This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Red Biohazard Desktop

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:56 PM, on 1/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BySoft FreeRAM\FreeRAM.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: SXG Advisor - {9C22FF6B-11B2-43B0-9F1A-8B0C209C1FAB} - C:\WINDOWS\dpvtportwf.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The elfwgps - {A6074EA4-01C7-40A1-82C3-FC683866AB03} - C:\WINDOWS\elfwgps.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Program Files\BySoft FreeRAM\FreeRAM.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6796D92-C0EA-4E04-9CE7-C6A2E8D406F6}: NameServer = 66.75.164.90,66.75.164.89
O21 - SSODL: aswmklt - {7D9EBA49-4272-47D3-B581-65492D03FBC0} - C:\WINDOWS\aswmklt.dll
O21 - SSODL: bqxomdo - {33E1C64D-8C8A-4C8E-A032-0B0193BBE3BC} - C:\WINDOWS\bqxomdo.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 8343 bytes
Hello Digitalcursive and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.



Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
SDFix: Version 1.131

Run by [removed] on Sat 01/26/2008 at 12:52 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\TREVOR~1\Desktop\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\Trevor Blake\Favorites\Error Cleaner.url - Deleted
C:\Documents and Settings\Trevor Blake\My Documents\Error Cleaner.url - Deleted
C:\Documents and Settings\Trevor Blake\Desktop\Privacy Protector.url - Deleted
C:\Documents and Settings\Trevor Blake\Favorites\Privacy Protector.url - Deleted
C:\Documents and Settings\Trevor Blake\Desktop\Spyware&Malware; Protection.url - Deleted
C:\Documents and Settings\Trevor Blake\Favorites\Spyware&Malware; Protection.url - Deleted
C:\WINDOWS\privacy_danger\index.htm - Deleted
C:\WINDOWS\privacy_danger\images\capt.gif - Deleted
C:\WINDOWS\privacy_danger\images\danger.jpg - Deleted
C:\WINDOWS\privacy_danger\images\down.gif - Deleted
C:\WINDOWS\privacy_danger\images\spacer.gif - Deleted
C:\DOCUME~1\TREVOR~1\LOCALS~1\Temp\ac8zt2.dat - Deleted
C:\WINDOWS\aswmklt.dll - Deleted
C:\WINDOWS\bqxomdo.dll - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\dpvtportwf.dll - Deleted
C:\WINDOWS\elfwgps.dll - Deleted
C:\WINDOWS\fvqkfsp.exe - Deleted



Folder C:\WINDOWS\privacy_danger - Removed


Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\explorer.exe
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 12:59:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Documents and Settings\\Trevor Blake\\My Documents\\WoW-BurningCrusade-enUS-Installer-downloader.exe"="C:\\Documents and Settings\\Trevor Blake\\My Documents\\WoW-BurningCrusade-enUS-Installer-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\DC++\\DCPlusPlus.exe"="C:\\Program Files\\DC++\\DCPlusPlus.exe:*:Enabled:DC++"
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa"
"C:\\Program Files\\Kazaa Lite\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite\\KazaaLite.kpp:*:Enabled:Kazaa Lite"
"C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"="C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe:*:Enabled:iMesh"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Starcraft\\StarCraft.exe"="C:\\Program Files\\Starcraft\\StarCraft.exe:*:Enabled:Starcraft"
"C:\\Program Files\\Opera\\Opera.exe"="C:\\Program Files\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

File Backups: - C:\DOCUME~1\TREVOR~1\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 17 Nov 2005 217,088 A..HR — "C:\WINDOWS\Alcrmv.exe"
Sat 21 Jul 2007 94,208 A..H. — "C:\WINDOWS\DIIUnin.exe"
Sat 21 Jul 2007 2,829 A..H. — "C:\WINDOWS\DIIUnin.pif"
Thu 26 May 2005 10,752 A..H. — "C:\WINDOWS\hh.exe"
Wed 20 Jun 2007 737,280 A..H. — "C:\WINDOWS\iun6002.exe"
Tue 28 Feb 2006 69,120 A..H. — "C:\WINDOWS\NOTEPAD.EXE"
Tue 28 Feb 2006 146,432 A..H. — "C:\WINDOWS\regedit.exe"
Sat 21 Jul 2007 94,208 A..H. — "C:\WINDOWS\ScUnin.exe"
Sat 21 Jul 2007 967 A..H. — "C:\WINDOWS\ScUnin.pif"
Tue 28 Feb 2006 14,573 A..HR — "C:\WINDOWS\SET25.tmp"
Tue 28 Feb 2006 1,042,903 A..HR — "C:\WINDOWS\SET3.tmp"
Tue 28 Feb 2006 1,086,058 A..HR — "C:\WINDOWS\SET4.tmp"
Tue 28 Feb 2006 13,753 A..HR — "C:\WINDOWS\SET8.tmp"
Thu 10 Nov 2005 90,112 A..HR — "C:\WINDOWS\SOUNDMAN.EXE"
Tue 28 Feb 2006 15,360 A..H. — "C:\WINDOWS\TASKMAN.EXE"
Tue 28 Feb 2006 94,784 A..H. — "C:\WINDOWS\twain.dll"
Tue 28 Feb 2006 50,688 A..H. — "C:\WINDOWS\twain_32.dll"
Tue 28 Feb 2006 49,680 A..H. — "C:\WINDOWS\twunk_16.exe"
Tue 28 Feb 2006 25,600 A..H. — "C:\WINDOWS\twunk_32.exe"
Tue 28 Feb 2006 18,944 A..H. — "C:\WINDOWS\vmmreg32.dll"
Tue 28 Feb 2006 256,192 A..H. — "C:\WINDOWS\winhelp.exe"
Tue 28 Feb 2006 283,648 A..H. — "C:\WINDOWS\winhlp32.exe"
Fri 25 Dec 1998 254,976 A..H. — "C:\WINDOWS\xaudio.dll"
Tue 28 Feb 2006 707 A..H. — "C:\WINDOWS\_default.pif"
Thu 14 Oct 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB873339\spmsg.dll"
Thu 14 Oct 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB873339\spuninst.exe"
Thu 14 Oct 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\spmsg.dll"
Thu 14 Oct 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\spuninst.exe"
Thu 14 Oct 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB885836\spmsg.dll"
Thu 14 Oct 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB885836\spuninst.exe"
Thu 14 Oct 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB886185\spmsg.dll"
Thu 14 Oct 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB886185\spuninst.exe"
Thu 14 Oct 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB887472\spmsg.dll"
Thu 14 Oct 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB887472\spuninst.exe"
Tue 30 Nov 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB888302\spmsg.dll"
Tue 30 Nov 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB888302\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\spuninst.exe"
Tue 30 Nov 2004 7,168 A..H. — "C:\WINDOWS\$hf_mig$\KB891781\spmsg.dll"
Tue 30 Nov 2004 169,984 A..H. — "C:\WINDOWS\$hf_mig$\KB891781\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\spuninst.exe"
Thu 24 Feb 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\spupdsvc.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\spuninst.exe"
Thu 24 Feb 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\spmsg.dll"
Thu 24 Feb 2005 209,632 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\spuninst.exe"
Wed 12 Oct 2005 14,048 A..H. — "C:\WINDOWS\$hf_mig$\KB924191\spmsg.dll"
Wed 12 Oct 2005 213,216 A..H. — "C:\WINDOWS\$hf_mig$\KB924191\spuninst.exe"
Wed 20 Jun 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 17 Nov 2004 347,136 A..H. — "C:\WINDOWS\$hf_mig$\KB873339\SP2QFE\hypertrm.dll"
Thu 14 Oct 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB873339\update\spcustom.dll"
Thu 14 Oct 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB873339\update\update.exe"
Wed 27 Oct 2004 721,920 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\lsasrv.dll"
Wed 27 Oct 2004 448,128 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\mrxsmb.sys"
Wed 27 Oct 2004 174,592 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\rdbss.sys"
Thu 14 Oct 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\update\spcustom.dll"
Thu 14 Oct 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB885835\update\update.exe"
Thu 14 Oct 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB885836\update\spcustom.dll"
Thu 14 Oct 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB885836\update\update.exe"
Wed 29 Sep 2004 134,912 A..H. — "C:\WINDOWS\$hf_mig$\KB886185\SP2QFE\ipnat.sys"
Thu 14 Oct 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB886185\update\spcustom.dll"
Thu 14 Oct 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB886185\update\update.exe"
Wed 13 Oct 2004 1,694,208 A..H. — "C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe"
Thu 14 Oct 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB887472\update\spcustom.dll"
Thu 14 Oct 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB887472\update\update.exe"
Tue 7 Dec 2004 96,768 A..H. — "C:\WINDOWS\$hf_mig$\KB888302\SP2QFE\srvsvc.dll"
Tue 30 Nov 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB888302\update\spcustom.dll"
Tue 30 Nov 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB888302\update\update.exe"
Thu 21 Apr 2005 57,344 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\SP2QFE\agentdpv.dll"
Mon 16 May 2005 17,920 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\SP2QFE\xpsp3res.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB890046\update\updspapi.dll"
Wed 2 Mar 2005 62,464 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\authz.dll"
Tue 1 Mar 2005 2,135,552 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlmp.exe"
Tue 1 Mar 2005 2,056,832 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe"
Tue 1 Mar 2005 2,015,232 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrpamp.exe"
Tue 1 Mar 2005 2,179,456 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe"
Wed 2 Mar 2005 577,024 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll"
Tue 1 Mar 2005 1,836,160 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\win32k.sys"
Wed 2 Mar 2005 291,328 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\winsrv.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB890859\update\updspapi.dll"
Tue 30 Nov 2004 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB891781\update\spcustom.dll"
Tue 30 Nov 2004 654,848 A..H. — "C:\WINDOWS\$hf_mig$\KB891781\update\update.exe"
Fri 8 Jul 2005 249,344 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\SP2QFE\tapisrv.dll"
Thu 7 Jul 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB893756\update\updspapi.dll"
Thu 28 Apr 2005 1,286,144 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\ole32.dll"
Thu 28 Apr 2005 74,752 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\olecli32.dll"
Thu 28 Apr 2005 37,376 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\olecnv32.dll"
Thu 28 Apr 2005 396,288 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\rpcss.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB894391\update\updspapi.dll"
Thu 26 May 2005 10,752 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\hh.exe"
Thu 26 May 2005 41,472 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\hhsetup.dll"
Thu 26 May 2005 155,136 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\itircl.dll"
Thu 26 May 2005 137,216 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\itss.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB896358\update\updspapi.dll"
Fri 10 Jun 2005 57,856 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe"
Wed 29 Jun 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB896423\update\updspapi.dll"
Tue 10 May 2005 75,776 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\SP2QFE\telnet.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB896428\update\updspapi.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB898461\update\updspapi.dll"
Wed 15 Jun 2005 297,984 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\SP2QFE\kerberos.dll"
Wed 29 Jun 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB899587\update\updspapi.dll"
Thu 9 Jun 2005 139,528 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\SP2QFE\rdpwd.sys"
Wed 29 Jun 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB899591\update\updspapi.dll"
Tue 14 Feb 2006 142,464 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\SP2QFE\aec.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB900485\update\updspapi.dll"
Wed 31 Aug 2005 19,968 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\linkinfo.dll"
Thu 22 Sep 2005 8,452,608 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\shell32.dll"
Fri 2 Sep 2005 474,112 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\shlwapi.dll"
Wed 31 Aug 2005 291,840 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\winsrv.dll"
Mon 26 Sep 2005 21,504 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\xpsp3res.dll"
Mon 26 Sep 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB900725\update\updspapi.dll"
Fri 9 Sep 2005 2,068,480 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\SP2QFE\cdosys.dll"
Fri 9 Sep 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB901017\update\updspapi.dll"
Tue 28 Jun 2005 254,976 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\SP2QFE\icm32.dll"
Tue 28 Jun 2005 73,728 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\SP2QFE\mscms.dll"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB901214\update\updspapi.dll"
Mon 25 Jul 2005 225,792 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrv.dll"
Mon 25 Jul 2005 625,152 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrvut.dll"
Mon 25 Jul 2005 110,080 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll"
Mon 25 Jul 2005 498,688 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll"
Mon 25 Jul 2005 60,416 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\colbact.dll"
Mon 25 Jul 2005 195,072 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comadmin.dll"
Mon 25 Jul 2005 97,792 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comrepl.dll"
Mon 25 Jul 2005 1,267,200 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comsvcs.dll"
Mon 25 Jul 2005 540,160 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\comuid.dll"
Mon 25 Jul 2005 243,200 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\es.dll"
Mon 25 Jul 2005 8,704 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\migregdb.exe"
Mon 25 Jul 2005 425,472 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcprx.dll"
Mon 25 Jul 2005 945,152 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtctm.dll"
Mon 25 Jul 2005 161,280 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\msdtcuiu.dll"
Mon 25 Jul 2005 66,560 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxclu.dll"
Mon 25 Jul 2005 91,136 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\mtxoci.dll"
Mon 25 Jul 2005 1,285,632 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\ole32.dll"
Mon 25 Jul 2005 74,752 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\olecli32.dll"
Mon 25 Jul 2005 37,376 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\olecnv32.dll"
Mon 25 Jul 2005 398,336 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\rpcss.dll"
Mon 25 Jul 2005 101,376 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\txflog.dll"
Mon 25 Jul 2005 11,776 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\xolehlp.dll"
Mon 25 Jul 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB902400\update\updspapi.dll"
Mon 29 Aug 2005 1,287,680 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\SP2QFE\quartz.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB904706\update\updspapi.dll"
Mon 22 Aug 2005 197,632 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\SP2QFE\netman.dll"
Fri 19 Aug 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB905414\update\updspapi.dll"
Mon 22 Aug 2005 123,392 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\SP2QFE\umpnpmgr.dll"
Mon 22 Aug 2005 30,720 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\update\arpidfix.exe"
Thu 24 Feb 2005 22,240 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\update\spcustom.dll"
Thu 24 Feb 2005 718,048 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\update\update.exe"
Thu 24 Feb 2005 371,936 A..H. — "C:\WINDOWS\$hf_mig$\KB905749\update\updspapi.dll"
Mon 17 Oct 2005 80,896 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\SP2QFE\fontsub.dll"
Mon 17 Oct 2005 117,760 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\SP2QFE\t2embed.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB908519\update\updspapi.dll"
Thu 16 Mar 2006 8,454,656 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\SP2QFE\shell32.dll"
Thu 16 Mar 2006 28,672 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\SP2QFE\verclsid.exe"
Tue 21 Mar 2006 23,040 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\SP2QFE\xpsp3res.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB908531\update\updspapi.dll"
Thu 20 Oct 2005 1,082,368 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\SP2QFE\esent.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB910437\update\updspapi.dll"
Tue 21 Feb 2006 1,022,976 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\browseui.dll"
Tue 24 Jan 2006 251,904 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\iepeers.dll"
Tue 21 Feb 2006 3,052,032 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\mshtml.dll"
Tue 21 Feb 2006 1,495,040 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\shdocvw.dll"
Tue 24 Jan 2006 474,112 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\shlwapi.dll"
Mon 9 Jan 2006 613,376 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\urlmon.dll"
Tue 31 Jan 2006 22,528 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\SP2QFE\xpsp3res.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\update\update.exe"
Thu 19 Jan 2006 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB911164\update\updspapi.dll"
Thu 22 Jun 2006 180,736 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\SP2QFE\rasmans.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB911280\update\updspapi.dll"
Wed 22 Mar 2006 143,360 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\SP2QFE\msadco.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB911562\update\updspapi.dll"
Tue 3 Jan 2006 68,096 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\SP2QFE\webclnt.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB911927\update\updspapi.dll"
Wed 1 Mar 2006 426,496 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtcprx.dll"
Wed 1 Mar 2006 956,416 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtctm.dll"
Wed 1 Mar 2006 161,280 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\msdtcuiu.dll"
Wed 1 Mar 2006 66,560 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\mtxclu.dll"
Wed 1 Mar 2006 91,136 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\mtxoci.dll"
Wed 1 Mar 2006 11,776 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\SP2QFE\xolehlp.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB913580\update\updspapi.dll"
Fri 19 May 2006 112,128 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\SP2QFE\dhcpcsvc.dll"
Fri 19 May 2006 147,456 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\SP2QFE\dnsapi.dll"
Fri 19 May 2006 94,720 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\SP2QFE\iphlpapi.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB914388\update\updspapi.dll"
Fri 5 May 2006 454,400 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\SP2QFE\mrxsmb.sys"
Fri 5 May 2006 174,592 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\SP2QFE\rdbss.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB914389\update\updspapi.dll"
Thu 16 Mar 2006 262,656 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\SP2QFE\http.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB916595\update\updspapi.dll"
Wed 17 May 2006 450,560 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\SP2QFE\jscript.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB917344\update\updspapi.dll"
Thu 20 Apr 2006 360,576 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB917953\update\updspapi.dll"
Mon 27 Nov 2006 539,136 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\SP2QFE\msftedit.dll"
Mon 27 Nov 2006 433,664 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\SP2QFE\riched20.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB918118\update\updspapi.dll"
Thu 1 Jun 2006 163,840 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\SP2QFE\jgdw400.dll"
Thu 1 Jun 2006 27,648 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\SP2QFE\jgpl400.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB918439\update\updspapi.dll"
Thu 13 Jul 2006 202,496 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\SP2QFE\rmcast.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB919007\update\updspapi.dll"
Thu 12 Oct 2006 42,496 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdp2.dll"
Thu 12 Oct 2006 57,344 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdpv.dll"
Thu 12 Oct 2006 256,512 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe"
Mon 16 Oct 2006 248,320 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\xpsp3res.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB920213\update\updspapi.dll"
Fri 21 Jul 2006 72,704 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\SP2QFE\hlink.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB920670\update\updspapi.dll"
Mon 26 Jun 2006 147,456 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\SP2QFE\dnsapi.dll"
Mon 26 Jun 2006 7,680 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\SP2QFE\rasadhlp.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB920683\update\updspapi.dll"
Wed 21 Jun 2006 69,120 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\SP2QFE\ciodm.dll"
Wed 21 Jun 2006 1,435,648 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\SP2QFE\query.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB920685\update\updspapi.dll"
Wed 14 Jun 2006 172,416 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\kmixer.sys"
Wed 14 Jun 2006 6,272 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\splitter.sys"
Wed 14 Jun 2006 82,944 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\wdmaud.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB920872\update\updspapi.dll"
Thu 17 May 2007 549,888 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\SP2QFE\oleaut32.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB921503\update\updspapi.dll"
Mon 21 Aug 2006 16,896 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\SP2QFE\fltlib.dll"
Mon 21 Aug 2006 23,040 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\SP2QFE\fltmc.exe"
Mon 21 Aug 2006 128,768 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\SP2QFE\fltmgr.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB922582\update\updspapi.dll"
Wed 16 Aug 2006 100,352 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\SP2QFE\6to4svc.dll"
Wed 16 Aug 2006 225,664 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\SP2QFE\tcpip6.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB922819\update\updspapi.dll"
Mon 14 Aug 2006 332,928 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\SP2QFE\srv.sys"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB923414\update\updspapi.dll"
Fri 13 Oct 2006 64,000 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwapi32.dll"
Fri 13 Oct 2006 142,336 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwprovau.dll"
Fri 13 Oct 2006 163,456 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwrdr.sys"
Fri 13 Oct 2006 65,536 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwwks.dll"
Wed 12 Oct 2005 22,752 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\update\spcustom.dll"
Wed 12 Oct 2005 716,000 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\update\update.exe"
Wed 12 Oct 2005 371,424 A..H. — "C:\WINDOWS\$hf_mig$\KB923980\update\updspapi.dll"
Tue 20 Jan 2004 4,348 A..H. — "C:\Documents and Settings\Trevor Blake\My Documents\My Music\My Videos\My Music\License Backup\drmv1key.bak"
Sat 29 Oct 2005 401 A..H. — "C:\Documents and Settings\Trevor Blake\My Documents\My Music\My Videos\My Music\License Backup\drmv1lic.bak"
Fri 29 Apr 2005 488 A.SH. — "C:\Documents and Settings\Trevor Blake\My Documents\My Music\My Videos\My Music\License Backup\drmv2key.bak"

Finished!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:06:49 PM, on 1/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BySoft FreeRAM\FreeRAM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Program Files\BySoft FreeRAM\FreeRAM.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6796D92-C0EA-4E04-9CE7-C6A2E8D406F6}: NameServer = 66.75.164.90,66.75.164.89
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 7768 bytes
A. I notice from the log that there are running more than one different Anti-Virus programs with Auto-protect enabled. Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

So you have to make a decision here and keep the Antivirus you prefer and uninstall the other one.
Then reboot after uninstalling.

Once you have done the above, please post a fresh HijackThis log.


B. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.


Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.

C. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System


  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in this thread so we can check how everything looks now. In addition, please tell me if there are any more malware problems that you are aware of.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:14:16 PM, on 1/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\BySoft FreeRAM\FreeRAM.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Program Files\BySoft FreeRAM\FreeRAM.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6796D92-C0EA-4E04-9CE7-C6A2E8D406F6}: NameServer = 66.75.164.90,66.75.164.89
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 7238 bytes


There doesnt seem to be any other problems that I notice myself, thanks for everything so far :D
Congratulations, your log looks CLEAN

There are a few things you must do once you are completely clean:

1. Please DELETE SDFix from your system.

2. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

7. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI