1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Trojan horse patched_c.lxt services.exe!! Plz Help.

Discussion in 'Virus & Other Malware Removal' started by lucasle146, Aug 30, 2012.

Thread Status:
Not open for further replies.
Advertisement
  1. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Hi,

    Today my AVG keep warn me that there is trojan horse patched_c.lxt in services,exe, I have tried many ways to remove it but it did not work well. Please help me with my situation.

    I really need your help,

    Thanks:(:(
     
  2. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Here is my DDS Scan:


    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
    Run by Lucas at 22:01:31 on 2012-08-30
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3959.1863 [GMT 3:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Launch Manager\dsiwmis.exe
    C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
    C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
    C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
    C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
    C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
    C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
    C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
    C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
    C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe
    C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Windows\System32\StikyNot.exe
    C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Users\Lucas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Program Files (x86)\Launch Manager\LManager.exe
    C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
    C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
    C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
    C:\Program Files (x86)\AVG Secure Search\vprot.exe
    C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
    C:\Program Files (x86)\Launch Manager\LMworker.exe
    C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingApp.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingBar.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Origin\Origin.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\msiexec.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    mWinlogon: Userinit=userinit.exe
    BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
    BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
    TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll"
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
    uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    uRun: [Google Update] "C:\Users\Lucas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [Spotify Web Helper] "C:\Users\Lucas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
    mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
    mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    mRun: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    mRun: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
    mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
    mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
    IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
    IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    LSP: mswsock.dll
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    TCP: DhcpNameServer = 193.210.19.19 192.168.252.17
    TCP: Interfaces\{07839156-7A26-41E4-BDB0-1CAD7BB795BC} : DhcpNameServer = 193.210.19.19 192.168.252.17
    TCP: Interfaces\{4D520CE4-CCD0-4DB4-B9EA-38FF25585AF8} : DhcpNameServer = 193.210.19.19 192.168.252.17
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
    BHO-X64: IDM Helper - No File
    BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    BHO-X64: 0x1 - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
    BHO-X64: AVG Do Not Track - No File
    BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
    BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
    TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll"
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
    mRun-x64: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    mRun-x64: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    mRun-x64: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
    mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
    mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    mRun-x64: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    Hosts: 207.44.199.159 registeridm.com
    Hosts: 205.199.44.16 registeridm.com
    Hosts: 205.199.44.156 registeridm.com
    Hosts: 205.199.44.156 registeridm.com
    Hosts: 207.44.199.16 registeridm.com
    .
    Note: multiple HOSTS entries found. Please refer to Attach.txt
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\
    FF - prefs.js: browser.startup.homepage - hxxp://isearch.avg.com?cid=%7Bb44ef5ce-53c8-45ea-9c28-b0d7ea8d83f8%7D&mid=32459530c18547d0a67db1a22fb4dca9-cf5db69f9f47e232c34ec0042c263703df43a613&ds=AVG&v=11.1.0.12&lang=en&pr=fr&d=2012-07-16%2022%3A53%3A21&sap=hp
    FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bb44ef5ce-53c8-45ea-9c28-b0d7ea8d83f8%7D&mid=32459530c18547d0a67db1a22fb4dca9-cf5db69f9f47e232c34ec0042c263703df43a613&ds=AVG&v=11.1.0.12&lang=en&pr=fr&d=2012-07-16%2022%3A53%3A21&sap=ku&q=
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
    FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
    FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Users\Lucas\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
    R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
    R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [?]
    R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [?]
    R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-7-4 5160568]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
    R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-9-6 321104]
    R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2012-7-17 868896]
    R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-9-6 13336]
    R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-2 2804568]
    R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-6-29 255744]
    R2 ODDPwrSvc;Acer ODD Power Service;C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [2010-9-6 171040]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-12-12 378472]
    R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-7-17 2533400]
    R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-9-6 243232]
    R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-16 935008]
    R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
    R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
    R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
    R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
    R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\system32\DRIVERS\nvstusb.sys --> C:\Windows\system32\DRIVERS\nvstusb.sys [?]
    R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-16 135664]
    S2 IDMWFP;IDMWFP;C:\Windows\system32\DRIVERS\idmwfp.sys --> C:\Windows\system32\DRIVERS\idmwfp.sys [?]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
    S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS --> C:\Windows\system32\drivers\AmUStor.SYS [?]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-16 135664]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-16 113120]
    S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-5-27 305520]
    S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
    S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2009-8-22 19952]
    S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2012-08-30 16:49:08 152576 ----a-w- C:\Users\Lucas\AppData\Roaming\scsol.dll
    2012-08-26 12:26:25 902656 ----a-w- C:\Windows\System32\d2d1.dll
    2012-08-26 12:26:25 1139200 ----a-w- C:\Windows\System32\FntCache.dll
    2012-08-26 12:26:24 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
    2012-08-26 11:02:02 73416 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-08-26 11:02:02 696520 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-08-23 06:28:05 -------- d-----r- C:\Program Files (x86)\Skype
    2012-08-21 16:42:31 -------- d-----w- C:\ProgramData\PopCap Games
    2012-08-21 16:42:31 -------- d-----w- C:\Program Files\PopCap Games
    2012-08-15 06:53:41 503808 ----a-w- C:\Windows\System32\srcore.dll
    2012-08-15 06:53:41 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
    2012-08-15 06:53:39 751104 ----a-w- C:\Windows\System32\win32spl.dll
    2012-08-15 06:53:38 67072 ----a-w- C:\Windows\splwow64.exe
    2012-08-15 06:53:38 59392 ----a-w- C:\Windows\System32\browcli.dll
    2012-08-15 06:53:38 559104 ----a-w- C:\Windows\System32\spoolsv.exe
    2012-08-15 06:53:38 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
    2012-08-15 06:53:38 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
    2012-08-15 06:53:38 136704 ----a-w- C:\Windows\System32\browser.dll
    2012-08-15 06:53:34 3148800 ----a-w- C:\Windows\System32\win32k.sys
    2012-08-15 06:53:33 956928 ----a-w- C:\Windows\System32\localspl.dll
    2012-08-14 21:10:32 -------- d-----w- C:\Users\Lucas\AppData\Roaming\YourFileDownloader
    2012-08-14 21:10:32 -------- d-----w- C:\Program Files (x86)\YourFileDownloader
    2012-08-14 21:08:54 -------- d-----w- C:\Users\Lucas\AppData\Roaming\IDM
    2012-08-06 21:54:36 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
    2012-08-06 21:54:01 -------- d-----w- C:\Program Files (x86)\Oracle
    2012-08-06 21:53:46 772544 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
    2012-08-06 21:53:46 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-08-05 06:32:53 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-08-04 16:17:36 -------- d-----w- C:\Users\Lucas\AppData\Local\visi_coupon
    .
    ==================== Find3M ====================
    .
    2012-07-19 01:06:00 794906 ----a-w- C:\Windows\unins000.exe
    2012-07-17 00:17:06 3 ----a-w- C:\Windows\System32\PLD_Framework.cmd
    2012-07-16 20:44:47 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
    2012-07-16 20:44:46 175616 ----a-w- C:\Windows\System32\msclmd.dll
    2012-07-16 19:31:26 99056 ----a-w- C:\Windows\System32\MfeOtlkAddin.dll
    2012-07-16 19:31:08 74848 ----a-w- C:\Windows\SysWow64\MfeOtlkAddin.dll
    2012-07-16 19:31:07 22816 ----a-w- C:\Windows\SysWow64\MFEOtlk.dll
    2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-06-11 18:17:46 71680 ----a-w- C:\Windows\System32\frapsv64.dll
    2012-06-11 18:17:42 65536 ----a-w- C:\Windows\SysWow64\frapsvid.dll
    2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
    2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
    2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
    2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
    2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
    2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
    2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
    2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
    2012-06-02 12:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
    2012-06-02 12:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
    2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
    2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
    2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
    2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
    2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
    2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
    2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
    2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    .
    ============= FINISH: 22:02:00.36 ===============
     
  3. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Here is my Hijackthis scan and Attach file:


    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:24:40 PM, on 8/30/2012
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16448)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
    C:\Users\Lucas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Program Files (x86)\Launch Manager\LManager.exe
    C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
    C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
    C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
    C:\Program Files (x86)\AVG Secure Search\vprot.exe
    C:\Program Files (x86)\Launch Manager\LMworker.exe
    C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingApp.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingBar.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingSurrogate.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Origin\Origin.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lucas\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5745dg&r=273607127126l0433z105v47n17302
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    F2 - REG:system.ini: UserInit=userinit.exe
    O1 - Hosts: 207.44.199.159 registeridm.com
    O1 - Hosts: 205.199.44.16 registeridm.com
    O1 - Hosts: 205.199.44.156 registeridm.com
    O1 - Hosts: 205.199.44.156 registeridm.com
    O1 - Hosts: 207.44.199.16 registeridm.com
    O1 - Hosts: 207.44.199.159 registeridm.com
    O1 - Hosts: 207.44.199.16 registeridm.com
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
    O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    O4 - HKLM\..\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
    O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    O4 - HKLM\..\Run: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Lucas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Lucas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
    O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: Acer ODD Power Service (ODDPwrSvc) - Acer Incorporated - C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of file - 17496 bytes
     

    Attached Files:

  4. jeffce

    jeffce Malware Specialist

    Joined:
    May 10, 2011
    Messages:
    1,727
    Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
    • The fixes are specific to your problem and should only be used for the issues on this machine.
    • It's often worth reading through these instructions and printing them for ease of reference.
    • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
    • Please reply to this thread. Do not start a new topic.
    • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
    IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
    DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


    Having said that....Let's get going!! :thumbup:
    ----------

    Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan but do nothing else as we are just looking for what is there.
    • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
    • Attach the log in your next reply
      • A copy of the log will be saved automatically to the root of the drive (typically C:\)
    ----------
     
  5. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Hi Jeff, thank you very much for your help, I really appreciate it! According to your instruction, in the attachment is my log result:eek:
     

    Attached Files:

  6. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Waiting for your reply Jeff :(
     
  7. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Up, please help :(
     
  8. jeffce

    jeffce Malware Specialist

    Joined:
    May 10, 2011
    Messages:
    1,727
    Hi,

    I understand your frustration with wanting your computer back and working properly (believe me I have been in your shoes), but please try and be patient with the timeframe for replies. :)
    ----------

    Download Combofix from the link below, and save it to your desktop.
    Link

    **Note: It is important that it is saved directly to your desktop**
    If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


    --------------------------------------------------------------------

    IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

    --------------------------------------------------------------------

    Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the C:\ComboFix.txt for further review.
    ----------
     
  9. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Hi Jeff, thanks for your reply. I have tried to run combofix 3 times, The process run well but I cant find the combofix.txt in my C drives. the only outcome of the process is the computer icon named "32788R22FWJFW" and when I click on that icon, it's bring me back to My Computer screen. What can I do now?
     
  10. jeffce

    jeffce Malware Specialist

    Joined:
    May 10, 2011
    Messages:
    1,727
    FRST

    Download Farbar Recovery Scan Tool64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
    ----------
     
  11. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    As your instruction, here is the result of the scan:

    Scan result of Farbar Recovery Scan Tool Version: 31-08-2012 01
    Ran by SYSTEM at 31-08-2012 15:51:42
    Running from H:\
    Windows 7 Home Premium (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ==================== Registry (Whitelisted) ===================

    HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2098792 2010-06-22] (Realtek Semiconductor)
    HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324608 2010-06-09] (Alcor Micro Corp.)
    HKLM\...\Run: [ODDPwr] "C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe" [223264 2010-04-22] (Acer Incorporated)
    HKLM\...\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
    HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2097960 2010-04-22] (Synaptics Incorporated)
    HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
    HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
    HKLM\...\Run: [scsol] rundll32.exe "C:\Users\Lucas\AppData\Roaming\scsol.dll",ReplaceCharsW [152576 2012-08-30] ()
    HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
    HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
    HKLM-x32\...\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
    HKLM-x32\...\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
    HKLM-x32\...\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
    HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k [265984 2010-06-28] (NewTech Infosystems, Inc.)
    HKLM-x32\...\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" [222504 2009-05-19] (CyberLink Corp.)
    HKLM-x32\...\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [124136 2010-08-26] (CyberLink Corp.)
    HKLM-x32\...\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2587008 2012-04-04] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1107552 2012-07-16] ()
    HKLM-x32\...\Run: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction [36960 2012-07-18] ()
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
    HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
    HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
    HKU\Lucas\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
    HKU\Lucas\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet [6595928 2012-05-24] (Yahoo! Inc.)
    HKU\Lucas\...\Run: [Google Update] "C:\Users\Lucas\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-16] (Google Inc.)
    HKU\Lucas\...\Run: [Spotify Web Helper] "C:\Users\Lucas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1193176 2012-07-22] ()
    HKU\Lucas\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-09-06] (Google Inc.)
    HKU\Lucas\...\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot [3491264 2012-08-14] (Tonec Inc.)
    Tcpip\Parameters: [DhcpNameServer] 193.210.19.19 192.168.252.17

    ==================== Services (Whitelisted) ======

    2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.)
    2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-13] (AVG Technologies CZ, s.r.o.)
    3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
    2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
    2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated)
    2 RichVideo; "C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe" [244904 2010-02-24] ()
    2 vToolbarUpdater11.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [935008 2012-07-16] ()

    ==================== Drivers (Whitelisted) ===================

    3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. )
    3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
    0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-18] (AVG Technologies CZ, s.r.o. )
    1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [289872 2012-02-21] (AVG Technologies CZ, s.r.o.)
    1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
    0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-30] (AVG Technologies CZ, s.r.o.)
    1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [383808 2012-03-18] (AVG Technologies CZ, s.r.o.)
    3 NvStUSB; C:\Windows\System32\Drivers\NvStUSB.sys [119912 2010-11-17] ()
    3 RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [19952 2012-07-18] ()
    2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13784 2009-11-02] ()

    ==================== NetSvcs (Whitelisted) =================


    ==================== One Month Created Files and Folders ======================

    2012-08-31 04:27 - 2012-08-31 04:27 - 01450731 ____A (Farbar) C:\Users\Lucas\Downloads\FRST64.exe
    2012-08-31 04:27 - 2012-08-31 04:27 - 01450731 ____A (Farbar) C:\Users\Lucas\Downloads\FRST64 (1).exe
    2012-08-30 21:10 - 2012-08-30 21:12 - 00000000 ___SD C:\32788R22FWJFW
    2012-08-30 21:10 - 2012-08-30 21:10 - 00000000 ____D C:\Windows\erdnt
    2012-08-30 21:09 - 2012-08-30 21:10 - 04741772 ____R (Swearware) C:\Users\Lucas\Desktop\ComboFix.exe
    2012-08-30 12:49 - 2012-08-24 02:28 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Lucas\Desktop\TDSSKiller.exe
    2012-08-30 12:49 - 2010-12-31 14:14 - 00002254 ___RA C:\Users\Lucas\Desktop\eula.txt
    2012-08-30 12:48 - 2012-08-30 12:48 - 02193184 ____A C:\Users\Lucas\Downloads\tdsskiller.zip
    2012-08-30 11:24 - 2012-08-30 11:24 - 00388608 ____A (Trend Micro Inc.) C:\Users\Lucas\Downloads\HijackThis.exe
    2012-08-30 11:24 - 2012-08-30 11:24 - 00017498 ____A C:\Users\Lucas\Downloads\hijackthis.log
    2012-08-30 11:24 - 2012-08-30 11:24 - 00017498 ____A C:\Users\Lucas\Desktop\hijackthis.log
    2012-08-30 11:04 - 2012-08-30 11:04 - 00010773 ____A C:\Users\Lucas\Desktop\Attach.zip
    2012-08-30 11:02 - 2012-08-30 11:02 - 00030766 ____A C:\Users\Lucas\Desktop\DDS.txt
    2012-08-30 11:02 - 2012-08-30 11:02 - 00007487 ____A C:\Users\Lucas\Desktop\Attach.txt
    2012-08-30 11:01 - 2012-08-30 11:01 - 00607260 ____R (Swearware) C:\Users\Lucas\Downloads\dds.com
    2012-08-30 10:43 - 2012-08-30 10:44 - 04165104 ____A (PC Tools) C:\Users\Lucas\Downloads\SDAV_Online_aff_GenericRevenueWire_207_2.exe
    2012-08-30 08:49 - 2012-08-30 08:49 - 00152576 ____A C:\Users\Lucas\AppData\Roaming\scsol.dll
    2012-08-30 08:49 - 2012-08-30 08:49 - 00000012 ____A C:\Windows\srun.log
    2012-08-26 04:26 - 2011-02-19 04:05 - 01139200 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
    2012-08-26 04:26 - 2011-02-19 04:04 - 00902656 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
    2012-08-26 04:26 - 2011-02-18 22:30 - 00739840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
    2012-08-26 03:02 - 2012-08-30 09:40 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-26 03:02 - 2012-08-30 09:40 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-22 22:28 - 2012-08-23 23:29 - 00000000 ____D C:\Users\Lucas\AppData\Roaming\Skype
    2012-08-22 22:28 - 2012-08-22 22:28 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
    2012-08-22 22:28 - 2012-08-22 22:28 - 00000000 ___RD C:\Program Files (x86)\Skype
    2012-08-22 22:23 - 2012-08-22 22:28 - 00000000 ____D C:\Users\All Users\Skype
    2012-08-22 01:16 - 2012-08-22 01:16 - 00001107 ____A C:\Users\Public\Desktop\Rocket Mania Deluxe.lnk
    2012-08-22 01:16 - 2012-08-22 01:16 - 00000194 ____A C:\Users\Public\Desktop\Play More Great Games!.url
    2012-08-21 08:47 - 2012-08-26 06:20 - 00000017 ____A C:\Windows\popcinfo.dat
    2012-08-21 08:42 - 2012-08-22 01:15 - 00000000 ____D C:\Users\All Users\PopCap Games
    2012-08-21 08:42 - 2012-08-22 01:15 - 00000000 ____D C:\Program Files\PopCap Games
    2012-08-16 11:44 - 2012-08-16 11:44 - 00751104 ____A C:\Users\Lucas\Downloads\ReferencingGuide.ppt
    2012-08-15 09:53 - 2012-06-28 20:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-08-15 09:53 - 2012-06-28 20:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-08-15 09:53 - 2012-06-28 19:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-08-15 09:53 - 2012-06-28 19:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-08-15 09:53 - 2012-06-28 19:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-08-15 09:53 - 2012-06-28 19:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-08-15 09:53 - 2012-06-28 19:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-08-15 09:53 - 2012-06-28 19:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-08-15 09:53 - 2012-06-28 19:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-08-15 09:53 - 2012-06-28 19:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-08-15 09:53 - 2012-06-28 19:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-08-15 09:53 - 2012-06-28 19:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-08-15 09:53 - 2012-06-28 19:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-08-15 09:53 - 2012-06-28 19:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-08-15 09:53 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-08-15 09:53 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-08-15 09:53 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-08-15 09:53 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-08-15 09:53 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-08-15 09:53 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-08-15 09:53 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-08-15 09:53 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-08-15 09:53 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-08-15 09:53 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-08-15 09:53 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-08-15 09:53 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-08-15 09:53 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-08-15 09:53 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-08-14 22:53 - 2012-07-18 10:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-08-14 22:53 - 2012-07-04 14:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-08-14 22:53 - 2012-07-04 14:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
    2012-08-14 22:53 - 2012-07-04 14:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
    2012-08-14 22:53 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2012-08-14 22:53 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2012-08-14 22:53 - 2012-05-13 21:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
    2012-08-14 22:53 - 2012-05-05 00:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
    2012-08-14 22:53 - 2012-05-04 23:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2012-08-14 22:53 - 2012-02-10 22:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
    2012-08-14 22:53 - 2012-02-10 22:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
    2012-08-14 22:53 - 2012-02-10 22:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
    2012-08-14 22:53 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2012-08-14 13:14 - 2012-08-14 13:14 - 00001250 ____A C:\Windows\serial
    2012-08-14 13:13 - 2012-08-14 13:13 - 05721803 ____A C:\Users\Lucas\Downloads\[congdongbaclieu.info] IDM 6.11 beta.rar
    2012-08-14 13:10 - 2012-08-15 06:44 - 00000000 ____D C:\Program Files (x86)\YourFileDownloader
    2012-08-14 13:10 - 2012-08-14 13:10 - 00000000 ____D C:\Users\Lucas\AppData\Roaming\YourFileDownloader
    2012-08-14 13:08 - 2012-08-17 12:53 - 00000000 ____D C:\Users\Lucas\AppData\Roaming\IDM
    2012-08-14 13:08 - 2012-08-14 13:08 - 04110768 ____A (http://yourfiledownloader.com) C:\Users\Lucas\Downloads\Internet_Download_Manager_6.11.8.2_key_Patch.rar_downloader_224.exe
    2012-08-14 13:02 - 2012-08-14 13:02 - 00027520 ____A C:\Users\Lucas\AppData\Local\dt.dat
    2012-08-13 13:21 - 2012-08-13 13:35 - 124621250 ____A C:\Users\Lucas\Downloads\breaking.bad.s05e04.480p.hdtv.x264-orenji.MP4
    2012-08-13 11:17 - 2012-08-13 11:17 - 00039051 ____A C:\Users\Lucas\Downloads\L5.1b_Thesis_template_word2007.dotx
    2012-08-12 12:38 - 2012-08-12 12:40 - 143912514 ____A C:\Users\Lucas\Downloads\breaking.bad.s05e03.hdtv.x264-fqm.MP4
    2012-08-06 13:54 - 2012-08-06 13:54 - 00000000 ____D C:\Windows\Sun
    2012-08-06 13:54 - 2012-08-06 13:54 - 00000000 ____D C:\Users\Lucas\AppData\Roaming\SystemRequirementsLab
    2012-08-06 13:54 - 2012-08-06 13:54 - 00000000 ____D C:\Users\All Users\Sun
    2012-08-06 13:54 - 2012-08-06 13:54 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
    2012-08-06 13:54 - 2012-08-06 13:54 - 00000000 ____D C:\Program Files (x86)\Oracle
    2012-08-06 13:53 - 2012-08-06 13:53 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-08-06 13:53 - 2012-08-06 13:53 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-08-06 13:53 - 2012-08-06 13:53 - 00000000 ____D C:\Program Files (x86)\Java
    2012-08-06 13:53 - 2012-07-05 11:06 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-08-06 13:53 - 2012-07-05 11:06 - 00687544 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-08-06 13:53 - 2012-07-05 11:06 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-08-06 13:52 - 2012-08-06 13:52 - 00893936 ____A (Oracle Corporation) C:\Users\Lucas\Downloads\jxpiinstall.exe
    2012-08-05 15:14 - 2012-08-05 15:25 - 200000000 ____A C:\Users\Lucas\Downloads\Hunger Game 2 - BadBoy199x.part1.rar
    2012-08-05 15:13 - 2012-08-05 15:20 - 40899486 ____A C:\Users\Lucas\Downloads\Hunger Game 2 - BadBoy199x.part2.rar
    2012-08-05 15:12 - 2012-08-05 15:24 - 200000000 ____A C:\Users\Lucas\Downloads\Hunger Game 1 - BadBoy199x.part1.rar
    2012-08-05 15:12 - 2012-08-05 15:20 - 32084174 ____A C:\Users\Lucas\Downloads\Hunger Game 1 - BadBoy199x.part2.rar
    2012-08-04 22:32 - 2012-08-04 22:32 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
    2012-08-04 08:17 - 2012-08-04 08:17 - 00000000 ____D C:\Users\Lucas\AppData\Local\visi_coupon
    2012-08-03 15:01 - 2012-08-03 15:09 - 148076057 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part3.rar
    2012-08-03 14:58 - 2012-08-03 15:10 - 204800000 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part2.rar
    2012-08-03 14:56 - 2012-08-03 15:00 - 204800000 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part1.rar
    2012-08-03 14:07 - 2012-08-03 14:22 - 256000000 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part2.rar
    2012-08-03 14:05 - 2012-08-03 14:15 - 256000000 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part1.rar
    2012-08-03 14:05 - 2012-08-03 14:06 - 18262156 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part3.rar
    2012-08-02 03:24 - 2012-08-02 03:24 - 00288897 ____A C:\Users\Lucas\Documents\Desk 1


    ==================== 3 Months Modified Files ================================

    2012-08-31 04:27 - 2012-08-31 04:27 - 01450731 ____A (Farbar) C:\Users\Lucas\Downloads\FRST64.exe
    2012-08-31 04:27 - 2012-08-31 04:27 - 01450731 ____A (Farbar) C:\Users\Lucas\Downloads\FRST64 (1).exe
    2012-08-31 04:16 - 2012-07-16 07:01 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2012-08-31 04:11 - 2012-07-16 07:00 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-173249258-721920281-3489915689-1000UA.job
    2012-08-31 04:01 - 2012-07-19 01:42 - 00374560 ____A C:\shared.log
    2012-08-30 21:13 - 2009-07-13 20:45 - 00018736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-30 21:13 - 2009-07-13 20:45 - 00018736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-30 21:10 - 2012-08-30 21:09 - 04741772 ____R (Swearware) C:\Users\Lucas\Desktop\ComboFix.exe
    2012-08-30 21:07 - 2012-07-16 07:01 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2012-08-30 21:07 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-30 21:07 - 2009-07-13 20:51 - 00044266 ____A C:\Windows\setupact.log
    2012-08-30 12:48 - 2012-08-30 12:48 - 02193184 ____A C:\Users\Lucas\Downloads\tdsskiller.zip
    2012-08-30 11:24 - 2012-08-30 11:24 - 00388608 ____A (Trend Micro Inc.) C:\Users\Lucas\Downloads\HijackThis.exe
    2012-08-30 11:24 - 2012-08-30 11:24 - 00017498 ____A C:\Users\Lucas\Downloads\hijackthis.log
    2012-08-30 11:24 - 2012-08-30 11:24 - 00017498 ____A C:\Users\Lucas\Desktop\hijackthis.log
    2012-08-30 11:04 - 2012-08-30 11:04 - 00010773 ____A C:\Users\Lucas\Desktop\Attach.zip
    2012-08-30 11:02 - 2012-08-30 11:02 - 00030766 ____A C:\Users\Lucas\Desktop\DDS.txt
    2012-08-30 11:02 - 2012-08-30 11:02 - 00007487 ____A C:\Users\Lucas\Desktop\Attach.txt
    2012-08-30 11:01 - 2012-08-30 11:01 - 00607260 ____R (Swearware) C:\Users\Lucas\Downloads\dds.com
    2012-08-30 10:44 - 2012-08-30 10:43 - 04165104 ____A (PC Tools) C:\Users\Lucas\Downloads\SDAV_Online_aff_GenericRevenueWire_207_2.exe
    2012-08-30 10:24 - 2012-07-16 16:10 - 00038882 ____A C:\Windows\PFRO.log
    2012-08-30 09:40 - 2012-08-26 03:02 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-30 09:40 - 2012-08-26 03:02 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-30 08:49 - 2012-08-30 08:49 - 00152576 ____A C:\Users\Lucas\AppData\Roaming\scsol.dll
    2012-08-30 08:49 - 2012-08-30 08:49 - 00000012 ____A C:\Windows\srun.log
    2012-08-30 08:49 - 2012-07-16 16:13 - 01993982 ____A C:\Windows\WindowsUpdate.log
    2012-08-26 06:20 - 2012-08-21 08:47 - 00000017 ____A C:\Windows\popcinfo.dat
    2012-08-24 02:28 - 2012-08-30 12:49 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Lucas\Desktop\TDSSKiller.exe
    2012-08-22 22:28 - 2012-08-22 22:28 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
    2012-08-22 01:16 - 2012-08-22 01:16 - 00001107 ____A C:\Users\Public\Desktop\Rocket Mania Deluxe.lnk
    2012-08-22 01:16 - 2012-08-22 01:16 - 00000194 ____A C:\Users\Public\Desktop\Play More Great Games!.url
    2012-08-21 14:14 - 2012-07-18 12:44 - 00002453 ____A C:\Users\Lucas\Desktop\Google Chrome.lnk
    2012-08-19 20:26 - 2012-07-23 12:29 - 00002018 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
    2012-08-18 17:11 - 2012-07-16 07:00 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-173249258-721920281-3489915689-1000Core.job
    2012-08-16 15:16 - 2009-07-13 21:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-16 11:44 - 2012-08-16 11:44 - 00751104 ____A C:\Users\Lucas\Downloads\ReferencingGuide.ppt
    2012-08-15 09:59 - 2009-07-13 20:45 - 00414656 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-08-15 09:49 - 2012-07-16 10:06 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-08-14 13:14 - 2012-08-14 13:14 - 00001250 ____A C:\Windows\serial
    2012-08-14 13:13 - 2012-08-14 13:13 - 05721803 ____A C:\Users\Lucas\Downloads\[congdongbaclieu.info] IDM 6.11 beta.rar
    2012-08-14 13:08 - 2012-08-14 13:08 - 04110768 ____A (http://yourfiledownloader.com) C:\Users\Lucas\Downloads\Internet_Download_Manager_6.11.8.2_key_Patch.rar_downloader_224.exe
    2012-08-14 13:02 - 2012-08-14 13:02 - 00027520 ____A C:\Users\Lucas\AppData\Local\dt.dat
    2012-08-13 13:35 - 2012-08-13 13:21 - 124621250 ____A C:\Users\Lucas\Downloads\breaking.bad.s05e04.480p.hdtv.x264-orenji.MP4
    2012-08-13 11:17 - 2012-08-13 11:17 - 00039051 ____A C:\Users\Lucas\Downloads\L5.1b_Thesis_template_word2007.dotx
    2012-08-12 12:40 - 2012-08-12 12:38 - 143912514 ____A C:\Users\Lucas\Downloads\breaking.bad.s05e03.hdtv.x264-fqm.MP4
    2012-08-06 13:53 - 2012-08-06 13:53 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-08-06 13:53 - 2012-08-06 13:53 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-08-06 13:52 - 2012-08-06 13:52 - 00893936 ____A (Oracle Corporation) C:\Users\Lucas\Downloads\jxpiinstall.exe
    2012-08-05 15:25 - 2012-08-05 15:14 - 200000000 ____A C:\Users\Lucas\Downloads\Hunger Game 2 - BadBoy199x.part1.rar
    2012-08-05 15:24 - 2012-08-05 15:12 - 200000000 ____A C:\Users\Lucas\Downloads\Hunger Game 1 - BadBoy199x.part1.rar
    2012-08-05 15:20 - 2012-08-05 15:13 - 40899486 ____A C:\Users\Lucas\Downloads\Hunger Game 2 - BadBoy199x.part2.rar
    2012-08-05 15:20 - 2012-08-05 15:12 - 32084174 ____A C:\Users\Lucas\Downloads\Hunger Game 1 - BadBoy199x.part2.rar
    2012-08-03 15:10 - 2012-08-03 14:58 - 204800000 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part2.rar
    2012-08-03 15:09 - 2012-08-03 15:01 - 148076057 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part3.rar
    2012-08-03 15:00 - 2012-08-03 14:56 - 204800000 ____A C:\Users\Lucas\Downloads\Chocolate.2008.720p.BluRay.DTS.x264-ESiR_Tablet_HDVNBits.part1.rar
    2012-08-03 14:22 - 2012-08-03 14:07 - 256000000 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part2.rar
    2012-08-03 14:15 - 2012-08-03 14:05 - 256000000 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part1.rar
    2012-08-03 14:06 - 2012-08-03 14:05 - 18262156 ____A C:\Users\Lucas\Downloads\Flash Point.BrripBobobo1996(2007).part3.rar
    2012-08-02 03:24 - 2012-08-02 03:24 - 00288897 ____A C:\Users\Lucas\Documents\Desk 1
    2012-07-30 14:36 - 2012-07-30 14:28 - 204800000 ____A C:\Users\Lucas\Downloads\Hijacker 2012.part2.rar
    2012-07-30 14:36 - 2012-07-30 14:28 - 204800000 ____A C:\Users\Lucas\Downloads\Hijacker 2012.part1.rar
    2012-07-30 14:34 - 2012-07-30 14:28 - 135958283 ____A C:\Users\Lucas\Downloads\Hijacker 2012.part3.rar
    2012-07-30 14:28 - 2012-07-30 14:19 - 204800000 ____A C:\Users\Lucas\Downloads\The Scorpion King 3 Battle for Redemption (2012).part1.rar
    2012-07-30 14:27 - 2012-07-30 14:19 - 204800000 ____A C:\Users\Lucas\Downloads\The Scorpion King 3 Battle for Redemption (2012).part2.rar
    2012-07-30 14:26 - 2012-07-30 14:18 - 204800000 ____A C:\Users\Lucas\Downloads\The Scorpion King 3 Battle for Redemption (2012).part3.rar
    2012-07-30 14:20 - 2012-07-30 14:19 - 18628535 ____A C:\Users\Lucas\Downloads\The Scorpion King 3 Battle for Redemption (2012).part4.rar
    2012-07-29 16:08 - 2012-07-29 16:09 - 20452456 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 18580072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 15039080 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 13029992 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-07-29 16:08 - 2012-07-29 16:09 - 13011560 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 12832872 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 10054248 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 07712360 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 06598248 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 05633640 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 04936808 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 03182184 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 02954856 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 02871400 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 02579560 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 02197608 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 01962600 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 01612392 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco642090.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 01359976 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64hda.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 01359976 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco642040.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 00155752 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-07-29 16:08 - 2012-07-29 16:09 - 00067176 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 00057960 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 00029288 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-07-29 16:08 - 2012-07-29 16:09 - 00011240 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvBridge.kmd
    2012-07-29 16:08 - 2012-07-29 16:09 - 00007621 ____A C:\Windows\System32\nvinfo.pb
    2012-07-27 14:29 - 2012-07-27 14:29 - 00001377 ____A C:\Users\Lucas\Downloads\map_005.ace
    2012-07-25 14:56 - 2012-07-25 14:55 - 28056345 ____A C:\Users\Lucas\Downloads\Foot_Mana_3.4.apk
    2012-07-24 16:06 - 2012-07-24 16:05 - 50992732 ____A C:\Users\Lucas\Downloads\popcap.pvz.apk
    2012-07-24 15:37 - 2012-07-24 15:37 - 14823741 ____A C:\Users\Lucas\Downloads\com.outfit7.talkingtom.apk
    2012-07-24 15:35 - 2012-07-24 15:35 - 02502554 ____A C:\Users\Lucas\Downloads\fireworks.ndroidz.com.apk
    2012-07-24 11:08 - 2012-07-24 11:08 - 02271031 ____A C:\Users\Lucas\Downloads\app.apk
    2012-07-24 10:42 - 2012-07-24 10:40 - 39334397 ____A C:\Users\Lucas\Downloads\com.subatomicstudios1.0.2.apk
    2012-07-24 10:31 - 2012-07-24 10:30 - 39392968 ____A C:\Users\Lucas\Downloads\f101.apk
    2012-07-24 10:17 - 2012-07-24 10:17 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    2012-07-24 10:16 - 2012-07-24 10:16 - 03269413 ____A C:\Users\Lucas\Downloads\[ApkViet.com]Fieldrunners_HD_1.18.apk
    2012-07-24 07:14 - 2012-07-24 07:14 - 07507114 ____A C:\Users\Lucas\Downloads\qui 4-2011.rar
    2012-07-24 07:14 - 2012-07-24 07:14 - 03861376 ____A C:\Users\Lucas\Downloads\WP Cty TNHH DV Zim Integrated Shipping (VN) 2011.rar
    2012-07-24 07:14 - 2012-07-24 07:14 - 03644530 ____A C:\Users\Lucas\Downloads\Administration.rar
    2012-07-24 04:14 - 2012-07-24 04:10 - 48829954 ____A C:\Users\Lucas\Downloads\EP-3.Johnny.Cage.mp4
    2012-07-24 04:13 - 2012-07-24 04:10 - 37466551 ____A C:\Users\Lucas\Downloads\EP-2.Jax,.Sonya.&.Kano.(Part.2).mp4
    2012-07-24 04:12 - 2012-07-24 04:08 - 55429693 ____A C:\Users\Lucas\Downloads\EP-1.Jax,.Sonya.&.Kano.(Part.1).mp4
    2012-07-23 14:58 - 2012-07-23 14:52 - 307200000 ____A C:\Users\Lucas\Downloads\300- bioix.com.part1.rar
    2012-07-23 14:55 - 2012-07-23 14:52 - 86078507 ____A C:\Users\Lucas\Downloads\300- bioix.com.part3.rar
    2012-07-23 14:53 - 2012-07-23 14:52 - 17112525 ____A C:\Users\Lucas\Downloads\300- bioix.com.part4.rar
    2012-07-23 14:51 - 2012-07-23 14:46 - 307200000 ____A C:\Users\Lucas\Downloads\300- bioix.com.part2.rar
    2012-07-22 10:57 - 2012-07-22 10:57 - 00001809 ____A C:\Users\Lucas\Desktop\Spotify.lnk
    2012-07-22 10:50 - 2012-07-22 10:50 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2012-07-20 17:01 - 2012-07-18 17:06 - 00000910 ____A C:\Users\Public\Desktop\File Splitter & Joiner.lnk
    2012-07-19 13:12 - 2012-07-19 13:12 - 00011130 ____A C:\Users\Lucas\Downloads\Dixvi.com - f6ea0128.htm
    2012-07-19 13:10 - 2012-07-19 13:10 - 00182334 ____A C:\Users\Lucas\Downloads\abc.htm
    2012-07-18 17:06 - 2012-07-18 17:06 - 00794906 ____A C:\Windows\unins000.exe
    2012-07-18 17:06 - 2012-07-18 17:06 - 00004151 ____A C:\Windows\unins000.dat
    2012-07-18 13:46 - 2012-07-18 13:44 - 107330965 ____A C:\Users\Lucas\Downloads\Hatchet.mp4.003
    2012-07-18 13:43 - 2012-07-18 13:41 - 107330964 ____A C:\Users\Lucas\Downloads\Hatchet.mp4.002
    2012-07-18 13:40 - 2012-07-18 13:38 - 107330964 ____A C:\Users\Lucas\Downloads\Hatchet.mp4.001
    2012-07-18 13:12 - 2012-07-18 13:04 - 00000720 ____A C:\Users\Lucas\Downloads\Settings.ini
    2012-07-18 10:50 - 2012-07-18 10:50 - 00000995 ____A C:\Users\Lucas\Desktop\SopCast.lnk
    2012-07-18 10:15 - 2012-08-14 22:53 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-18 09:35 - 2012-07-18 09:33 - 06654296 ____A (Advanced Fix, Inc. ) C:\Users\Lucas\Downloads\AdvancedFix_ErrorsRepair_Setup.exe
    2012-07-18 09:30 - 2012-07-18 09:30 - 02841613 ____A (Igor Pavlov) C:\Users\Lucas\Downloads\RivaTuner224c-[Guru3D.com].exe
    2012-07-18 09:29 - 2012-07-18 09:29 - 01323056 ____A C:\Users\Lucas\Downloads\ADLSoft_UnCompressor_v2_3.exe
    2012-07-18 08:47 - 2012-07-18 08:47 - 00000566 ____A C:\Users\Lucas\Desktop\Fraps.lnk
    2012-07-18 03:25 - 2012-07-16 07:35 - 00000123 ____A C:\Windows\wininit.ini
    2012-07-18 03:24 - 2012-07-18 03:24 - 00001141 ____A C:\Users\Public\Desktop\Yahoo! Messenger.lnk
    2012-07-16 17:05 - 2009-07-13 21:38 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
    2012-07-16 17:05 - 2009-07-13 21:32 - 00028672 ____A C:\Windows\System32\config\BCD-Template
    2012-07-16 16:46 - 2009-07-13 20:46 - 00003043 ____A C:\Windows\DtcInstall.log
    2012-07-16 16:34 - 2012-07-16 16:31 - 00017316 ____A C:\Users\All Users\ArcadeDeluxe4.log
    2012-07-16 16:30 - 2012-07-16 16:30 - 00001024 __RAH C:\Users\Public\Documents\NTILiveUpdateV9.dll
    2012-07-16 16:29 - 2012-07-16 16:29 - 00001024 __RAH C:\Users\Public\Documents\NTIMPEG-2.dll
    2012-07-16 16:29 - 2012-07-16 16:29 - 00001024 __RAH C:\Users\Public\Documents\NTIMMV9REGET.dll
    2012-07-16 16:29 - 2012-07-16 16:29 - 00001024 __RAH C:\Users\Public\Documents\NTIMMV9Acer.dll
    2012-07-16 16:24 - 2012-07-16 16:24 - 00015772 ____A C:\Windows\devices.txt
    2012-07-16 16:22 - 2012-07-16 16:22 - 00004844 ____A C:\Windows\DPINST.LOG
    2012-07-16 16:22 - 2012-07-16 16:22 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf
    2012-07-16 16:17 - 2012-07-16 16:17 - 00000003 ____A C:\Windows\System32\PLD_Framework.cmd
    2012-07-16 16:11 - 2010-09-06 02:25 - 00003540 ____A C:\Windows\TSSysprep.log
    2012-07-16 16:00 - 2012-07-16 10:40 - 00287130 ____A C:\Windows\msxml4-KB973688-enu.LOG
    2012-07-16 16:00 - 2012-07-16 10:33 - 00290524 ____A C:\Windows\msxml4-KB954430-enu.LOG
    2012-07-16 12:44 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
    2012-07-16 12:44 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
    2012-07-16 11:53 - 2012-07-16 11:53 - 00000969 ____A C:\Users\Public\Desktop\AVG 2012.lnk
    2012-07-16 11:31 - 2012-07-16 11:32 - 00099056 ____A (McAfee, Inc.) C:\Windows\System32\MfeOtlkAddin.dll
    2012-07-16 11:31 - 2012-07-16 11:32 - 00074848 ____A (McAfee, Inc.) C:\Windows\SysWOW64\MfeOtlkAddin.dll
    2012-07-16 11:31 - 2012-07-16 11:32 - 00022816 ____A (McAfee, Inc.) C:\Windows\SysWOW64\MFEOtlk.dll
    2012-07-16 10:51 - 2012-07-16 08:53 - 00772682 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-07-16 10:44 - 2012-07-16 10:44 - 00001134 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2012-07-16 10:37 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
    2012-07-16 10:15 - 2012-07-16 10:13 - 00003881 ____A C:\Windows\IE9_main.log
    2012-07-16 10:14 - 2012-07-16 10:14 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
    2012-07-16 10:14 - 2012-07-16 10:14 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
    2012-07-16 10:14 - 2012-07-16 10:14 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
    2012-07-16 10:14 - 2012-07-16 10:14 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2012-07-16 10:14 - 2012-07-16 10:14 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
    2012-07-16 10:14 - 2012-07-16 10:14 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2012-07-16 10:14 - 2012-07-16 10:14 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
    2012-07-16 10:14 - 2012-07-16 10:14 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
    2012-07-16 10:14 - 2012-07-16 10:14 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
    2012-07-16 09:21 - 2012-07-16 16:28 - 00058765 ____A C:\Windows\DirectX.log
    2012-07-16 09:21 - 2012-07-16 09:21 - 00001238 ____A C:\Users\Public\Desktop\FIFA 12.lnk
    2012-07-16 09:15 - 2012-07-16 09:15 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_xusb21_01009.Wdf
    2012-07-16 08:13 - 2012-07-16 06:51 - 00108824 ____A C:\Users\Lucas\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-16 07:35 - 2012-07-16 07:35 - 00000983 ____A C:\Users\Public\Desktop\Origin.lnk
    2012-07-16 07:35 - 2012-07-16 07:35 - 00000527 ____A C:\Windows\KB893803v2.log
    2012-07-16 07:34 - 2012-07-16 07:32 - 17063192 ____A (Electronic Arts, Inc.) C:\Users\Lucas\Downloads\OriginThinSetup.exe
    2012-07-16 07:06 - 2012-07-16 07:06 - 04563200 ____A (Tonec Inc.) C:\Users\Lucas\Downloads\idman611.exe
    2012-07-16 06:55 - 2012-07-16 06:55 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
    2012-07-16 06:54 - 2010-09-06 02:56 - 00058185 ____A C:\Windows\patch.log
    2012-07-16 06:51 - 2012-07-16 06:51 - 00002609 ____A C:\Users\Public\Desktop\eBay.lnk
    2012-07-16 06:50 - 2012-07-16 06:50 - 00000020 ___SH C:\Users\Lucas\ntuser.ini
    2012-07-05 11:06 - 2012-08-06 13:53 - 00772544 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-07-05 11:06 - 2012-08-06 13:53 - 00687544 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-07-05 11:06 - 2012-08-06 13:53 - 00227760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-07-04 14:16 - 2012-08-14 22:53 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-07-04 14:13 - 2012-08-14 22:53 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
    2012-07-04 14:13 - 2012-08-14 22:53 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
    2012-07-04 13:16 - 2012-08-14 22:53 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2012-07-04 13:14 - 2012-08-14 22:53 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2012-06-28 20:55 - 2012-08-15 09:53 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-28 20:09 - 2012-08-15 09:53 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-28 19:56 - 2012-08-15 09:53 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-28 19:49 - 2012-08-15 09:53 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-28 19:49 - 2012-08-15 09:53 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-28 19:48 - 2012-08-15 09:53 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-28 19:47 - 2012-08-15 09:53 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-28 19:45 - 2012-08-15 09:53 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-28 19:44 - 2012-08-15 09:53 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-28 19:43 - 2012-08-15 09:53 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-28 19:42 - 2012-08-15 09:53 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-28 19:40 - 2012-08-15 09:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-28 19:39 - 2012-08-15 09:53 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-28 19:35 - 2012-08-15 09:53 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-28 16:52 - 2012-08-15 09:53 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-28 16:27 - 2012-08-15 09:53 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-28 16:16 - 2012-08-15 09:53 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-28 16:09 - 2012-08-15 09:53 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-28 16:09 - 2012-08-15 09:53 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-28 16:08 - 2012-08-15 09:53 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-28 16:07 - 2012-08-15 09:53 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-28 16:06 - 2012-08-15 09:53 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-28 16:04 - 2012-08-15 09:53 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-28 16:04 - 2012-08-15 09:53 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-28 16:01 - 2012-08-15 09:53 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-28 16:01 - 2012-08-15 09:53 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-28 16:00 - 2012-08-15 09:53 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-28 15:57 - 2012-08-15 09:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-11 10:17 - 2012-06-11 10:17 - 00071680 ____A (Beepa P/L) C:\Windows\System32\frapsv64.dll
    2012-06-11 10:17 - 2012-06-11 10:17 - 00065536 ____A (Beepa P/L) C:\Windows\SysWOW64\frapsvid.dll
    2012-06-08 21:43 - 2012-07-16 09:42 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-08 20:41 - 2012-07-16 09:42 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-06-05 22:06 - 2012-07-16 09:42 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-05 22:06 - 2012-07-16 09:42 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-05 22:02 - 2012-07-16 09:34 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
    2012-06-05 21:05 - 2012-07-16 09:42 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-06-05 21:05 - 2012-07-16 09:42 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-06-05 21:03 - 2012-07-16 09:34 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll

    ZeroAccess:
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\L
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\L\00000004.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\00000004.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\00000008.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\000000cb.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\80000000.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\80000032.@
    C:\Windows\Installer\{6e6e9c1c-fca1-3516-fb18-753f5d94a7e9}\U\80000064.@

    ZeroAccess:
    C:\Windows\assembly\GAC_32\Desktop.ini

    ZeroAccess:
    C:\Windows\assembly\GAC_64\Desktop.ini

    ==================== Known DLLs (Whitelisted) =================


    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 50BEA589F7D7958BDD2528A8F69D05CC ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================

    Restore point made on: 2012-08-15 09:49:03
    Restore point made on: 2012-08-22 14:04:56
    Restore point made on: 2012-08-26 13:21:35
    Restore point made on: 2012-08-30 11:00:16

    ==================== Memory info ===========================

    Percentage of memory in use: 18%
    Total physical RAM: 3958.76 MB
    Available physical RAM: 3217.64 MB
    Total Pagefile: 3956.91 MB
    Available Pagefile: 3220.33 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ==================== Partitions ============================

    1 Drive c: (Acer) (Fixed) (Total:256.35 GB) (Free:168.42 GB) NTFS
    2 Drive d: (Lucas) (Fixed) (Total:195.31 GB) (Free:124.76 GB) NTFS
    3 Drive f: (PQSERVICE) (Fixed) (Total:14 GB) (Free:2.2 GB) NTFS
    5 Drive h: () (Removable) (Total:7.58 GB) (Free:5.19 GB) FAT32
    6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    7 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 465 GB 1024 KB
    Disk 1 Online 7764 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Recovery 14 GB 1024 KB
    Partition 2 Primary 100 MB 14 GB
    Partition 3 Primary 256 GB 14 GB
    Partition 0 Extended 195 GB 270 GB
    Partition 4 Logical 195 GB 270 GB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 27
    Hidden: Yes
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 F PQSERVICE NTFS Partition 14 GB Healthy Hidden

    ==================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy

    ==================================================================================

    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C Acer NTFS Partition 256 GB Healthy

    ==================================================================================

    Disk: 0
    Partition 4
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 D Lucas NTFS Partition 195 GB Healthy

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 7762 MB 58 KB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 0C
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 H FAT32 Removable 7762 MB Healthy

    ==================================================================================

    Last Boot: 2012-08-27 06:06

    ==================== End Of Log =============================
     
  12. jeffce

    jeffce Malware Specialist

    Joined:
    May 10, 2011
    Messages:
    1,727
    In Vista or Windows 7: Boot to System Recovery Options and run FRST.
    Type the following in the edit box after "Search:"
    It should look like:
    Click Search button and post the log (Search.txt) it makes to your reply.
     
  13. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    Thanks for your instruction, here is the search result:

    Farbar Recovery Scan Tool Version: 31-08-2012 01
    Ran by SYSTEM at 2012-08-31 22:00:48
    Running from H:\

    ================== Search: "services.exe" ===================

    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0329216 ____A (Microsoft Corporation) 50BEA589F7D7958BDD2528A8F69D05CC

    ====== End Of Search ======
     
  14. jeffce

    jeffce Malware Specialist

    Joined:
    May 10, 2011
    Messages:
    1,727
    I need to get a different look. If you have your Windows 7 disk please get it out...we may need it.
    -----

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Right-click and Run as Administrator SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      *services*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  15. lucasle146

    lucasle146 Thread Starter

    Joined:
    Aug 30, 2012
    Messages:
    15
    I am doing that but I dont have a Win 7 Disk. Does it matter? And here is the result that you need:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 22:47 on 31/08/2012 by Lucas
    Administrator - Elevation successful
    WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

    ========== filefind ==========

    Searching for "*services*"
    C:\OEM\Preload\Autorun\DRV\Intel Turbo Boost Manageability Engine Code\MEWMIProv\ME\cim_schema\Core\CIM_ServiceSAPDependency.mof --a---- 1206 bytes [11:21 06/09/2010] [04:15 06/05/2010] 46F393250F8EC73854EDA3AB1FF871A3
    C:\OEM\Preload\Autorun\DRV\Intel Turbo Boost Manageability Engine Code\MEWMIProv\ME\cim_schema\Core\CIM_ServiceServiceDependency.mof --a---- 3220 bytes [11:21 06/09/2010] [04:15 06/05/2010] E06DE0EBA3A43982619BF8FAB0ADCC7E
    C:\OEM\Preload\Autorun\DRV\Intel Turbo Boost Manageability Engine Code\MEWMIProv\ME\cim_schema\Core\CIM_ServiceStatisticalInformation.mof --a---- 1931 bytes [11:21 06/09/2010] [04:15 06/05/2010] 63AD6225E182187B1E0001438E0B443F
    C:\OEM\Preload\Autorun\DRV\Intel Turbo Boost Manageability Engine Code\MEWMIProv\ME\cim_schema\Core\CIM_ServiceStatistics.mof --a---- 909 bytes [11:21 06/09/2010] [04:15 06/05/2010] EE754B57FB9AD9606F124A2BF8FCCC7C
    C:\Program Files\Intel\TurboBoost\ConfigureServices.bat -ra---- 598 bytes [19:22 02/11/2009] [19:22 02/11/2009] 4479BD154EAA784EBAAA01AD99B9BF03
    C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] CFC8379D9C0294EAEBF60A4E7F797202
    C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 9B7DD551A633887E255497E54298A468
    C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] B7F8F89042E6FB6E66605E746977282F
    C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] 7008BDA459F4D54E01064C1195BF7542
    C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.WorkflowServices.dll --a---- 479232 bytes [20:14 16/07/2012] [01:52 05/11/2010] 2970705DC9080AE0932BD4CB4A63F343
    C:\Program Files\Windows NT\TableTextService\TableTextServiceSimplifiedQuanPin.txt --a---- 1665878 bytes [21:25 13/07/2009] [21:04 10/06/2009] 532ED87BB64CF19C58AE0F91FA439983
    C:\Program Files\Windows NT\TableTextService\TableTextServiceSimplifiedShuangPin.txt --a---- 1445430 bytes [21:25 13/07/2009] [21:04 10/06/2009] 51B31EB324CB5C6936D7A14D49B0BD67
    C:\Program Files\Windows NT\TableTextService\TableTextServiceSimplifiedZhengMa.txt --a---- 1810352 bytes [21:25 13/07/2009] [21:04 10/06/2009] 6D2BE04D9605C2D479E3CD205C406D7C
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\MEWMIProv\ME\cim_schema\Core\CIM_ServiceSAPDependency.mof --a---- 1206 bytes [00:24 17/07/2012] [04:15 06/05/2010] 46F393250F8EC73854EDA3AB1FF871A3
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\MEWMIProv\ME\cim_schema\Core\CIM_ServiceServiceDependency.mof --a---- 3220 bytes [00:24 17/07/2012] [04:15 06/05/2010] E06DE0EBA3A43982619BF8FAB0ADCC7E
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\MEWMIProv\ME\cim_schema\Core\CIM_ServiceStatisticalInformation.mof --a---- 1931 bytes [00:24 17/07/2012] [04:15 06/05/2010] 63AD6225E182187B1E0001438E0B443F
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\MEWMIProv\ME\cim_schema\Core\CIM_ServiceStatistics.mof --a---- 909 bytes [00:24 17/07/2012] [04:15 06/05/2010] EE754B57FB9AD9606F124A2BF8FCCC7C
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\apps\fbsharedservices\7.1.391\js\sharedServices.js --a---- 1328 bytes [12:04 12/10/2011] [12:04 12/10/2011] 0BD6A56DBC2542667BF0EE793774221D
    C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\scripts\objectmodel\servicesapi.js --a---- 6440 bytes [16:50 19/12/2011] [16:50 19/12/2011] BD356785E223646AAF5ACA04ECDEE87C
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\StartServices.exe --a---- 14592 bytes [22:23 28/06/2010] [22:23 28/06/2010] 4EAA41115C3A546F5397C4DAFF1A8167
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] 606ACF1553423BFDD3CABEBA3DF264B9
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 0ACA904F87E674CF3CB6746D9D3AB321
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] 4BA482E447D6096E8D4348AAE306CE1B
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] CD86BDCB5E115635E6AB7DFE77FC1D11
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\System.WorkflowServices.dll --a---- 507904 bytes [20:14 16/07/2012] [01:52 05/11/2010] CC3B424ED10A8E477B5D466188531F26
    C:\Program Files (x86)\VideoLAN\VLC\sdk\include\vlc\plugins\vlc_services_discovery.h --a---- 6159 bytes [09:08 19/07/2012] [09:08 19/07/2012] 403B876F78733A2B9CC7787B3665BAC8
    C:\Program Files (x86)\Windows Live\Photo Gallery\ImagingServices.dll --a---- 426864 bytes [19:12 10/07/2009] [19:12 10/07/2009] CFBC07AE8F9E9E9E2C2B88F60DCF1464
    C:\Program Files (x86)\Windows Live\Writer\WindowsLive.Writer.CoreServices.dll --a---- 952160 bytes [03:13 27/07/2009] [03:13 27/07/2009] E76B975DACA5376B3CC248E9D664CB10
    C:\Program Files (x86)\Windows NT\TableTextService\TableTextServiceSimplifiedQuanPin.txt --a---- 1665878 bytes [21:38 13/07/2009] [21:43 10/06/2009] 532ED87BB64CF19C58AE0F91FA439983
    C:\Program Files (x86)\Windows NT\TableTextService\TableTextServiceSimplifiedShuangPin.txt --a---- 1445430 bytes [21:38 13/07/2009] [21:43 10/06/2009] 51B31EB324CB5C6936D7A14D49B0BD67
    C:\Program Files (x86)\Windows NT\TableTextService\TableTextServiceSimplifiedZhengMa.txt --a---- 1810352 bytes [21:38 13/07/2009] [21:43 10/06/2009] 6D2BE04D9605C2D479E3CD205C406D7C
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk --a---- 1242 bytes [04:57 14/07/2009] [04:57 14/07/2009] 00CEF6E74EA2178C6D033489EDCAAC99
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk --a---- 1288 bytes [04:54 14/07/2009] [04:54 14/07/2009] CA0D9F4743DFF86EBAF09D763139E958
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk --a---- 1242 bytes [04:57 14/07/2009] [04:57 14/07/2009] 00CEF6E74EA2178C6D033489EDCAAC99
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk --a---- 1288 bytes [04:54 14/07/2009] [04:54 14/07/2009] CA0D9F4743DFF86EBAF09D763139E958
    C:\Users\Lucas\AppData\Local\Microsoft\BingBar\Apps\fbsharedservices_bb9c6e8b961d477e9ec95f9698bde610\7.1.391\js\sharedServices.js --a---- 1328 bytes [21:45 06/08/2012] [12:04 12/10/2011] 0BD6A56DBC2542667BF0EE793774221D
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_appsMetadata --a---- 2041 bytes [09:32 09/08/2012] [09:32 09/08/2012] D616603743E29C3DDC712634A3E74248
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_appTrackingFirstTime --a---- 96 bytes [09:32 09/08/2012] [09:32 09/08/2012] 9BBC30DAA42D85ED6CCFF52859247754
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_gottenAppsContextMenu --a---- 5408 bytes [09:32 09/08/2012] [09:32 09/08/2012] 83ED3B717E645803108FD8601B4DC144
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_login --a---- 3420 bytes [09:32 09/08/2012] [09:32 09/08/2012] FBDC464E469B7A6478053D0225FBD8EF
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_menu_769c590835a76d075fe33b9a87a87786 --a---- 7095 bytes [09:32 09/08/2012] [09:32 09/08/2012] 49CA68FFD1D94270C334C65512B69CED
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_menu_d32f45618f5a02bd965c56155a643855 --a---- 3703 bytes [09:32 09/08/2012] [09:32 09/08/2012] BB4E17BFA426C80A510F930698FE834D
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_optimizer --a---- 82 bytes [09:32 09/08/2012] [09:32 09/08/2012] EAEF3A3C06AB0BC3510D292E0DE2B5FC
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_otherAppsContextMenu --a---- 4279 bytes [09:32 09/08/2012] [09:32 09/08/2012] 84C627B1D47DF87054E82E412BAB3DEF
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_searchAPI --a---- 389 bytes [09:32 09/08/2012] [09:32 09/08/2012] F47879B95A94B9E593FDDE09D60B6156
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_serviceMap --a---- 6191 bytes [09:32 09/08/2012] [09:35 09/08/2012] 72B7D25FB81903FEE506796C0A7A2F58
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_toolbarContextMenu --a---- 4279 bytes [09:32 09/08/2012] [09:32 09/08/2012] D79FCCC1116043ADA88C7287C8B8278C
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_toolbarSettings --a---- 38404 bytes [09:32 09/08/2012] [09:35 09/08/2012] 58540166983EB8405B927623BE1608DD
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_10.10.20.14.serviceLayer_services_translation --a---- 75370 bytes [09:32 09/08/2012] [09:32 09/08/2012] CF822204C3B3902131CE3A394F869E73
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_appsMetadata --a---- 1980 bytes [09:32 09/08/2012] [09:32 09/08/2012] 2DA58B22EA38581F39AAC296F642F250
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_appTrackingFirstTime --a---- 35 bytes [09:32 09/08/2012] [09:32 09/08/2012] D7768A85E04450AC03CB49E519BBF56D
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_gottenAppsContextMenu --a---- 7474 bytes [09:32 09/08/2012] [09:32 09/08/2012] 2682578A5731DB0C66E6DF0FF417C2AD
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_login --a---- 4971 bytes [09:32 09/08/2012] [09:32 09/08/2012] 37494F0497CE5878ED6DEA44BD192695
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_menu_769c590835a76d075fe33b9a87a87786 --a---- 7305 bytes [09:32 09/08/2012] [09:32 09/08/2012] E8F113F7E118258CC53F5B6750016848
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_menu_d32f45618f5a02bd965c56155a643855 --a---- 4119 bytes [09:32 09/08/2012] [09:32 09/08/2012] 9D625B9467EDAA9568F5C6AB43B7C280
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_optimizer --a---- 59 bytes [09:32 09/08/2012] [09:32 09/08/2012] 8FBF5F031782754B4377C1FD471B1682
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_otherAppsContextMenu --a---- 5876 bytes [09:32 09/08/2012] [09:32 09/08/2012] 5E57965F3897996F407C2DFF6C682F7C
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_searchAPI --a---- 328 bytes [09:32 09/08/2012] [09:32 09/08/2012] E21D1F62B2E3AFF4E941FEE541BA97ED
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_serviceMap --a---- 6252 bytes [09:32 09/08/2012] [09:32 09/08/2012] 44E910F7D13727BCB24C99C5449CED37
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_toolbarContextMenu --a---- 5875 bytes [09:32 09/08/2012] [09:32 09/08/2012] 9CA4DFB6640F45182A69DFB6C5674FEE
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_toolbarSettings --a---- 35081 bytes [09:32 09/08/2012] [09:32 09/08/2012] 70D02827AFA2431980E76F6E58E8027A
    C:\Users\Lucas\AppData\Roaming\Mozilla\Firefox\Profiles\7870vo6t.default\CT3196716\CT3196716_RAW.serviceLayer_services_translation --a---- 105251 bytes [09:32 09/08/2012] [09:32 09/08/2012] 964835E863499A3806F2805C50671E82
    C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll --a---- 258048 bytes [20:11 16/07/2012] [01:58 05/11/2010] 6DB969DF540BC71722848940D180AC08
    C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll --a---- 113664 bytes [20:11 16/07/2012] [04:12 20/11/2010] C865DC05ADE0B41A9E14DD585E0CDF94
    C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll --a---- 245760 bytes [20:11 16/07/2012] [01:57 05/11/2010] B395F8BE6E578FAB80A1D568911857D7
    C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll --a---- 133120 bytes [20:11 16/07/2012] [01:57 05/11/2010] D9C192B9CD25DC5C9C05DF98C945E3F1
    C:\Windows\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.dll --a---- 1689472 bytes [18:21 16/07/2012] [18:21 16/07/2012] E47BBE96323350665A90709686461EB5
    C:\Windows\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll --a---- 51072 bytes [15:43 16/07/2012] [15:43 16/07/2012] 7133E8677E11DC09D12DAB476C068DE1
    C:\Windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] 4BA482E447D6096E8D4348AAE306CE1B
    C:\Windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] 606ACF1553423BFDD3CABEBA3DF264B9
    C:\Windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 0ACA904F87E674CF3CB6746D9D3AB321
    C:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll --a---- 401408 bytes [20:11 16/07/2012] [01:58 05/11/2010] AF1F47FBADABB9134002359970F5FD1C
    C:\Windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] CD86BDCB5E115635E6AB7DFE77FC1D11
    C:\Windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll --a---- 188416 bytes [20:46 13/07/2009] [21:23 10/06/2009] EE1DCDAA3EA8F53DA56116875CD01653
    C:\Windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll --a---- 839680 bytes [20:12 16/07/2012] [01:58 05/11/2010] 8C0B098B41A27B08D58CAE7A61A3BA19
    C:\Windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll --a---- 507904 bytes [20:14 16/07/2012] [01:52 05/11/2010] CC3B424ED10A8E477B5D466188531F26
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\330d3ad45a00455b537047183e128def\System.Data.Services.Client.ni.dll --a---- 1378816 bytes [10:46 18/07/2012] [10:46 18/07/2012] 1E996D6B36D3EFAD50B83CCD0FFFB7B3
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e36e03067b12bc35fcc3787dc81022c8\System.Data.Services.Design.ni.dll --a---- 462336 bytes [10:46 18/07/2012] [10:46 18/07/2012] 5768759589EFDB82BA65DC36F8004802
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\3285887b33030a7ce453573d3bed4e95\System.Data.Services.ni.dll --a---- 2029568 bytes [10:46 18/07/2012] [10:46 18/07/2012] D317CAB86C99E56E9ECEA521638A420E
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\4d73a7649876bb6e54a01ccbf235919b\System.DirectoryServices.AccountManagement.ni.dll --a---- 888320 bytes [10:46 18/07/2012] [10:46 18/07/2012] 844D3C7A28FDA33184DEA1645A9A552D
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\55545e89f96539ef93375524d1145a6f\System.DirectoryServices.Protocols.ni.dll --a---- 455680 bytes [00:07 18/07/2012] [00:07 18/07/2012] 09A0276C9EFAF182FD3BC8E423B8E171
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll --a---- 1117184 bytes [00:07 18/07/2012] [00:07 18/07/2012] 6F36D13EE887744CA30356C30E39C1A1
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.ni.dll --a---- 628224 bytes [00:07 18/07/2012] [00:07 18/07/2012] DE47D88909CD06505F8A3E4DF6B82C27
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\168755d010e5a96ac940b0ddd27616a4\System.EnterpriseServices.Wrapper.dll --a---- 280064 bytes [00:07 18/07/2012] [00:07 18/07/2012] B9AF7100749F4DE9B7E5A471DF85522F
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\a434580a5940ac406740714ff238829b\System.Web.Services.ni.dll --a---- 1840640 bytes [00:07 18/07/2012] [00:07 18/07/2012] 9E0CEE5A2BD06F9491EF1E9DF1645AF6
    C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\e3e5aa45736b95804bf6bb7eca08a57b\System.WorkflowServices.ni.dll --a---- 1358336 bytes [10:46 18/07/2012] [10:46 18/07/2012] BC5D5C763293DC6D1D25DBC221CDBEEB
    C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\579e9f2d0d25b50996964b4976002535\WindowsLive.Writer.CoreServices.ni.dll --a---- 2002432 bytes [10:44 18/07/2012] [10:44 18/07/2012] 534F42DAE688BA9F7D70B24B2289BF90
    C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.Office.Bu#\6c90684061fd4e7703858b8a7315a899\Microsoft.Office.BusinessApplications.SyncServices.ni.dll --a---- 6566400 bytes [00:14 18/07/2012] [00:14 18/07/2012] 509B889CA3A2C666212A590AC9F44E8A
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\2e9de1acfb7974cad94b747442ca325f\System.Data.Services.Client.ni.dll --a---- 1868288 bytes [00:16 18/07/2012] [00:16 18/07/2012] 375BF4A6B292793708690F57754FD1C0
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Service#\7c4ce1b8a2f83ef29aa6d5f126ab5b71\System.Data.Services.Design.ni.dll --a---- 629760 bytes [00:16 18/07/2012] [00:16 18/07/2012] C61CA9866D67813A1AD2F33CD0379765
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\0679fe5f3f9164f499e50cdade962ba3\System.Data.Services.ni.dll --a---- 2805760 bytes [00:16 18/07/2012] [00:16 18/07/2012] 1DD6DEDE6D036E3FEB133B72E6684C57
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\152ef61928f1c300fdad8fa6d5905880\System.DirectoryServices.ni.dll --a---- 1640448 bytes [00:09 18/07/2012] [00:09 18/07/2012] 332896C99B364134D376472AB7D56430
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\39d16229a3d5c6e7c1594ef10758bf75\System.DirectoryServices.AccountManagement.ni.dll --a---- 1230848 bytes [00:16 18/07/2012] [00:16 18/07/2012] 6A9DC1D5E8727EB6462A897C3878D4BF
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\4bb1134d9b166434327385ddf3c5dd54\System.DirectoryServices.Protocols.ni.dll --a---- 649728 bytes [00:10 18/07/2012] [00:10 18/07/2012] 23FE5DC98E85A779E74A8578680ED61D
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.ni.dll --a---- 1081344 bytes [00:10 18/07/2012] [00:10 18/07/2012] 83763D5C3C8232C3F9FF2C72DEE32443
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.EnterpriseSe#\d50cde53634ccbb5e0231738784ff4b8\System.EnterpriseServices.Wrapper.dll --a---- 446464 bytes [00:10 18/07/2012] [00:10 18/07/2012] 910271BF26AA56CBA9B76FA786341F12
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\a32734087cd0db5607d5744ca63235d7\System.Web.Services.ni.dll --a---- 2292224 bytes [00:10 18/07/2012] [00:10 18/07/2012] D7AB79F938470391FA31090A738B00BF
    C:\Windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\70cc5e8a5a3372fe0b104c1b20392cd2\System.WorkflowServices.ni.dll --a---- 1818112 bytes [10:47 18/07/2012] [10:47 18/07/2012] C3AE2A2D022C5314C8F18901EFC7BB2E
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\9242a5a839c4ae4f203c32b409dc7c42\System.Data.Services.Design.ni.dll --a---- 508928 bytes [22:04 16/07/2012] [22:04 16/07/2012] B1607B2502E589C6C0F2CCAB5413AB39
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\b894a1df3e6d58ada8f1aa303465ca23\System.Data.Services.Client.ni.dll --a---- 1343488 bytes [22:04 16/07/2012] [22:04 16/07/2012] EDD1AEFD73DA9B3A6063E00FC4126657
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\9b0a11f0270b5bbeae593ca5c584afaa\System.Data.Services.ni.dll --a---- 2026496 bytes [22:03 16/07/2012] [22:03 16/07/2012] F207E3A5B059836C3527DCFC975F0101
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\0fe1e56d17858b6156a3a46330f75f27\System.DirectoryServices.ni.dll --a---- 1172992 bytes [22:02 16/07/2012] [22:02 16/07/2012] FD670B45802FE92AE8BE8136C866A8EA
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\94d45f7f28d81304d7fa83bcea849141\System.DirectoryServices.AccountManagement.ni.dll --a---- 913920 bytes [22:04 16/07/2012] [22:04 16/07/2012] 4212CE1F95E6A51CE29C5697ACF7DDAB
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\e41e86da56bb60523251e0e08210a77b\System.DirectoryServices.Protocols.ni.dll --a---- 470528 bytes [22:02 16/07/2012] [22:02 16/07/2012] 5434FF62059CA920E0CC2212D8F5A320
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.ni.dll --a---- 787456 bytes [22:02 16/07/2012] [22:02 16/07/2012] 2BFB83BA5B2CED8B5720C4692D7C047A
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\bb40644f323a93fa9bc09be350918ef3\System.EnterpriseServices.Wrapper.dll --a---- 236032 bytes [22:02 16/07/2012] [22:02 16/07/2012] 768230C78724CB23F8166D6F6A2106AD
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Applicat#\9b418f37f4594806e1f4b0ed6d083a95\System.Web.ApplicationServices.ni.dll --a---- 71680 bytes [22:02 16/07/2012] [22:02 16/07/2012] AD564C410BC10B4B08CCA978A68D115D
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\dbe597aa9c12df5d08fb2f3f9872b834\System.Web.Services.ni.dll --a---- 1925632 bytes [22:02 16/07/2012] [22:02 16/07/2012] BFCAED0C3CD2903D04322113001256E9
    C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\6831f648f5b925f1194f691b0b491662\System.WorkflowServices.ni.dll --a---- 1226752 bytes [22:04 16/07/2012] [22:04 16/07/2012] 94FB639AE81EC5545D0D4BE217047A35
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\536e12016ad3adc78e0708b77e6b9219\System.Data.Services.Client.ni.dll --a---- 1799168 bytes [22:13 16/07/2012] [22:13 16/07/2012] EB1FE96580BB86B682A537EF20699343
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\a7528e9723fb3c77bba4ce617a9c9e03\System.Data.Services.Design.ni.dll --a---- 662528 bytes [22:13 16/07/2012] [22:13 16/07/2012] 07681E577A5AFB07A473B931D385CCEB
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Data.Services\ef77bd7c278e00372440bc2a2d6bfef0\System.Data.Services.ni.dll --a---- 2703360 bytes [22:13 16/07/2012] [22:13 16/07/2012] 0CD28DD11C6C3DB04F5EA78D4648D1AF
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\3a737af86a6a819af97a6d1a04c0e944\System.DirectoryServices.ni.dll --a---- 1622528 bytes [22:10 16/07/2012] [22:10 16/07/2012] 185896E7D5E039AD2CA531C8ACB784CA
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\6a8bd7d373c988a585e90bb61c5ec8cc\System.DirectoryServices.Protocols.ni.dll --a---- 632832 bytes [22:11 16/07/2012] [22:11 16/07/2012] 4D52E3395BC4767C1EABE74C397EFD59
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.DirectorySer#\a68116468a194678fd04167067134712\System.DirectoryServices.AccountManagement.ni.dll --a---- 1217024 bytes [22:14 16/07/2012] [22:14 16/07/2012] 9B46A5C6B35D75EEBACC0902ED5ABE59
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.ni.dll --a---- 1098752 bytes [22:10 16/07/2012] [22:10 16/07/2012] 3B9242D743C5C63DC04ED9D284E68FB4
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.EnterpriseSe#\8e10d4f2a408dc5a9740f8d0df5cebac\System.EnterpriseServices.Wrapper.dll --a---- 348672 bytes [22:10 16/07/2012] [22:10 16/07/2012] C9ECB00F92E4F09142C78983F098BCD8
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Applicat#\ff78ec1b5bf38a8fb74c2d4f41bb308a\System.Web.ApplicationServices.ni.dll --a---- 86016 bytes [22:11 16/07/2012] [22:11 16/07/2012] 33B2FB6ED36F362709D89DA0B71B1997
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\d27c82130281d30a958f94d9f7027e34\System.Web.Services.ni.dll --a---- 2287104 bytes [22:11 16/07/2012] [22:11 16/07/2012] 16076E521F121F6C69BF0298CCC2CDEE
    C:\Windows\assembly\NativeImages_v4.0.30319_64\System.WorkflowServ#\fb9bda76fdb95462be5964d24b3a3694\System.WorkflowServices.ni.dll --a---- 1602560 bytes [22:14 16/07/2012] [22:14 16/07/2012] 48E36287592F86755BB5FB258E7E5E97
    C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll --a---- 246128 bytes [18:52 16/07/2012] [18:52 16/07/2012] F8C1508FAF0DD3CC9A61A02BF0CEC2B6
    C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll --a---- 109568 bytes [18:52 16/07/2012] [18:52 16/07/2012] C755E17BAC396F9A9F468320B3F6CF46
    C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll --a---- 237424 bytes [18:53 16/07/2012] [18:53 16/07/2012] 4B091BA37D2D8E336822CA223EA4F48C
    C:\Windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll --a---- 125440 bytes [18:53 16/07/2012] [18:53 16/07/2012] 9A1563235169C94DFF5A541774CCCD6B
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll --a---- 683368 bytes [18:50 16/07/2012] [18:50 16/07/2012] 65BBC872E434FF876AB82046CB108C35
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll --a---- 436600 bytes [18:53 16/07/2012] [18:53 16/07/2012] F7FDD963EC0DB59437CA637475110D33
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll --a---- 178040 bytes [18:50 16/07/2012] [18:50 16/07/2012] 59E3A44249D12758566B9A58C28FAEC0
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll --a---- 395120 bytes [18:53 16/07/2012] [18:53 16/07/2012] 5CD0E30C15DDFC47199F864F7334B86F
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll --a---- 285072 bytes [18:53 16/07/2012] [18:53 16/07/2012] F3079930C82DB5B200943FBCAF9D8CD5
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll --a---- 182144 bytes [18:53 16/07/2012] [18:53 16/07/2012] 535C6EEB62E46D1BB5A47887E58F16EA
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.ApplicationServices.dll --a---- 44920 bytes [18:53 16/07/2012] [18:53 16/07/2012] 7EE951D6B7E6016D23C8024BD5708BF1
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll --a---- 857960 bytes [18:53 16/07/2012] [18:53 16/07/2012] 5015A44944DC0807AEF926EA2D3211CB
    C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll --a---- 431984 bytes [18:51 16/07/2012] [18:51 16/07/2012] 6F317F21781E7D5914D9A1E8F52B4F84
    C:\Windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll --a---- 11112 bytes [20:46 13/07/2009] [21:22 10/06/2009] 12C7E5852D3ADB85F23CD90C810A1805
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll --a---- 401408 bytes [20:11 16/07/2012] [01:58 05/11/2010] AF1F47FBADABB9134002359970F5FD1C
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll --a---- 188416 bytes [20:46 13/07/2009] [21:23 10/06/2009] EE1DCDAA3EA8F53DA56116875CD01653
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll --a---- 258048 bytes [20:11 16/07/2012] [01:58 05/11/2010] 6DB969DF540BC71722848940D180AC08
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll --a---- 54144 bytes [20:46 13/07/2009] [21:23 10/06/2009] 6058809BBD4515A5EAF22336AF245150
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb --a---- 40960 bytes [20:46 13/07/2009] [21:23 10/06/2009] A0920D54C4F4DCF5C70A5F277740EAAA
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll --a---- 113664 bytes [20:11 16/07/2012] [04:12 20/11/2010] C865DC05ADE0B41A9E14DD585E0CDF94
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll --a---- 839680 bytes [20:12 16/07/2012] [01:58 05/11/2010] 8C0B098B41A27B08D58CAE7A61A3BA19
    C:\Windows\Microsoft.NET\Framework\v3.5\WFServicesReg.exe --a---- 193368 bytes [21:09 13/07/2009] [21:14 10/06/2009] 9001B463C2108F3B05A1A9285512C749
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.Client.dll --a---- 436600 bytes [10:16 18/03/2010] [10:16 18/03/2010] F7FDD963EC0DB59437CA637475110D33
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.Design.dll --a---- 178040 bytes [13:47 18/03/2010] [13:47 18/03/2010] 59E3A44249D12758566B9A58C28FAEC0
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.Services.dll --a---- 683368 bytes [13:47 18/03/2010] [13:47 18/03/2010] 65BBC872E434FF876AB82046CB108C35
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.AccountManagement.dll --a---- 285072 bytes [10:16 18/03/2010] [10:16 18/03/2010] F3079930C82DB5B200943FBCAF9D8CD5
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.dll --a---- 395120 bytes [10:16 18/03/2010] [10:16 18/03/2010] 5CD0E30C15DDFC47199F864F7334B86F
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.DirectoryServices.Protocols.dll --a---- 182144 bytes [10:16 18/03/2010] [10:16 18/03/2010] 535C6EEB62E46D1BB5A47887E58F16EA
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.dll --a---- 246128 bytes [10:16 18/03/2010] [10:16 18/03/2010] F8C1508FAF0DD3CC9A61A02BF0CEC2B6
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Thunk.dll --a---- 45952 bytes [10:16 18/03/2010] [10:16 18/03/2010] 78D1677F6400916639FC59AF6208253E
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.tlb --a---- 33280 bytes [22:08 17/03/2010] [22:08 17/03/2010] C57A8DD291A39BB74A993A783EB95EC1
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.EnterpriseServices.Wrapper.dll --a---- 109568 bytes [21:51 17/03/2010] [21:51 17/03/2010] C755E17BAC396F9A9F468320B3F6CF46
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Web.ApplicationServices.dll --a---- 44920 bytes [10:16 18/03/2010] [10:16 18/03/2010] 7EE951D6B7E6016D23C8024BD5708BF1
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Services.dll --a---- 857960 bytes [10:16 18/03/2010] [10:16 18/03/2010] 5015A44944DC0807AEF926EA2D3211CB
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.WorkflowServices.dll --a---- 431984 bytes [13:47 18/03/2010] [13:47 18/03/2010] 6F317F21781E7D5914D9A1E8F52B4F84
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.DirectoryServices.dll --a---- 401408 bytes [20:11 16/07/2012] [01:56 05/11/2010] AF1F47FBADABB9134002359970F5FD1C
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.DirectoryServices.Protocols.dll --a---- 188416 bytes [20:37 13/07/2009] [20:40 10/06/2009] EE1DCDAA3EA8F53DA56116875CD01653
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.dll --a---- 245760 bytes [20:11 16/07/2012] [01:57 05/11/2010] B395F8BE6E578FAB80A1D568911857D7
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.Thunk.dll --a---- 60272 bytes [20:37 13/07/2009] [20:40 10/06/2009] FFF957EF1040F6B4A3A2F230E96593CA
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.tlb --a---- 33280 bytes [20:37 13/07/2009] [20:40 10/06/2009] B1443345D6FB6E8E5825DF00BB3F6A3F
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.Wrapper.dll --a---- 133120 bytes [20:11 16/07/2012] [01:57 05/11/2010] D9C192B9CD25DC5C9C05DF98C945E3F1
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.Services.dll --a---- 839680 bytes [20:12 16/07/2012] [01:57 05/11/2010] 8C0B098B41A27B08D58CAE7A61A3BA19
    C:\Windows\Microsoft.NET\Framework64\v3.5\WFServicesReg.exe --a---- 279880 bytes [20:53 13/07/2009] [20:30 10/06/2009] 2B36976B7C35846EC551A0995BCC67C9
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.Client.dll --a---- 436600 bytes [10:16 18/03/2010] [10:16 18/03/2010] F7FDD963EC0DB59437CA637475110D33
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.Design.dll --a---- 178040 bytes [13:47 18/03/2010] [13:47 18/03/2010] 59E3A44249D12758566B9A58C28FAEC0
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Data.Services.dll --a---- 683368 bytes [13:47 18/03/2010] [13:47 18/03/2010] 65BBC872E434FF876AB82046CB108C35
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.AccountManagement.dll --a---- 285072 bytes [10:16 18/03/2010] [10:16 18/03/2010] F3079930C82DB5B200943FBCAF9D8CD5
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.dll --a---- 395120 bytes [10:16 18/03/2010] [10:16 18/03/2010] 5CD0E30C15DDFC47199F864F7334B86F
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.DirectoryServices.Protocols.dll --a---- 182144 bytes [10:16 18/03/2010] [10:16 18/03/2010] 535C6EEB62E46D1BB5A47887E58F16EA
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.dll --a---- 237424 bytes [11:27 18/03/2010] [11:27 18/03/2010] 4B091BA37D2D8E336822CA223EA4F48C
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.Thunk.dll --a---- 52608 bytes [11:27 18/03/2010] [11:27 18/03/2010] B320B9C60DC9DCB77D13EAB140777337
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.tlb --a---- 33280 bytes [02:57 18/03/2010] [02:57 18/03/2010] 50B34D6ACBCB815C6E1397127CC1A650
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.EnterpriseServices.Wrapper.dll --a---- 125440 bytes [02:46 18/03/2010] [02:46 18/03/2010] 9A1563235169C94DFF5A541774CCCD6B
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.ApplicationServices.dll --a---- 44920 bytes [10:16 18/03/2010] [10:16 18/03/2010] 7EE951D6B7E6016D23C8024BD5708BF1
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Services.dll --a---- 857960 bytes [10:16 18/03/2010] [10:16 18/03/2010] 5015A44944DC0807AEF926EA2D3211CB
    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\System.WorkflowServices.dll --a---- 431984 bytes [13:47 18/03/2010] [13:47 18/03/2010] 6F317F21781E7D5914D9A1E8F52B4F84
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 7878 bytes [05:36 14/07/2009] [03:50 14/07/2009] 156814110DD07FAF80936653678A7262
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1868 bytes [05:36 14/07/2009] [02:30 14/07/2009] 9161CC906A7A533BEF8B6A01E1C59168
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 8296 bytes [19:49 16/07/2012] [12:07 20/11/2010] 2C3D101084366480759B1FDCF48AE1D0
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1846 bytes [19:49 16/07/2012] [11:40 20/11/2010] 6E4ADFF375925479D564BD57DB943F79
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9924 bytes [05:29 14/07/2009] [03:01 14/07/2009] 27817423AB2699DE514BF415B9679F1B
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1430 bytes [05:29 14/07/2009] [20:54 13/07/2009] B46AC42FD97990BD3A52E83F2A8C06BF
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 12098 bytes [19:48 16/07/2012] [13:37 20/11/2010] 80621C130070DF202A03D31244F788AF
    C:\Windows\servicing\Packages\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1444 bytes [19:48 16/07/2012] [13:22 20/11/2010] 478684B9383BF9FF9ED8A88AEEC0E036
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 13524 bytes [05:36 14/07/2009] [03:50 14/07/2009] 2DAC4E2BB9DB37F27B5E4ABC5A1A4139
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1348 bytes [05:36 14/07/2009] [02:30 14/07/2009] 95ECA6F8804FAAFDB7B9CBDD70403C37
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 13942 bytes [19:49 16/07/2012] [11:59 20/11/2010] D9C2C659DB16C761DAE4FBCEAF46A832
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1368 bytes [19:49 16/07/2012] [11:40 20/11/2010] C299A9AAD8DDB3D4BE55C919BD26BA3A
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 13524 bytes [05:29 14/07/2009] [03:01 14/07/2009] 568FAA79D8110809F563A854CE3B995F
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1286 bytes [05:29 14/07/2009] [20:46 13/07/2009] 38852413FA56D3769B3BDE084D1577AD
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 18694 bytes [19:48 16/07/2012] [13:39 20/11/2010] 981965A949FAC351CC9A3BBB28A08F71
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1310 bytes [19:48 16/07/2012] [13:22 20/11/2010] 9351C96218CEA9E9A7C13ABC3170DBFD
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 10535 bytes [05:36 14/07/2009] [03:50 14/07/2009] DE1C34D5E691B1BF8306CF004BE85797
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1367 bytes [05:36 14/07/2009] [02:30 14/07/2009] ADEB5C81F3BD63F18F1F1633F2601A85
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 10938 bytes [19:49 16/07/2012] [11:59 20/11/2010] 8639374548FFD5330B22F76239B00D7A
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1387 bytes [19:49 16/07/2012] [11:40 20/11/2010] 1AF72B447B51DF000EB7CB6B39EA5F95
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 14902 bytes [05:29 14/07/2009] [03:01 14/07/2009] 6A7078D23AB5B59025D129444E682114
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1284 bytes [05:29 14/07/2009] [20:46 13/07/2009] 8A25EB8F3943140FFD573023684AFE5E
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 21419 bytes [19:49 16/07/2012] [13:39 20/11/2010] B7279F5D07E5449C02878CA55D3D2402
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1308 bytes [19:49 16/07/2012] [13:22 20/11/2010] D05D7B55258CBEAA1E21ECCDB1E213D7
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 8771 bytes [05:36 14/07/2009] [03:49 14/07/2009] FA5DAA201350BEBF0A790C032D110105
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1386 bytes [05:36 14/07/2009] [02:30 14/07/2009] 4C26CF7DCD09F28D1C0CA841435EED51
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 10044 bytes [19:49 16/07/2012] [11:59 20/11/2010] 8B097CC7DE945E8716FAC1B815C28391
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1406 bytes [19:49 16/07/2012] [11:40 20/11/2010] 8847861C948D8A65EDCEF91713E4D39A
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9069 bytes [05:29 14/07/2009] [03:01 14/07/2009] 76D68A1083BCA8EBD7CC334954E56618
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1308 bytes [05:29 14/07/2009] [20:46 13/07/2009] 9869C1065A62AB8182D3ECA68AB6BB77
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 10938 bytes [19:49 16/07/2012] [13:39 20/11/2010] DCC290FF240DD580E66D456EFC05F4A6
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1332 bytes [19:49 16/07/2012] [13:22 20/11/2010] 237DE9AC8F68D5F86885A5EBB16E44F7
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 9344 bytes [05:36 14/07/2009] [03:50 14/07/2009] 833618F605CE4CC4F018ABC891EA5666
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1417 bytes [05:36 14/07/2009] [02:30 14/07/2009] 2133C325196EBE9E6C821462B6D7E8AE
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 9762 bytes [19:49 16/07/2012] [11:59 20/11/2010] B4FBAFF385B98212BF55E2050F7F14BB
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1437 bytes [19:49 16/07/2012] [11:40 20/11/2010] 146BA477AE3B8F11942CE4A2EC8CE11B
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9932 bytes [05:29 14/07/2009] [03:01 14/07/2009] A8A77690EE56702798FAE69AE0491D29
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1324 bytes [05:29 14/07/2009] [20:46 13/07/2009] F2388252C7C7ED10CCDD6DF6F1B7062D
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 11526 bytes [19:49 16/07/2012] [13:39 20/11/2010] 28A0E4170ED8FD677C1C96F9EE886A01
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1348 bytes [19:49 16/07/2012] [13:22 20/11/2010] 660171EDF411829B07D92D7948EAE9C4
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 7893 bytes [05:36 14/07/2009] [03:49 14/07/2009] ED5872D40BF3DB77F12BB56780B14154
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1334 bytes [05:36 14/07/2009] [02:30 14/07/2009] F7429B4A4F7282BD05415970E56B40B3
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 8296 bytes [19:49 16/07/2012] [11:59 20/11/2010] 9D72DA39C03A917D901B1C4A0BD9BA58
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1354 bytes [19:49 16/07/2012] [11:40 20/11/2010] CB463ECD320B5AC1848713C47942D341
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 8779 bytes [05:29 14/07/2009] [03:00 14/07/2009] AD3381E61A49177768A0F0AAFCF8F581
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1253 bytes [05:29 14/07/2009] [20:46 13/07/2009] 50D1FA713494E83EAB9EC5681182835A
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 10060 bytes [19:49 16/07/2012] [13:39 20/11/2010] 26DA563D1A2EEB86456965971BE363E8
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1277 bytes [19:49 16/07/2012] [13:22 20/11/2010] 4F3529FB278E5434FEC1A31DD0C50584
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 9046 bytes [05:36 14/07/2009] [03:50 14/07/2009] E99CED0921FF970C675A5FA724193AAD
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.mum --a---- 1311 bytes [05:36 14/07/2009] [02:30 14/07/2009] 87D09004E3999903D11EA694984E249C
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat --a---- 10342 bytes [19:49 16/07/2012] [11:59 20/11/2010] C1D1F73172AE62F2F5CCC130DA54E8BE
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum --a---- 1331 bytes [19:49 16/07/2012] [11:40 20/11/2010] 70CE610A07C70BD365896C5F4875F161
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9046 bytes [05:29 14/07/2009] [03:00 14/07/2009] F7957281A8DC7CA9116848E863C5212E
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.mum --a---- 1254 bytes [05:29 14/07/2009] [20:46 13/07/2009] 7EB23BB38EB04BC437EB9CB8BC28C163
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat --a---- 10342 bytes [19:48 16/07/2012] [13:39 20/11/2010] 3B101421E59D263F64C079EA44AE526B
    C:\Windows\servicing\Packages\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.mum --a---- 1278 bytes [19:48 16/07/2012] [13:22 20/11/2010] F560AD8EA31E1F9032C48C32451C1875
    C:\Windows\System32\OpcServices.dll --a---- 1160192 bytes [20:11 16/07/2012] [12:20 20/11/2010] 37485CC09B7E6E70093A4DF62B3CC744
    C:\Windows\System32\services.msc --a---- 92745 bytes [21:44 13/07/2009] [21:21 10/06/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\System32\webservices.dll --a---- 782336 bytes [20:13 16/07/2012] [12:21 20/11/2010] DB846EECA70EE9D2E2FF31147C57B0F4
    C:\Windows\System32\xpsservices.dll --a---- 1712640 bytes [20:14 16/07/2012] [12:21 20/11/2010] 9C8E9CAAF237E8CD8BEBDE700AAFF9E0
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 7878 bytes [05:36 14/07/2009] [03:50 14/07/2009] 156814110DD07FAF80936653678A7262
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 8296 bytes [19:49 16/07/2012] [12:07 20/11/2010] 2C3D101084366480759B1FDCF48AE1D0
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9924 bytes [05:29 14/07/2009] [03:01 14/07/2009] 27817423AB2699DE514BF415B9679F1B
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-XPSServices-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 12098 bytes [19:48 16/07/2012] [13:37 20/11/2010] 80621C130070DF202A03D31244F788AF
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 13524 bytes [05:36 14/07/2009] [03:50 14/07/2009] 2DAC4E2BB9DB37F27B5E4ABC5A1A4139
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 13942 bytes [19:49 16/07/2012] [11:59 20/11/2010] D9C2C659DB16C761DAE4FBCEAF46A832
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 13524 bytes [05:29 14/07/2009] [03:01 14/07/2009] 568FAA79D8110809F563A854CE3B995F
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 18694 bytes [19:48 16/07/2012] [13:39 20/11/2010] 981965A949FAC351CC9A3BBB28A08F71
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 10535 bytes [05:36 14/07/2009] [03:50 14/07/2009] DE1C34D5E691B1BF8306CF004BE85797
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 10938 bytes [19:49 16/07/2012] [11:59 20/11/2010] 8639374548FFD5330B22F76239B00D7A
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 14902 bytes [05:29 14/07/2009] [03:01 14/07/2009] 6A7078D23AB5B59025D129444E682114
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 21419 bytes [19:49 16/07/2012] [13:39 20/11/2010] B7279F5D07E5449C02878CA55D3D2402
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 8771 bytes [05:36 14/07/2009] [03:49 14/07/2009] FA5DAA201350BEBF0A790C032D110105
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 10044 bytes [19:49 16/07/2012] [11:59 20/11/2010] 8B097CC7DE945E8716FAC1B815C28391
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9069 bytes [05:29 14/07/2009] [03:01 14/07/2009] 76D68A1083BCA8EBD7CC334954E56618
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-Publishing-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 10938 bytes [19:49 16/07/2012] [13:39 20/11/2010] DCC290FF240DD580E66D456EFC05F4A6
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 9344 bytes [05:36 14/07/2009] [03:50 14/07/2009] 833618F605CE4CC4F018ABC891EA5666
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 9762 bytes [19:49 16/07/2012] [11:59 20/11/2010] B4FBAFF385B98212BF55E2050F7F14BB
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9932 bytes [05:29 14/07/2009] [03:01 14/07/2009] A8A77690EE56702798FAE69AE0491D29
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 11526 bytes [19:49 16/07/2012] [13:39 20/11/2010] 28A0E4170ED8FD677C1C96F9EE886A01
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 7893 bytes [05:36 14/07/2009] [03:49 14/07/2009] ED5872D40BF3DB77F12BB56780B14154
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 8296 bytes [19:49 16/07/2012] [11:59 20/11/2010] 9D72DA39C03A917D901B1C4A0BD9BA58
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 8779 bytes [05:29 14/07/2009] [03:00 14/07/2009] AD3381E61A49177768A0F0AAFCF8F581
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 10060 bytes [19:49 16/07/2012] [13:39 20/11/2010] 26DA563D1A2EEB86456965971BE363E8
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7600.16385.cat --a---- 9046 bytes [05:36 14/07/2009] [03:50 14/07/2009] E99CED0921FF970C675A5FA724193AAD
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat ----s-- 10342 bytes [19:49 16/07/2012] [11:59 20/11/2010] C1D1F73172AE62F2F5CCC130DA54E8BE
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7600.16385.cat --a---- 9046 bytes [05:29 14/07/2009] [03:00 14/07/2009] F7957281A8DC7CA9116848E863C5212E
    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat ----s-- 10342 bytes [19:48 16/07/2012] [13:39 20/11/2010] 3B101421E59D263F64C079EA44AE526B
    C:\Windows\System32\en-US\services.msc --a---- 92745 bytes [05:35 14/07/2009] [02:08 14/07/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\System32\en-US\webservices.dll.mui --a---- 194048 bytes [05:35 14/07/2009] [02:08 14/07/2009] A83D3EAB50A5146B837FBB5B06326DA8
    C:\Windows\System32\LogFiles\WMI\Terminal-Services-Core.etl --a---- 9216 bytes [04:45 14/07/2009] [05:14 14/07/2009] CEFC636365D084B97C6754760DDD47F5
    C:\Windows\System32\LogFiles\WMI\Terminal-Services-IP-Virtualization.etl --a---- 3072 bytes [04:45 14/07/2009] [05:14 14/07/2009] E117BEE651A7CA4FE60F50F2A27EC28E
    C:\Windows\System32\LogFiles\WMI\Terminal-Services-RPC-Client.etl --a---- 21504 bytes [04:45 14/07/2009] [05:14 14/07/2009] F5493B3EECEA364AA01D12461B5D51E0
    C:\Windows\System32\LogFiles\WMI\Terminal-Services-Unified-APIs.etl --a---- 3072 bytes [04:45 14/07/2009] [05:14 14/07/2009] 9D4AA8233026D3859A7CAD3CF767A690
    C:\Windows\System32\migwiz\dlmanifests\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:39 13/07/2009] [21:16 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\System32\migwiz\dlmanifests\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:39 13/07/2009] [21:16 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\System32\migwiz\dlmanifests\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:39 13/07/2009] [21:16 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\System32\migwiz\dlmanifests\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:39 13/07/2009] [21:16 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\System32\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:42 10/06/2009] [21:42 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\System32\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:42 10/06/2009] [21:42 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\System32\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:42 10/06/2009] [21:42 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\System32\migwiz\dlmanifests\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [21:00 13/07/2009] [21:19 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-Drivers-DL.man --a---- 1277 bytes [21:19 10/06/2009] [21:19 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\System32\migwiz\dlmanifests\terminalservices-licenseserver-DL.man --a---- 2117 bytes [21:00 13/07/2009] [21:19 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [21:22 10/06/2009] [21:22 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [21:00 13/07/2009] [21:19 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [21:00 13/07/2009] [21:19 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [21:26 10/06/2009] [21:26 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\System32\migwiz\dlmanifests\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [21:00 13/07/2009] [21:19 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\System32\migwiz\dlmanifests\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [21:17 10/06/2009] [21:17 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\System32\migwiz\dlmanifests\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:40 10/06/2009] [21:40 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\System32\migwiz\replacementmanifests\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:39 13/07/2009] [21:16 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\System32\migwiz\replacementmanifests\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [21:19 10/06/2009] [21:19 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\System32\migwiz\replacementmanifests\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:58 13/07/2009] [21:19 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\System32\migwiz\replacementmanifests\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:58 13/07/2009] [21:19 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\System32\migwiz\replacementmanifests\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:58 13/07/2009] [21:19 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\System32\migwiz\replacementmanifests\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:58 13/07/2009] [21:19 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\System32\spp\tokens\ppdlic\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4518 bytes [20:11 16/07/2012] [12:33 20/11/2010] 8AE2AC3750FD1F2BCEE17123A4122462
    C:\Windows\System32\spp\tokens\ppdlic\TerminalServices-RemoteConnectionManager-UiEffects-ppdlic.xrm-ms --a---- 3084 bytes [01:25 14/07/2009] [01:25 14/07/2009] 13AC4873830B38C9B9FC65A3CC4155C2
    C:\Windows\SysWOW64\OpcServices.dll --a---- 1160192 bytes [20:11 16/07/2012] [12:20 20/11/2010] 37485CC09B7E6E70093A4DF62B3CC744
    C:\Windows\SysWOW64\services.msc --a---- 92745 bytes [21:44 13/07/2009] [21:21 10/06/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\SysWOW64\webservices.dll --a---- 782336 bytes [20:13 16/07/2012] [12:21 20/11/2010] DB846EECA70EE9D2E2FF31147C57B0F4
    C:\Windows\SysWOW64\xpsservices.dll --a---- 1712640 bytes [20:14 16/07/2012] [12:21 20/11/2010] 9C8E9CAAF237E8CD8BEBDE700AAFF9E0
    C:\Windows\SysWOW64\en-US\services.msc --a---- 92745 bytes [05:35 14/07/2009] [02:08 14/07/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\SysWOW64\en-US\webservices.dll.mui --a---- 194048 bytes [05:35 14/07/2009] [02:08 14/07/2009] A83D3EAB50A5146B837FBB5B06326DA8
    C:\Windows\SysWOW64\migwiz\dlmanifests\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:39 13/07/2009] [21:16 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\SysWOW64\migwiz\dlmanifests\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:39 13/07/2009] [21:16 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\SysWOW64\migwiz\dlmanifests\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:39 13/07/2009] [21:16 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\SysWOW64\migwiz\dlmanifests\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:39 13/07/2009] [21:16 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:42 10/06/2009] [21:42 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:42 10/06/2009] [21:42 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:42 10/06/2009] [21:42 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\SysWOW64\migwiz\dlmanifests\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [21:00 13/07/2009] [21:19 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-Drivers-DL.man --a---- 1277 bytes [21:19 10/06/2009] [21:19 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\SysWOW64\migwiz\dlmanifests\terminalservices-licenseserver-DL.man --a---- 2117 bytes [21:00 13/07/2009] [21:19 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [21:22 10/06/2009] [21:22 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [21:00 13/07/2009] [21:19 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [21:00 13/07/2009] [21:19 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [21:26 10/06/2009] [21:26 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\SysWOW64\migwiz\dlmanifests\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [21:00 13/07/2009] [21:19 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\SysWOW64\migwiz\dlmanifests\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [21:17 10/06/2009] [21:17 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\SysWOW64\migwiz\dlmanifests\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:40 10/06/2009] [21:40 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\SysWOW64\migwiz\replacementmanifests\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:39 13/07/2009] [21:16 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\SysWOW64\migwiz\replacementmanifests\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [21:19 10/06/2009] [21:19 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\SysWOW64\migwiz\replacementmanifests\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:58 13/07/2009] [21:19 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\SysWOW64\migwiz\replacementmanifests\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:58 13/07/2009] [21:19 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\SysWOW64\migwiz\replacementmanifests\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:58 13/07/2009] [21:19 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\SysWOW64\migwiz\replacementmanifests\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:58 13/07/2009] [21:19 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\SysWOW64\spp\tokens\ppdlic\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4518 bytes [20:11 16/07/2012] [12:33 20/11/2010] 8AE2AC3750FD1F2BCEE17123A4122462
    C:\Windows\SysWOW64\spp\tokens\ppdlic\TerminalServices-RemoteConnectionManager-UiEffects-ppdlic.xrm-ms --a---- 3084 bytes [01:25 14/07/2009] [01:25 14/07/2009] 13AC4873830B38C9B9FC65A3CC4155C2
    C:\Windows\winsxs\amd64_microsoft-windows-c..t-xpsomandstreaming_31bf3856ad364e35_6.1.7600.16385_none_0b0d6c20fed24b6d\xpsservices.dll --a---- 3008000 bytes [00:45 14/07/2009] [01:41 14/07/2009] 633E9EDFD5EB952EAADF5BAFDBD655B6
    C:\Windows\winsxs\amd64_microsoft-windows-c..t-xpsomandstreaming_31bf3856ad364e35_6.1.7601.17514_none_0d3e7fe8fbc0cf07\xpsservices.dll --a---- 3008000 bytes [20:15 16/07/2012] [13:27 20/11/2010] 3D840598CECAAE8470804918EE5A00B5
    C:\Windows\winsxs\amd64_microsoft-windows-component-opcom_31bf3856ad364e35_6.1.7600.16385_none_ff2bf37acc42094f\OpcServices.dll --a---- 1911808 bytes [00:43 14/07/2009] [01:41 14/07/2009] 2038E1FD0371FA49F7401DC20ACA2BCC
    C:\Windows\winsxs\amd64_microsoft-windows-component-opcom_31bf3856ad364e35_6.1.7601.17514_none_015d0742c9308ce9\OpcServices.dll --a---- 1911808 bytes [20:11 16/07/2012] [13:27 20/11/2010] 03DC34242009D26061A4B1E91DF51C9B
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:31 13/07/2009] [20:31 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:31 13/07/2009] [20:31 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:31 13/07/2009] [20:31 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:31 13/07/2009] [20:31 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:03 10/06/2009] [21:03 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:03 10/06/2009] [21:03 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:04 10/06/2009] [21:04 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [20:47 13/07/2009] [20:37 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-Drivers-DL.man --a---- 1277 bytes [20:37 10/06/2009] [20:37 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\terminalservices-licenseserver-DL.man --a---- 2117 bytes [20:47 13/07/2009] [20:37 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [20:40 10/06/2009] [20:40 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [20:47 13/07/2009] [20:37 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [20:47 13/07/2009] [20:37 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [20:44 10/06/2009] [20:44 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [20:47 13/07/2009] [20:37 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [20:31 10/06/2009] [20:31 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_5e6da7259d4ac682\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:00 10/06/2009] [21:00 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:31 13/07/2009] [20:31 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:31 13/07/2009] [20:31 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:31 13/07/2009] [20:31 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:31 13/07/2009] [20:31 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:03 10/06/2009] [21:03 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:03 10/06/2009] [21:03 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:04 10/06/2009] [21:04 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [20:47 13/07/2009] [20:37 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-Drivers-DL.man --a---- 1277 bytes [20:37 10/06/2009] [20:37 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\terminalservices-licenseserver-DL.man --a---- 2117 bytes [20:47 13/07/2009] [20:37 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [20:40 10/06/2009] [20:40 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [20:47 13/07/2009] [20:37 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [20:47 13/07/2009] [20:37 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [20:44 10/06/2009] [20:44 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [20:47 13/07/2009] [20:37 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [20:31 10/06/2009] [20:31 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:00 10/06/2009] [21:00 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:31 13/07/2009] [20:31 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [20:37 10/06/2009] [20:37 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:45 13/07/2009] [20:37 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:45 13/07/2009] [20:37 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:45 13/07/2009] [20:37 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_57e94db50528923a\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:45 13/07/2009] [20:37 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:31 13/07/2009] [20:31 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [20:37 10/06/2009] [20:37 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:45 13/07/2009] [20:37 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:45 13/07/2009] [20:37 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:45 13/07/2009] [20:37 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:45 13/07/2009] [20:37 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\winsxs\amd64_microsoft-windows-m..providers.resources_31bf3856ad364e35_6.1.7600.16385_en-us_b823e4c5e86dde32\AuxiliaryDisplayServices.dll.mui --a---- 4096 bytes [05:35 14/07/2009] [02:30 14/07/2009] 3D6746327BFADF0C7F73AA8D02A962F4
    C:\Windows\winsxs\amd64_microsoft-windows-m..systemdataproviders_31bf3856ad364e35_6.1.7600.16385_none_6436124fb636fa27\AuxiliaryDisplayServices.dll --a---- 135680 bytes [00:00 14/07/2009] [01:40 14/07/2009] 24C3DB60058CFE73A53198CA708CF42A
    C:\Windows\winsxs\amd64_microsoft-windows-m..systemdataproviders_31bf3856ad364e35_6.1.7600.16385_none_6436124fb636fa27\auxiliarydisplayservices.mof --a---- 3039 bytes [20:31 10/06/2009] [20:31 10/06/2009] 55CDB0BF117EC597F3B1065CDADE98DB
    C:\Windows\winsxs\amd64_microsoft-windows-m..systemdataproviders_31bf3856ad364e35_6.1.7601.17514_none_66672617b3257dc1\AuxiliaryDisplayServices.dll --a---- 135680 bytes [20:12 16/07/2012] [13:25 20/11/2010] AE67E6224419C1A88800DF29E6A95F88
    C:\Windows\winsxs\amd64_microsoft-windows-m..systemdataproviders_31bf3856ad364e35_6.1.7601.17514_none_66672617b3257dc1\auxiliarydisplayservices.mof --a---- 3039 bytes [20:31 10/06/2009] [20:31 10/06/2009] 55CDB0BF117EC597F3B1065CDADE98DB
    C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc --a---- 92745 bytes [05:35 14/07/2009] [02:23 14/07/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui --a---- 17408 bytes [05:35 14/07/2009] [02:25 14/07/2009] 6507BF0DC2D1F5F32493C288EAA59277
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe --a---- 328704 bytes [23:19 13/07/2009] [01:39 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof --a---- 2866 bytes [20:44 10/06/2009] [20:44 10/06/2009] 26A11C895A7F0B6D32105EBE127D8500
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml --a---- 1061 bytes [20:16 13/07/2009] [20:16 13/07/2009] 640D7DD61B1CFA6C96F80F68F78CDFA7
    C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc --a---- 92745 bytes [21:34 13/07/2009] [20:38 10/06/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\winsxs\amd64_microsoft-windows-t..d-chinese-shuangpin_31bf3856ad364e35_6.1.7600.16385_none_7aab2462f08e2d02\TableTextServiceSimplifiedShuangPin.txt --a---- 1445430 bytes [21:25 13/07/2009] [21:04 10/06/2009] 51B31EB324CB5C6936D7A14D49B0BD67
    C:\Windows\winsxs\amd64_microsoft-windows-t..edirection-licenses_31bf3856ad364e35_6.1.7600.16385_none_a73503c5cc87655b\TerminalServices-DeviceRedirection-Licenses-ppdlic.xrm-ms --a---- 3375 bytes [01:53 14/07/2009] [01:53 14/07/2009] 4DE3C2190B1DAC1486949271FD6A280C
    C:\Windows\winsxs\amd64_microsoft-windows-t..ied-chinese-quanpin_31bf3856ad364e35_6.1.7600.16385_none_53b99503d9f5dfe1\TableTextServiceSimplifiedQuanPin.txt --a---- 1665878 bytes [21:25 13/07/2009] [21:04 10/06/2009] 532ED87BB64CF19C58AE0F91FA439983
    C:\Windows\winsxs\amd64_microsoft-windows-t..ied-chinese-zhengma_31bf3856ad364e35_6.1.7600.16385_none_bf4b6db34317721d\TableTextServiceSimplifiedZhengMa.txt --a---- 1810352 bytes [21:25 13/07/2009] [21:04 10/06/2009] 6D2BE04D9605C2D479E3CD205C406D7C
    C:\Windows\winsxs\amd64_microsoft-windows-t..lications-clientsku_31bf3856ad364e35_6.1.7600.16385_none_7ad012005fd49990\TerminalServices-RemoteApplications-ClientSku-ppdlic.xrm-ms --a---- 3067 bytes [01:53 14/07/2009] [01:53 14/07/2009] 64C9EF528365FA88C242788284CDEE52
    C:\Windows\winsxs\amd64_microsoft-windows-t..lications-clientsku_31bf3856ad364e35_6.1.7601.17514_none_7d0125c85cc31d2a\TerminalServices-RemoteApplications-ClientSku-ppdlic.xrm-ms --a---- 3067 bytes [01:53 14/07/2009] [01:53 14/07/2009] 64C9EF528365FA88C242788284CDEE52
    C:\Windows\winsxs\amd64_microsoft-windows-t..onmanager-uieffects_31bf3856ad364e35_6.1.7600.16385_none_535bb613109cd074\TerminalServices-RemoteConnectionManager-UiEffects-ppdlic.xrm-ms --a---- 3084 bytes [01:53 14/07/2009] [01:53 14/07/2009] 554E4EDFB12C4760E1305C451C88D07E
    C:\Windows\winsxs\amd64_microsoft-windows-t..tionmanager-license_31bf3856ad364e35_6.1.7600.16385_none_54f48e43e8d3903b\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4420 bytes [01:53 14/07/2009] [01:53 14/07/2009] B35A8385D0C28BEADF4837E3F7D668A8
    C:\Windows\winsxs\amd64_microsoft-windows-t..tionmanager-license_31bf3856ad364e35_6.1.7601.17514_none_5725a20be5c213d5\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4518 bytes [20:11 16/07/2012] [13:39 20/11/2010] DC84D07D2BAF14403645E08C3F001A15
    C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services --a---- 17463 bytes [20:40 13/07/2009] [21:00 10/06/2009] D9E1A01B480D961B7CF0509D597A92D6
    C:\Windows\winsxs\amd64_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6aac11498ff0f4ac\webservices.dll.mui --a---- 194048 bytes [05:35 14/07/2009] [02:29 14/07/2009] 68DD58B977B0194FEDB36FABDC3AC2FB
    C:\Windows\winsxs\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7600.16385_none_6a7149e048634679\webservices.dll --a---- 1159168 bytes [00:01 14/07/2009] [01:41 14/07/2009] A3EA403D2B74C5F71B7E8B3DAE92DE1E
    C:\Windows\winsxs\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_6ca25da84551ca13\webservices.dll --a---- 1158656 bytes [20:14 16/07/2012] [13:27 20/11/2010] C55516D98DD5D8F0153C2A9B4227DA86
    C:\Windows\winsxs\amd64_netfx-clr_sys_entservcs_thunk_dll_b03f5f7f11d50a3a_6.1.7600.16385_none_df3a1ffa5faa4434\System.EnterpriseServices.Thunk.dll --a---- 60272 bytes [20:37 13/07/2009] [20:40 10/06/2009] FFF957EF1040F6B4A3A2F230E96593CA
    C:\Windows\winsxs\amd64_netfx-system.directoryservices.protocols_b03f5f7f11d50a3a_6.1.7600.16385_none_f65534c04a41b956\System.DirectoryServices.Protocols.dll --a---- 188416 bytes [20:37 13/07/2009] [20:40 10/06/2009] EE1DCDAA3EA8F53DA56116875CD01653
    C:\Windows\winsxs\amd64_netfx-system.directoryservices_b03f5f7f11d50a3a_6.1.7600.16385_none_16e1bb11a03cda57\System.DirectoryServices.dll --a---- 401408 bytes [20:37 13/07/2009] [20:40 10/06/2009] 217FD2DD18AF542143406F654A172999
    C:\Windows\winsxs\amd64_netfx-system.directoryservices_b03f5f7f11d50a3a_6.1.7601.17514_none_16b6c895a094210d\System.DirectoryServices.dll --a---- 401408 bytes [20:11 16/07/2012] [01:56 05/11/2010] AF1F47FBADABB9134002359970F5FD1C
    C:\Windows\winsxs\amd64_netfx-system.web.services_b03f5f7f11d50a3a_6.1.7600.16385_none_f8b72150e4a181a2\System.Web.Services.dll --a---- 839680 bytes [20:37 13/07/2009] [20:40 10/06/2009] 8C003C74490965809C31872AD37AB3D0
    C:\Windows\winsxs\amd64_netfx-system.web.services_b03f5f7f11d50a3a_6.1.7601.17514_none_f88c2ed4e4f8c858\System.Web.Services.dll --a---- 839680 bytes [20:12 16/07/2012] [01:57 05/11/2010] 8C0B098B41A27B08D58CAE7A61A3BA19
    C:\Windows\winsxs\amd64_netfx-sys_enterpriseservices_tlb_b03f5f7f11d50a3a_6.1.7600.16385_none_a8a4035909e14dff\System.EnterpriseServices.tlb --a---- 33280 bytes [20:37 13/07/2009] [20:40 10/06/2009] B1443345D6FB6E8E5825DF00BB3F6A3F
    C:\Windows\winsxs\amd64_netfx35cdf-csd_cdf_installer_31bf3856ad364e35_6.1.7600.16385_none_b45109ec45a678fc\WFServicesReg.exe --a---- 279880 bytes [20:53 13/07/2009] [20:30 10/06/2009] 2B36976B7C35846EC551A0995BCC67C9
    C:\Windows\winsxs\amd64_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_c3db5e05024b8ce5\System.WorkflowServices.dll --a---- 479232 bytes [20:53 13/07/2009] [20:30 10/06/2009] 1E8C6A9A00F97A06E1E0E415492CAD75
    C:\Windows\winsxs\amd64_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_c60c71ccff3a107f\System.WorkflowServices.dll --a---- 479232 bytes [20:14 16/07/2012] [01:52 05/11/2010] 2970705DC9080AE0932BD4CB4A63F343
    C:\Windows\winsxs\amd64_netfx35linq-system...s.accountmanagement_31bf3856ad364e35_6.1.7600.16385_none_dae31ab1a97a0968\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:54 13/07/2009] [20:30 10/06/2009] 9E81016205AB5765135B690F630F32CA
    C:\Windows\winsxs\amd64_netfx35linq-system...s.accountmanagement_31bf3856ad364e35_6.1.7601.17514_none_dd142e79a6688d02\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] 7008BDA459F4D54E01064C1195BF7542
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7600.16385_none_2a0ef8205af8ab02\System.Data.Services.Client.dll --a---- 294912 bytes [20:54 13/07/2009] [20:30 10/06/2009] 2381B995CF122855F12CB3B9DAF33FF5
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7601.17514_none_2c400be857e72e9c\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] CFC8379D9C0294EAEBF60A4E7F797202
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7600.16385_none_55c53440c7be9b37\System.Data.Services.Design.dll --a---- 114688 bytes [20:54 13/07/2009] [20:30 10/06/2009] D4C496A81FBE7110E6178B658E670D6E
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7601.17514_none_57f64808c4ad1ed1\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 9B7DD551A633887E255497E54298A468
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7600.16385_none_4b4f1fc3dd7c2acd\System.Data.Services.dll --a---- 442368 bytes [20:54 13/07/2009] [20:30 10/06/2009] F09D82EB9D5C8DE4AEB2367080334C70
    C:\Windows\winsxs\amd64_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7601.17514_none_4d80338bda6aae67\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] B7F8F89042E6FB6E66605E746977282F
    C:\Windows\winsxs\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_6280b6b155e77311\System.EnterpriseServices.dll --a---- 245760 bytes [20:37 13/07/2009] [20:40 10/06/2009] 78348CDFDB6BEC66643FA947A9889535
    C:\Windows\winsxs\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_6280b6b155e77311\System.EnterpriseServices.Wrapper.dll --a---- 133120 bytes [20:37 13/07/2009] [20:40 10/06/2009] EB24132FC40F6A0C301539D29C63DC54
    C:\Windows\winsxs\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_6255c435563eb9c7\System.EnterpriseServices.dll --a---- 245760 bytes [20:11 16/07/2012] [01:57 05/11/2010] B395F8BE6E578FAB80A1D568911857D7
    C:\Windows\winsxs\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_6255c435563eb9c7\System.EnterpriseServices.Wrapper.dll --a---- 133120 bytes [20:11 16/07/2012] [01:57 05/11/2010] D9C192B9CD25DC5C9C05DF98C945E3F1
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_2ad2380d0ae7577e.manifest --a---- 3666 bytes [02:59 14/07/2009] [02:58 14/07/2009] 198016EAD2646F7B227C2680CDDC5775
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_2ad2380d0ae7577e_ntdsapi.dll_23e20303 --a---- 152064 bytes [02:59 14/07/2009] [02:58 14/07/2009] EE26D130808D16C0E417BBBED0451B34
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_2ad2380d0ae7577e_w32topl.dll_1a0f388b --a---- 35328 bytes [02:59 14/07/2009] [02:58 14/07/2009] 3300BC295FB80B65B745EE9A5805BAB7
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7601.17514_none_10145eccb79418a5.manifest --a---- 94460 bytes [20:50 16/07/2012] [20:46 16/07/2012] 0B7594B41364364DC073A566D2538D0A
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7601.17514_none_10145eccb79418a5_samlib.dll_caeebf04 --a---- 107008 bytes [20:50 16/07/2012] [20:46 16/07/2012] 5B3EBFC3DA142324B388DDCC4465E1FF
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7601.17514_none_10145eccb79418a5_samsrv.dll_b7a400ca --a---- 758784 bytes [20:50 16/07/2012] [20:46 16/07/2012] A744BA6E04C8AA4592818178DBF89521
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7601.17514_none_10145eccb79418a5_samsrv.mof_b7a3f662 --a---- 62541 bytes [20:50 16/07/2012] [20:46 16/07/2012] 3A7926F427B2745D678AFCB7B37AFAF2
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468_services.exe.mui_86ea5e71 --a---- 17408 bytes [05:37 14/07/2009] [05:37 14/07/2009] 6507BF0DC2D1F5F32493C288EAA59277
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1_services.exe_abfc33da --a---- 328704 bytes [02:59 14/07/2009] [02:58 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1_services.mof_abfc36b4 --a---- 2866 bytes [02:59 14/07/2009] [02:58 14/07/2009] 26A11C895A7F0B6D32105EBE127D8500
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1_services.ptxml_5928319f --a---- 1061 bytes [02:59 14/07/2009] [02:58 14/07/2009] 640D7DD61B1CFA6C96F80F68F78CDFA7
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_3b05f4d3e2a0703c.manifest --a---- 2962 bytes [20:50 16/07/2012] [20:44 16/07/2012] DCA924A6442AE5D7CC8F746BD61C6028
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_3b05f4d3e2a0703c_winsta.dll_4e6f9a4e --a---- 235008 bytes [20:50 16/07/2012] [20:44 16/07/2012] 0D9764D58C5EFD672B7184854B152E5E
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7600.16385_none_2325dd04e00642c2.manifest --a---- 2624 bytes [02:59 14/07/2009] [02:57 14/07/2009] 10616AE38D3F614AF4C01E341ED28DA5
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7600.16385_none_2325dd04e00642c2_wtsapi32.dll_470d4d41 --a---- 54272 bytes [02:59 14/07/2009] [02:57 14/07/2009] BD3674BE7FC9D8D3732C83E8499576ED
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_354c8605d3d714f3.manifest --a---- 3345 bytes [05:37 14/07/2009] [05:37 14/07/2009] 4F697666EEE3555EC22972ECE91B80A0
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_354c8605d3d714f3_sti.dll.mui_00a4f15b --a---- 6656 bytes [05:37 14/07/2009] [05:37 14/07/2009] 9367527DAF5B87770AC682F5BF6F5F2C
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_354c8605d3d714f3_wiaservc.dll.mui_54051b53 --a---- 2560 bytes [05:37 14/07/2009] [05:37 14/07/2009] 33CF243A832745F520EFF20E66692BBF
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210_services_d4a357ca --a---- 17463 bytes [02:59 14/07/2009] [02:57 14/07/2009] D9E1A01B480D961B7CF0509D597A92D6
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648.manifest --a---- 46643 bytes [20:50 16/07/2012] [20:46 16/07/2012] 9ACA2C727429C3E5F8C3079E5A1C4B90
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648_sti.dll_d93e8a42 --a---- 292352 bytes [20:50 16/07/2012] [20:46 16/07/2012] 2E483EC51216B52C711C7EC642798BB7
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648_wiarpc.dll_5aecac54 --a---- 43520 bytes [20:50 16/07/2012] [20:46 16/07/2012] 8269210DAF3B12BC8300631B28A2A442
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648_wiaservc.dll_08fa1e78 --a---- 580096 bytes [20:50 16/07/2012] [20:46 16/07/2012] 8DD52E8E6128F4B2DA92CE27402871C1
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648_wiatrace.dll_dfb4e972 --a---- 14848 bytes [20:50 16/07/2012] [20:46 16/07/2012] 0364256B4A2A93A8C8CDA6B3B5A0EFF5
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6aac11498ff0f4ac.manifest --a---- 2104 bytes [05:37 14/07/2009] [05:37 14/07/2009] 7F5D08010613799F08A1D78E37FC2FBB
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6aac11498ff0f4ac_webservices.dll.mui_eecc809d --a---- 194048 bytes [05:37 14/07/2009] [05:37 14/07/2009] 68DD58B977B0194FEDB36FABDC3AC2FB
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_6ca25da84551ca13.manifest --a---- 2728 bytes [20:50 16/07/2012] [20:46 16/07/2012] EB69E90165C0E721BFFFC619AA646D5C
    C:\Windows\winsxs\Backup\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_6ca25da84551ca13_webservices.dll_58f50a80 --a---- 1158656 bytes [20:50 16/07/2012] [20:46 16/07/2012] C55516D98DD5D8F0153C2A9B4227DA86
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7600.16385_none_1837f556ef065706.manifest --a---- 81227 bytes [02:59 14/07/2009] [02:57 14/07/2009] FE8F567B42F6322032A7CA0F3ED9141C
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7600.16385_none_1837f556ef065706_samlib.dll_caeebf04 --a---- 60928 bytes [02:59 14/07/2009] [02:57 14/07/2009] C30A3E5DEEEBA22E782AC54C5AF5F352
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7600.16385_none_1837f556ef065706_samsrv.mof_b7a3f662 --a---- 62541 bytes [02:59 14/07/2009] [02:57 14/07/2009] 3A7926F427B2745D678AFCB7B37AFAF2
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7600.16385_none_98ddd70b016524a9.manifest --a---- 43786 bytes [05:32 14/07/2009] [05:32 14/07/2009] 1A43898EFD2DF7D68CD74961084BB1CD
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7600.16385_none_98ddd70b016524a9_sti.dll_d93e8a42 --a---- 199680 bytes [05:32 14/07/2009] [05:32 14/07/2009] F2A24E4AEC0F8D5DBAB10CB87A8EFED2
    C:\Windows\winsxs\Backup\wow64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7600.16385_none_98ddd70b016524a9_wiatrace.dll_dfb4e972 --a---- 12800 bytes [05:32 14/07/2009] [05:32 14/07/2009] B087F2B901570F6EF62F6C2E01A480F3
    C:\Windows\winsxs\Backup\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_ceb39c895289e648.manifest --a---- 3662 bytes [02:59 14/07/2009] [02:57 14/07/2009] BD74FA5EBD3AEA7E7E349B62D73C4B72
    C:\Windows\winsxs\Backup\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_ceb39c895289e648_ntdsapi.dll_23e20303 --a---- 90112 bytes [02:59 14/07/2009] [02:57 14/07/2009] E3E811471DE781900FF21C1FD84E941E
    C:\Windows\winsxs\Backup\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_ceb39c895289e648_w32topl.dll_1a0f388b --a---- 26624 bytes [02:59 14/07/2009] [02:57 14/07/2009] DE518E5D4636A00A3247CB92EA61E114
    C:\Windows\winsxs\Backup\x86_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_dee759502a42ff06.manifest --a---- 2958 bytes [20:50 16/07/2012] [20:45 16/07/2012] 852C9EBA1C2702590F5154C15CECA9C3
    C:\Windows\winsxs\Backup\x86_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_dee759502a42ff06_winsta.dll_4e6f9a4e --a---- 156672 bytes [20:50 16/07/2012] [20:45 16/07/2012] 418E881201583A3039D81F43E39E6C78
    C:\Windows\winsxs\Backup\x86_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7601.17514_none_c938554924975526.manifest --a---- 2622 bytes [20:50 16/07/2012] [20:46 16/07/2012] 5EEAF895B67B74F2BF43CB841C7937FE
    C:\Windows\winsxs\Backup\x86_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7601.17514_none_c938554924975526_wtsapi32.dll_470d4d41 --a---- 40448 bytes [20:50 16/07/2012] [20:46 16/07/2012] 6A6B2EE4565A178035BE2A4FF6F2C968
    C:\Windows\winsxs\Backup\x86_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d92dea821b79a3bd.manifest --a---- 3343 bytes [05:37 14/07/2009] [05:37 14/07/2009] C42A8C5A5F95A7A4D45FB7FD13C7CD6F
    C:\Windows\winsxs\Backup\x86_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d92dea821b79a3bd_sti.dll.mui_00a4f15b --a---- 6656 bytes [05:37 14/07/2009] [05:37 14/07/2009] 37E34E74D063FDAEAC54B72641EC04C9
    C:\Windows\winsxs\Backup\x86_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d92dea821b79a3bd_wiaservc.dll.mui_54051b53 --a---- 2560 bytes [05:37 14/07/2009] [05:37 14/07/2009] 0DB339514C551F1F0FFD34F832C74F5E
    C:\Windows\winsxs\Backup\x86_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_0e8d75c5d7938376.manifest --a---- 2102 bytes [05:37 14/07/2009] [05:37 14/07/2009] 3C0DC8AD964DBE6E7A02DF1199C02EB0
    C:\Windows\winsxs\Backup\x86_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_0e8d75c5d7938376_webservices.dll.mui_eecc809d --a---- 194048 bytes [05:37 14/07/2009] [05:37 14/07/2009] A83D3EAB50A5146B837FBB5B06326DA8
    C:\Windows\winsxs\Backup\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_1083c2248cf458dd.manifest --a---- 2724 bytes [20:50 16/07/2012] [20:44 16/07/2012] 6B3ADAB5FCB23D94C27DC9403ABD8ACE
    C:\Windows\winsxs\Backup\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_1083c2248cf458dd_webservices.dll_58f50a80 --a---- 782336 bytes [20:50 16/07/2012] [20:44 16/07/2012] DB846EECA70EE9D2E2FF31147C57B0F4
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_dlmanifests_microsoft-activedirectory-webservices-dl_b2cdce29afb29e47.cdf-ms --a---- 716 bytes [05:32 14/07/2009] [05:32 14/07/2009] 25658DB4AE3706E3B4988984191094D8
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_dlmanifests_microsoft-windows-directoryservices-adam-dl_6c3018cc6f347ede.cdf-ms --a---- 720 bytes [05:32 14/07/2009] [05:32 14/07/2009] B3138D47743B803BDFD7BDF29711519C
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_dlmanifests_microsoft-windows-textservicesframework-migration-dl_549205906affe6bf.cdf-ms --a---- 1096 bytes [05:32 14/07/2009] [05:32 14/07/2009] D900A66B5115479CDB6F366931CAC7D5
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_replacementmanifests_microsoft-activedirectory-webservices_fbfc8031b6420fb6.cdf-ms --a---- 724 bytes [05:32 14/07/2009] [05:32 14/07/2009] E0FD654E384825653BD876818D11DD29
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_replacementmanifests_microsoft-windows-terminalservices-appserver-licensing_10d3d9d862990d9c.cdf-ms --a---- 740 bytes [05:32 14/07/2009] [05:32 14/07/2009] 02E58A0B7A6A23313F3FF94D1DECB963
    C:\Windows\winsxs\FileMaps\$$_system32_migwiz_replacementmanifests_microsoft-windows-terminalservices-licenseserver_cff2bf5f876a8fcd.cdf-ms --a---- 736 bytes [05:32 14/07/2009] [05:32 14/07/2009] A8AD80CFFB5A041F4D16D806E6B9F4CC
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_dlmanifests_microsoft-activedirectory-webservices-dl_01510d03ddc6bd7b.cdf-ms --a---- 712 bytes [05:32 14/07/2009] [05:32 14/07/2009] 4FE9C9594A9088FB53F4AE99F546A005
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_dlmanifests_microsoft-windows-directoryservices-adam-dl_f3fca213969e9fd8.cdf-ms --a---- 716 bytes [05:32 14/07/2009] [05:32 14/07/2009] 681A8EC1CE1A3DEF7DF269936542E16F
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_dlmanifests_microsoft-windows-textservicesframework-migration-dl_c487ba76d2956e8b.cdf-ms --a---- 1092 bytes [05:32 14/07/2009] [05:32 14/07/2009] 0EBC2D5C0C9D7A52B9CD3CB4B097E2EE
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_replacementmanifests_microsoft-activedirectory-webservices_4493d5d4ce0f5a62.cdf-ms --a---- 720 bytes [05:32 14/07/2009] [05:32 14/07/2009] CAE525C90545DB3942331C4E8ADFD64E
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_replacementmanifests_microsoft-windows-terminalservices-appserver-licensing_2d620688732de522.cdf-ms --a---- 736 bytes [05:32 14/07/2009] [05:32 14/07/2009] 09AACB12D2A4310AF6DE6362852175BE
    C:\Windows\winsxs\FileMaps\$$_syswow64_migwiz_replacementmanifests_microsoft-windows-terminalservices-licenseserver_12784e8d99d63995.cdf-ms --a---- 732 bytes [05:32 14/07/2009] [05:32 14/07/2009] 8DD858506BCE3495911E2AEFF279B3B5
    C:\Windows\winsxs\FileMaps\program_files_common_files_services_e36ba211a9258e5f.cdf-ms --a---- 596 bytes [02:59 14/07/2009] [02:59 14/07/2009] 8C5ECAA5CBC811D3DE1A043F95179EAB
    C:\Windows\winsxs\FileMaps\program_files_x86_common_files_services_6790b84ed64d877a.cdf-ms --a---- 600 bytes [02:59 14/07/2009] [02:59 14/07/2009] 89AAED3DA5AC33E762DB5A7196004400
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-commonlogservicesapi_31bf3856ad364e35_6.1.7600.16385_none_caaa1808998835c4.manifest --a---- 1797 bytes [02:33 14/07/2009] [02:26 14/07/2009] BE30BD6DDB00043124DB1C308AF8C50A
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_2ad2380d0ae7577e.manifest --a---- 3666 bytes [02:33 14/07/2009] [02:15 14/07/2009] 198016EAD2646F7B227C2680CDDC5775
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-d..services-sam-netapi_31bf3856ad364e35_6.1.7600.16385_none_e2b73230dfdc1b89.manifest --a---- 2242 bytes [02:33 14/07/2009] [02:16 14/07/2009] DE13FF857E47F91B0E1D7048BA5C6D85
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-d..services-sam-netapi_31bf3856ad364e35_6.1.7601.17514_none_e4e845f8dcca9f23.manifest ------- 2242 bytes [19:36 16/07/2012] [03:15 20/11/2010] E1FF018B918E07352D4EDB1EB69E089E
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-d..t-services-unattend_31bf3856ad364e35_6.1.7600.16385_none_25104b6dbe690465.manifest --a---- 2289 bytes [02:33 14/07/2009] [02:24 14/07/2009] 0321DA5C5C629BB8EC4D6FB66D973A58
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7600.16385_none_0de34b04baa5950b.manifest --a---- 94505 bytes [02:33 14/07/2009] [02:25 14/07/2009] 6E5A12EC456ED44FBB9BC522046DB9C6
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7601.17514_none_10145eccb79418a5.manifest ------- 94460 bytes [19:36 16/07/2012] [03:40 20/11/2010] 0B7594B41364364DC073A566D2538D0A
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7600.16385_none_195e6fab3b4f60d0.manifest --a---- 18630 bytes [02:24 14/07/2009] [02:24 14/07/2009] 58ED28D81568AB6C1AD6449FC024A38F
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7600.16590_none_194ea2193b5bf85c.manifest --a---- 18630 bytes [10:32 06/09/2010] [11:31 09/05/2010] E75F5B4FE4A47EA082D163B4EFDB9603
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7600.16648_none_198cb5eb3b2c3486.manifest ------- 18630 bytes [17:35 16/07/2012] [07:49 04/08/2010] 51FDEC28DFD203EFF207730F58D3A8FC
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7600.20710_none_1a2ec02a5438b5c5.manifest --a---- 18630 bytes [10:32 06/09/2010] [10:51 09/05/2010] C65134859EEEAD6D5213DC477C2AE3EE
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7600.20771_none_19eee0ec546876c2.manifest ------- 18630 bytes [17:35 16/07/2012] [07:55 04/08/2010] 5AF42D665B5E8F84DFCD2FA12FA65FC4
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehrecvr_31bf3856ad364e35_6.1.7601.17514_none_1b8f8373383de46a.manifest ------- 18630 bytes [19:36 16/07/2012] [03:20 20/11/2010] C925A44CA2CC3CB72081B4C851503B96
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ehome-services-ehsched_31bf3856ad364e35_6.1.7600.16385_none_0167f08155bf1c81.manifest --a---- 15629 bytes [02:25 14/07/2009] [02:25 14/07/2009] CE4F5BE083EC092F1580C54E4CAD35CD
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-live-services_31bf3856ad364e35_6.1.7600.16385_none_31a075c6a5802364.manifest --a---- 9841 bytes [02:13 14/07/2009] [02:13 14/07/2009] 29C412177E355929FBB3EB1908D65366
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-r..ityanalysisservices_31bf3856ad364e35_6.1.7600.16385_none_028d6f641b44051d.manifest --a---- 2447 bytes [02:33 14/07/2009] [02:11 14/07/2009] A7BA9A2802BB6468F226B6D1924245B0
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-r..ityanalysisservices_31bf3856ad364e35_6.1.7601.17514_none_04be832c183288b7.manifest ------- 2450 bytes [19:36 16/07/2012] [07:42 20/11/2010] EE0B96DEC6C88C77C725DA7A1671AF2E
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-recoveryservices_31bf3856ad364e35_6.1.7600.16385_none_0654603ef5512fc6.manifest --a---- 3601 bytes [02:34 14/07/2009] [02:11 14/07/2009] EB58382F99C1D3394FDE66B38A7BEA30
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-recoveryservices_31bf3856ad364e35_6.1.7601.17514_none_08857406f23fb360.manifest ------- 3616 bytes [19:36 16/07/2012] [07:42 20/11/2010] 603E1A5D62F80EE7C96FCA8C9953B74F
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c.manifest --a---- 6467 bytes [02:33 14/07/2009] [02:26 14/07/2009] 045411317E00563A2748AEB944EC6E14
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a.manifest --a---- 3451 bytes [02:33 14/07/2009] [02:22 14/07/2009] 5B07A7425C5BC353840BC9CC68CDDBC8
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-services_31bf3856ad364e35_6.1.7600.16385_none_72c47a721c36ee57.manifest --a---- 1715 bytes [02:33 14/07/2009] [02:11 14/07/2009] 37A168325AC6D6E6C9E4709A4187E927
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..alservices-lsmproxy_31bf3856ad364e35_6.1.7600.16385_none_678126e1e50e6208.manifest --a---- 20017 bytes [02:33 14/07/2009] [02:24 14/07/2009] CA51A1DA09A80D26E9CB2AFBCBFE7D91
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..alservices-lsmproxy_31bf3856ad364e35_6.1.7601.17514_none_69b23aa9e1fce5a2.manifest ------- 20848 bytes [19:36 16/07/2012] [03:19 20/11/2010] 82C003D96503AF577DEF0AA37E78BF87
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..alservices-webproxy_31bf3856ad364e35_6.1.7600.16385_none_8d6c9c807200865a.manifest --a---- 12946 bytes [02:33 14/07/2009] [02:17 14/07/2009] 77A318E866A44437F7693377DE9E180A
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..andinkinputservices_31bf3856ad364e35_6.1.7600.16385_none_78a21c7b32c3c9c9.manifest --a---- 100260 bytes [02:19 14/07/2009] [02:19 14/07/2009] 966F1C51A85A222FD597547AE06B7F03
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..andinkinputservices_31bf3856ad364e35_6.1.7601.17514_none_7ad330432fb24d63.manifest ------- 100260 bytes [19:36 16/07/2012] [03:17 20/11/2010] 6C0A982ED2B4706AC17882B2115D0CEA
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..inalservices-drprov_31bf3856ad364e35_6.1.7600.16385_none_29cdb92232f3fab5.manifest --a---- 4123 bytes [02:33 14/07/2009] [02:18 14/07/2009] 813291BF93E9C6578E6570B717532AE0
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..lservices-workspace_31bf3856ad364e35_6.1.7600.16385_none_2ce3f21173cfd0f9.manifest --a---- 49653 bytes [02:33 14/07/2009] [02:26 14/07/2009] 6579A1800C33CEDEAEBD41A2CE8A159D
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..lservices-workspace_31bf3856ad364e35_6.1.7601.17514_none_2f1505d970be5493.manifest ------- 49653 bytes [19:36 16/07/2012] [03:22 20/11/2010] AC7837FDC98B72397E6D33D1A694F77B
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.16385_none_a9d13f3c3ac896a5.manifest --a---- 20886 bytes [02:33 14/07/2009] [02:22 14/07/2009] A7937E5C1CE064A81A285292A81D4007
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.16722_none_aa0f257e3a9a9796.manifest ------- 20886 bytes [17:30 16/07/2012] [06:57 18/12/2010] BF7090B4D1A94851E44C2A0150E5A8F9
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.20861_none_aa6c824f53d98dcd.manifest ------- 20886 bytes [17:30 16/07/2012] [06:54 18/12/2010] F9572C0B12AD9D275458FB76B5E455DD
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7601.17514_none_ac02530437b71a3f.manifest ------- 20886 bytes [19:36 16/07/2012] [03:19 20/11/2010] A3655BE1E63E6BB0C1203F79A4806396
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-drivers_31bf3856ad364e35_6.1.7600.16385_none_ad4509ed102b50b5.manifest --a---- 6279 bytes [02:33 14/07/2009] [02:24 14/07/2009] 6191364891215F28253FE976C0C4A6AC
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-drivers_31bf3856ad364e35_6.1.7601.17514_none_af761db50d19d44f.manifest ------- 6234 bytes [19:36 16/07/2012] [03:40 20/11/2010] 26BC52BC81009045B79653E1B50D184E
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7600.16385_none_38d4e10be5b1eca2.manifest --a---- 2962 bytes [02:33 14/07/2009] [02:15 14/07/2009] D86BCD8FB1FABBC99116A3879E5690C3
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_3b05f4d3e2a0703c.manifest ------- 2962 bytes [19:36 16/07/2012] [03:14 20/11/2010] DCA924A6442AE5D7CC8F746BD61C6028
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-sysprep_31bf3856ad364e35_6.1.7600.16385_none_8d8e87f861f2a220.manifest --a---- 2327 bytes [02:33 14/07/2009] [02:15 14/07/2009] 75C1A0B34524B6EFA2F91537416D4C69
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..nalservices-utildll_31bf3856ad364e35_6.1.7600.16385_none_6d72db8caaefcdee.manifest --a---- 2771 bytes [02:33 14/07/2009] [02:18 14/07/2009] 23A4BB03F7E8150C95490863F07C2AF5
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7600.16385_none_2325dd04e00642c2.manifest --a---- 2624 bytes [02:33 14/07/2009] [02:16 14/07/2009] 10616AE38D3F614AF4C01E341ED28DA5
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..services-remotepage_31bf3856ad364e35_6.1.7600.16385_none_60eb835ac72a8cdd.manifest --a---- 4687 bytes [02:33 14/07/2009] [02:27 14/07/2009] 4E93341E060C5E23CD194FED7CC2D07B
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..services-remotepage_31bf3856ad364e35_6.1.7601.17514_none_631c9722c4191077.manifest ------- 4687 bytes [19:36 16/07/2012] [03:22 20/11/2010] 99A17256191973DABB4B8104FB697336
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-t..tservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6d56e46461ee1b1a.manifest --a---- 2225 bytes [05:35 14/07/2009] [02:43 14/07/2009] E70A7E12E6F487B2B566428C3F7B8F40
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-terminalservices-core_31bf3856ad364e35_6.1.7600.16385_none_467728539e995a41.manifest --a---- 735 bytes [02:33 14/07/2009] [02:12 14/07/2009] 5C0CB4D546CD4BCCC97C80D7850A6058
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-terminalservices-rdpdr_31bf3856ad364e35_6.1.7600.16385_none_5d2f015562b84a8a.manifest --a---- 4724 bytes [02:15 14/07/2009] [02:15 14/07/2009] 4233EDE3891B04B8F1F94884F239C9C8
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-terminalservices-rdpdr_31bf3856ad364e35_6.1.7601.17514_none_5f60151d5fa6ce24.manifest ------- 4724 bytes [19:36 16/07/2012] [03:14 20/11/2010] 2B90E81ED1FE3CFCD3E3384FD0A22759
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-terminalservices-rdp_31bf3856ad364e35_6.1.7600.16385_none_b8079b14d0c05352.manifest --a---- 733 bytes [02:33 14/07/2009] [02:12 14/07/2009] CFAEB280D55D4AF709EBD64984510E05
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-terminalservices-theme_31bf3856ad364e35_6.1.7600.16385_none_31db018394805d6b.manifest --a---- 7771 bytes [02:33 14/07/2009] [02:13 14/07/2009] 5C17AE3B4AD875E118387C374B8F7BBE
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_354c8605d3d714f3.manifest --a---- 3345 bytes [05:35 14/07/2009] [02:44 14/07/2009] 4F697666EEE3555EC22972ECE91B80A0
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7600.16385_none_8e892cb8cd0462ae.manifest --a---- 46784 bytes [02:15 14/07/2009] [02:15 14/07/2009] E1128C981F150A7EEF0A0FC36ABCD9AD
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7601.17514_none_90ba4080c9f2e648.manifest ------- 46643 bytes [19:36 16/07/2012] [03:40 20/11/2010] 9ACA2C727429C3E5F8C3079E5A1C4B90
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-webservices-events_31bf3856ad364e35_6.1.7600.16385_none_f49d1ef8d90c4c73.manifest --a---- 50289 bytes [02:33 14/07/2009] [02:12 14/07/2009] E0C34071DD15E5E16ED16D6B2BF65C4B
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6aac11498ff0f4ac.manifest --a---- 2104 bytes [05:35 14/07/2009] [02:44 14/07/2009] 7F5D08010613799F08A1D78E37FC2FBB
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7600.16385_none_6a7149e048634679.manifest --a---- 2728 bytes [02:33 14/07/2009] [02:19 14/07/2009] 59B71A398CFB81085F6E071320C10DBF
    C:\Windows\winsxs\Manifests\amd64_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_6ca25da84551ca13.manifest ------- 2728 bytes [19:36 16/07/2012] [03:18 20/11/2010] EB69E90165C0E721BFFFC619AA646D5C
    C:\Windows\winsxs\Manifests\amd64_netfx-system.directoryservices.protocols_b03f5f7f11d50a3a_6.1.7600.16385_none_f65534c04a41b956.manifest --a---- 2208 bytes [02:33 14/07/2009] [02:18 14/07/2009] EE0ED9C635BDED504E01207A8BCF3EDA
    C:\Windows\winsxs\Manifests\amd64_netfx-system.directoryservices_b03f5f7f11d50a3a_6.1.7600.16385_none_16e1bb11a03cda57.manifest --a---- 2168 bytes [02:33 14/07/2009] [02:16 14/07/2009] B122FF6F7D08C44F5E8E5C3D014B1B19
    C:\Windows\winsxs\Manifests\amd64_netfx-system.directoryservices_b03f5f7f11d50a3a_6.1.7601.17514_none_16b6c895a094210d.manifest ------- 2168 bytes [19:36 16/07/2012] [03:15 20/11/2010] 4B015040318050F30E04299D3AE521E0
    C:\Windows\winsxs\Manifests\amd64_netfx-system.web.services_b03f5f7f11d50a3a_6.1.7600.16385_none_f8b72150e4a181a2.manifest --a---- 2148 bytes [02:33 14/07/2009] [02:15 14/07/2009] FCF0FDC7EBF62F2B0DD3843E01A45E64
    C:\Windows\winsxs\Manifests\amd64_netfx-system.web.services_b03f5f7f11d50a3a_6.1.7601.17514_none_f88c2ed4e4f8c858.manifest ------- 2148 bytes [19:36 16/07/2012] [03:14 20/11/2010] CF0E7ADA12FC9CC1DBF4FF840744B682
    C:\Windows\winsxs\Manifests\amd64_netfx-sys_enterpriseservices_tlb_b03f5f7f11d50a3a_6.1.7600.16385_none_a8a4035909e14dff.manifest --a---- 2092 bytes [02:33 14/07/2009] [02:21 14/07/2009] DEAD6F3FA543372EF3313CA7FD0A32C9
    C:\Windows\winsxs\Manifests\amd64_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_c3db5e05024b8ce5.manifest --a---- 2184 bytes [02:25 14/07/2009] [02:25 14/07/2009] E98C876A35BD515F1C92F8D7B558E07B
    C:\Windows\winsxs\Manifests\amd64_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_c60c71ccff3a107f.manifest ------- 2184 bytes [19:36 16/07/2012] [03:21 20/11/2010] 9F638139403E2A1A9BC9A51D2180E1F2
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7600.16385_none_2a0ef8205af8ab02.manifest --a---- 2205 bytes [02:26 14/07/2009] [02:26 14/07/2009] BF3BB13C9B00380F4B41BB467D84F1A6
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7601.17514_none_2c400be857e72e9c.manifest ------- 2205 bytes [19:36 16/07/2012] [03:21 20/11/2010] F560EDC0C1239A082972F44886B414D4
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7600.16385_none_55c53440c7be9b37.manifest --a---- 2205 bytes [02:17 14/07/2009] [02:17 14/07/2009] EA3CC6EEB4D4EFB41B0A828AC9CCA563
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7601.17514_none_57f64808c4ad1ed1.manifest ------- 2205 bytes [19:36 16/07/2012] [03:16 20/11/2010] A0C153F385E990DE4AA3BD7C19DCA47B
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7600.16385_none_4b4f1fc3dd7c2acd.manifest --a---- 2177 bytes [02:12 14/07/2009] [02:12 14/07/2009] F0D9E1FC7B244EB9703DB03AA243022E
    C:\Windows\winsxs\Manifests\amd64_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7601.17514_none_4d80338bda6aae67.manifest ------- 2177 bytes [19:36 16/07/2012] [03:12 20/11/2010] 24C6F8769A0F7E1B70B5508674341CA8
    C:\Windows\winsxs\Manifests\amd64_system.enterpriseservices.tlb_31bf3856ad364e35_6.1.7600.16385_none_11fa12a35622b98c.manifest --a---- 58227 bytes [02:33 14/07/2009] [02:11 14/07/2009] 67FDC9E3AD85BFFD66EF0D921A2C7D9B
    C:\Windows\winsxs\Manifests\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_6280b6b155e77311.manifest --a---- 28020 bytes [02:33 14/07/2009] [02:23 14/07/2009] 4FC2FC2BAB505033FEC0F5A1877D1328
    C:\Windows\winsxs\Manifests\amd64_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_6255c435563eb9c7.manifest ------- 28020 bytes [19:36 16/07/2012] [03:19 20/11/2010] 383C1C8E3A4E61718BF24FC8785CE0E5
    C:\Windows\winsxs\Manifests\msil_system.data.services.client.resources_b77a5c561934e089_6.1.7600.16385_en-us_60ac92ba65dfe140.manifest --a---- 577 bytes [05:35 14/07/2009] [02:42 14/07/2009] AF24B9BBB6535B69C960D1D4AB22854C
    C:\Windows\winsxs\Manifests\msil_system.data.services.client_b77a5c561934e089_6.1.7600.16385_none_ef59273eec19d069.manifest --a---- 1933 bytes [01:50 14/07/2009] [01:50 14/07/2009] 85B2A0C7C2AD4D412E56F418BDAD4995
    C:\Windows\winsxs\Manifests\msil_system.data.services.client_b77a5c561934e089_6.1.7601.17514_none_f18a3b06e9085403.manifest ------- 1933 bytes [19:35 16/07/2012] [02:04 20/11/2010] C92DBBAAB50775303361B729C6C89B3E
    C:\Windows\winsxs\Manifests\msil_system.data.services.design.resources_b77a5c561934e089_6.1.7600.16385_en-us_91cbb651035b5d8f.manifest --a---- 577 bytes [05:35 14/07/2009] [02:42 14/07/2009] 16053D3EF21E5694DA11D16DD3DC8E29
    C:\Windows\winsxs\Manifests\msil_system.data.services.design_b77a5c561934e089_6.1.7600.16385_none_1b0f635f58dfc09e.manifest --a---- 1933 bytes [01:55 14/07/2009] [01:55 14/07/2009] 0A8A1D52681BBD63F5E95DEFCBB740B7
    C:\Windows\winsxs\Manifests\msil_system.data.services.design_b77a5c561934e089_6.1.7601.17514_none_1d40772755ce4438.manifest ------- 1933 bytes [19:35 16/07/2012] [02:08 20/11/2010] BB25D783CC2705B42B189D05D8C358DB
    C:\Windows\winsxs\Manifests\msil_system.data.services.resources_b77a5c561934e089_6.1.7600.16385_en-us_6696ed7980c4b777.manifest --a---- 563 bytes [05:35 14/07/2009] [02:42 14/07/2009] 97DE1A87130A2E2F2C93B569D5BC5E6A
    C:\Windows\winsxs\Manifests\msil_system.data.services_b77a5c561934e089_6.1.7600.16385_none_fdadd025d6080082.manifest --a---- 1898 bytes [01:58 14/07/2009] [01:58 14/07/2009] 9FFCE12A6CDB14C2C7C3C6E8D2A8E24F
    C:\Windows\winsxs\Manifests\msil_system.data.services_b77a5c561934e089_6.1.7601.17514_none_ffdee3edd2f6841c.manifest ------- 1898 bytes [19:35 16/07/2012] [02:11 20/11/2010] 6C7DDE4BA093A0A3BDE59AC0B1F92A6D
    C:\Windows\winsxs\Manifests\msil_system.directoryservices.protocols_b03f5f7f11d50a3a_6.1.7600.16385_none_83a19ecc10aa89e7.manifest --a---- 2727 bytes [02:33 14/07/2009] [01:52 14/07/2009] 834AD6E683D72F4EA471BC56857F9871
    C:\Windows\winsxs\Manifests\msil_system.directoryservices.resources_b03f5f7f11d50a3a_6.1.7600.16385_en-us_0de147968fe2ebf3.manifest --a---- 487 bytes [05:35 14/07/2009] [02:42 14/07/2009] FA5FC517FAD292758E26D4B41ABCF5D1
    C:\Windows\winsxs\Manifests\msil_system.directoryservices_b03f5f7f11d50a3a_6.1.7600.16385_none_2b25936fedbeb29c.manifest --a---- 2677 bytes [02:33 14/07/2009] [01:54 14/07/2009] EF3F9658DFEC298622E1687570D8A6B9
    C:\Windows\winsxs\Manifests\msil_system.directoryservices_b03f5f7f11d50a3a_6.1.7601.17514_none_2afaa0f3ee15f952.manifest ------- 2677 bytes [19:35 16/07/2012] [02:07 20/11/2010] 4BF82B28058309A911769E08B6791657
    C:\Windows\winsxs\Manifests\msil_system.enterpriseservices.resources_b03f5f7f11d50a3a_6.1.7600.16385_en-us_3e7ada89ceea3db5.manifest --a---- 489 bytes [05:35 14/07/2009] [02:42 14/07/2009] DC02A61B041B218D855C8E08302EBCCE
    C:\Windows\winsxs\Manifests\msil_system.web.services.resources_b03f5f7f11d50a3a_6.1.7600.16385_en-us_da88eb0b7fad6d92.manifest --a---- 477 bytes [05:35 14/07/2009] [02:42 14/07/2009] B9394B7442B2E98B20DFF504A11F9DFF
    C:\Windows\winsxs\Manifests\msil_system.web.services_b03f5f7f11d50a3a_6.1.7600.16385_none_c74cebec6e652ac7.manifest --a---- 2652 bytes [02:33 14/07/2009] [01:58 14/07/2009] 068934736908E42C9E657DB78FBB386C
    C:\Windows\winsxs\Manifests\msil_system.web.services_b03f5f7f11d50a3a_6.1.7601.17514_none_c721f9706ebc717d.manifest ------- 2652 bytes [19:35 16/07/2012] [02:11 20/11/2010] 67C8817BA0CE4A988A80AF5B9AF15B24
    C:\Windows\winsxs\Manifests\msil_system.workflowservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_9c0a1bcbd00b0690.manifest --a---- 567 bytes [05:35 14/07/2009] [02:42 14/07/2009] F4B1B64F40F35D6E07C3F654D9AB69B6
    C:\Windows\winsxs\Manifests\msil_system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_e3c597b829f3bac9.manifest --a---- 1910 bytes [01:47 14/07/2009] [01:47 14/07/2009] 0805620713A879FD292AEE666AAEE68E
    C:\Windows\winsxs\Manifests\msil_system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_e5f6ab8026e23e63.manifest ------- 1910 bytes [19:35 16/07/2012] [02:02 20/11/2010] 0B8AC2260BAFE28486340F7391F43551
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.1.7600.16385_none_1837f556ef065706.manifest --a---- 81227 bytes [02:33 14/07/2009] [01:44 14/07/2009] FE8F567B42F6322032A7CA0F3ED9141C
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-r..ityanalysisservices_31bf3856ad364e35_6.1.7600.16385_none_0ce219b64fa4c718.manifest --a---- 2064 bytes [02:33 14/07/2009] [01:42 14/07/2009] CAC046AB824F4EFC8EC799C26873E7D5
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-r..ityanalysisservices_31bf3856ad364e35_6.1.7601.17514_none_0f132d7e4c934ab2.manifest ------- 2067 bytes [19:35 16/07/2012] [07:42 20/11/2010] 3A94487A9144D83673568E6A5517816E
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..andinkinputservices_31bf3856ad364e35_6.1.7600.16385_none_82f6c6cd67248bc4.manifest --a---- 100260 bytes [01:43 14/07/2009] [01:43 14/07/2009] 4320DC65D2260458F3EF8F5E7E758AE5
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..lservices-workspace_31bf3856ad364e35_6.1.7600.16385_none_37389c63a83092f4.manifest --a---- 43601 bytes [02:33 14/07/2009] [01:43 14/07/2009] 581052983B3B8FD5111C64E30367F266
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..lservices-workspace_31bf3856ad364e35_6.1.7601.17514_none_3969b02ba51f168e.manifest ------- 43601 bytes [19:35 16/07/2012] [01:59 20/11/2010] B7CB4167A3C9A14E20D241FE55F03172
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.16385_none_b425e98e6f2958a0.manifest --a---- 13023 bytes [02:33 14/07/2009] [01:43 14/07/2009] 35AC3EF3A3FF3A296BD41635FB70B10B
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.16722_none_b463cfd06efb5991.manifest ------- 13023 bytes [17:30 16/07/2012] [05:59 18/12/2010] B37712141BBC2D68A3D7270CADA40963
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7600.20861_none_b4c12ca1883a4fc8.manifest ------- 13023 bytes [17:30 16/07/2012] [05:51 18/12/2010] 324DCF5AEF7B210CF21304766A074618
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_6.1.7601.17514_none_b656fd566c17dc3a.manifest ------- 13023 bytes [19:35 16/07/2012] [01:59 20/11/2010] E56592E854DFA51AC01833C1E9D02023
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-t..tservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_77ab8eb6964edd15.manifest --a---- 2225 bytes [05:35 14/07/2009] [02:28 14/07/2009] 79B40023056395F3A76F47BE9E68E497
    C:\Windows\winsxs\Manifests\wow64_microsoft-windows-w..sition-coreservices_31bf3856ad364e35_6.1.7600.16385_none_98ddd70b016524a9.manifest --a---- 43786 bytes [01:43 14/07/2009] [01:43 14/07/2009] 1A43898EFD2DF7D68CD74961084BB1CD
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-commonlogservicesapi_31bf3856ad364e35_6.1.7600.16385_none_6e8b7c84e12ac48e.manifest --a---- 1795 bytes [02:33 14/07/2009] [01:57 14/07/2009] 93DAC711F0B8F4B363FF69C9BC9E9090
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.1.7600.16385_none_ceb39c895289e648.manifest --a---- 3662 bytes [02:33 14/07/2009] [01:49 14/07/2009] BD74FA5EBD3AEA7E7E349B62D73C4B72
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-d..services-sam-netapi_31bf3856ad364e35_6.1.7600.16385_none_869896ad277eaa53.manifest --a---- 2240 bytes [02:33 14/07/2009] [01:50 14/07/2009] 871A8D9E88C979C9EA7A8E21870A5092
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-d..services-sam-netapi_31bf3856ad364e35_6.1.7601.17514_none_88c9aa75246d2ded.manifest ------- 2240 bytes [19:35 16/07/2012] [02:04 20/11/2010] 1257F7A3C39803D02238410418468C60
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-live-services_31bf3856ad364e35_6.1.7600.16385_none_d581da42ed22b22e.manifest --a---- 9839 bytes [01:48 14/07/2009] [01:48 14/07/2009] 1FDFD0967461D4D27C5840C3A7C47522
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356.manifest --a---- 6333 bytes [02:33 14/07/2009] [01:57 14/07/2009] 7F022A0569EB657173EFCD79865259A0
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54.manifest --a---- 3447 bytes [02:33 14/07/2009] [01:54 14/07/2009] 00267EC7D3DE2B1EF982350EDB51162C
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..alservices-lsmproxy_31bf3856ad364e35_6.1.7600.16385_none_0b628b5e2cb0f0d2.manifest --a---- 20015 bytes [02:33 14/07/2009] [01:55 14/07/2009] 7D330D94B35458806F2BF1AFCF98229F
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..alservices-lsmproxy_31bf3856ad364e35_6.1.7601.17514_none_0d939f26299f746c.manifest ------- 20846 bytes [19:35 16/07/2012] [02:08 20/11/2010] 79DD838D8C1DAA365C0993F29508C307
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..inalservices-drprov_31bf3856ad364e35_6.1.7600.16385_none_cdaf1d9e7a96897f.manifest --a---- 4119 bytes [02:33 14/07/2009] [01:52 14/07/2009] 33E85C48FD84A4BDE66B565C3BD3D526
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7600.16385_none_dcb645882d547b6c.manifest --a---- 2958 bytes [02:33 14/07/2009] [01:50 14/07/2009] D67214CCC59DCF7E65A3FDA35CADD1F2
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..nalservices-runtime_31bf3856ad364e35_6.1.7601.17514_none_dee759502a42ff06.manifest ------- 2958 bytes [19:35 16/07/2012] [02:04 20/11/2010] 852C9EBA1C2702590F5154C15CECA9C3
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..nalservices-sysprep_31bf3856ad364e35_6.1.7600.16385_none_316fec74a99530ea.manifest --a---- 2325 bytes [02:33 14/07/2009] [01:49 14/07/2009] FA618FB0F06AE6981FFAB0DDAA1D3B4D
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..nalservices-utildll_31bf3856ad364e35_6.1.7600.16385_none_11544008f2925cb8.manifest --a---- 2767 bytes [02:33 14/07/2009] [01:53 14/07/2009] D0D69F12918E97F9519349A0B90F6307
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..nalservices-utildll_31bf3856ad364e35_6.1.7601.17514_none_138553d0ef80e052.manifest ------- 2767 bytes [19:35 16/07/2012] [02:06 20/11/2010] DB973718D46FAF217E53FCD5866A6414
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7600.16385_none_c707418127a8d18c.manifest --a---- 2622 bytes [02:33 14/07/2009] [01:50 14/07/2009] 76F8E0A9906AE13F894DAC2F31F00BFB
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..services-publicapis_31bf3856ad364e35_6.1.7601.17514_none_c938554924975526.manifest ------- 2622 bytes [19:35 16/07/2012] [02:04 20/11/2010] 5EEAF895B67B74F2BF43CB841C7937FE
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..services-remotepage_31bf3856ad364e35_6.1.7600.16385_none_04cce7d70ecd1ba7.manifest --a---- 4681 bytes [02:33 14/07/2009] [01:57 14/07/2009] F69CED6BDA04BB4C8E879514A12D0CB8
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-t..services-remotepage_31bf3856ad364e35_6.1.7601.17514_none_06fdfb9f0bbb9f41.manifest ------- 4681 bytes [19:35 16/07/2012] [02:10 20/11/2010] 9D391A6A0124AAABE3AB6B4D351D7AA8
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-terminalservices-rdp_31bf3856ad364e35_6.1.7600.16385_none_5be8ff911862e21c.manifest --a---- 731 bytes [02:33 14/07/2009] [01:46 14/07/2009] C5BD0D3254FD375F310ACA8CDCE17DAF
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-terminalservices-theme_31bf3856ad364e35_6.1.7600.16385_none_d5bc65ffdc22ec35.manifest --a---- 7767 bytes [02:33 14/07/2009] [01:47 14/07/2009] 85DE6661DBB5E0C0E8336B7C6AA25713
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-w..eservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_d92dea821b79a3bd.manifest --a---- 3343 bytes [05:35 14/07/2009] [02:29 14/07/2009] C42A8C5A5F95A7A4D45FB7FD13C7CD6F
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-webservices-events_31bf3856ad364e35_6.1.7600.16385_none_987e837520aedb3d.manifest --a---- 50287 bytes [02:33 14/07/2009] [01:46 14/07/2009] CCCB160C643573390518A8BB65163AD0
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_0e8d75c5d7938376.manifest --a---- 2102 bytes [05:35 14/07/2009] [02:29 14/07/2009] 3C0DC8AD964DBE6E7A02DF1199C02EB0
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7600.16385_none_0e52ae5c9005d543.manifest --a---- 2724 bytes [02:33 14/07/2009] [01:53 14/07/2009] A4AA75F810F9CF63FF48CBF7637E25C3
    C:\Windows\winsxs\Manifests\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_1083c2248cf458dd.manifest ------- 2724 bytes [19:35 16/07/2012] [02:07 20/11/2010] 6B3ADAB5FCB23D94C27DC9403ABD8ACE
    C:\Windows\winsxs\Manifests\x86_netfx-sys_enterpriseservices_tlb_b03f5f7f11d50a3a_6.1.7600.16385_none_f0513a301e5d7705.manifest --a---- 2088 bytes [02:33 14/07/2009] [01:54 14/07/2009] 83927CB286D0F2AA4689766A3E23A78F
    C:\Windows\winsxs\Manifests\x86_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_67bcc28149ee1baf.manifest --a---- 2182 bytes [01:56 14/07/2009] [01:56 14/07/2009] 1B95DAB4D0ED2AEEC9AD6B9E2185B698
    C:\Windows\winsxs\Manifests\x86_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_69edd64946dc9f49.manifest ------- 2182 bytes [19:36 16/07/2012] [02:09 20/11/2010] 899CE5E81FABDE2C8EB03D651E797ED5
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7600.16385_none_cdf05c9ca29b39cc.manifest --a---- 2203 bytes [01:56 14/07/2009] [01:56 14/07/2009] AEE58D52A1DD07F82C725EDD53A21883
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7601.17514_none_d02170649f89bd66.manifest ------- 2203 bytes [19:36 16/07/2012] [02:09 20/11/2010] 4DC9B282DB4EE50470CB32190A180733
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7600.16385_none_f9a698bd0f612a01.manifest --a---- 2203 bytes [01:51 14/07/2009] [01:51 14/07/2009] BC3C0DA0666ACA3B522690717B736CC2
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7601.17514_none_fbd7ac850c4fad9b.manifest ------- 2203 bytes [19:36 16/07/2012] [02:05 20/11/2010] A2FCF187DE2C218849275F3D6D13C8F9
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7600.16385_none_ef308440251eb997.manifest --a---- 2175 bytes [01:47 14/07/2009] [01:47 14/07/2009] C2F427AA8D59A0D566D137575ACAA0D3
    C:\Windows\winsxs\Manifests\x86_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7601.17514_none_f1619808220d3d31.manifest ------- 2175 bytes [19:36 16/07/2012] [02:02 20/11/2010] AD60F9FA962D00E84400491AEC483813
    C:\Windows\winsxs\Manifests\x86_system.enterpriseservices.tlb_31bf3856ad364e35_6.1.7600.16385_none_b5db771f9dc54856.manifest --a---- 58223 bytes [02:33 14/07/2009] [01:46 14/07/2009] 59671CDC039094A45059F36032DA2A56
    C:\Windows\winsxs\Manifests\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_aa2ded886a639c17.manifest --a---- 28014 bytes [02:33 14/07/2009] [01:54 14/07/2009] 69BC85EBC263E174213E586CBD864E6A
    C:\Windows\winsxs\Manifests\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_aa02fb0c6abae2cd.manifest ------- 28014 bytes [19:36 16/07/2012] [02:08 20/11/2010] 38307E6F0181D55C36AC8A3FB38E3E23
    C:\Windows\winsxs\msil_system.data.services.client_b77a5c561934e089_6.1.7600.16385_none_ef59273eec19d069\System.Data.Services.Client.dll --a---- 294912 bytes [21:10 13/07/2009] [21:14 10/06/2009] 97D188D493FF91087D6EAD51909FA9C2
    C:\Windows\winsxs\msil_system.data.services.client_b77a5c561934e089_6.1.7601.17514_none_f18a3b06e9085403\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] 606ACF1553423BFDD3CABEBA3DF264B9
    C:\Windows\winsxs\msil_system.data.services.design_b77a5c561934e089_6.1.7600.16385_none_1b0f635f58dfc09e\System.Data.Services.Design.dll --a---- 114688 bytes [21:10 13/07/2009] [21:14 10/06/2009] 13CE6E1B97C942CF8C3F1DDDC2A7CD6E
    C:\Windows\winsxs\msil_system.data.services.design_b77a5c561934e089_6.1.7601.17514_none_1d40772755ce4438\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 0ACA904F87E674CF3CB6746D9D3AB321
    C:\Windows\winsxs\msil_system.data.services_b77a5c561934e089_6.1.7600.16385_none_fdadd025d6080082\System.Data.Services.dll --a---- 442368 bytes [21:10 13/07/2009] [21:14 10/06/2009] 99FA5DF098453E10F2FF1704E53F1B3F
    C:\Windows\winsxs\msil_system.data.services_b77a5c561934e089_6.1.7601.17514_none_ffdee3edd2f6841c\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] 4BA482E447D6096E8D4348AAE306CE1B
    C:\Windows\winsxs\msil_system.directoryser..s.accountmanagement_b77a5c561934e089_6.1.7600.16385_none_fcc048285d1e33af\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [21:10 13/07/2009] [21:14 10/06/2009] 50A720849C74464E2282F478B094A605
    C:\Windows\winsxs\msil_system.directoryser..s.accountmanagement_b77a5c561934e089_6.1.7601.17514_none_fef15bf05a0cb749\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] CD86BDCB5E115635E6AB7DFE77FC1D11
    C:\Windows\winsxs\msil_system.directoryservices.protocols_b03f5f7f11d50a3a_6.1.7600.16385_none_83a19ecc10aa89e7\System.DirectoryServices.Protocols.dll --a---- 188416 bytes [20:46 13/07/2009] [21:23 10/06/2009] EE1DCDAA3EA8F53DA56116875CD01653
    C:\Windows\winsxs\msil_system.directoryservices_b03f5f7f11d50a3a_6.1.7600.16385_none_2b25936fedbeb29c\System.DirectoryServices.dll --a---- 401408 bytes [20:46 13/07/2009] [21:23 10/06/2009] 217FD2DD18AF542143406F654A172999
    C:\Windows\winsxs\msil_system.directoryservices_b03f5f7f11d50a3a_6.1.7601.17514_none_2afaa0f3ee15f952\System.DirectoryServices.dll --a---- 401408 bytes [20:11 16/07/2012] [01:58 05/11/2010] AF1F47FBADABB9134002359970F5FD1C
    C:\Windows\winsxs\msil_system.web.services_b03f5f7f11d50a3a_6.1.7600.16385_none_c74cebec6e652ac7\System.Web.Services.dll --a---- 839680 bytes [20:46 13/07/2009] [21:23 10/06/2009] 8C003C74490965809C31872AD37AB3D0
    C:\Windows\winsxs\msil_system.web.services_b03f5f7f11d50a3a_6.1.7601.17514_none_c721f9706ebc717d\System.Web.Services.dll --a---- 839680 bytes [20:12 16/07/2012] [01:58 05/11/2010] 8C0B098B41A27B08D58CAE7A61A3BA19
    C:\Windows\winsxs\msil_system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_e3c597b829f3bac9\System.WorkflowServices.dll --a---- 507904 bytes [21:09 13/07/2009] [21:14 10/06/2009] 78E116F57E03D87E4AEAC40983E89CB2
    C:\Windows\winsxs\msil_system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_e5f6ab8026e23e63\System.WorkflowServices.dll --a---- 507904 bytes [20:14 16/07/2012] [01:52 05/11/2010] CC3B424ED10A8E477B5D466188531F26
    C:\Windows\winsxs\x86_microsoft-windows-c..t-xpsomandstreaming_31bf3856ad364e35_6.1.7600.16385_none_aeeed09d4674da37\xpsservices.dll --a---- 1712640 bytes [00:22 14/07/2009] [01:16 14/07/2009] 0BFA740F9F5E04422A5E131A0B82E134
    C:\Windows\winsxs\x86_microsoft-windows-c..t-xpsomandstreaming_31bf3856ad364e35_6.1.7601.17514_none_b11fe46543635dd1\xpsservices.dll --a---- 1712640 bytes [20:14 16/07/2012] [12:21 20/11/2010] 9C8E9CAAF237E8CD8BEBDE700AAFF9E0
    C:\Windows\winsxs\x86_microsoft-windows-component-opcom_31bf3856ad364e35_6.1.7600.16385_none_a30d57f713e49819\OpcServices.dll --a---- 1160192 bytes [00:21 14/07/2009] [01:16 14/07/2009] 9E5B8A02AFDC7C909F45CB0B8D8B145E
    C:\Windows\winsxs\x86_microsoft-windows-component-opcom_31bf3856ad364e35_6.1.7601.17514_none_a53e6bbf10d31bb3\OpcServices.dll --a---- 1160192 bytes [20:11 16/07/2012] [12:20 20/11/2010] 37485CC09B7E6E70093A4DF62B3CC744
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:39 13/07/2009] [21:16 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:39 13/07/2009] [21:16 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:39 13/07/2009] [21:16 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:39 13/07/2009] [21:16 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:42 10/06/2009] [21:42 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:42 10/06/2009] [21:42 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:42 10/06/2009] [21:42 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [21:00 13/07/2009] [21:19 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-Drivers-DL.man --a---- 1277 bytes [21:19 10/06/2009] [21:19 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\terminalservices-licenseserver-DL.man --a---- 2117 bytes [21:00 13/07/2009] [21:19 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [21:22 10/06/2009] [21:22 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [21:00 13/07/2009] [21:19 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [21:00 13/07/2009] [21:19 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [21:26 10/06/2009] [21:26 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [21:00 13/07/2009] [21:19 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [21:17 10/06/2009] [21:17 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7600.16385_none_024f0ba1e4ed554c\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:40 10/06/2009] [21:40 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\ActiveDirectory-WebServices-DL.man --a---- 667 bytes [20:39 13/07/2009] [21:16 10/06/2009] B3AFF6666D3E01C7C062D1448BA29833
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\DirectoryServices-ADAM-DL.man --a---- 2570 bytes [20:39 13/07/2009] [21:16 10/06/2009] E09A468EBBFF11563E3CEF5A08809F40
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\DirectoryServices-Domain-DL.man --a---- 2397 bytes [20:39 13/07/2009] [21:16 10/06/2009] 793663FEC42993EE6171814D714E5604
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\DirectoryServices-ISM-Smtp-DL.man --a---- 2204 bytes [20:39 13/07/2009] [21:16 10/06/2009] BEFDFC143B0CB557387BCDDAE86D54B8
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\Microsoft-Windows-CertificateServices-CA-DL.man --a---- 1865 bytes [21:42 10/06/2009] [21:42 10/06/2009] 04DF7A15A7FC1C5D777C2B5E724E1DD8
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\Microsoft-Windows-CertificateServices-CAManagement-DL.man --a---- 1439 bytes [21:42 10/06/2009] [21:42 10/06/2009] AE8B30E04A3785D32C06BEA3CC4BD120
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\Microsoft-Windows-CertificateServices-MSCEP-DL.man --a---- 1721 bytes [21:42 10/06/2009] [21:42 10/06/2009] CA8A8B54C1720BC9023AF3A3CF0FC3A7
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\terminalservices-AppServer-Licensing-DL.man --a---- 1305 bytes [21:00 13/07/2009] [21:19 10/06/2009] 5169D09C79B91100F484F3998A0DFB61
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-Drivers-DL.man --a---- 1277 bytes [21:19 10/06/2009] [21:19 10/06/2009] EC3DA941FFE9910C7A3F610AF541D562
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\terminalservices-licenseserver-DL.man --a---- 2117 bytes [21:00 13/07/2009] [21:19 10/06/2009] D30628CB82FD7B8E08520144E596FFEA
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-LocalSessionManager-DL.man --a---- 1438 bytes [21:22 10/06/2009] [21:22 10/06/2009] 5A2BA1DFBF70F93FC91B8C4DE0D35ED3
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-RDP-WinStationExtensions-DL.man --a---- 20863 bytes [21:00 13/07/2009] [21:19 10/06/2009] B61F5D5331BCDB91A01FD718C9AED83B
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-RemoteConnectionManager-DL.man --a---- 1438 bytes [21:00 13/07/2009] [21:19 10/06/2009] 30EDA5D79E91982C35DB4F24EF032CA0
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-SessionDirectory-Client-DL.man --a---- 2240 bytes [21:26 10/06/2009] [21:26 10/06/2009] F79CC050D67F4F93CC97E86B63D56121
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TerminalServices-TerminalServicesClient-DL.man --a---- 1919 bytes [21:00 13/07/2009] [21:19 10/06/2009] 6CAD5FF3C0879EBEE29F787BC16CD094
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\TextServicesFramework-Migration-DL.man --a---- 2285 bytes [21:17 10/06/2009] [21:17 10/06/2009] E81C87F0700A7873C190E0F0B82B69FC
    C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\Web-Services-for-Management-Core-DL.man --a---- 1914 bytes [21:40 10/06/2009] [21:40 10/06/2009] 2A110F0D2AE009C4F5CC41CB754B3A93
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:39 13/07/2009] [21:16 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [21:19 10/06/2009] [21:19 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:58 13/07/2009] [21:19 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:58 13/07/2009] [21:19 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:58 13/07/2009] [21:19 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7600.16385_none_fbcab2314ccb2104\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:58 13/07/2009] [21:19 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\activedirectory-webservices-replacement.man --a---- 1704 bytes [20:39 13/07/2009] [21:16 10/06/2009] 950030AFEBFC8DC7CA872520AACD87AF
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\TerminalServices-AppServer-Licensing-replacement.man --a---- 1134 bytes [21:19 10/06/2009] [21:19 10/06/2009] 85DF92406ED3B7E5C69DE4B535461F64
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\TerminalServices-LicenseServer-Replacement.man --a---- 1488 bytes [20:58 13/07/2009] [21:19 10/06/2009] 0C92181E41CD93763C6C11126CC9957E
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\TerminalServices-Manager-SnapIn-Replacement.man --a---- 1136 bytes [20:58 13/07/2009] [21:19 10/06/2009] 9C1D9345E9F3D2478F90642F0ED0D264
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\TerminalServices-RAPWebPart-Replacement.man --a---- 1083 bytes [20:58 13/07/2009] [21:19 10/06/2009] 90B669EB398E5D178B261B1A1EED20DB
    C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\TerminalServices-SBMgr-SnapIn-non_msil-Replacement.man --a---- 786 bytes [20:58 13/07/2009] [21:19 10/06/2009] F128096CE3C9576FD6FDA03A7BB00B6A
    C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc --a---- 92745 bytes [05:35 14/07/2009] [02:08 14/07/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc --a---- 92745 bytes [21:44 13/07/2009] [21:21 10/06/2009] 7A1D35F59468B8118AF5B8E21DF78AE2
    C:\Windows\winsxs\x86_microsoft-windows-t..d-chinese-shuangpin_31bf3856ad364e35_6.1.7600.16385_none_1e8c88df3830bbcc\TableTextServiceSimplifiedShuangPin.txt --a---- 1445430 bytes [21:38 13/07/2009] [21:43 10/06/2009] 51B31EB324CB5C6936D7A14D49B0BD67
    C:\Windows\winsxs\x86_microsoft-windows-t..ied-chinese-quanpin_31bf3856ad364e35_6.1.7600.16385_none_f79af98021986eab\TableTextServiceSimplifiedQuanPin.txt --a---- 1665878 bytes [21:38 13/07/2009] [21:43 10/06/2009] 532ED87BB64CF19C58AE0F91FA439983
    C:\Windows\winsxs\x86_microsoft-windows-t..ied-chinese-zhengma_31bf3856ad364e35_6.1.7600.16385_none_632cd22f8aba00e7\TableTextServiceSimplifiedZhengMa.txt --a---- 1810352 bytes [21:38 13/07/2009] [21:43 10/06/2009] 6D2BE04D9605C2D479E3CD205C406D7C
    C:\Windows\winsxs\x86_microsoft-windows-t..onmanager-uieffects_31bf3856ad364e35_6.1.7600.16385_none_f73d1a8f583f5f3e\TerminalServices-RemoteConnectionManager-UiEffects-ppdlic.xrm-ms --a---- 3084 bytes [01:25 14/07/2009] [01:25 14/07/2009] 13AC4873830B38C9B9FC65A3CC4155C2
    C:\Windows\winsxs\x86_microsoft-windows-t..tionmanager-license_31bf3856ad364e35_6.1.7600.16385_none_f8d5f2c030761f05\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4420 bytes [01:25 14/07/2009] [01:25 14/07/2009] 1348977AA0487A60D989112B89ED4926
    C:\Windows\winsxs\x86_microsoft-windows-t..tionmanager-license_31bf3856ad364e35_6.1.7601.17514_none_fb0706882d64a29f\TerminalServices-RemoteConnectionManager-License-ppdlic.xrm-ms --a---- 4518 bytes [20:11 16/07/2012] [12:33 20/11/2010] 8AE2AC3750FD1F2BCEE17123A4122462
    C:\Windows\winsxs\x86_microsoft-windows-webservices.resources_31bf3856ad364e35_6.1.7600.16385_en-us_0e8d75c5d7938376\webservices.dll.mui --a---- 194048 bytes [05:35 14/07/2009] [02:08 14/07/2009] A83D3EAB50A5146B837FBB5B06326DA8
    C:\Windows\winsxs\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7600.16385_none_0e52ae5c9005d543\webservices.dll --a---- 782336 bytes [23:46 13/07/2009] [01:16 14/07/2009] 4262220B609AD082CE66914172597A96
    C:\Windows\winsxs\x86_microsoft-windows-webservices_31bf3856ad364e35_6.1.7601.17514_none_1083c2248cf458dd\webservices.dll --a---- 782336 bytes [20:13 16/07/2012] [12:21 20/11/2010] DB846EECA70EE9D2E2FF31147C57B0F4
    C:\Windows\winsxs\x86_netfx-clr_sys_entservcs_thunk_dll_b03f5f7f11d50a3a_6.1.7600.16385_none_26e756d174266d3a\System.EnterpriseServices.Thunk.dll --a---- 54144 bytes [20:46 13/07/2009] [21:23 10/06/2009] 6058809BBD4515A5EAF22336AF245150
    C:\Windows\winsxs\x86_netfx-sbs_sys_enterprisesvc_dll_31bf3856ad364e35_6.1.7600.16385_none_60ffafae87253a03\sbs_system.enterpriseservices.dll --a---- 11112 bytes [20:46 13/07/2009] [21:22 10/06/2009] 12C7E5852D3ADB85F23CD90C810A1805
    C:\Windows\winsxs\x86_netfx-sys_enterpriseservices_tlb_b03f5f7f11d50a3a_6.1.7600.16385_none_f0513a301e5d7705\System.EnterpriseServices.tlb --a---- 40960 bytes [20:46 13/07/2009] [21:23 10/06/2009] A0920D54C4F4DCF5C70A5F277740EAAA
    C:\Windows\winsxs\x86_netfx35cdf-csd_cdf_installer_31bf3856ad364e35_6.1.7600.16385_none_58326e688d4907c6\WFServicesReg.exe --a---- 193368 bytes [21:09 13/07/2009] [21:14 10/06/2009] 9001B463C2108F3B05A1A9285512C749
    C:\Windows\winsxs\x86_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7600.16385_none_67bcc28149ee1baf\System.WorkflowServices.dll --a---- 507904 bytes [21:09 13/07/2009] [21:14 10/06/2009] 78E116F57E03D87E4AEAC40983E89CB2
    C:\Windows\winsxs\x86_netfx35cdf-system.workflowservices_31bf3856ad364e35_6.1.7601.17514_none_69edd64946dc9f49\System.WorkflowServices.dll --a---- 507904 bytes [20:14 16/07/2012] [01:52 05/11/2010] CC3B424ED10A8E477B5D466188531F26
    C:\Windows\winsxs\x86_netfx35linq-system...s.accountmanagement_31bf3856ad364e35_6.1.7600.16385_none_7ec47f2df11c9832\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [21:10 13/07/2009] [21:14 10/06/2009] 50A720849C74464E2282F478B094A605
    C:\Windows\winsxs\x86_netfx35linq-system...s.accountmanagement_31bf3856ad364e35_6.1.7601.17514_none_80f592f5ee0b1bcc\System.DirectoryServices.AccountManagement.dll --a---- 290816 bytes [20:14 16/07/2012] [01:53 05/11/2010] CD86BDCB5E115635E6AB7DFE77FC1D11
    C:\Windows\winsxs\x86_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7600.16385_none_cdf05c9ca29b39cc\System.Data.Services.Client.dll --a---- 294912 bytes [21:10 13/07/2009] [21:14 10/06/2009] 97D188D493FF91087D6EAD51909FA9C2
    C:\Windows\winsxs\x86_netfx35linq-system.data.services.client_31bf3856ad364e35_6.1.7601.17514_none_d02170649f89bd66\System.Data.Services.Client.dll --a---- 462848 bytes [20:15 16/07/2012] [01:53 05/11/2010] 606ACF1553423BFDD3CABEBA3DF264B9
    C:\Windows\winsxs\x86_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7600.16385_none_f9a698bd0f612a01\System.Data.Services.Design.dll --a---- 114688 bytes [21:10 13/07/2009] [21:14 10/06/2009] 13CE6E1B97C942CF8C3F1DDDC2A7CD6E
    C:\Windows\winsxs\x86_netfx35linq-system.data.services.design_31bf3856ad364e35_6.1.7601.17514_none_fbd7ac850c4fad9b\System.Data.Services.Design.dll --a---- 163840 bytes [20:15 16/07/2012] [01:53 05/11/2010] 0ACA904F87E674CF3CB6746D9D3AB321
    C:\Windows\winsxs\x86_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7600.16385_none_ef308440251eb997\System.Data.Services.dll --a---- 442368 bytes [21:10 13/07/2009] [21:14 10/06/2009] 99FA5DF098453E10F2FF1704E53F1B3F
    C:\Windows\winsxs\x86_netfx35linq-system.data.services_31bf3856ad364e35_6.1.7601.17514_none_f1619808220d3d31\System.Data.Services.dll --a---- 692224 bytes [20:15 16/07/2012] [01:53 05/11/2010] 4BA482E447D6096E8D4348AAE306CE1B
    C:\Windows\winsxs\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_aa2ded886a639c17\System.EnterpriseServices.dll --a---- 258048 bytes [20:46 13/07/2009] [21:23 10/06/2009] C18C30BFFDF790463B4F5B2311652208
    C:\Windows\winsxs\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7600.16385_none_aa2ded886a639c17\System.EnterpriseServices.Wrapper.dll --a---- 113664 bytes [20:46 13/07/2009] [20:46 13/07/2009] D16E07E806ABA236B604B92693CE35E0
    C:\Windows\winsxs\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_aa02fb0c6abae2cd\System.EnterpriseServices.dll --a---- 258048 bytes [20:11 16/07/2012] [01:58 05/11/2010] 6DB969DF540BC71722848940D180AC08
    C:\Windows\winsxs\x86_system.enterpriseservices_b03f5f7f11d50a3a_6.1.7601.17514_none_aa02fb0c6abae2cd\System.EnterpriseServices.Wrapper.dll --a---- 113664 bytes [20:11 16/07/2012] [04:12 20/11/2010] C865DC05ADE0B41A9E14DD585E0CDF94

    -= EOF =-
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1067118