![]() |
| |||||||
| Foro Oficial de HijackThis en espańol Analizamos tu log de HijackThis para eliminar Hijackers, Spyware, Adware, ToolBars, Virus, Troyanos y Malwares en gral. Antes lea las Políticas del Foro de HijackThis. |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| bueno inicie la computadora en modo a prueba de fallos pero no desactive el restaurar resgistro por que no encontre dicha opcion (segun lei en alguna parte del foro era Sistema y Mantenimiento o algo asi ---> Sistema ---> Proteccion del sistema y luego desactivar la restuaracion (que no encotre ni la solapa ni la opcion)) pase el Hijackthis y les paso a comentar lo que me paso: el lunes (argentina) me instale algunos softs (paragon partition y norton partition) segun creo alguno de ellos estaba infectado y lo que resulta es que cuando ejecute paragon partition me aparecio un a ventana que decia algo como VISTA ANTIVIRUS 2008 y que me empezo a escanear la maquina, paralelamente me salto el eset smart security con la temible pantallita roja que me daba algunas opciones creo a ver puesto eliminar pero no se pudo hacer nada, tambien me salto el windows defender para que validara o no cambios en el sector de inicio lo que recuerdo no haber hecho (validar) y el Spybot S&D tambien me pedia hacer lo mismo. pero como bloquee eso me seguia pidiendo que hiciera algo entre al starup manager de TuneUp Utilities y borre directamente las entradas y ahi dejo de romper las pelotas Reinicie la maquina en modo a pruebas de fallos e hice un Scan con el Kaspersky Online que me tiro una lista larga de "cosas" entre ellos un nombre para el troyano. Bueno les pego el log del HijackThis y espero instrucciones o consejos Desde ya muchas gracias Vituperio Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:54:53 a.m., on 20/08/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16546) Boot mode: Safe mode with network support Running processes: C:\Windows\Explorer.EXE C:\Program Files\SysinternalsSuite\procexp.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=es_ar&c=81&bd=Presario &pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=es_ar&c=81&bd=Presario &pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe" O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Los Dávola\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red') O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/spanish/kavwebscan_unicode.cab O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1219107051555 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 6680 bytes |
![]() | ![]() |
| ||||
| Re: troyano not-a-virus:FraudTool.Win32.WinAntiVirus.bb segun kaspersky online Hola Vituperio Viole El VISTA ANTIVIRUS 2008 es un Rogue o Falso antispyware Descarga y/o Actualiza: Realiza lo Siguiente: Con todos los programas cerrados ejecuta el HijackThis y dale a estas entradas:O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe Ejecuta estas herramientas, de a una:
Cita:
Descarga CCleaner y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad).Reinicia y nos cuentas los resultados. junto con el reporte de C:\ComboFix.txt y Malwarebytes' Anti-Malware en este mismo mensaje. Saludos nos comentas. ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: troyano not-a-virus:FraudTool.Win32.WinAntiVirus.bb segun kaspersky online ante todo gracias Thecat_re ![]() bueno los logs son estos: Malwarebytes' Anti-Malware 1.25 Versión de la Base de Datos: 1073 Windows 6.0.6000 21:51:02 2008-08-20 mbam-log-08-20-2008 (21-50-58).txt Tipo de examen : Examen Completo (C:\|D:\|E:\|) Objetos examinados: 127138 Tiempo transcurrido: 11 minute(s), 25 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 0 Claves del Registro Infectadas: 1 Valores del Registro Infectados: 0 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 2 Ficheros Infectados: 17 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: HKEY_CURRENT_USER\SOFTWARE\VAV (Rogue.VistaAntivirus2008) -> No action taken. Valores del Registro Infectados: (No se han detectado elementos maliciosos) Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> No action taken. C:\Program Files\VAV (Rogue.VistaAntivirus2008) -> No action taken. Ficheros Infectados: C:\Program Files\PCHealthCenter\0.exe (Trojan.FakeAlert) -> No action taken. C:\Program Files\PCHealthCenter\7.exe (Trojan.FakeAlert) -> No action taken. C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> No action taken. C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> No action taken. C:\Program Files\VAV\vav.cpl (Rogue.VistaAntivirus2008) -> No action taken. C:\Program Files\VAV\vav0.dat (Rogue.VistaAntivirus2008) -> No action taken. C:\Program Files\VAV\vav1.dat (Rogue.VistaAntivirus2008) -> No action taken. C:\WINDOWS\System32\sex1.ico (Malware.Trace) -> No action taken. C:\WINDOWS\System32\sex2.ico (Malware.Trace) -> No action taken. C:\WINDOWS\System32\vav.cpl (Rogue.VistaAntivirus2008) -> No action taken. C:\Users\Los Dávola\AppData\Local\Temp\bindsrv2.exe (Trojan.FakeAlert) -> No action taken. C:\Users\Los Dávola\AppData\Local\Temp\atmadm2.exe (Trojan.FakeAlert) -> No action taken. --------------------------------------------------------------------------------------------------------------------------------------------------------------- ComboFix 08-08-19.06 - Los Dávola 2008-08-20 23:38:56.1 - NTFSx86 Microsoft® Windows Vista™ Starter 6.0.6000.0.1252.1.3082.18.86 [GMT -3:00] Se ejecuta desde: C:\Users\Los Dávola\Desktop\Emilio\Soft\ComboFix.exe * Creado un nuevo punto de restauración . (((((((((((((((((( Archivos creados desde 2008-07-21 - 2008-08-21 ))))))))))))))))))))))))))))))))) . 2008-08-20 22:24 . 2008-08-20 22:24 <DIR> d-------- C:\Program Files\MSXML 4.0 2008-08-20 21:34 . 2008-08-20 21:34 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Malwarebytes 2008-08-20 21:34 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\System32\drivers\mbam.sys 2008-08-20 21:33 . 2008-08-20 21:33 <DIR> d-------- C:\Users\All Users\Malwarebytes 2008-08-20 21:33 . 2008-08-20 21:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-08-20 21:33 . 2008-08-20 21:33 <DIR> d-------- C:\PROGRA~2\Malwarebytes 2008-08-20 00:26 . 2008-08-20 02:42 <DIR> d-------- C:\Program Files\EsetOnlineScanner 2008-08-20 00:22 . 2008-08-20 00:22 <DIR> d-------- C:\!KillBox 2008-08-19 00:35 . 2008-08-19 00:35 <DIR> d-------- C:\WINDOWS\System32\Kaspersky Lab 2008-08-18 23:27 . 2008-08-18 23:30 <DIR> d-------- C:\Program Files\CCleaner 2008-08-18 19:57 . 2008-01-21 17:43 13,576 --a------ C:\WINDOWS\System32\wnaspi32.dll 2008-08-18 06:08 . 2008-08-18 06:08 <DIR> d-------- C:\Users\Los Dávola\Program Files 2008-08-18 06:08 . 2008-08-18 06:08 <DIR> d-------- C:\Users\Los Dávola\Program Files 2008-08-18 05:11 . 2008-08-18 05:14 <DIR> d-------- C:\Program Files\ISOpen 2008-08-18 05:00 . 2008-08-18 05:01 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-08-18 04:12 . 2008-08-18 04:12 1,712,984 --a------ C:\WINDOWS\System32\wuaueng.dll 2008-08-18 04:12 . 2008-08-18 04:12 1,524,224 --a------ C:\WINDOWS\System32\wucltux.dll 2008-08-18 04:12 . 2008-08-18 04:12 549,720 --a------ C:\WINDOWS\System32\wuapi.dll 2008-08-18 04:12 . 2008-08-18 04:12 163,000 --a------ C:\WINDOWS\System32\wuwebv.dll 2008-08-18 04:12 . 2008-08-18 04:12 80,896 --a------ C:\WINDOWS\System32\wudriver.dll 2008-08-18 04:12 . 2008-08-18 04:12 53,080 --a------ C:\WINDOWS\System32\wuauclt.exe 2008-08-18 04:12 . 2008-08-18 04:12 43,352 --a------ C:\WINDOWS\System32\wups2.dll 2008-08-18 04:12 . 2008-08-18 04:12 33,624 --a------ C:\WINDOWS\System32\wups.dll 2008-08-18 04:12 . 2008-08-18 04:12 31,232 --a------ C:\WINDOWS\System32\wuapp.exe 2008-08-18 03:38 . 2008-08-18 03:38 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\Users\All Users\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\Program Files\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\PROGRA~2\ESET 2008-08-18 02:55 . 2008-08-20 23:37 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\DNA 2008-08-18 02:55 . 2008-08-18 19:45 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\BitTorrent 2008-08-18 02:55 . 2008-08-18 02:55 <DIR> d-------- C:\Program Files\DNA 2008-08-18 02:55 . 2008-08-18 03:30 <DIR> d-------- C:\Program Files\BitTorrent 2008-08-18 02:34 . 2008-08-18 02:34 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\WinRAR 2008-08-18 02:08 . 2008-08-18 02:08 <DIR> d-------- C:\Program Files\Skype 2008-08-18 02:08 . 2008-08-18 02:08 <DIR> d-------- C:\Program Files\Common Files\Skype 2008-08-18 02:07 . 2008-08-18 02:08 <DIR> d-------- C:\Users\All Users\Skype 2008-08-18 02:07 . 2008-08-18 02:08 <DIR> d-------- C:\PROGRA~2\Skype 2008-08-18 01:18 . 2008-08-18 23:28 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy 2008-08-18 01:18 . 2008-08-18 01:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-08-18 01:18 . 2008-08-18 23:28 <DIR> d-------- C:\PROGRA~2\Spybot - Search & Destroy 2008-08-18 01:13 . 2006-10-04 23:42 2,560 --------- C:\WINDOWS\System32\drivers\cdralw2k.sys 2008-08-18 01:13 . 2006-10-04 23:42 2,432 --------- C:\WINDOWS\System32\drivers\cdr4_xp.sys 2008-08-18 01:12 . 2008-08-18 01:13 <DIR> d-------- C:\Program Files\Picasa2 2008-08-18 01:12 . 2008-08-18 01:12 <DIR> d-------- C:\Program Files\Google 2008-08-18 00:33 . 2008-08-18 02:45 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller 2008-08-18 00:32 . 2008-08-18 02:45 <DIR> d-------- C:\Program Files\Windows Live 2008-08-18 00:31 . 2008-08-18 00:31 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Macromedia 2008-08-18 00:31 . 2008-08-18 02:31 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Adobe 2008-08-18 00:30 . 2008-08-18 00:30 <DIR> d-------- C:\Users\Los Dávola\Application Data 2008-08-18 00:30 . 2008-08-18 00:30 <DIR> d-------- C:\Users\Los Dávola\Application Data 2008-08-18 00:28 . 2008-08-18 02:35 <DIR> d-------- C:\Users\All Users\WLInstaller 2008-08-18 00:28 . 2008-08-18 02:35 <DIR> d-------- C:\PROGRA~2\WLInstaller 2008-08-18 00:26 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\System32\mdimon.dll 2008-08-18 00:19 . 2008-08-18 00:19 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Mozilla 2008-08-18 00:15 . 2008-08-18 00:15 <DIR> d-------- C:\WINDOWS\PCHEALTH 2008-08-18 00:15 . 2008-08-18 00:15 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-08-18 00:07 . 2008-08-18 00:07 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8 2008-08-18 00:07 . 2008-08-18 00:07 <DIR> d-------- C:\IDE 2008-08-18 00:06 . 2008-08-18 00:16 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-08-18 00:05 . 2008-08-18 00:05 <DIR> dr-h----- C:\MSOCache 2008-08-17 23:56 . 2008-08-17 23:56 <DIR> d-------- C:\WINDOWS\System32\ShellExt 2008-08-17 23:54 . 2008-08-17 23:59 <DIR> d-------- C:\Program Files\SysinternalsSuite 2008-08-17 23:53 . 2008-08-17 23:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-08-17 23:45 . 2008-08-17 23:45 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\Users\All Users\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\PROGRA~2\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 306,432 --a------ C:\WINDOWS\System32\TuneUpDefragService.exe 2008-08-17 23:44 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\System32\uxtuneup.dll 2008-08-17 23:44 . 2007-12-20 10:44 16,640 --a------ C:\WINDOWS\System32\authuitu.dll 2008-08-17 23:42 . 2008-08-17 23:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-08-17 23:42 . 2008-08-17 23:42 717,296 --a------ C:\WINDOWS\System32\drivers\sptd.sys 2008-08-17 23:41 . 2008-08-17 23:41 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\DAEMON Tools 2008-08-17 23:22 . 2008-08-17 23:22 <DIR> d-------- C:\WINDOWS\System32\msmq 2008-08-17 23:22 . 2008-08-17 23:22 <DIR> d-------- C:\inetpub 2008-08-17 23:22 . 2008-08-17 23:22 862 --a------ C:\WINDOWS\System32\termcap 2008-08-17 23:18 . 2008-08-17 23:18 <DIR> d-------- C:\Users\All Users\HP Product Assistant 2008-08-17 23:18 . 2008-08-17 23:18 <DIR> d-------- C:\PROGRA~2\HP Product Assistant 2008-08-17 23:16 . 2008-08-17 23:16 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard 2008-08-17 23:11 . 2007-03-17 13:11 675,840 --a------ C:\WINDOWS\System32\hpowiax3.dll 2008-08-17 23:11 . 2007-03-17 13:11 569,344 --a------ C:\WINDOWS\System32\hpotscl3.dll 2008-08-17 23:11 . 2007-03-08 01:20 364,544 --a------ C:\WINDOWS\System32\hppldcoi.dll 2008-08-17 23:11 . 2007-03-08 01:20 309,760 --a------ C:\WINDOWS\System32\difxapi.dll 2008-08-17 23:11 . 2007-03-17 13:11 303,104 --a------ C:\WINDOWS\System32\hpovst10.dll 2008-08-17 23:07 . 2008-08-18 21:05 159,330 --a------ C:\WINDOWS\hpoins14.dat 2008-08-17 23:07 . 2007-09-19 22:14 2,000 --------- C:\WINDOWS\hpomdl14.dat 2008-08-17 23:06 . 2007-03-30 12:07 267,864 --a------ C:\WINDOWS\System32\hpzids01.dll 2008-08-17 23:05 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\System32\hpzll5ha.dll 2008-08-17 22:35 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\System32\msonpmon.dll 2008-08-17 22:28 . 2008-08-20 23:30 <DIR> d-------- C:\Users\All Users\Microsoft Help 2008-08-17 22:28 . 2008-08-20 23:30 <DIR> d-------- C:\PROGRA~2\Microsoft Help 2008-08-17 22:21 . 2008-08-17 22:21 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Symantec 2008-08-17 22:19 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Searches 2008-08-17 22:19 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Searches 2008-08-17 22:19 . 2008-08-18 02:52 <DIR> dr------- C:\Users\Los Dávola\Contacts 2008-08-17 22:19 . 2008-08-18 02:52 <DIR> dr------- C:\Users\Los Dávola\Contacts 2008-08-17 22:19 . 2008-08-17 22:19 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Identities 2008-08-17 22:19 . 2008-08-17 22:19 44 --a------ C:\WINDOWS\system\hpsysdrv.dat 2008-08-17 22:17 . 2008-08-17 22:17 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Hewlett-Packard 2008-08-17 22:16 . 2008-08-17 22:16 1,669 -rahs---- C:\WINDOWS\System32\drivers\103C_HP_CPC_KC868AA-ABM SG3203LA_YC_0Pres_QCNX812_E81LAv3PrA2_49_IIris8_SE CS_V1.0_B5.25_T080229_WUU0_LC0A_M446_J160_7AMD_8Se mpron LE-1150_92_#080818_N10DE03EF_Z14F12F20_G10DE03D0.MRK 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Videos 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Videos 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Saved Games 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Saved Games 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Pictures 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Pictures 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Music 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Music 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Links 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Links 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Favorites 2008-08-17 22:15 . 2008-08-17 22:19 <DIR> dr------- C:\Users\Los Dávola\Favorites 2008-08-17 22:15 . 2008-08-18 05:41 <DIR> dr------- C:\Users\Los Dávola\Downloads 2008-08-17 22:15 . 2008-08-18 05:41 <DIR> dr------- C:\Users\Los Dávola\Downloads 2008-08-17 22:15 . 2008-08-18 23:31 <DIR> dr------- C:\Users\Los Dávola\Documents 2008-08-17 22:15 . 2008-08-18 23:31 <DIR> dr------- C:\Users\Los Dávola\Documents 2008-08-17 22:15 . 2008-08-20 22:14 <DIR> dr------- C:\Users\Los Dávola\Desktop 2008-08-17 22:15 . 2008-08-20 22:14 <DIR> dr------- C:\Users\Los Dávola\Desktop 2008-08-17 22:15 . 2008-08-18 02:47 <DIR> d---s---- C:\Users\Los Dávola\AppData\Roaming\Microsoft 2008-08-17 22:15 . 2008-08-17 22:16 <DIR> d--h----- C:\Users\Los Dávola\AppData 2008-08-17 22:15 . 2008-08-17 22:16 <DIR> d--h----- C:\Users\Los Dávola\AppData 2008-08-17 22:15 . 2008-08-20 23:43 4,456,448 --ahs---- C:\Users\Los Dávola\NTUSER.DAT 2008-08-17 22:15 . 2008-08-20 23:43 4,456,448 --ahs---- C:\Users\Los Dávola\NTUSER.DAT 2008-08-17 22:14 . 2008-08-18 21:31 <DIR> d-------- C:\Users\Los Dávola 2008-08-17 22:09 . 2008-08-17 22:09 <DIR> dr------- C:\WINDOWS\System32\config\systemprofile\Contacts . (((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) ) . 2008-08-21 02:43 4,456,448 --sha-w C:\Users\Los Dávola\NTUSER.DAT 2008-08-21 02:43 4,456,448 --sha-w C:\Users\Los Dávola\NTUSER.DAT 2008-08-21 02:37 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\DNA 2008-08-21 00:34 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Malwarebytes 2008-08-19 00:50 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-08-19 00:38 --------- d-----w C:\Program Files\Microsoft Works 2008-08-18 22:45 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\BitTorrent 2008-08-18 06:38 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\ESET 2008-08-18 05:47 --------- d-s---w C:\Users\Los Dávola\AppData\Roaming\Microsoft 2008-08-18 05:34 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\WinRAR 2008-08-18 05:31 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Adobe 2008-08-18 04:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-08-18 04:03 --------- d-----w C:\PROGRA~2\Symantec 2008-08-18 03:31 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Macromedia 2008-08-18 03:19 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Mozilla 2008-08-18 03:17 --------- d-----w C:\Program Files\MSBuild 2008-08-18 02:45 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\TuneUp Software 2008-08-18 02:41 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\DAEMON Tools 2008-08-18 02:18 --------- d-----w C:\PROGRA~2\HP 2008-08-18 02:07 --------- d-----w C:\PROGRA~2\Hewlett-Packard 2008-08-18 01:21 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Symantec 2008-08-18 01:19 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Identities 2008-08-18 01:17 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Hewlett-Packard 2008-08-18 01:10 --------- d-sh--w C:\Program Files\Archivos comunes 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Plantillas 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Menú Inicio 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Favoritos 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Escritorio 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Documentos 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Datos de programa 2008-08-17 18:01 38,472 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys 2008-07-01 12:04 71,688 ----a-w C:\Windows\system32\drivers\epfw.sys 2008-07-01 12:04 54,280 ----a-w C:\Windows\system32\drivers\epfwtdi.sys 2008-07-01 12:04 30,728 ----a-w C:\Windows\system32\drivers\epfwndis.sys 2008-07-01 11:57 53,256 ----a-w C:\Windows\system32\drivers\easdrv.sys 2008-07-01 11:56 39,944 ----a-w C:\Windows\system32\drivers\eamon.sys 2007-12-14 14:19 174 --sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((( Cargando Puntos Reg )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368] "BitTorrent DNA"="C:\Users\Los Dávola\Program Files\DNA\btdna.exe" [2008-08-18 06:08 342336] "ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-07-29 10:41 1213680] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 12:01 65536] "KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 13:16 65536] "OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 08:59 118784] "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 22:45 86016] "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 22:45 8466432] "NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-07-06 22:45 81920] "DPService"="C:\Program Files\HP\DVDPlay\DPService.exe" [2007-10-09 07:07 90112] "SunJavaUpdateReg"="C:\Windows\system32\jureg. exe" [2007-04-06 22:56 54936] "egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-07-01 09:01 1447168] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648] "RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 10:52 4702208 C:\WINDOWS\RtHDVCpl.exe] [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer] "NoDFSTab"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer] "NoDFSTab"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3codecp"= l3codecp.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpo licy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules] "{8B080A29-3930-4CD7-93C6-492614CB282C}"= C:\Program Files\HP\DVDPlay\DVDPlay.exe:DVD Play "{3A74838C-B9DF-4576-A0F6-6BAC22A06117}"= C:\Program Files\HP\DVDPlay\DPService.exe:DVD Play Resident Program "{1B162528-E983-4E4E-B49A-5F0366D1B591}"= c:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{4CF6CBB6-C4C2-40E9-BCDC-74B956E9E6F7}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{FF26B67E-E36A-433B-A9A3-81449942C1B5}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{BF97D38D-ECD7-4C8B-9518-4DAD366584E9}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{2740F04E-541F-4E5F-A284-D15A9D1542C5}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{34E2B27D-FEF5-4299-8AFC-C73794CC219F}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{93EF6454-C47D-40E3-8F85-5FDB5BE52002}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl "{DAC2E681-BB50-4FD9-9BA6-AA2ADD0D9159}"= UDP:C:\WINDOWS\System32\mqsvc.exe:Message Queuing "{4A1CF2D4-CBCD-4DA9-A934-1469E9DB3D44}"= TCP:C:\WINDOWS\System32\mqsvc.exe:Message Queuing "{55E9515B-2AEB-4FD8-A3E2-002EDC658E03}"= UDP:C:\WINDOWS\System32\mqsvc.exe:Message Queuing "{09F6DC23-F5D4-4E9A-AAEA-7E7A082650FF}"= TCP:C:\WINDOWS\System32\mqsvc.exe:Message Queuing "{A530994D-0EE0-4AB2-8713-33B72A279EE7}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{01541B36-4A6C-4BD8-A27D-A35C2E4CF15F}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{83829050-F889-4769-8A3E-15369C094010}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{F6473581-8CC9-4B9B-8620-403E4102DC18}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{F0A64986-91FA-4032-A812-CA675CF3377D}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{CB75FBD9-59E7-4B7F-A262-356CB4AD002C}"= C:\Program Files\Skype\Phone\Skype.exe:Skype "{C7CF0EEE-E6CB-4847-A0A8-A4226FEC8342}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{131D1C12-DEEF-4F43-8FB1-B59B1226B3A0}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In) "{C05A0308-F300-4E44-9E3A-D644D4317C46}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In) "TCP Query User{2BAA3AF5-4387-42A8-9929-6EF48FBBD228}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent "UDP Query User{89382A04-3F74-4BFB-AD63-A335CA574408}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent "TCP Query User{7A7F7E9F-D647-4BF9-BDC6-E492E6AF7F57}C:\\users\\los dávola\\program files\\dna\\btdna.exe"= UDP:C:\users\los dávola\program files\dna\btdna.exe:btdna.exe "UDP Query User{CF4BA493-EF32-41E1-BB08-3B1C7786EA2A}C:\\users\\los dávola\\program files\\dna\\btdna.exe"= TCP:C:\users\los dávola\program files\dna\btdna.exe:btdna.exe [HKLM\~\services\sharedaccess\parameters\firewallpo licy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink "C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorre nt R2 NetMsmqActivator;Adaptador de escucha Net.Msmq;C:\Windows\Microsoft.NET\Framework\v3.0\W indows Communication Foundation\SMSvcHost.exe [2006-11-02 09:32] R2 NetPipeActivator;Adaptador de escucha Net.Pipe;C:\Windows\Microsoft.NET\Framework\v3.0\W indows Communication Foundation\SMSvcHost.exe [2006-11-02 09:32] R2 NetTcpActivator;Adaptador de escucha Net.Tcp;C:\Windows\Microsoft.NET\Framework\v3.0\Wi ndows Communication Foundation\SMSvcHost.exe [2006-11-02 09:32] R2 UxTuneUp;TuneUp Ampliación del thema;C:\Windows\System32\svchost.exe [2006-11-02 06:45] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 04:30] S3 GameConsoleService;GameConsoleService;C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-23 20:33] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.ex e [2008-08-17 23:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 rsmsvcs REG_MULTI_SZ ntmssvc HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp *Newly Created Service* - MBAMSWISSARMY *Newly Created Service* - PROCEXP90 . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Users\LOSDVO~1\AppData\Roaming\Mozilla\Firefox\ Profiles\1d8vrkel.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.ar/ FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll FF -: plugin - C:\Users\Los Dávola\Program Files\DNA\plugins\npbtdna.dll . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-20 23:43:15 Windows 6.0.6000 NTFS escaneando procesos ocultos ... escaneando entradas ocultas de autostart ... escaneando archivos ocultos ... el escaneo se completo con exito archivos ocultos: 0 ************************************************** ************************ . Tiempo completado: 2008-08-20 23:44:51 ComboFix-quarantined-files.txt 2008-08-21 02:44:43 ComboFix2.txt 2008-08-21 00:57:44 Pre-Run: 126,366,326,784 bytes libres Post-Run: 126,339,670,016 bytes libres 284 --- E O F --- 2008-08-21 02:30:55 espero que todo este bien y te agradezco por la ayuda y al foro por ser un lugar donde encontrar soluciones (lo que no es poco) y capacitacion Gracias Vituperio Violeta |
![]() | ![]() |
| |||
| Re: troyano not-a-virus:FraudTool.Win32.WinAntiVirus.bb segun kaspersky online una cosita mas queria agregar (me acorde) hubo una modificacion (luego de correr estos programas) se borro la entrada de incio del windows defender eso es bueno? un saludo |
![]() | ![]() |
| ||||
| Re: troyano not-a-virus:FraudTool.Win32.WinAntiVirus.bb segun kaspersky online Hola Nuevamemnte El MBAM detcto mas no mandaste a Eliminar, por lo que te recomiendo que lo vuelvas a ejcutar tal cual se muestra en el Manul y mandes a Eliminar todo lo que encuentre. desactivando el Tea Timer de Spybo S&D, y no tranquilo no es de preocuparse sobre lo del windows defender. Luego de ejcutar Nuevamente el MBAM ejecutas el ComboFix y me envias los 2 Reportes. Saludos. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: troyano not-a-virus:FraudTool.Win32.WinAntiVirus.bb segun kaspersky online no entonces me equivoque de reporte porque lo pase dos veces una en modo a prueba de fallos en el que elimine todo y otro (luego) en modo normal que no me detecto nada con respecto al combo fix hice lo mismo esta tarde cuando vuelvo a casa vuelvo a subir los log gracias |
![]() | ![]() |
| |||
| bueno pego los logs y espero que salamin salamado este cuento se haya acabado sino diganme que seguimos en la lucha de todos modos muchas gracias log del: Malwarebytes' Anti-Malware 1.25 Versión de la Base de Datos: 1076 Windows 6.0.6001 Service Pack 1 07:12:28 a.m. 22/08/2008 mbam-log-08-22-2008 (07-12-27).txt Tipo de examen : Examen Completo (C:\|D:\|E:\|) Objetos examinados: 135577 Tiempo transcurrido: 1 hour(s), 2 minute(s), 27 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 0 Claves del Registro Infectadas: 0 Valores del Registro Infectados: 0 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 0 Ficheros Infectados: 0 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: (No se han detectado elementos maliciosos) Valores del Registro Infectados: (No se han detectado elementos maliciosos) Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: (No se han detectado elementos maliciosos) Ficheros Infectados: (No se han detectado elementos maliciosos) |
![]() | ![]() |
| |||
| y este es el log del combofix: ComboFix 08-08-19.06 - Los Dávola 2008-08-23 0:00:21.2 - NTFSx86 Se ejecuta desde: C:\Users\Los Dávola\Desktop\Emilio\Soft\ComboFix.exe . (((((((((((((((((( Archivos creados desde 2008-07-23 - 2008-08-23 ))))))))))))))))))))))))))))))))) . 2008-08-22 01:30 . 2008-08-22 01:30 0 --ah----- C:\WINDOWS\System32\drivers\Msft_User_WpdFs_01_00_ 00.Wdf 2008-08-22 00:58 . 2008-06-25 07:49 4,244,744 --a------ C:\WINDOWS\System32\qtp-mt334.dll 2008-08-22 00:58 . 2008-06-25 07:49 247,560 --a------ C:\WINDOWS\System32\prgiso.dll 2008-08-22 00:58 . 2008-06-25 07:49 40,368 --a------ C:\WINDOWS\System32\drivers\hotcore3.sys 2008-08-22 00:57 . 2008-08-22 00:59 <DIR> d-------- C:\Program Files\Paragon Software 2008-08-21 23:31 . 2008-08-21 23:31 <DIR> d-------- C:\PerfLogs 2008-08-21 07:25 . 2008-01-19 04:38 4,595,712 --a------ C:\WINDOWS\System32\AuthFWSnapin.dll 2008-08-21 07:24 . 2008-01-19 04:33 8,139,264 --a------ C:\WINDOWS\System32\ssBranded.scr 2008-08-21 07:23 . 2008-01-19 04:34 6,103,040 --a------ C:\WINDOWS\System32\chtbrkr.dll 2008-08-21 07:22 . 2008-01-19 03:06 8,147,456 --a------ C:\WINDOWS\System32\wmploc.DLL 2008-08-21 07:21 . 2008-01-19 04:36 704,512 --a------ C:\WINDOWS\System32\SmiEngine.dll 2008-08-21 07:21 . 2008-01-19 04:36 357,888 --a------ C:\WINDOWS\System32\wbemcomn.dll 2008-08-21 07:21 . 2008-01-19 04:34 305,152 --a------ C:\WINDOWS\System32\msdelta.dll 2008-08-21 07:21 . 2008-01-19 04:34 258,560 --a------ C:\WINDOWS\System32\dpx.dll 2008-08-21 07:21 . 2008-01-19 04:34 246,784 --a------ C:\WINDOWS\System32\drvstore.dll 2008-08-21 07:21 . 2008-01-19 04:36 218,624 --a------ C:\WINDOWS\System32\wdscore.dll 2008-08-21 07:21 . 2008-01-19 04:36 139,264 --a------ C:\WINDOWS\System32\SmiInstaller.dll 2008-08-21 07:21 . 2008-01-19 04:33 130,560 --a------ C:\WINDOWS\System32\PkgMgr.exe 2008-08-21 07:21 . 2008-01-19 04:35 35,328 --a------ C:\WINDOWS\System32\mspatcha.dll 2008-08-21 01:51 . 2008-08-21 01:51 269,312 --a------ C:\WINDOWS\System32\es.dll 2008-08-21 01:41 . 2008-08-21 01:41 1,811,656 --a------ C:\WINDOWS\System32\wuaueng.dll 2008-08-21 01:41 . 2008-08-21 01:41 1,524,736 --a------ C:\WINDOWS\System32\wucltux.dll 2008-08-21 01:41 . 2008-08-21 01:41 53,448 --a------ C:\WINDOWS\System32\wuauclt.exe 2008-08-21 01:41 . 2008-08-21 01:41 45,768 --a------ C:\WINDOWS\System32\wups2.dll 2008-08-21 01:40 . 2008-08-21 01:40 563,912 --a------ C:\WINDOWS\System32\wuapi.dll 2008-08-21 01:40 . 2008-08-21 01:40 163,904 --a------ C:\WINDOWS\System32\wuwebv.dll 2008-08-21 01:40 . 2008-08-21 01:40 83,456 --a------ C:\WINDOWS\System32\wudriver.dll 2008-08-21 01:40 . 2008-08-21 01:40 36,552 --a------ C:\WINDOWS\System32\wups.dll 2008-08-21 01:40 . 2008-08-21 01:40 31,232 --a------ C:\WINDOWS\System32\wuapp.exe 2008-08-21 01:09 . 2008-08-21 01:09 9,892,864 --a------ C:\WINDOWS\System32\NlsLexicons000a.dll 2008-08-21 01:00 . 2008-08-21 01:00 <DIR> d-------- C:\Program Files\Microsoft Silverlight 2008-08-20 23:28 . 2008-08-20 23:28 361,984 --a------ C:\WINDOWS\System32\IPSECSVC.DLL 2008-08-20 23:28 . 2008-08-20 23:28 272,896 --a------ C:\WINDOWS\System32\polstore.dll 2008-08-20 23:28 . 2008-08-20 23:28 61,440 --a------ C:\WINDOWS\System32\winipsec.dll 2008-08-20 23:28 . 2008-08-20 23:28 28,672 --a------ C:\WINDOWS\System32\FwRemoteSvr.dll 2008-08-20 23:22 . 2008-08-20 23:22 2,048 --a------ C:\WINDOWS\System32\tzres.dll 2008-08-20 23:13 . 2008-08-20 23:13 1,383,424 --a------ C:\WINDOWS\System32\mshtml.tlb 2008-08-20 23:13 . 2008-08-20 23:13 827,392 --a------ C:\WINDOWS\System32\wininet.dll 2008-08-20 23:10 . 2008-08-20 23:10 988,216 --a------ C:\WINDOWS\System32\winload.exe 2008-08-20 23:10 . 2008-08-20 23:10 927,288 --a------ C:\WINDOWS\System32\winresume.exe 2008-08-20 23:10 . 2008-08-20 23:10 615,992 --a------ C:\WINDOWS\System32\ci.dll 2008-08-20 23:10 . 2008-08-20 23:10 378,368 --a------ C:\WINDOWS\System32\srcore.dll 2008-08-20 23:10 . 2008-08-20 23:10 318,464 --a------ C:\WINDOWS\System32\rstrui.exe 2008-08-20 23:10 . 2008-08-20 23:10 46,592 --a------ C:\WINDOWS\System32\setbcdlocale.dll 2008-08-20 23:10 . 2008-08-20 23:10 40,960 --a------ C:\WINDOWS\System32\srclient.dll 2008-08-20 23:10 . 2008-08-20 23:10 19,000 --a------ C:\WINDOWS\System32\kd1394.dll 2008-08-20 23:10 . 2008-08-20 23:10 14,848 --a------ C:\WINDOWS\System32\srdelayed.exe 2008-08-20 23:10 . 2008-08-20 23:10 6,656 --a------ C:\WINDOWS\System32\kbd106n.dll 2008-08-20 22:56 . 2008-08-20 22:56 2,032,128 --a------ C:\WINDOWS\System32\win32k.sys 2008-08-20 22:56 . 2008-08-20 22:56 295,936 --a------ C:\WINDOWS\System32\gdi32.dll 2008-08-20 22:55 . 2008-08-20 22:55 113,664 --a------ C:\WINDOWS\System32\drivers\rmcast.sys 2008-08-20 22:55 . 2008-08-20 22:55 14,848 --a------ C:\WINDOWS\System32\wshrm.dll 2008-08-20 22:54 . 2008-08-20 22:54 4,240,384 --a------ C:\WINDOWS\System32\GameUXLegacyGDFs.dll 2008-08-20 22:54 . 2008-08-20 22:54 1,695,744 --a------ C:\WINDOWS\System32\gameux.dll 2008-08-20 22:29 . 2008-08-20 22:29 738,304 --a------ C:\WINDOWS\System32\inetcomm.dll 2008-08-20 22:29 . 2008-08-20 22:29 84,480 --a------ C:\WINDOWS\System32\INETRES.dll 2008-08-20 22:26 . 2008-08-20 22:26 1,314,816 --a------ C:\WINDOWS\System32\quartz.dll 2008-08-20 22:24 . 2008-08-20 22:24 <DIR> d-------- C:\Program Files\MSXML 4.0 2008-08-20 21:34 . 2008-08-20 21:34 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Malwarebytes 2008-08-20 21:34 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\System32\drivers\mbam.sys 2008-08-20 21:33 . 2008-08-20 21:33 <DIR> d-------- C:\Users\All Users\Malwarebytes 2008-08-20 21:33 . 2008-08-20 21:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-08-20 21:33 . 2008-08-20 21:33 <DIR> d-------- C:\PROGRA~2\Malwarebytes 2008-08-20 21:33 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\System32\drivers\mbamswissarmy.sys 2008-08-20 00:26 . 2008-08-20 02:42 <DIR> d-------- C:\Program Files\EsetOnlineScanner 2008-08-20 00:22 . 2008-08-20 00:22 <DIR> d-------- C:\!KillBox 2008-08-19 00:35 . 2008-08-19 00:35 <DIR> d-------- C:\WINDOWS\System32\Kaspersky Lab 2008-08-18 23:27 . 2008-08-18 23:30 <DIR> d-------- C:\Program Files\CCleaner 2008-08-18 19:59 . 2007-11-06 09:06 131,672 --a------ C:\WINDOWS\System32\drivers\Uim_IM.sys 2008-08-18 19:59 . 2007-11-06 09:06 32,080 --a------ C:\WINDOWS\System32\drivers\UimBus.sys 2008-08-18 19:59 . 2007-11-06 09:06 11,568 --a------ C:\WINDOWS\System32\drivers\UimFIO.sys 2008-08-18 19:57 . 2008-01-21 17:43 13,576 --a------ C:\WINDOWS\System32\wnaspi32.dll 2008-08-18 06:08 . 2008-08-18 06:08 <DIR> d-------- C:\Users\Los Dávola\Program Files 2008-08-18 06:08 . 2008-08-18 06:08 <DIR> d-------- C:\Users\Los Dávola\Program Files 2008-08-18 05:11 . 2008-08-18 05:14 <DIR> d-------- C:\Program Files\ISOpen 2008-08-18 05:00 . 2008-08-18 05:01 <DIR> d-------- C:\Program Files\DAEMON Tools Lite 2008-08-18 03:38 . 2008-08-18 03:38 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\Users\All Users\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\Program Files\ESET 2008-08-18 03:33 . 2008-08-18 03:33 <DIR> d-------- C:\PROGRA~2\ESET 2008-08-18 02:55 . 2008-08-22 23:57 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\DNA 2008-08-18 02:55 . 2008-08-22 01:23 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\BitTorrent 2008-08-18 02:55 . 2008-08-18 02:55 <DIR> d-------- C:\Program Files\DNA 2008-08-18 02:55 . 2008-08-18 03:30 <DIR> d-------- C:\Program Files\BitTorrent 2008-08-18 02:34 . 2008-08-18 02:34 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\WinRAR 2008-08-18 02:08 . 2008-08-18 02:08 <DIR> d-------- C:\Program Files\Skype 2008-08-18 02:08 . 2008-08-18 02:08 <DIR> d-------- C:\Program Files\Common Files\Skype 2008-08-18 02:07 . 2008-08-18 02:08 <DIR> d-------- C:\Users\All Users\Skype 2008-08-18 02:07 . 2008-08-18 02:08 <DIR> d-------- C:\PROGRA~2\Skype 2008-08-18 01:18 . 2008-08-21 22:37 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy 2008-08-18 01:18 . 2008-08-18 01:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-08-18 01:18 . 2008-08-21 22:37 <DIR> d-------- C:\PROGRA~2\Spybot - Search & Destroy 2008-08-18 01:13 . 2006-10-04 23:42 2,560 --------- C:\WINDOWS\System32\drivers\cdralw2k.sys 2008-08-18 01:13 . 2006-10-04 23:42 2,432 --------- C:\WINDOWS\System32\drivers\cdr4_xp.sys 2008-08-18 01:12 . 2008-08-18 01:13 <DIR> d-------- C:\Program Files\Picasa2 2008-08-18 01:12 . 2008-08-18 01:12 <DIR> d-------- C:\Program Files\Google 2008-08-18 00:33 . 2008-08-18 02:45 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller 2008-08-18 00:32 . 2008-08-18 02:45 <DIR> d-------- C:\Program Files\Windows Live 2008-08-18 00:31 . 2008-08-18 00:31 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Macromedia 2008-08-18 00:31 . 2008-08-18 02:31 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Adobe 2008-08-18 00:30 . 2008-08-18 00:30 <DIR> d-------- C:\Users\Los Dávola\Application Data 2008-08-18 00:30 . 2008-08-18 00:30 <DIR> d-------- C:\Users\Los Dávola\Application Data 2008-08-18 00:28 . 2008-08-18 02:35 <DIR> d-------- C:\Users\All Users\WLInstaller 2008-08-18 00:28 . 2008-08-18 02:35 <DIR> d-------- C:\PROGRA~2\WLInstaller 2008-08-18 00:26 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\System32\mdimon.dll 2008-08-18 00:19 . 2008-08-18 00:19 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\Mozilla 2008-08-18 00:15 . 2008-08-18 00:15 <DIR> d-------- C:\WINDOWS\PCHEALTH 2008-08-18 00:15 . 2008-08-18 00:15 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-08-18 00:07 . 2008-08-18 00:07 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8 2008-08-18 00:07 . 2008-08-18 00:07 <DIR> d-------- C:\IDE 2008-08-18 00:06 . 2008-08-18 00:16 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-08-18 00:05 . 2008-08-18 00:05 <DIR> dr-h----- C:\MSOCache 2008-08-17 23:56 . 2008-08-17 23:56 <DIR> d-------- C:\WINDOWS\System32\ShellExt 2008-08-17 23:54 . 2008-08-17 23:59 <DIR> d-------- C:\Program Files\SysinternalsSuite 2008-08-17 23:53 . 2008-08-17 23:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-08-17 23:45 . 2008-08-17 23:45 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\Users\All Users\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008 2008-08-17 23:44 . 2008-08-17 23:44 <DIR> d-------- C:\PROGRA~2\TuneUp Software 2008-08-17 23:44 . 2008-08-17 23:44 306,432 --a------ C:\WINDOWS\System32\TuneUpDefragService.exe 2008-08-17 23:44 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\System32\uxtuneup.dll 2008-08-17 23:44 . 2007-12-20 10:44 16,640 --a------ C:\WINDOWS\System32\authuitu.dll 2008-08-17 23:42 . 2008-08-17 23:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-08-17 23:42 . 2008-08-17 23:42 717,296 --a------ C:\WINDOWS\System32\drivers\sptd.sys 2008-08-17 23:41 . 2008-08-17 23:41 <DIR> d-------- C:\Users\Los Dávola\AppData\Roaming\DAEMON Tools . (((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) ) . 2008-08-23 03:06 4,456,448 --sha-w C:\Users\Los Dávola\NTUSER.DAT 2008-08-23 03:06 4,456,448 --sha-w C:\Users\Los Dávola\NTUSER.DAT 2008-08-23 02:57 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\DNA 2008-08-22 04:34 --------- d-s---w C:\Users\Los Dávola\AppData\Roaming\Microsoft 2008-08-22 04:23 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\BitTorrent 2008-08-22 02:54 --------- d-----w C:\PROGRA~2\NVIDIA 2008-08-22 02:49 174 --sha-w C:\Program Files\desktop.ini 2008-08-22 02:38 --------- d-----w C:\Program Files\Windows Sidebar 2008-08-22 02:38 --------- d-----w C:\Program Files\Windows Photo Gallery 2008-08-22 02:38 --------- d-----w C:\Program Files\Windows Mail 2008-08-22 02:38 --------- d-----w C:\Program Files\Windows Defender 2008-08-22 02:38 --------- d-----w C:\Program Files\Windows Calendar 2008-08-21 01:54 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-08-21 01:54 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-08-21 01:54 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll 2008-08-21 01:54 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-08-21 01:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-08-21 00:34 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Malwarebytes 2008-08-19 00:50 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-08-19 00:38 --------- d-----w C:\Program Files\Microsoft Works 2008-08-18 06:38 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\ESET 2008-08-18 05:34 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\WinRAR 2008-08-18 05:31 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Adobe 2008-08-18 04:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-08-18 04:03 --------- d-----w C:\PROGRA~2\Symantec 2008-08-18 03:31 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Macromedia 2008-08-18 03:19 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Mozilla 2008-08-18 03:17 --------- d-----w C:\Program Files\MSBuild 2008-08-18 02:45 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\TuneUp Software 2008-08-18 02:41 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\DAEMON Tools 2008-08-18 02:18 --------- d-----w C:\PROGRA~2\HP 2008-08-18 02:07 --------- d-----w C:\PROGRA~2\Hewlett-Packard 2008-08-18 01:21 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Symantec 2008-08-18 01:19 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Identities 2008-08-18 01:17 --------- d-----w C:\Users\Los Dávola\AppData\Roaming\Hewlett-Packard 2008-08-18 01:10 --------- d-sh--w C:\Program Files\Archivos comunes 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Plantillas 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Menú Inicio 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Favoritos 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Escritorio 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Documentos 2008-08-18 01:10 --------- d-sh--w C:\PROGRA~2\Datos de programa 2008-07-01 12:04 71,688 ----a-w C:\Windows\system32\drivers\epfw.sys 2008-07-01 12:04 54,280 ----a-w C:\Windows\system32\drivers\epfwtdi.sys 2008-07-01 12:04 30,728 ----a-w C:\Windows\system32\drivers\epfwndis.sys 2008-07-01 11:57 53,256 ----a-w C:\Windows\system32\drivers\easdrv.sys 2008-07-01 11:56 39,944 ----a-w C:\Windows\system32\drivers\eamon.sys . ((((((((((((((((((((((((((((( snapshot@2008-08-20_23.44.22.20 ))))))))))))))))))))))))))))))))))))))))) . - 2006-11-02 09:46:02 237,568 ----a-w C:\Windows\AppPatch\AcRedir.dll + 2008-01-19 07:33:41 237,568 ----a-w C:\Windows\AppPatch\AcRedir.dll - 2006-11-02 09:46:02 40,960 ----a-w C:\Windows\AppPatch\apihex86.dll + 2008-01-19 07:33:43 40,960 ----a-w C:\Windows\AppPatch\apihex86.dll - 2007-12-14 23:06:57 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll + 2008-01-19 07:34:28 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll - 2006-10-20 01:13:56 69,120 ----a-w C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0. 0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2008-01-05 11:26:08 69,120 ----a-w C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0. 0__b03f5f7f11d50a3a\CustomMarshalers.dll - 2006-10-20 01:14:03 72,192 ----a-w C:\Windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b0 3f5f7f11d50a3a\ISymWrapper.dll + 2008-01-05 11:26:17 72,192 ----a-w C:\Windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b0 3f5f7f11d50a3a\ISymWrapper.dll - 2006-11-02 12:32:10 507,904 ----a-w C:\Windows\assembly\GAC_32\Microsoft.Ink\6.0.0.0__ 31bf3856ad364e35\Microsoft.Ink.dll + 2008-01-19 07:38:34 507,904 ----a-w C:\Windows\assembly\GAC_32\Microsoft.Ink\6.0.0.0__ 31bf3856ad364e35\Microsoft.Ink.dll - 2006-11-02 12:32:40 151,552 ----a-w C:\Windows\assembly\GAC_32\Microsoft.Transactions. Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Tra nsactions.Bridge.Dtc.dll + 2008-01-05 11:21:39 151,552 ----a-w C:\Windows\assembly\GAC_32\Microsoft.Transactions. Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Tra nsactions.Bridge.Dtc.dll - 2007-12-14 14:37:47 4,308,992 ----a-w C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5 c561934e089\mscorlib.dll + 2008-01-05 11:26:32 4,444,160 ----a-w C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5 c561934e089\mscorlib.dll - 2006-11-02 09:47:03 39,936 ----a-w C:\Windows\assembly\GAC_32\napcrypt\6.0.0.0__31bf3 856ad364e35\NAPCRYPT.DLL + 2008-01-19 07:38:44 46,080 ----a-w C:\Windows\assembly\GAC_32\napcrypt\6.0.0.0__31bf3 856ad364e35\NAPCRYPT.DLL - 2006-11-02 09:47:03 98,816 ----a-w C:\Windows\assembly\GAC_32\naphlpr\6.0.0.0__31bf38 56ad364e35\NAPHLPR.DLL + 2008-01-19 07:38:45 103,936 ----a-w C:\Windows\assembly\GAC_32\naphlpr\6.0.0.0__31bf38 56ad364e35\NAPHLPR.DLL - 2006-11-02 12:32:37 3,915,264 ----a-w C:\Windows\assembly\GAC_32\PresentationCore\3.0.0. 0__31bf3856ad364e35\PresentationCore.dll + 2008-01-05 11:21:53 4,174,336 ----a-w C:\Windows\assembly\GAC_32\PresentationCore\3.0.0. 0__31bf3856ad364e35\PresentationCore.dll - 2006-10-20 01:14:47 482,304 ----a-w C:\Windows\assembly\GAC_32\System.Data.OracleClien t\2.0.0.0__b77a5c561934e089\System.Data.OracleClie nt.dll + 2008-01-05 11:26:54 483,840 ----a-w C:\Windows\assembly\GAC_32\System.Data.OracleClien t\2.0.0.0__b77a5c561934e089\System.Data.OracleClie nt.dll - 2006-10-20 01:14:47 2,894,336 ----a-w C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b7 7a5c561934e089\System.Data.dll + 2008-01-05 11:26:54 3,036,160 ----a-w C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b7 7a5c561934e089\System.Data.dll - 2006-10-20 01:14:51 258,048 ----a-w C:\Windows\assembly\GAC_32\System.EnterpriseServic es\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServ ices.dll + 2008-01-05 11:26:55 258,048 ----a-w C:\Windows\assembly\GAC_32\System.EnterpriseServic es\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServ ices.dll - 2006-11-02 06:34:22 114,176 ----a-w C:\Windows\assembly\GAC_32\System.EnterpriseServic es\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServ ices.Wrapper.dll + 2008-01-19 03:22:55 113,664 ----a-w C:\Windows\assembly\GAC_32\System.EnterpriseServic es\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServ ices.Wrapper.dll - 2006-11-02 12:32:37 344,064 ----a-w C:\Windows\assembly\GAC_32\System.Printing\3.0.0.0 __31bf3856ad364e35\System.Printing.dll + 2008-01-05 11:21:55 346,624 ----a-w C:\Windows\assembly\GAC_32\System.Printing\3.0.0.0 __31bf3856ad364e35\System.Printing.dll - 2006-10-20 01:14:53 260,096 ----a-w C:\Windows\assembly\GAC_32\System.Transactions\2.0 .0.0__b77a5c561934e089\System.Transactions.dll + 2008-01-05 11:26:59 261,120 ----a-w C:\Windows\assembly\GAC_32\System.Transactions\2.0 .0.0__b77a5c561934e089\System.Transactions.dll - 2007-12-14 23:00:34 5,156,864 ----a-w C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03 f5f7f11d50a3a\System.Web.dll + 2008-01-05 11:26:59 5,431,296 ----a-w C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03 f5f7f11d50a3a\System.Web.dll - 2006-10-20 01:13:37 10,752 ----a-w C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0 __b03f5f7f11d50a3a\Accessibility.dll + 2008-01-05 11:25:52 10,752 ----a-w C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0 __b03f5f7f11d50a3a\Accessibility.dll - 2007-12-14 22:24:43 315,392 ----a-w C:\Windows\assembly\GAC_MSIL\AspNetMMCExt.resource s\2.0.0.0_es_b03f5f7f11d50a3a\aspnetmmcext.resourc es.dll + 2008-01-05 11:24:43 315,392 ----a-w C:\Windows\assembly\GAC_MSIL\AspNetMMCExt.resource s\2.0.0.0_es_b03f5f7f11d50a3a\aspnetmmcext.resourc es.dll - 2006-10-20 01:13:41 503,808 ----a-w C:\Windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0_ _b03f5f7f11d50a3a\AspNetMMCExt.dll + 2008-01-05 11:25:59 507,904 ----a-w C:\Windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0_ _b03f5f7f11d50a3a\AspNetMMCExt.dll - 2006-11-02 12:32:40 159,744 ----a-w C:\Windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0_ _b03f5f7f11d50a3a\ComSvcConfig.exe + 2008-01-05 11:21:39 159,744 ----a-w C:\Windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0_ _b03f5f7f11d50a3a\ComSvcConfig.exe - 2006-10-20 01:13:56 13,312 ----a-w C:\Windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b0 3f5f7f11d50a3a\cscompmgd.dll + 2008-01-05 11:26:08 13,312 ----a-w C:\Windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b0 3f5f7f11d50a3a\cscompmgd.dll - 2006-10-20 01:13:57 5,120 ----a-w C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f 7f11d50a3a\dfsvc.exe + 2008-01-05 11:26:11 5,120 ----a-w C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f 7f11d50a3a\dfsvc.exe - 2007-12-14 22:24:44 9,728 ----a-w C:\Windows\assembly\GAC_MSIL\EventViewer.Resources \6.0.0.0_es_31bf3856ad364e35\EventViewer.resources .dll + 2008-01-19 07:54:09 9,728 ----a-w C:\Windows\assembly\GAC_MSIL\EventViewer.Resources \6.0.0.0_es_31bf3856ad364e35\EventViewer.resources .dll - 2006-11-02 09:46:54 364,544 ----a-w C:\Windows\assembly\GAC_MSIL\EventViewer\6.0.0.0__ 31bf3856ad364e35\EventViewer.dll + 2008-01-19 07:38:21 364,544 ----a-w C:\Windows\assembly\GAC_MSIL\EventViewer\6.0.0.0__ 31bf3856ad364e35\EventViewer.dll - 2006-10-20 01:14:02 8,192 ----a-w C:\Windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0_ _b03f5f7f11d50a3a\IEExecRemote.dll + 2008-01-05 11:26:12 8,192 ----a-w C:\Windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0_ _b03f5f7f11d50a3a\IEExecRemote.dll - 2006-10-20 01:14:02 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5 f7f11d50a3a\IEHost.dll + 2008-01-05 11:26:12 77,824 ----a-w C:\Windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5 f7f11d50a3a\IEHost.dll - 2006-10-20 01:14:02 5,632 ----a-w C:\Windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f 5f7f11d50a3a\IIEHost.dll + 2008-01-05 11:26:13 6,656 ----a-w C:\Windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f 5f7f11d50a3a\IIEHost.dll - 2007-12-14 22:24:53 53,248 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Engin e.resources\2.0.0.0_es_b03f5f7f11d50a3a\Microsoft. Build.Engine.resources.dll + 2008-01-05 11:24:43 53,248 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Engin e.resources\2.0.0.0_es_b03f5f7f11d50a3a\Microsoft. Build.Engine.resources.dll - 2006-10-20 01:14:03 413,696 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Engin e\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine .dll + 2008-01-05 11:26:17 348,160 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Engin e\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine .dll - 2006-10-20 01:14:03 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Frame work\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Fra mework.dll + 2008-01-05 11:26:17 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Frame work\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Fra mework.dll - 2007-12-14 22:24:51 139,264 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Tasks .resources\2.0.0.0_es_b03f5f7f11d50a3a\Microsoft.B uild.Tasks.resources.dll + 2008-01-05 11:24:44 139,264 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Tasks .resources\2.0.0.0_es_b03f5f7f11d50a3a\Microsoft.B uild.Tasks.resources.dll - 2006-10-20 01:14:03 647,168 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Tasks \2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.d ll + 2008-01-05 11:26:17 655,360 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Tasks \2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.d ll - 2007-12-14 22:24:43 10,240 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.build.utili ties.resources\2.0.0.0_es_b03f5f7f11d50a3a\Microso ft.Build.Utilities.Resources.dll + 2008-01-05 11:24:45 10,752 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.build.utili ties.resources\2.0.0.0_es_b03f5f7f11d50a3a\Microso ft.Build.Utilities.Resources.dll - 2006-10-20 01:14:04 73,728 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Utili ties\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Uti lities.dll + 2008-01-05 11:26:17 77,824 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Build.Utili ties\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Uti lities.dll - 2007-12-14 22:24:58 40,960 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Ink.Resourc es\6.0.0.0_es_31bf3856ad364e35\Microsoft.Ink.Resou rces.dll + 2008-01-19 07:54:13 40,960 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Ink.Resourc es\6.0.0.0_es_31bf3856ad364e35\Microsoft.Ink.Resou rces.dll - 2007-12-14 22:23:55 45,056 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Jscript.res ources\8.0.0.0_es_b03f5f7f11d50a3a\Microsoft.JScri pt.Resources.dll + 2008-01-05 11:24:45 45,056 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Jscript.res ources\8.0.0.0_es_b03f5f7f11d50a3a\Microsoft.JScri pt.Resources.dll - 2006-10-20 01:14:04 749,568 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.JScript\8.0 .0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2008-01-05 11:26:19 749,568 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.JScript\8.0 .0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2006-11-02 09:47:01 245,760 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.ManagementC onsole\3.0.0.0__31bf3856ad364e35\Microsoft.Managem entConsole.dll + 2008-01-19 07:38:35 188,416 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.ManagementC onsole\3.0.0.0__31bf3856ad364e35\Microsoft.Managem entConsole.dll - 2007-12-14 22:25:10 28,672 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Transaction s.Bridge.resources\3.0.0.0_es_b03f5f7f11d50a3a\Mic rosoft.Transactions.Bridge.Resources.dll + 2008-01-05 11:25:15 28,672 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Transaction s.Bridge.resources\3.0.0.0_es_b03f5f7f11d50a3a\Mic rosoft.Transactions.Bridge.Resources.dll - 2006-11-02 12:32:41 352,256 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Transaction s.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Trans actions.Bridge.dll + 2008-01-05 11:21:39 397,312 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Transaction s.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Trans actions.Bridge.dll - 2007-12-14 22:24:26 9,216 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.visualbasic .compatibility.data.resources\8.0.0.0_es_b03f5f7f1 1d50a3a\Microsoft.VisualBasic.Compatibility.Data.r esources.dll + 2008-01-05 11:24:53 9,216 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.visualbasic .compatibility.data.resources\8.0.0.0_es_b03f5f7f1 1d50a3a\Microsoft.VisualBasic.Compatibility.Data.r esources.dll - 2006-10-20 01:14:05 110,592 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Micr osoft.VisualBasic.Compatibility.Data.dll + 2008-01-05 11:26:19 110,592 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Micr osoft.VisualBasic.Compatibility.Data.dll - 2007-12-14 22:24:54 9,216 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.visualbasic .compatibility.resources\8.0.0.0_es_b03f5f7f11d50a 3a\Microsoft.VisualBasic.Compatibility.resources.d ll + 2008-01-05 11:24:53 9,216 ----a-w C:\Windows\assembly\GAC_MSIL\microsoft.visualbasic .compatibility.resources\8.0.0.0_es_b03f5f7f11d50a 3a\Microsoft.VisualBasic.Compatibility.resources.d ll - 2006-10-20 01:14:05 372,736 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft .VisualBasic.Compatibility.dll + 2008-01-05 11:26:23 372,736 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft .VisualBasic.Compatibility.dll - 2007-12-14 22:24:38 61,440 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .resources\8.0.0.0_es_b03f5f7f11d50a3a\Microsoft.V isualBasic.resources.dll + 2008-01-05 11:24:45 61,440 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .resources\8.0.0.0_es_b03f5f7f11d50a3a\Microsoft.V isualBasic.resources.dll - 2006-10-20 01:14:05 28,672 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBas ic.Vsa.dll + 2008-01-05 11:26:23 28,672 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic .Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBas ic.Vsa.dll - 2006-10-20 01:14:05 667,648 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic \8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.d ll + 2008-01-05 11:26:23 671,744 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic \8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.d ll - 2006-10-20 01:14:05 12,800 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.Code DOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.V sa.Vb.CodeDOMProcessor.dll + 2008-01-05 11:26:24 12,800 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.Code DOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.V sa.Vb.CodeDOMProcessor.dll - 2006-10-20 01:14:05 32,768 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0 __b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2008-01-05 11:26:23 32,768 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0 __b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2007-12-14 22:25:13 7,168 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Web.Adminis tration.Resources\7.0.0.0_es_31bf3856ad364e35\Micr osoft.Web.Administration.resources.dll + 2008-01-19 07:54:14 7,168 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Web.Adminis tration.Resources\7.0.0.0_es_31bf3856ad364e35\Micr osoft.Web.Administration.resources.dll - 2006-11-02 12:32:49 114,688 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Web.Adminis tration\7.0.0.0__31bf3856ad364e35\Microsoft.Web.Ad ministration.dll + 2008-01-19 07:38:37 126,976 ----a-w C:\Windows\assembly\GAC_MSIL\Microsoft.Web.Adminis tration\7.0.0.0__31bf3856ad364e35\Microsoft.Web.Ad ministration.dll - 2007-12-14 22:24:24 1,396,736 ----a-w C:\Windows\assembly\GAC_MSIL\MiguiControls.Resourc es\1.0.0.0_es_31bf3856ad364e35\MIGUIControls.resou rces.dll + 2008-01-19 07:54:15 1,503,232 ----a-w C:\Windows\assembly\GAC_MSIL\MiguiControls.Resourc es\1.0.0.0_es_31bf3856ad364e35\MIGUIControls.resou rces.dll - 2006-11-02 09:47:03 3,100,672 ----a-w C:\Windows\assembly\GAC_MSIL\MiguiControls\1.0.0.0 __31bf3856ad364e35\MIGUIControls.dll + 2008-01-19 07:38:41 3,371,008 ----a-w C:\Windows\assembly\GAC_MSIL\MiguiControls\1.0.0.0 __31bf3856ad364e35\MIGUIControls.dll - 2007-12-14 22:23:38 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\MMCEx.Resources\3.0.0 .0_es_31bf3856ad364e35\MMCEx.Resources.dll + 2008-01-19 07:54:15 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\MMCEx.Resources\3.0.0 .0_es_31bf3856ad364e35\MMCEx.Resources.dll - 2006-11-02 09:47:03 413,696 ----a-w C:\Windows\assembly\GAC_MSIL\MMCEx\3.0.0.0__31bf38 56ad364e35\MMCEx.dll + 2008-01-19 07:38:41 417,792 ----a-w C:\Windows\assembly\GAC_MSIL\MMCEx\3.0.0.0__31bf38 56ad364e35\MMCEx.dll - 2007-12-14 14:37:53 307,200 ----a-w C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2. 0.0.0_es_b77a5c561934e089\mscorlib.Resources.dll + 2008-01-05 11:24:45 307,200 ----a-w C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2. 0.0.0_es_b77a5c561934e089\mscorlib.Resources.dll - 2006-11-02 09:47:03 65,536 ----a-w C:\Windows\assembly\GAC_MSIL\napinit\6.0.0.0__31bf 3856ad364e35\NAPINIT.DLL + 2008-01-19 07:38:45 65,536 ----a-w C:\Windows\assembly\GAC_MSIL\napinit\6.0.0.0__31bf 3856ad364e35\NAPINIT.DLL - 2007-12-14 22:24:55 245,760 ----a-w C:\Windows\assembly\GAC_MSIL\napsnap.resources\6.0 .0.0_es_31bf3856ad364e35\napsnap.resources.dll + 2008-01-19 07:54:17 245,760 ----a-w C:\Windows\assembly\GAC_MSIL\napsnap.resources\6.0 .0.0_es_31bf3856ad364e35\napsnap.resources.dll - 2006-11-02 09:47:04 458,752 ----a-w C:\Windows\assembly\GAC_MSIL\napsnap\6.0.0.0__31bf 3856ad364e35\NAPSNAP.DLL + 2008-01-19 07:38:45 458,752 ----a-w C:\Windows\assembly\GAC_MSIL\napsnap\6.0.0.0__31bf 3856ad364e35\NAPSNAP.DLL - 2006-11-02 12:32:36 593,920 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationBuildTask s\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks .dll + 2008-01-05 11:21:52 602,112 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationBuildTask s\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks .dll - 2006-11-02 12:32:35 32,768 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationCFFRaster izer\3.0.0.0__31bf3856ad364e35\PresentationCFFRast erizer.dll + 2008-01-05 11:21:52 32,768 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationCFFRaster izer\3.0.0.0__31bf3856ad364e35\PresentationCFFRast erizer.dll - 2006-11-02 12:32:37 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFontCache \3.0.0.0__31bf3856ad364e35\PresentationFontCache.e xe + 2008-01-05 11:21:53 36,864 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFontCache \3.0.0.0__31bf3856ad364e35\PresentationFontCache.e xe - 2006-11-02 12:32:36 184,320 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Aero\3.0.0.0__31bf3856ad364e35\PresentationFramew ork.Aero.dll + 2008-01-05 11:21:53 184,320 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Aero\3.0.0.0__31bf3856ad364e35\PresentationFramew ork.Aero.dll - 2006-11-02 12:32:38 126,976 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Classic\3.0.0.0__31bf3856ad364e35\PresentationFra mework.Classic.dll + 2008-01-05 11:21:53 131,072 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Classic\3.0.0.0__31bf3856ad364e35\PresentationFra mework.Classic.dll - 2006-11-02 12:32:37 376,832 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Luna\3.0.0.0__31bf3856ad364e35\PresentationFramew ork.Luna.dll + 2008-01-05 11:21:53 376,832 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Luna\3.0.0.0__31bf3856ad364e35\PresentationFramew ork.Luna.dll - 2006-11-02 12:32:37 151,552 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Royale\3.0.0.0__31bf3856ad364e35\PresentationFram ework.Royale.dll + 2008-01-05 11:21:54 151,552 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework .Royale\3.0.0.0__31bf3856ad364e35\PresentationFram ework.Royale.dll - 2006-11-02 12:32:38 4,972,544 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework \3.0.0.0__31bf3856ad364e35\PresentationFramework.d ll + 2008-01-05 11:21:53 5,210,112 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationFramework \3.0.0.0__31bf3856ad364e35\PresentationFramework.d ll - 2006-11-02 12:32:36 897,024 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationUI\3.0.0. 0__31bf3856ad364e35\PresentationUI.dll + 2008-01-05 11:21:55 897,024 ----a-w C:\Windows\assembly\GAC_MSIL\PresentationUI\3.0.0. 0__31bf3856ad364e35\PresentationUI.dll - 2006-11-02 12:32:35 528,384 ----a-w C:\Windows\assembly\GAC_MSIL\ReachFramework\3.0.0. 0__31bf3856ad364e35\ReachFramework.dll + 2008-01-05 11:21:55 528,384 ----a-w C:\Windows\assembly\GAC_MSIL\ReachFramework\3.0.0. 0__31bf3856ad364e35\ReachFramework.dll - 2006-11-02 12:32:41 61,440 ----a-w C:\Windows\assembly\GAC_MSIL\ServiceModelReg\3.0.0 .0__b03f5f7f11d50a3a\ServiceModelReg.exe + 2008-01-05 11:21:39 61,440 ----a-w C:\Windows\assembly\GAC_MSIL\ServiceModelReg\3.0.0 .0__b03f5f7f11d50a3a\ServiceModelReg.exe - 2006-11-02 12:32:40 94,208 ----a-w C:\Windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0 __b77a5c561934e089\SMdiagnostics.dll + 2008-01-05 11:21:39 102,400 ----a-w C:\Windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0 __b77a5c561934e089\SMdiagnostics.dll - 2006-11-02 12:32:39 122,880 ----a-w C:\Windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b0 3f5f7f11d50a3a\SMSvcHost.exe + 2008-01-05 11:21:39 122,880 ----a-w C:\Windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b0 3f5f7f11d50a3a\SMSvcHost.exe - 2007-12-14 22:24:29 10,752 ----a-w C:\Windows\assembly\GAC_MSIL\sysglobl.resources\2 |