GameUXLegacyGDFs.dll
    2008-07-01 23:01 . 2008-03-08 00:21 1,695,744 --a------ C:\WINDOWS\System32\gameux.dll
    2008-07-01 22:48 . 2008-02-29 03:11 988,216 --a------ C:\WINDOWS\System32\winload.exe
    2008-07-01 22:48 . 2008-02-29 03:11 927,288 --a------ C:\WINDOWS\System32\winresume.exe
    2008-07-01 22:48 . 2008-02-22 01:05 615,992 --a------ C:\WINDOWS\System32\ci.dll
    2008-07-01 22:48 . 2008-02-29 02:53 378,368 --a------ C:\WINDOWS\System32\srcore.dll
    2008-07-01 22:48 . 2008-02-29 00:12 318,464 --a------ C:\WINDOWS\System32\rstrui.exe
    2008-07-01 22:48 . 2008-02-29 02:53 46,592 --a------ C:\WINDOWS\System32\setbcdlocale.dll
    2008-07-01 22:48 . 2008-02-29 02:53 40,960 --a------ C:\WINDOWS\System32\srclient.dll
    2008-07-01 22:48 . 2008-02-29 03:14 19,000 --a------ C:\WINDOWS\System32\kd1394.dll
    2008-07-01 22:48 . 2008-02-29 00:12 14,848 --a------ C:\WINDOWS\System32\srdelayed.exe
    2008-07-01 22:48 . 2008-02-29 02:35 6,656 --a------ C:\WINDOWS\System32\kbd106n.dll
    2008-07-01 22:34 . 2008-02-29 00:21 2,032,128 --a------ C:\WINDOWS\System32\win32k.sys
    2008-07-01 22:34 . 2008-04-26 04:08 1,314,816 --a------ C:\WINDOWS\System32\quartz.dll
    2008-07-01 22:34 . 2008-02-22 00:57 295,936 --a------ C:\WINDOWS\System32\gdi32.dll
    2008-07-01 22:34 . 2008-04-28 21:42 220,160 --a------ C:\WINDOWS\System32\drivers\bthport.sys
    2008-07-01 22:34 . 2008-04-28 23:54 181,760 --a------ C:\WINDOWS\System32\fsquirt.exe
    2008-07-01 22:34 . 2008-05-09 21:33 113,664 --a------ C:\WINDOWS\System32\drivers\rmcast.sys
    2008-07-01 22:34 . 2008-04-28 21:42 29,184 --a------ C:\WINDOWS\System32\drivers\BTHUSB.SYS

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2008-07-08 00:22 --------- d-----w C:\Program Files\Java
    2008-07-03 07:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-07-02 12:54 --------- d-----w C:\ProgramData\Symantec
    2008-07-02 05:07 --------- d-----w C:\ProgramData\Hewlett-Packard
    2008-07-02 05:06 --------- d-----w C:\ProgramData\NVIDIA
    2008-07-02 04:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-02 04:52 --------- d-----w C:\Program Files\HPQ
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Templates
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Start Menu
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Favorites
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Documents
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Desktop
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Application Data
    2008-07-02 04:25 --------- d-----w C:\Program Files\Windows Mail
    2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 22:23 1233920]
    "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 20:36 455968]
    "HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 19:10 1783136]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [2008-07-06 09:52 171448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-19 16:05 86016]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-19 16:05 8497696]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-09-19 16:05 81920]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 07:31 1033512]
    "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-12-19 22:27 468264]
    "hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 19:31 80896]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 06:06 40048]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 19:24 54840]
    "hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 11:47 480560]
    "WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 18:53 311296]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-09-05 16:09:54 727592]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.l3codecp"= l3codecp.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
    "{9EF89A66-9698-4353-959C-C3313B2EC120}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{2FFE2449-05F4-431E-B5AA-DAF630828DF1}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{3AF4F8A4-CCDD-4A39-A1FC-977548871D41}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{16AA263D-9033-4D93-95CA-B8B3A1529993}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{F55BC89E-745A-4208-88C6-B6558614481F}"= C:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{05D3FAA0-F2DC-432F-AA2B-6F565814D674}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{FCE21A2C-A02C-4786-A723-919B1FD4DB2F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{EBD79006-D140-4DD3-8BA5-44078780CFEE}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{0429329E-0464-4D91-A359-809821A0E16F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{B576D741-6854-4188-9EEF-727EC31E27C1}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{77403D5F-6275-4BF9-850C-91F062BD4BCB}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{DBD1141F-3B22-4815-8604-32555D2B83D3}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
    "{AD408F5D-380C-4279-957B-FB0848ECC62C}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R2 QPCapSvc;QuickPlay Background Capture Service (QBCS);C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-12-19 22:28]
    R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-09-18 09:12]
    R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-09-18 09:12]
    R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwr chid.sys [2007-09-18 09:12]
    R3 HpqRemHid;HP Remote Control HID Device;C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 13:30]
    S2 QPSched;QuickPlay Task Scheduler (QTS);C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-12-19 22:28]
    S3 GameConsoleService;GameConsoleService;C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-23 19:33]
    S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 22:23]
    S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.s ys [2008-01-20 22:23]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ

    *Newly Created Service* - CATCHME

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-07-02 04:26:56 C:\Windows\Tasks\HPCeeScheduleFordonkeytime.job"
    - C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
    "2008-07-08 13:34:13 C:\Windows\Tasks\User_Feed_Synchronization-{D0CFEF7F-FC55-4643-B035-FC0672FE176C}.job"
    - C:\Windows\system32\msfeedssync.exe
    .
    - - - - ORPHANS REMOVED - - - -

    ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)


    ************************************************** ************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-08 21:34:56
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************
    .
    Completion time: 2008-07-08 21:35:33
    ComboFix-quarantined-files.txt 2008-07-09 01:35:30

    Pre-Run: 106,048,204,800 bytes free
    Post-Run: 106,078,285,824 bytes free

    187 --- E O F --- 2008-07-07 03:06:36

  5. #5
    donkeytime is offline Newbie
    Neal,

    Since I followed your directions, I have had greatly improved performance on my computer and so far no about:blanks. I have been moving between websites for about 1/2 an hour. I have AVG and SuperAnti-Spyware running. Is this adequate? I had AVG running when I got this about:blank so I am concerned about getting another about:blank. All security settings are reset to default. I will wait to hear back from you on the log and I will let you know if problems surface in the meantime.

    I want to thank you for undoing the harm others seek to create, and I wil send a donation once we know this is resolved.

    Many thanks for your being the Good Guy.

    D.

  6. #6
    donkeytime is offline Newbie
    premature joy----

    It is back. I know the program you had me run(bleepingcomputer) made a difference because between last night and today I had greatly increased performance and a few problems with connecting, which I attributed to the firewalls. However, either windows or AVG firewall has been on the entire time.

    After the program was run, I immediately upgraded AVG and Super-Anti-Spyware and it showed zero problems. I started having problems connecting to google. I placed the https://www.google.com and Google in my trusted sites. Otherwise, everything is updated and on: the firewall AVG, AVG, Anti-Spyware.

    I just got the about:blank flash again.

    Now what?

  7. #7
    Neal is offline Dedicated Member
    Down load About:Buster

    From: HERE

    Important steps to getting this tool to work properly:

    First unzip all files from the zip folder to a folder or your desktop. Start it and hit ok. Then hit update. A new screen should popup. On that screen hit Check for Updates. If it says it found an update hit Download Updates. If it doesnt it will automatically tell you and exit. Now for the scanning part. Hit start and then Ok. The program should start scanning. Then hit exit and reboot.

    Once rebooted run About:Buster once more to make sure everything is ok.



    How are things now?

  8. #8
    donkeytime is offline Newbie
    Hi Neal,

    I started having so many problems again that I redid the scan on bleepingcomputers to send to you. I was unable to get Exployer or Foxfire to allow me to open the aboutbuster. I got messages saying it was an unsafe site and their was no certificate and I could not bypass it. I tried putting it in the "allow" in exployer and that didn't help either. I tried turning off the firewalls for a moment. That didn't work either.

    My AVG says everything is fine. The superantispyware scanner removed 3 spyware. I keep getting the about:blank, which takes over my url and eventually freezes all.

    When I try to go to google on Exployer, it tells me it is an unsafe site. Am I being redirected and I can not "see" it?

    Here it is:

    ComboFix 08-07-08.1 - donkeytime 2008-07-09 20:49:24.2 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1578 [GMT -4:00]
    Running from: C:\Users\donkeytime\Downloads\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
    .

    No new files created in this timespan

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2008-07-10 00:12 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-07-09 13:55 --------- d-----w C:\Program Files\Windows Mail
    2008-07-09 04:10 12,936 ----a-w C:\Windows\system32\drivers\avgrkx86.sys
    2008-07-09 04:10 10,520 ----a-w C:\Windows\System32\avgrsstx.dll
    2008-07-09 04:09 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys
    2008-07-09 04:09 69,128 ----a-w C:\Windows\system32\drivers\avgwfpx.sys
    2008-07-09 04:09 --------- d-----w C:\ProgramData\avg8
    2008-07-09 03:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-07-09 01:42 136 ----a-w C:\Users\donkeytime\AppData\Roaming\wklnhst.dat
    2008-07-09 01:40 --------- d-----w C:\Users\donkeytime\AppData\Roaming\Template
    2008-07-08 00:22 --------- d-----w C:\Program Files\Java
    2008-07-07 13:40 3,646 ----a-w C:\Windows\System32\ealregsnapshot1.reg
    2008-07-06 17:24 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
    2008-07-06 17:23 --------- d-----w C:\Users\donkeytime\AppData\Roaming\SUPERAntiSpywa re.com
    2008-07-06 17:23 --------- d-----w C:\Program Files\SUPERAntiSpyware
    2008-07-06 16:35 --------- d-----w C:\Program Files\Google
    2008-07-06 14:49 --------- d-----w C:\Users\donkeytime\AppData\Roaming\Yahoo!
    2008-07-06 14:49 --------- d-----w C:\ProgramData\Yahoo! Companion
    2008-07-03 15:45 --------- d-----w C:\Users\donkeytime\AppData\Roaming\CyberLink
    2008-07-03 07:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-07-03 07:01 --------- d-----w C:\Program Files\MSXML 4.0
    2008-07-03 03:13 27,810 ----a-w C:\Users\donkeytime\AppData\Roaming\nvModes.dat
    2008-07-02 12:54 --------- d-----w C:\ProgramData\Symantec
    2008-07-02 05:07 --------- d-----w C:\Users\donkeytime\AppData\Roaming\Hewlett-Packard
    2008-07-02 05:07 --------- d-----w C:\ProgramData\Hewlett-Packard
    2008-07-02 05:06 --------- d-----w C:\Users\donkeytime\AppData\Roaming\Symantec
    2008-07-02 05:06 --------- d-----w C:\ProgramData\NVIDIA
    2008-07-02 04:59 --------- d-----w C:\Program Files\Yahoo!
    2008-07-02 04:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-02 04:58 --------- d-----w C:\ProgramData\Electronic Arts
    2008-07-02 04:58 --------- d-----w C:\Program Files\Electronic Arts
    2008-07-02 04:52 0 --sha-r C:\Windows\system32\drivers\103C_HP_cNB_Pavilion dv6700 Notebook PC_Y5335KV_0U_QCNF81228BK_E480576-002_4A_I30CF_SQuanta_V85.24_F.2A_T080222_WV3-1_L409_M3007_J160_7AMD_8F82_92.00_#080701_N10DE054 C;168C001C_(KN828UA#ABA)_XMOBILE_CN10_Z.MRK
    2008-07-02 04:52 --------- d-----w C:\Program Files\HPQ
    2008-07-02 04:52 --------- d-----w C:\Program Files\Common Files\LightScribe
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Templates
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Start Menu
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Favorites
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Documents
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Desktop
    2008-07-02 04:47 --------- d-sh--w C:\ProgramData\Application Data
    2008-07-02 04:18 --------- d-----w C:\Program Files\AVG
    2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
    2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
    2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
    2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
    2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
    2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
    2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
    2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
    2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
    2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
    2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
    2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe
    2008-04-26 08:25 3,600,952 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-04-26 08:25 3,549,240 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
    2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
    2008-04-23 04:42 428,544 ----a-w C:\Windows\System32\EncDec.dll
    2008-04-23 04:42 293,376 ----a-w C:\Windows\System32\psisdecd.dll
    2008-04-12 03:32 784,896 ----a-w C:\Windows\System32\rpcrt4.dll
    2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
    .

    ((((((((((((((((((((((((((((( snapshot@2008-07-08_21.35.23.82 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-07-09 00:55:06 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-07-09 23:20:03 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-03-04 19:04:30 580,848 ----a-w C:\Windows\Downloaded Program Files\sabminf.dll
    + 2008-07-10 00:49:14 6,209,536 ----a-w C:\Windows\erdnt\Hiv-backup\schema.dat
    + 2008-07-10 00:13:09 295,606 ----a-r C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
    + 2008-07-09 03:25:27 34,304 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF1.exe
    - 2008-07-09 00:53:54 169,640 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\FontCache3.0.0.0.dat
    + 2008-07-09 13:55:37 169,640 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\FontCache3.0.0.0.dat
    - 2008-07-09 00:55:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive0.dat
    + 2008-07-09 13:57:07 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive0.dat
    - 2008-07-09 00:55:06 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive1.dat
    + 2008-07-09 13:57:07 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive1.dat
    - 2008-07-09 01:18:09 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\History\History.IE5\index.da t
    + 2008-07-09 14:00:18 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\History\History.IE5\index.da t
    - 2008-07-09 01:18:09 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-07-09 14:00:18 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-07-09 01:18:09 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Ro aming\Microsoft\Windows\Cookies\index.dat
    + 2008-07-09 14:00:18 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Ro aming\Microsoft\Windows\Cookies\index.dat
    - 2008-07-09 01:18:14 204,800 ----a-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-07-09 13:57:47 204,800 ----a-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    - 2008-07-09 00:55:49 208,896 ----a-w C:\Windows\ServiceProfiles\NetworkService\ntuser.d at
    + 2008-07-09 13:57:52 208,896 ----a-w C:\Windows\ServiceProfiles\NetworkService\ntuser.d at
    - 2008-07-09 00:55:07 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\History\History.IE5\index.d at
    + 2008-07-09 13:57:13 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\History\History.IE5\index.d at
    - 2008-07-09 00:55:07 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-07-09 13:57:13 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-07-09 00:55:07 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\R oaming\Microsoft\Windows\Cookies\index.dat
    + 2008-07-09 13:57:13 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\R oaming\Microsoft\Windows\Cookies\index.dat
    + 2008-07-09 04:09:54 26,824 ----a-w C:\Windows\System32\drivers\avgmfx86.sys
    - 2008-01-21 02:24:13 72,192 ----a-w C:\Windows\System32\drivers\pacer.sys
    + 2008-04-05 0142 72,192 ----a-w C:\Windows\System32\drivers\pacer.sys
    - 2008-01-21 02:25:03 891,448 ----a-w C:\Windows\System32\drivers\tcpip.sys
    + 2008-04-26 08:26:49 891,448 ----a-w C:\Windows\System32\drivers\tcpip.sys
    - 2008-01-21 02:24:59 512,000 ----a-w C:\Windows\System32\jscript.dll
    + 2008-05-08 21:59:28 512,000 ----a-w C:\Windows\System32\jscript.dll
    - 2008-05-29 20:35:12 17,486,968 ----a-w C:\Windows\System32\mrt.exe
    + 2008-06-25 16:15:46 17,972,344 ----a-w C:\Windows\System32\mrt.exe
    - 2006-11-02 09:46:12 15,360 ----a-w C:\Windows\System32\pacerprf.dll
    + 2008-04-05 03:34:31 15,360 ----a-w C:\Windows\System32\pacerprf.dll
    - 2008-07-09 01:01:03 101,350 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-07-09 15:43:40 101,350 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-07-09 01:01:03 595,684 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-07-09 15:43:40 595,684 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-01-21 02:23:46 11,580,416 ----a-w C:\Windows\System32\shell32.dll
    + 2008-04-24 04:58:20 11,580,416 ----a-w C:\Windows\System32\shell32.dll
    - 2008-07-09 00:54:06 5,615,616 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
    + 2008-07-09 14:07:42 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
    - 2008-07-09 00:58:16 3,246 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2827589795-4099359866-16255571-1000_UserData.bin
    + 2008-07-09 13:59:18 3,528 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2827589795-4099359866-16255571-1000_UserData.bin
    - 2008-07-09 00:58:16 74,608 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics _SystemData.bin
    + 2008-07-09 13:59:18 75,400 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics _SystemData.bin
    - 2008-07-09 00:58:14 37,544 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnos tics_SystemData.bin
    + 2008-07-09 13:59:16 38,392 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnos tics_SystemData.bin
    - 2008-07-08 23:44:16 228,872 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnost ics_SystemData_S3.bin
    + 2008-07-09 23:20:04 234,978 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnost ics_SystemData_S3.bin
    - 2008-07-08 23:50:13 21,884,743 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001 c50b5_blobs.bin
    + 2008-07-10 00:11:40 22,438,271 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001 c50b5_blobs.bin
    + 2008-05-10 03:35:15 564,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.1 8069_none_9e540f60f6e2ecf1\emdmgmt.dll
    + 2008-05-10 03:17:36 564,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.2 2176_none_9ecfdb62100b5ca7\emdmgmt.dll
    + 2008-06-26 03:22:33 797,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NaturalLanguage6.dll
    + 2008-06-26 03:22:33 1,523,200 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0000.dll
    + 2008-06-26 03:22:33 2,597,888 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0001.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0002.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0003.dll
    + 2008-06-26 03:22:33 2,241,024 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0007.dll
    + 2008-06-26 03:22:33 4,874,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0009.dll
    + 2008-06-26 03:22:33 9,845,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData000a.dll
    + 2008-06-26 03:22:33 2,641,408 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData000c.dll
    + 2008-06-26 03:22:33 2,340,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData000d.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData000f.dll
    + 2008-06-26 03:22:33 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0010.dll
    + 2008-06-26 03:22:33 2,655,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0011.dll
    + 2008-06-26 03:22:33 3,464,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0013.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0018.dll
    + 2008-06-26 03:22:33 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0019.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData001a.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData001b.dll
    + 2008-06-26 03:22:33 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData001d.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0020.dll
    + 2008-06-26 03:22:33 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0021.dll
    + 2008-06-26 03:22:33 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0022.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0024.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0026.dll
    + 2008-06-26 03:22:33 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0027.dll
    + 2008-06-26 03:22:33 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData002a.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0039.dll
    + 2008-06-26 03:22:33 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData003e.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0045.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0046.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0047.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0049.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData004a.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData004b.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData004c.dll
    + 2008-06-26 03:22:33 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData004e.dll
    + 2008-06-26 03:22:33 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0414.dll
    + 2008-06-26 03:22:33 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0416.dll
    + 2008-06-26 03:22:33 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0816.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData081a.dll
    + 2008-06-26 03:22:33 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsData0c1a.dll
    + 2008-06-26 00:33:04 11,722,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0001.dll
    + 2008-06-26 00:34:20 4,164,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0002.dll
    + 2008-06-26 00:33:41 1,452,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0003.dll
    + 2008-06-26 00:33:35 12,240,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0007.dll
    + 2008-06-26 00:33:33 2,644,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0009.dll
    + 2008-06-26 00:33:39 9,892,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons000a.dll
    + 2008-06-26 00:33:34 6,237,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons000c.dll
    + 2008-06-26 00:33:36 1,722,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons000d.dll
    + 2008-06-26 00:33:48 5,654,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons000f.dll
    + 2008-06-26 00:33:49 4,175,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0010.dll
    + 2008-06-26 00:33:37 2,466,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0011.dll
    + 2008-06-26 00:33:12 4,981,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0013.dll
    + 2008-06-26 00:34:01 3,331,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0018.dll
    + 2008-06-26 00:34:03 6,781,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0019.dll
    + 2008-06-26 00:33:43 6,014,976 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons001a.dll
    + 2008-06-26 00:34:37 6,585,856 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons001b.dll
    + 2008-06-26 00:34:14 6,346,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons001d.dll
    + 2008-06-26 00:34:34 1,236,992 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0020.dll
    + 2008-06-26 00:33:40 2,136,064 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0021.dll
    + 2008-06-26 00:34:33 5,499,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0022.dll
    + 2008-06-26 00:34:39 7,964,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0024.dll
    + 2008-06-26 00:34:30 5,791,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0026.dll
    + 2008-06-26 00:33:50 6,224,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0027.dll
    + 2008-06-26 00:34:26 4,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons002a.dll
    + 2008-06-26 00:33:46 1,782,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0039.dll
    + 2008-06-26 00:33:52 4,045,824 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons003e.dll
    + 2008-06-26 00:34:18 1,793,536 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0045.dll
    + 2008-06-26 00:33:58 1,808,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0046.dll
    + 2008-06-26 00:33:45 1,411,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0047.dll
    + 2008-06-26 00:34:24 1,558,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0049.dll
    + 2008-06-26 00:34:25 3,419,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons004a.dll
    + 2008-06-26 00:34:22 1,702,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons004b.dll
    + 2008-06-26 00:34:36 4,093,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons004c.dll
    + 2008-06-26 00:34:23 1,972,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons004e.dll
    + 2008-06-26 00:33:54 4,616,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0414.dll
    + 2008-06-26 00:33:57 5,090,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0416.dll
    + 2008-06-26 00:33:56 5,031,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0816.dll
    + 2008-06-26 00:34:11 7,042,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons081a.dll
    + 2008-06-26 00:34:09 6,917,120 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsLexicons0c1a.dll
    + 2008-06-26 00:33:01 5,071,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.16710_n one_9be9c78e2d9d5d54\NlsModels0011.dll
    + 2008-06-26 03:18:12 797,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NaturalLanguage6.dll
    + 2008-06-26 03:18:18 1,523,200 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0000.dll
    + 2008-06-26 03:18:19 2,597,888 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0001.dll
    + 2008-06-26 03:18:20 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0002.dll
    + 2008-06-26 03:18:21 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0003.dll
    + 2008-06-26 03:18:21 2,241,024 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0007.dll
    + 2008-06-26 03:18:22 4,874,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0009.dll
    + 2008-06-26 03:18:24 9,845,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData000a.dll
    + 2008-06-26 03:18:24 2,641,408 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData000c.dll
    + 2008-06-26 03:18:26 2,340,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData000d.dll
    + 2008-06-26 03:18:26 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData000f.dll
    + 2008-06-26 03:18:30 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0010.dll
    + 2008-06-26 03:18:32 2,655,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0011.dll
    + 2008-06-26 03:18:33 3,464,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0013.dll
    + 2008-06-26 03:18:34 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0018.dll
    + 2008-06-26 03:18:38 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0019.dll
    + 2008-06-26 03:18:38 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData001a.dll
    + 2008-06-26 03:18:40 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData001b.dll
    + 2008-06-26 03:18:42 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData001d.dll
    + 2008-06-26 03:18:43 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0020.dll
    + 2008-06-26 03:18:44 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0021.dll
    + 2008-06-26 03:18:44 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0022.dll
    + 2008-06-26 03:18:44 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0024.dll
    + 2008-06-26 03:18:45 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0026.dll
    + 2008-06-26 03:18:45 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0027.dll
    + 2008-06-26 03:18:46 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData002a.dll
    + 2008-06-26 03:18:46 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0039.dll
    + 2008-06-26 03:18:47 1,799,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData003e.dll
    + 2008-06-26 03:18:49 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0045.dll
    + 2008-06-26 03:18:51 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0046.dll
    + 2008-06-26 03:18:52 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0047.dll
    + 2008-06-26 03:18:53 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0049.dll
    + 2008-06-26 03:18:54 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData004a.dll
    + 2008-06-26 03:18:54 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData004b.dll
    + 2008-06-26 03:18:57 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData004c.dll
    + 2008-06-26 03:18:58 3,102,720 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData004e.dll
    + 2008-06-26 03:19:00 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0414.dll
    + 2008-06-26 03:19:01 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0416.dll
    + 2008-06-26 03:19:04 4,493,312 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0816.dll
    + 2008-06-26 03:19:04 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData081a.dll
    + 2008-06-26 03:19:05 1,963,520 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsData0c1a.dll
    + 2008-06-26 00:30:04 11,722,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0001.dll
    + 2008-06-26 00:31:26 4,164,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0002.dll
    + 2008-06-26 00:30:49 1,452,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0003.dll
    + 2008-06-26 00:30:39 12,240,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0007.dll
    + 2008-06-26 00:30:36 2,644,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0009.dll
    + 2008-06-26 00:30:47 9,892,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons000a.dll
    + 2008-06-26 00:30:37 6,237,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons000c.dll
    + 2008-06-26 00:30:43 1,722,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons000d.dll
    + 2008-06-26 00:30:54 5,654,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons000f.dll
    + 2008-06-26 00:30:55 4,175,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0010.dll
    + 2008-06-26 00:30:45 2,466,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0011.dll
    + 2008-06-26 00:30:11 4,981,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0013.dll
    + 2008-06-26 00:31:06 3,331,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0018.dll
    + 2008-06-26 00:31:09 6,781,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0019.dll
    + 2008-06-26 00:30:50 6,014,976 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons001a.dll
    + 2008-06-26 00:31:46 6,585,856 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons001b.dll
    + 2008-06-26 00:31:23 6,346,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons001d.dll
    + 2008-06-26 00:31:44 1,236,992 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0020.dll
    + 2008-06-26 00:30:48 2,136,064 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0021.dll
    + 2008-06-26 00:31:40 5,499,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0022.dll
    + 2008-06-26 00:31:48 7,964,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0024.dll
    + 2008-06-26 00:31:35 5,791,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0026.dll
    + 2008-06-26 00:30:57 6,224,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0027.dll
    + 2008-06-26 00:31:34 4,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons002a.dll
    + 2008-06-26 00:30:53 1,782,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0039.dll
    + 2008-06-26 00:30:59 4,045,824 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons003e.dll
    + 2008-06-26 00:31:25 1,793,536 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0045.dll
    + 2008-06-26 00:31:04 1,808,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0046.dll
    + 2008-06-26 00:30:52 1,411,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0047.dll
    + 2008-06-26 00:31:32 1,558,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0049.dll
    + 2008-06-26 00:31:33 3,419,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons004a.dll
    + 2008-06-26 00:31:29 1,702,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons004b.dll
    + 2008-06-26 00:31:45 4,093,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons004c.dll
    + 2008-06-26 00:31:30 1,972,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons004e.dll
    + 2008-06-26 00:31:00 4,616,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0414.dll
    + 2008-06-26 00:31:03 5,090,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0416.dll
    + 2008-06-26 00:31:02 5,031,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0816.dll
    + 2008-06-26 00:31:22 7,042,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons081a.dll
    + 2008-06-26 00:31:16 6,917,120 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsLexicons0c1a.dll
    + 2008-06-26 00:30:01 5,071,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6000.20867_n one_9c4456c346dd3a34\NlsModels0011.dll
    + 2008-06-26 03:29:06 801,280 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NaturalLanguage6.dll
    + 2008-01-21 02:23:58 1,523,712 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0000.dll
    + 2008-01-21 02:23:58 2,599,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0001.dll
    + 2008-01-21 02:23:57 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0002.dll
    + 2008-01-21 02:23:57 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0003.dll
    + 2008-01-21 02:23:57 2,243,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0007.dll
    + 2008-01-21 02:23:57 4,875,776 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0009.dll
    + 2008-01-21 02:23:56 9,847,296 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData000a.dll
    + 2008-01-21 02:23:56 2,643,456 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData000c.dll
    + 2008-01-21 02:23:55 2,342,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData000d.dll
    + 2008-01-21 02:23:55 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData000f.dll
    + 2008-01-21 02:23:59 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0010.dll
    + 2008-01-21 02:23:58 2,657,280 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0011.dll
    + 2008-01-21 02:23:58 3,466,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0013.dll
    + 2008-01-21 02:23:58 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0018.dll
    + 2008-01-21 02:23:58 4,497,408 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0019.dll
    + 2008-01-21 02:23:56 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData001a.dll
    + 2008-01-21 02:23:56 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData001b.dll
    + 2008-01-21 02:23:56 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData001d.dll
    + 2008-01-21 02:24:00 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0020.dll
    + 2008-01-21 02:24:00 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0021.dll
    + 2008-01-21 02:24:00 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0022.dll
    + 2008-01-21 02:24:00 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0024.dll
    + 2008-01-21 02:24:00 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0026.dll
    + 2008-01-21 02:24:00 1,966,592 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0027.dll
    + 2008-01-21 02:23:56 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData002a.dll
    + 2008-01-21 02:24:01 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0039.dll
    + 2008-01-21 02:23:56 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData003e.dll
    + 2008-01-21 02:24:01 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0045.dll
    + 2008-01-21 02:24:01 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0046.dll
    + 2008-01-21 02:24:01 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0047.dll
    + 2008-01-21 02:24:01 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0049.dll
    + 2008-01-21 02:23:57 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData004a.dll
    + 2008-01-21 02:23:57 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData004b.dll
    + 2008-01-21 02:23:57 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData004c.dll
    + 2008-01-21 02:23:57 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData004e.dll
    + 2008-01-21 02:23:55 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0414.dll
    + 2008-01-21 02:23:55 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0416.dll
    + 2008-01-21 02:23:55 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0816.dll
    + 2008-01-21 02:23:55 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData081a.dll
    + 2008-01-21 02:23:55 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsData0c1a.dll
    + 2006-11-02 0855 11,722,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0001.dll
    + 2006-11-02 08:22:34 4,164,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0002.dll
    + 2006-11-02 08:22:13 1,452,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0003.dll
    + 2008-06-26 01:45:43 12,240,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0007.dll
    + 2008-06-26 01:45:55 2,644,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0009.dll
    + 2006-11-02 08:22:11 9,892,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons000a.dll
    + 2006-11-02 08:22:06 6,237,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons000c.dll
    + 2006-11-02 08:22:09 1,722,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons000d.dll
    + 2006-11-02 08:22:17 5,654,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons000f.dll
    + 2006-11-02 08:22:18 4,175,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0010.dll
    + 2006-11-02 08:22:10 2,466,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0011.dll
    + 2006-11-02 0858 4,981,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0013.dll
    + 2006-11-02 08:22:25 3,331,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0018.dll
    + 2006-11-02 08:22:26 6,781,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0019.dll
    + 2006-11-02 08:22:14 6,014,976 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons001a.dll
    + 2006-11-02 08:22:47 6,585,856 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons001b.dll
    + 2006-11-02 08:22:31 6,346,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons001d.dll
    + 2006-11-02 08:22:45 1,236,992 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0020.dll
    + 2006-11-02 08:22:12 2,136,064 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0021.dll
    + 2006-11-02 08:22:44 5,499,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0022.dll
    + 2006-11-02 08:22:49 7,964,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0024.dll
    + 2006-11-02 08:22:42 5,791,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0026.dll
    + 2006-11-02 08:22:19 6,224,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0027.dll
    + 2006-11-02 08:22:41 4,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons002a.dll
    + 2006-11-02 08:22:16 1,782,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0039.dll
    + 2006-11-02 08:22:20 4,045,824 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons003e.dll
    + 2006-11-02 08:22:33 1,793,536 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0045.dll
    + 2006-11-02 08:22:25 1,808,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0046.dll
    + 2006-11-02 08:22:15 1,411,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0047.dll
    + 2006-11-02 08:22:39 1,558,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0049.dll
    + 2006-11-02 08:22:39 3,419,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons004a.dll
    + 2006-11-02 08:22:36 1,702,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons004b.dll
    + 2006-11-02 08:22:46 4,093,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons004c.dll
    + 2006-11-02 08:22:37 1,972,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons004e.dll
    + 2006-11-02 08:22:21 4,616,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0414.dll
    + 2006-11-02 08:22:24 5,090,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0416.dll
    + 2006-11-02 08:22:22 5,031,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0816.dll
    + 2006-11-02 08:22:29 7,042,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons081a.dll
    + 2006-11-02 08:22:27 6,917,120 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsLexicons0c1a.dll
    + 2006-11-02 0854 5,071,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.18098_n one_9d81873e2afd9b5e\NlsModels0011.dll
    + 2008-06-26 03:19:03 801,280 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NaturalLanguage6.dll
    + 2008-06-26 03:19:12 1,523,712 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0000.dll
    + 2008-06-26 03:19:16 2,599,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0001.dll
    + 2008-06-26 03:19:20 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0002.dll
    + 2008-06-26 03:19:22 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0003.dll
    + 2008-06-26 03:19:23 2,243,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0007.dll
    + 2008-06-26 03:19:24 4,875,776 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0009.dll
    + 2008-06-26 03:19:27 9,847,296 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData000a.dll
    + 2008-06-26 03:19:27 2,643,456 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData000c.dll
    + 2008-06-26 03:19:31 2,342,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData000d.dll
    + 2008-06-26 03:19:32 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData000f.dll
    + 2008-06-26 03:19:32 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0010.dll
    + 2008-06-26 03:19:32 2,657,280 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0011.dll
    + 2008-06-26 03:19:34 3,466,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0013.dll
    + 2008-06-26 03:19:35 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0018.dll
    + 2008-06-26 03:19:36 4,497,408 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0019.dll
    + 2008-06-26 03:19:37 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData001a.dll
    + 2008-06-26 03:19:38 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData001b.dll
    + 2008-06-26 03:19:40 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData001d.dll
    + 2008-06-26 03:19:41 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0020.dll
    + 2008-06-26 03:19:42 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0021.dll
    + 2008-06-26 03:19:43 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0022.dll
    + 2008-06-26 03:19:44 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0024.dll
    + 2008-06-26 03:19:44 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0026.dll
    + 2008-06-26 03:19:45 1,966,592 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0027.dll
    + 2008-06-26 03:19:46 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData002a.dll
    + 2008-06-26 03:19:48 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0039.dll
    + 2008-06-26 03:19:48 1,801,216 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData003e.dll
    + 2008-06-26 03:19:50 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0045.dll
    + 2008-06-26 03:19:51 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0046.dll
    + 2008-06-26 03:19:52 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0047.dll
    + 2008-06-26 03:19:54 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0049.dll
    + 2008-06-26 03:19:56 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData004a.dll
    + 2008-06-26 03:19:57 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData004b.dll
    + 2008-06-26 03:19:58 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData004c.dll
    + 2008-06-26 03:20:00 3,104,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData004e.dll
    + 2008-06-26 03:20:04 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0414.dll
    + 2008-06-26 03:20:05 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0416.dll
    + 2008-06-26 03:20:07 4,495,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0816.dll
    + 2008-06-26 03:20:08 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData081a.dll
    + 2008-06-26 03:20:09 1,965,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsData0c1a.dll
    + 2008-06-26 01:42:33 11,722,752 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0001.dll
    + 2008-06-26 01:42:55 4,164,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0002.dll
    + 2008-06-26 01:42:31 1,452,544 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0003.dll
    + 2008-06-26 01:42:38 12,240,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0007.dll
    + 2008-06-26 01:42:38 2,644,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0009.dll
    + 2008-06-26 01:42:38 9,892,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons000a.dll
    + 2008-06-26 01:42:31 6,237,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons000c.dll
    + 2008-06-26 01:42:27 1,722,368 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons000d.dll
    + 2008-06-26 01:42:40 5,654,528 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons000f.dll
    + 2008-06-26 01:42:38 4,175,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0010.dll
    + 2008-06-26 01:42:29 2,466,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0011.dll
    + 2008-06-26 01:42:27 4,981,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0013.dll
    + 2008-06-26 01:42:48 3,331,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0018.dll
    + 2008-06-26 01:42:54 6,781,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0019.dll
    + 2008-06-26 01:42:36 6,014,976 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons001a.dll
    + 2008-06-26 01:43:07 6,585,856 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons001b.dll
    + 2008-06-26 01:42:55 6,346,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons001d.dll
    + 2008-06-26 01:43:07 1,236,992 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0020.dll
    + 2008-06-26 01:42:31 2,136,064 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0021.dll
    + 2008-06-26 01:43:07 5,499,904 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0022.dll
    + 2008-06-26 01:43:14 7,964,672 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0024.dll
    + 2008-06-26 01:43:07 5,791,232 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0026.dll
    + 2008-06-26 01:42:41 6,224,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0027.dll
    + 2008-06-26 01:42:55 4,096 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons002a.dll
    + 2008-06-26 01:42:35 1,782,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0039.dll
    + 2008-06-26 01:42:41 4,045,824 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons003e.dll
    + 2008-06-26 01:42:51 1,793,536 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0045.dll
    + 2008-06-26 01:42:43 1,808,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0046.dll
    + 2008-06-26 01:42:33 1,411,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0047.dll
    + 2008-06-26 01:42:56 1,558,016 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0049.dll
    + 2008-06-26 01:42:58 3,419,136 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons004a.dll
    + 2008-06-26 01:42:53 1,702,912 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons004b.dll
    + 2008-06-26 01:43:07 4,093,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons004c.dll
    + 2008-06-26 01:42:56 1,972,736 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons004e.dll
    + 2008-06-26 01:42:43 4,616,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0414.dll
    + 2008-06-26 01:42:47 5,090,816 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0416.dll
    + 2008-06-26 01:42:44 5,031,936 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0816.dll
    + 2008-06-26 01:42:57 7,042,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons081a.dll
    + 2008-06-26 01:42:57 6,917,120 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsLexicons0c1a.dll
    + 2008-06-26 01:42:23 5,071,872 ----a-w C:\Windows\winsxs\x86_microsoft-windows-naturallanguage6_31bf3856ad364e35_6.0.6001.22211_n one_9e5aa34943e0a766\NlsModels0011.dll
    + 2008-05-28 03:27:17 223,288 ----a-w C:\Windows\winsxs\x86_microsoft-windows-netio-infrastructure_31bf3856ad364e35_6.0.6001.22188_non e_56d68c90cea4d169\netio.sys
    + 2008-05-28 03:17:25 328,704 ----a-w C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f 8fa443e22213\BFE.DLL
    + 2008-05-28 03:28:43 101,432 ----a-w C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f 8fa443e22213\FWPKCLNT.SYS
    + 2008-05-28 03:19:07 595,456 ----a-w C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f 8fa443e22213\FWPUCLNT.DLL
    + 2008-05-28 03:19:32 438,272 ----a-w C:\Windows\winsxs\x86_microsoft-windows-network-security_31bf3856ad364e35_6.0.6001.22188_none_cd5f 8fa443e22213\IKEEXT.DLL
    + 2008-06-09 22:40:17 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16699_none_f0498ecc6 e94a1be\OESpamFilter.dat
    + 2008-06-09 22:37:40 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20855_none_f0fa6c058 795698f\OESpamFilter.dat
    + 2008-06-11 00:28:21 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18088_none_f2399d146 bb3fd67\OESpamFilter.dat
    + 2008-06-09 22:36:23 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22200_none_f311b8d58 497f018\OESpamFilter.dat
    + 2008-04-26 08:25:53 3,600,952 ----a-w C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282 f6b4510613\ntkrnlpa.exe
    + 2008-04-26 08:25:54 3,549,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282 f6b4510613\ntoskrnl.exe
    + 2008-04-26 08:11:34 3,601,464 ----a-w C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020 e9cd6b0b39\ntkrnlpa.exe
    + 2008-04-26 08:11:33 3,549,240 ----a-w C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020 e9cd6b0b39\ntoskrnl.exe
    + 2008-04-05 0142 72,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c5 7bfa9b1\pacer.sys
    + 2008-04-05 03:34:31 15,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.18046_none_ae262a9c5 7bfa9b1\pacerprf.dll
    + 2008-04-05 01:20:52 72,192 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff6097 0e9e6b9\pacer.sys
    + 2008-04-05 03:20:42 15,360 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff6097 0e9e6b9\pacerprf.dll
    + 2008-04-05 0319 33,280 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff6097 0e9e6b9\traffic.dll
    + 2008-04-05 0339 13,824 ----a-w C:\Windows\winsxs\x86_microsoft-windows-qos_31bf3856ad364e35_6.0.6001.22151_none_ae9ff6097 0e9e6b9\wshqos.dll
    + 2008-04-12 03:32:11 784,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.18051_none_b3c58fc 5453bf46b\rpcrt4.dll
    + 2008-04-12 03:16:32 784,896 ----a-w C:\Windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.22156_none_b4542e0 25e5512e8\rpcrt4.dll
    + 2008-05-08 21:59:35 90,112 ----a-w C:\Windows\winsxs\x86_microsoft-windows-s..ing-shell-extension_31bf3856ad364e35_6.0.6001.18068_none_0a4 8f9ec246cf834\wshext.dll
    + 2008-05-08 05:22:33 90,112 ----a-w C:\Windows\winsxs\x86_microsoft-windows-s..ing-shell-extension_31bf3856ad364e35_6.0.6001.22175_none_0ac 4c5ed3d9567ea\wshext.dll
    + 2008-05-08 21:59:28 512,000 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.18068_none_82a70 b5ef74dc96b\jscript.dll
    + 2008-05-08 05:18:59 512,000 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_6.0.6001.22175_none_8322d 76010763921\jscript.dll
    + 2008-05-08 21:59:33 430,080 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_6.0.6001.18068_none_4821 26172e1075a7\vbscript.dll
    + 2008-05-08 05:22:13 430,080 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_6.0.6001.22175_none_489c f2184738e55d\vbscript.dll
    + 2008-05-08 21:58:40 135,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482 f75de008363d9\cscript.exe
    + 2008-05-08 21:59:32 180,224 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482 f75de008363d9\scrobj.dll
    + 2008-05-08 21:59:32 172,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482 f75de008363d9\scrrun.dll
    + 2008-05-08 21:59:26 155,648 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.18068_none_482 f75de008363d9\wscript.exe
    + 2008-05-08 03:12:11 135,168 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\cscript.exe
    + 2008-05-08 05:17:02 32,768 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\dispex.dll
    + 2008-05-08 0552 180,224 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\scrobj.dll
    + 2008-05-08 0552 172,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\scrrun.dll
    + 2008-05-08 03:12:11 155,648 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\wscript.exe
    + 2008-05-08 05:22:33 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-scripting_31bf3856ad364e35_6.0.6001.22175_none_48a b41df19abd38f\wshcon.dll
    + 2008-04-24 04:51:39 11,315,712 ----a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6000.16680_none_69ec6 cd815163c56\shell32.dll
    + 2008-04-24 04:40:28 11,319,808 ----a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6000.20822_none_6ab8e ba52e01644f\shell32.dll
    + 2008-04-24 04:58:20 11,580,416 ----a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.18062_none_6bea4 bea122ac813\shell32.dll
    + 2008-04-24 04:45:45 11,581,440 ----a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.22166_none_6c77e 9dd2b44cd39\shell32.dll
    + 2008-04-26 08:26:49 891,448 ----a-w C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e0 33a8669434a1\tcpip.sys
    + 2008-04-26 08:08:16 891,448 ----a-w C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36d d19b7fae39c7\tcpip.sys
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 22:23 1233920]
    "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 20:36 455968]
    "HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 19:10 1783136]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [2008-07-06 09:52 171448]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-19 16:05 86016]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-19 16:05 8497696]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-09-19 16:05 81920]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 07:31 1033512]
    "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-12-19 22:27 468264]
    "hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 19:31 80896]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 19:24 54840]
    "hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 11:47 480560]
    "WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 18:53 311296]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
    "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-09 00:09 1232152]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-09-05 16:09:54 727592]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.l3codecp"= l3codecp.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
    "{9EF89A66-9698-4353-959C-C3313B2EC120}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{2FFE2449-05F4-431E-B5AA-DAF630828DF1}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{3AF4F8A4-CCDD-4A39-A1FC-977548871D41}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{16AA263D-9033-4D93-95CA-B8B3A1529993}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{F55BC89E-745A-4208-88C6-B6558614481F}"= C:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{05D3FAA0-F2DC-432F-AA2B-6F565814D674}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{FCE21A2C-A02C-4786-A723-919B1FD4DB2F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{EBD79006-D140-4DD3-8BA5-44078780CFEE}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{0429329E-0464-4D91-A359-809821A0E16F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{B576D741-6854-4188-9EEF-727EC31E27C1}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{77403D5F-6275-4BF9-850C-91F062BD4BCB}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{DBD1141F-3B22-4815-8604-32555D2B83D3}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
    "{AD408F5D-380C-4279-957B-FB0848ECC62C}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
    "{28E3C68A-F93B-4267-98F9-C80D73F5C03C}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
    "{857EE887-F8CC-4911-AAC6-57D276EB5EC4}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
    "{15EDE148-7BC6-4D02-8259-BFD3F3718630}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\PublicProfile]
    "EnableFirewall"= 0 (0x0)
    "DoNotAllowExceptions"= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\ avgrkx86.sys [2008-07-09 00:10]
    R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-07-09 00:09]
    R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-09 00:09]
    R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-09 00:09]
    R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-07-09 00:09]
    R2 QPCapSvc;QuickPlay Background Capture Service (QBCS);C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-12-19 22:28]
    R2 QPSched;QuickPlay Task Scheduler (QTS);C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-12-19 22:28]
    R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-07-09 00:09]
    R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-09-18 09:12]
    R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-09-18 09:12]
    R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwr chid.sys [2007-09-18 09:12]
    R3 HpqRemHid;HP Remote Control HID Device;C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 13:30]
    S3 GameConsoleService;GameConsoleService;C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-23 19:33]
    S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 22:23]
    S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.s ys [2008-01-20 22:23]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-07-02 04:26:56 C:\Windows\Tasks\HPCeeScheduleFordonkeytime.job"
    - C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
    "2008-07-09 14:30:12 C:\Windows\Tasks\User_Feed_Synchronization-{D0CFEF7F-FC55-4643-B035-FC0672FE176C}.job"
    - C:\Windows\system32\msfeedssync.exe
    .
    ************************************************** ************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-09 20:51:27
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************
    .
    Completion time: 2008-07-09 20:52:14
    ComboFix-quarantined-files.txt 2008-07-10 00:52:09
    ComboFix2.txt 2008-07-09 01:35:34

    The system cannot find message text for message number 0x2379 in the message file for Application.
    Post-Run: 98,035,699,712 bytes free

    611 --- E O F --- 2008-07-09 04:03:29

  9. #9
    Neal is offline Dedicated Member
    Try running about:buster while in safe mode:


    Now reboot into safe mode( without networking support) by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.


    Then try about:buster twice from safe mode.


    If no go...


    Go to start >run and type: services.msc and click OK
    Scroll down in that list and look if the following services are present:

    Network Security Service (NSS)
    Remote Procedure Call (RPC) Helper
    Workstation NetLogon Service


    Please make sure it is exactly the same written as above.

  10. #10
    donkeytime is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    Hey Neal,

    *Network Security Service (NSS) Nothing remotely like that
    Remote Procedure Call (RPC) Helper ---Remote Procedure locater and Remote Procedure Call (RPC) without "helper" next to it. There is not Remote Procedure Call (RPC) Helper.
    Workstation NetLogon Service* Nothing remotely like that.

    I have a Vistas system.

    SUPERAntiSpyware says nothing there.

    Last night I downloaded Foxfire and so far I have not received about:blank here. I was having lots of problems on Exployer last night.

    I was able to download about:buster from geeks to the desktop but whether in safe mode or not, I get the message

    run-time error 339 component 'comct132.ocx' missing or invalid.

    I looked this up on my computer and it said that this is an external command.

    I will now try the about_:buster in safe mode and report back.

+ Reply to Thread
Page 1 of 3 1 2 3 LastLast