This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Pop-up tabs in Firefox

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I realized I had a problem with my computer when SpyBot started repeatedly giving me alerts about changes (you know, that thing where it asks permission to change certain things.) I kept denying the changes over and over again and then I started getting pop-up tabs in my browser. I tried running Spybot, Malwarebyte's Antimalware, and RogueRemover. Spybot kept finding and removing Virtumonde, but ever time I would run it, it would come back. RogueRemover would freeze up when I tried to run it.

My girlfriend told me about this website; she had a problem last year and you guys were able to help her out. Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:27 PM, on 11/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\seek.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {a93de238-14ac-46b8-9d6d-6e2a28c6eb27} - C:\WINDOWS\system32\sajuyaya.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [zogosogisa] Rundll32.exe "C:\WINDOWS\system32\yubuguyi.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [zogosogisa] Rundll32.exe "C:\WINDOWS\system32\yubuguyi.dll",s (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sosafuji.dll c:\windows\system32\tesawuzo.dll c:\windows\system32\jidesoti.dll c:\windows\system32\bosotozo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bosotozo.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

–
End of file - 6832 bytes
Hi frankswildyears, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • If you have problems with or do not understand the instructions, Please ask before continuing.
I will post back soon with additional instructions.

Thanks
Hi frankswildyears,

Important
Spybot's teatimer may interfere with our cleaning efforts. It is important that you disable it and leave it disabled until we are done.

Open Spybot and make sure teatimer is disabled, we will re-enable afterwards. To do so do the following
  • Click mode
  • click Advanced mode
  • if you get a warning answer "yes"
  • click tools
  • click resident
  • uncheck resident "teatimer"
  • click allow change

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

We will be using combofix to clean your computer.

Please visit this webpage for download links, and instructions for running the tool and installing the recovery console:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure of how to disable these programs, please refer to this page for details.

Extra info

Please note you have Service pack 2 installed.

In your case the programs to disable are:
Ad-Aware
ESET NOD32 Antivirus


After you have finished running Combofix, please copy and paste the log it produces into your next reply along with a new HJT (hijackthis log)

Thanks
Thank you very much
Here is my combofix log:

ComboFix 08-11-30.01 - laura 2008-11-30 23:07:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1471 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\afovotuj.ini
c:\windows\system32\bosotozo.dll
c:\windows\system32\cucejovc.ini
c:\windows\system32\dkvrdblu.ini
c:\windows\system32\erqqwiwh.ini
c:\windows\system32\gcyondbw.ini
c:\windows\system32\jutovofa.dll
c:\windows\system32\migitiho.dll
c:\windows\system32\ohitigim.ini
c:\windows\system32\phxpjbpu.ini
c:\windows\system32\pjwmyfgo.ini
c:\windows\system32\sajuyaya.dll
c:\windows\system32\sosafuji.dll
c:\windows\system32\uzejituh.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV
——-\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-11-30 15:17 . 2008-11-30 15:17 d——– c:\program files\ERUNT
2008-11-28 13:15 . 2008-11-28 13:15 d–h—– c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 20:03 ——— d—–w c:\program files\RogueRemover FREE
2008-11-29 19:33 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-11-29 18:21 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-29 16:59 ——— d—–w c:\program files\Spybot
2008-11-26 15:34 ——— d—–w c:\documents and settings\laura\Application Data\BitTorrent
2008-11-25 12:27 ——— d—–w c:\documents and settings\laura\Application Data\Corel
2008-11-02 09:26 ——— d—–w c:\program files\Soulseek
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 21:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 21:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-10-18 21:30 ——— d—–w c:\program files\Winamp
2008-10-10 14:27 ——— d—–w c:\documents and settings\laura\Application Data\gtk-2.0
2006-10-28 03:02 22 –sha-w c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-20_19.56.21.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-26 11:48:44 297,984 —-a-w c:\windows\$hf_mig$\KB932823-v3\SP2QFE\msctf.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB932823-v3\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB932823-v3\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB932823-v3\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB932823-v3\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB932823-v3\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB938464\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB938464\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB938464\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 —-a-w c:\windows\$hf_mig$\KB938464\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB938464\update\updspapi.dll
+ 2008-05-02 13:30:08 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP2QFE\msgsc.dll
+ 2008-05-02 14:01:49 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP3GDR\msgsc.dll
+ 2008-05-02 13:42:10 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 —-a-w c:\windows\$hf_mig$\KB946648\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
+ 2008-01-23 04:56:21 554,008 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-27 07:39:13 151,583 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-12-10 12:41:14 621,344 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB950749\update\updspapi.dll
+ 2008-04-23 03:35:35 124,928 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\advpack.dll
+ 2008-04-23 03:35:35 347,136 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\dxtmsft.dll
+ 2008-04-23 03:35:35 214,528 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\dxtrans.dll
+ 2008-04-23 03:35:35 132,608 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\extmgr.dll
+ 2008-04-23 03:35:35 63,488 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\icardie.dll
+ 2008-04-22 08:02:19 70,656 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ie4uinit.exe
+ 2008-04-23 03:35:35 153,088 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieakeng.dll
+ 2008-04-23 03:35:35 230,400 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieaksie.dll
+ 2008-04-20 05:07:38 161,792 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dat
+ 2008-04-23 03:35:35 383,488 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dll
+ 2008-04-23 03:35:35 388,608 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iedkcs32.dll
+ 2008-04-23 03:35:36 6,068,224 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieframe.dll
+ 2008-04-23 03:35:36 44,544 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iernonce.dll
+ 2008-04-23 03:35:36 267,776 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iertutil.dll
+ 2008-04-22 08:02:19 13,824 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieudinit.exe
+ 2008-04-22 08:02:46 625,664 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
+ 2008-04-23 03:35:36 27,648 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\jsproxy.dll
+ 2008-04-23 03:35:36 459,264 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msfeeds.dll
+ 2008-04-23 03:35:36 52,224 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msfeedsbs.dll
+ 2008-04-23 03:35:36 3,593,728 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
+ 2008-04-23 03:35:36 478,208 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtmled.dll
+ 2008-04-23 03:35:36 193,024 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msrating.dll
+ 2008-04-23 03:35:36 671,232 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mstime.dll
+ 2008-04-23 03:35:36 102,912 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\occache.dll
+ 2008-04-23 03:35:36 44,544 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\pngfilt.dll
+ 2008-04-23 03:35:36 105,984 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\url.dll
+ 2008-04-23 03:35:36 1,162,752 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\urlmon.dll
+ 2008-04-23 03:35:36 233,472 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\webcheck.dll
+ 2008-04-23 03:35:36 827,392 —-a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 —-a-w c:\windows\$hf_mig$\KB950759-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 —-a-w c:\windows\$hf_mig$\KB950759-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 —-a-w c:\windows\$hf_mig$\KB950759-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 —-a-w c:\windows\$hf_mig$\KB950759-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB950759-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB950760\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB950760\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB950760\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB950760\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB950760\update\updspapi.dll
+ 2008-05-08 12:14:51 203,008 —-a-w c:\windows\$hf_mig$\KB950762\SP2QFE\rmcast.sys
+ 2008-05-08 14:02:52 203,136 —-a-w c:\windows\$hf_mig$\KB950762\SP3GDR\rmcast.sys
+ 2008-05-08 13:58:17 203,136 —-a-w c:\windows\$hf_mig$\KB950762\SP3QFE\rmcast.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB950762\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB950762\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB950762\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB950762\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB950762\update\updspapi.dll
+ 2008-07-07 20:06:43 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
+ 2008-07-07 20:26:58 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
+ 2008-07-07 20:23:18 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 —-a-w c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:19 382,840 —-a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-04-11 18:39:39 683,520 —-a-w c:\windows\$hf_mig$\KB951066\SP2QFE\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 —-a-w c:\windows\$hf_mig$\KB951066\SP3GDR\inetcomm.dll
+ 2008-04-12 04:22:26 691,712 —-a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
+ 2007-12-03 15:25:31 755,576 —-a-w c:\windows\$hf_mig$\KB951066\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
+ 2008-07-14 11:03:00 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
+ 2008-07-11 12:42:28 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
+ 2008-07-11 12:51:51 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-13 09:52:16 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys
+ 2008-06-13 11:05:51 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys
+ 2008-06-13 11:27:43 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951376-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951376-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\updspapi.dll
+ 2008-05-07 05:12:40 1,288,192 —-a-w c:\windows\$hf_mig$\KB951698\SP3GDR\quartz.dll
+ 2008-05-07 05:04:15 1,288,192 —-a-w c:\windows\$hf_mig$\KB951698\SP3QFE\quartz.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951698\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951698\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951698\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB951698\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB951698\update\updspapi.dll
+ 2006-08-16 12:08:32 100,352 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\6to4svc.dll
+ 2008-06-20 10:44:08 138,368 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\afd.sys
+ 2008-06-20 17:36:11 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\dnsapi.dll
+ 2008-06-20 17:36:11 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
+ 2008-06-20 10:44:42 360,960 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
+ 2008-06-20 09:32:39 225,920 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip6.sys
+ 2008-06-20 11:40:08 138,496 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\afd.sys
+ 2008-06-20 17:46:57 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\dnsapi.dll
+ 2008-06-20 17:46:57 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
+ 2008-06-20 11:51:12 361,600 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
+ 2008-06-20 11:08:27 225,856 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip6.sys
+ 2008-06-20 11:48:03 138,496 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys
+ 2008-06-20 17:43:05 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
+ 2008-06-20 17:43:05 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
+ 2008-06-20 11:59:02 361,600 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
+ 2008-06-20 11:16:44 225,856 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB951748\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB951748\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB951748\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 —-a-w c:\windows\$hf_mig$\KB951748\update\update.exe
+ 2007-11-30 12:39:19 382,840 —-a-w c:\windows\$hf_mig$\KB951748\update\updspapi.dll
+ 2008-05-01 15:04:00 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP2QFE\msadce.dll
+ 2008-05-01 14:33:02 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP3GDR\msadce.dll
+ 2008-05-01 14:38:05 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2008-06-24 16:28:00 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP2QFE\mscms.dll
+ 2008-06-24 16:43:16 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP3GDR\mscms.dll
+ 2008-06-24 16:53:10 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-06-23 16:01:38 124,928 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\advpack.dll
+ 2008-06-23 16:01:38 347,136 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtmsft.dll
+ 2008-06-23 16:01:39 214,528 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtrans.dll
+ 2008-06-23 16:01:39 132,608 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\extmgr.dll
+ 2008-06-23 16:01:39 63,488 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\icardie.dll
+ 2008-06-23 08:23:18 70,656 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe
+ 2008-06-23 16:01:39 153,088 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakeng.dll
+ 2008-06-23 16:01:39 230,400 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieaksie.dll
+ 2008-06-21 05:23:53 161,792 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dat
+ 2008-06-23 16:01:40 383,488 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dll
+ 2008-06-23 16:01:40 388,608 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iedkcs32.dll
+ 2008-06-23 16:01:43 6,068,736 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieframe.dll
+ 2008-06-23 16:01:43 44,544 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iernonce.dll
+ 2008-06-23 16:01:44 267,776 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iertutil.dll
+ 2008-06-23 08:23:18 13,824 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe
+ 2008-06-23 08:23:52 625,664 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
+ 2008-06-23 16:01:46 27,648 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\jsproxy.dll
+ 2008-06-23 16:01:46 459,264 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeeds.dll
+ 2008-06-23 16:01:46 52,224 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeedsbs.dll
+ 2008-06-23 16:01:49 3,594,240 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
+ 2008-06-23 16:01:49 477,696 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtmled.dll
+ 2008-06-23 16:01:49 193,024 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msrating.dll
+ 2008-06-23 16:01:50 671,232 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mstime.dll
+ 2008-06-23 16:01:50 102,912 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\occache.dll
+ 2008-06-23 16:01:50 44,544 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\pngfilt.dll
+ 2008-06-23 16:01:50 105,984 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\url.dll
+ 2008-06-23 16:01:51 1,162,752 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\urlmon.dll
+ 2008-06-23 16:01:51 233,472 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\webcheck.dll
+ 2008-06-23 16:01:51 827,904 —-a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 —-a-w c:\windows\$hf_mig$\KB953838-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 —-a-w c:\windows\$hf_mig$\KB953838-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 —-a-w c:\windows\$hf_mig$\KB953838-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 —-a-w c:\windows\$hf_mig$\KB953838-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB953838-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB953839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB953839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB953839\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB953839\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB953839\update\updspapi.dll
+ 2008-09-15 12:17:07 1,846,912 —-a-w c:\windows\$hf_mig$\KB954211\SP2QFE\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 —-a-w c:\windows\$hf_mig$\KB954211\SP3GDR\win32k.sys
+ 2008-09-15 12:25:27 1,846,912 —-a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB954211\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
+ 2008-08-26 09:08:35 124,928 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\advpack.dll
+ 2008-08-26 09:08:36 347,136 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
+ 2008-08-26 09:08:36 214,528 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
+ 2008-08-26 09:08:36 132,608 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\extmgr.dll
+ 2008-08-26 09:08:36 63,488 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
+ 2008-08-25 08:43:21 70,656 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
+ 2008-08-26 09:08:36 153,088 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
+ 2008-08-26 09:08:36 230,400 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieaksie.dll
+ 2008-08-23 05:54:50 161,792 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
+ 2008-08-26 09:08:36 380,928 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dll
+ 2008-08-26 09:08:37 388,608 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-03 17:26:50 6,068,224 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
+ 2008-08-26 09:08:39 44,544 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
+ 2008-08-26 09:08:39 267,776 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
+ 2008-08-25 08:43:21 13,824 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
+ 2008-08-26 09:08:40 27,648 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
+ 2008-08-26 09:08:40 459,264 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
+ 2008-08-26 09:08:40 52,224 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
+ 2008-08-26 09:08:43 3,594,752 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
+ 2008-08-26 09:08:43 477,696 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
+ 2008-08-26 09:08:44 193,024 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
+ 2008-08-26 09:08:44 671,232 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
+ 2008-08-26 09:08:44 102,912 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
+ 2008-08-26 09:08:44 44,544 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
+ 2008-08-26 09:08:44 105,984 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
+ 2008-08-26 09:08:45 1,162,752 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
+ 2008-08-26 09:08:45 233,472 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\webcheck.dll
+ 2008-08-26 09:08:45 827,904 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-08-14 09:48:52 138,368 —-a-w c:\windows\$hf_mig$\KB956803\SP2QFE\afd.sys
+ 2008-08-14 10:04:36 138,496 —-a-w c:\windows\$hf_mig$\KB956803\SP3GDR\afd.sys
+ 2008-08-14 10:34:26 138,496 —-a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-08-14 10:09:26 2,145,280 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlmp.exe
+ 2008-08-14 09:33:16 2,066,048 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,023,936 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrpamp.exe
+ 2008-08-14 10:11:02 2,189,184 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
+ 2008-08-14 10:39:28 2,145,280 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
+ 2008-08-14 19:39:46 2,066,048 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
+ 2008-08-14 10:09:44 2,023,936 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
+ 2008-08-14 20:11:10 2,189,184 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB956841\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
+ 2008-08-28 10:35:33 333,056 —-a-w c:\windows\$hf_mig$\KB957095\SP2QFE\srv.sys
+ 2008-09-08 10:41:42 333,824 —-a-w c:\windows\$hf_mig$\KB957095\SP3GDR\srv.sys
+ 2008-09-08 11:37:19 333,824 —-a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
+ 2008-10-15 16:53:28 339,456 —-a-w c:\windows\$hf_mig$\KB958644\SP2QFE\netapi32.dll
+ 2008-10-15 16:34:24 337,408 —-a-w c:\windows\$hf_mig$\KB958644\SP3GDR\netapi32.dll
+ 2008-10-15 16:25:53 339,456 —-a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2006-03-16 04:00:00 294,400 -c—-w c:\windows\$NtUninstallKB932823-v3$\msctf.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\$NtUninstallKB932823-v3$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\$NtUninstallKB932823-v3$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB938464$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB938464$\spuninst\updspapi.dll
+ 2004-08-04 16:06:34 82,944 -c—-w c:\windows\$NtUninstallKB946648$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB946648$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB946648$\spuninst\updspapi.dll
+ 2006-03-16 04:00:00 561,179 -c—-w c:\windows\$NtUninstallKB950749$\dao360.dll
+ 2006-03-16 04:00:00 512,029 -c—-w c:\windows\$NtUninstallKB950749$\msexch40.dll
+ 2006-03-16 04:00:00 319,517 -c—-w c:\windows\$NtUninstallKB950749$\msexcl40.dll
+ 2006-03-16 04:00:00 1,507,356 -c—-w c:\windows\$NtUninstallKB950749$\msjet40.dll
+ 2006-03-16 04:00:00 358,976 -c—-w c:\windows\$NtUninstallKB950749$\msjetoledb40.dll
+ 2006-03-16 04:00:00 151,583 -c—-w c:\windows\$NtUninstallKB950749$\msjint40.dll
+ 2006-03-16 04:00:00 53,279 -c—-w c:\windows\$NtUninstallKB950749$\msjter40.dll
+ 2006-03-16 04:00:00 241,693 -c—-w c:\windows\$NtUninstallKB950749$\msjtes40.dll
+ 2006-03-16 04:00:00 213,023 -c—-w c:\windows\$NtUninstallKB950749$\msltus40.dll
+ 2006-03-16 04:00:00 348,189 -c—-w c:\windows\$NtUninstallKB950749$\mspbde40.dll
+ 2006-03-16 04:00:00 421,919 -c—-w c:\windows\$NtUninstallKB950749$\msrd2x40.dll
+ 2006-03-16 04:00:00 315,423 -c—-w c:\windows\$NtUninstallKB950749$\msrd3x40.dll
+ 2006-03-16 04:00:00 552,989 -c—-w c:\windows\$NtUninstallKB950749$\msrepl40.dll
+ 2006-03-16 04:00:00 258,077 -c—-w c:\windows\$NtUninstallKB950749$\mstext40.dll
+ 2006-03-16 04:00:00 831,519 -c—-w c:\windows\$NtUninstallKB950749$\mswdat10.dll
+ 2006-03-16 04:00:00 614,429 -c—-w c:\windows\$NtUninstallKB950749$\mswstr10.dll
+ 2006-03-16 04:00:00 348,189 -c—-w c:\windows\$NtUninstallKB950749$\msxbde40.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\$NtUninstallKB950749$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\$NtUninstallKB950749$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB950760$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB950760$\spuninst\updspapi.dll
+ 2006-07-13 08:48:58 202,240 -c—-w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB950762$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB950762$\spuninst\updspapi.dll
+ 2005-07-26 04:39:45 243,200 -c—-w c:\windows\$NtUninstallKB950974$\es.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB950974$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c—-w c:\windows\$NtUninstallKB950974$\spuninst\updspapi.dll
+ 2007-08-21 06:15:44 683,520 -c—-w c:\windows\$NtUninstallKB951066$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB951066$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB951066$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951072-v2$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB951072-v2$\spuninst\updspapi.dll
+ 2007-11-13 11:31:11 60,416 -c—-w c:\windows\$NtUninstallKB951072-v2$\tzchange.exe
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951376-v2$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB951376-v2$\spuninst\updspapi.dll
+ 2007-10-29 22:35:13 1,287,680 -c—-w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951698$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB951698$\spuninst\updspapi.dll
+ 2006-03-16 04:00:00 138,496 -c—-w c:\windows\$NtUninstallKB951748$\afd.sys
+ 2008-02-20 05:32:43 148,992 -c—-w c:\windows\$NtUninstallKB951748$\dnsapi.dll
+ 2006-03-16 04:00:00 245,248 -c—-w c:\windows\$NtUninstallKB951748$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB951748$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c—-w c:\windows\$NtUninstallKB951748$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c—-w c:\windows\$NtUninstallKB951748$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c—-w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2006-03-16 04:00:00 331,776 -c—-w c:\windows\$NtUninstallKB952287$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB952287$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB952287$\spuninst\updspapi.dll
+ 2005-06-29 09:46:00 74,240 -c—-w c:\windows\$NtUninstallKB952954$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB952954$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB952954$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB953839$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB953839$\spuninst\updspapi.dll
+ 2007-07-27 14:41:48 231,288 -c—-w c:\windows\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe
+ 2007-07-27 14:41:48 382,840 -c—-w c:\windows\$NtUninstallKB954154_WM11$\spuninst\updspapi.dll
+ 2006-10-19 01:47:20 295,936 -c—-w c:\windows\$NtUninstallKB954154_WM11$\wmpeffects.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB954211$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB954211$\spuninst\updspapi.dll
+ 2008-03-19 09:47:00 1,845,248 -c—-w c:\windows\$NtUninstallKB954211$\win32k.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB956391$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB956391$\spuninst\updspapi.dll
+ 2008-06-20 10:44:38 138,368 -c—-w c:\windows\$NtUninstallKB956803$\afd.sys
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB956803$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB956803$\spuninst\updspapi.dll
+ 2007-02-28 09:53:04 2,137,600 -c—-w c:\windows\$NtUninstallKB956841$\ntkrnlmp.exe
+ 2007-02-28 09:15:59 2,017,280 -c—-w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
+ 2007-02-28 09:15:59 2,017,280 -c—-w c:\windows\$NtUninstallKB956841$\ntkrpamp.exe
+ 2007-02-28 09:53:04 2,137,600 -c—-w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB956841$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w c:\windows\$NtUninstallKB956841$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB957095$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB957095$\spuninst\updspapi.dll
+ 2006-08-14 10:34:41 332,928 -c—-w c:\windows\$NtUninstallKB957095$\srv.sys
+ 2006-08-17 12:28:27 332,288 -c—-w c:\windows\$NtUninstallKB958644$\netapi32.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB958644$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB958644$\spuninst\updspapi.dll
- 2006-05-16 23:11:54 213,216 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe
+ 2006-05-16 22:11:54 213,216 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe
- 2006-05-16 23:11:54 371,424 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\updspapi.dll
+ 2006-05-16 22:11:54 371,424 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\updspapi.dll
- 2006-11-02 16:46:52 13,312 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
+ 2006-11-02 15:46:52 13,312 -c—-w c:\windows\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
- 2006-05-16 23:11:54 213,216 -c—-w c:\windows\$NtUninstallwmp11$\spuninst\spuninst.exe
+ 2006-05-16 22:11:54 213,216 -c—-w c:\windows\$NtUninstallwmp11$\spuninst\spuninst.exe
- 2006-05-16 23:11:54 371,424 -c—-w c:\windows\$NtUninstallwmp11$\spuninst\updspapi.dll
+ 2006-05-16 22:11:54 371,424 -c—-w c:\windows\$NtUninstallwmp11$\spuninst\updspapi.dll
+ 2008-06-13 13:10:50 272,128 ——w c:\windows\Driver Cache\i386\bthport.sys
- 2006-05-05 09:41:45 453,120 —-a-w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-10-24 11:10:42 453,632 —-a-w c:\windows\Driver Cache\i386\mrxsmb.sys
- 2007-02-28 09:53:04 2,137,600 —-a-w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 09:55:01 2,142,720 —-a-w c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2007-02-28 09:15:56 2,059,392 —-a-w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:18:44 2,062,976 —-a-w c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2007-02-28 09:15:59 2,017,280 —-a-w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:18:46 2,020,864 —-a-w c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2007-02-28 09:55:14 2,182,144 —-a-w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 09:57:20 2,185,984 —-a-w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-10-20 17:02:28 163,328 —-a-w c:\windows\erdnt\11-30-2008\ERDNT.EXE
+ 2008-11-30 20:17:35 9,203,712 —-a-w c:\windows\erdnt\11-30-2008\Users\00000001\ntuser.dat
+ 2008-11-30 20:17:35 188,416 —-a-w c:\windows\erdnt\11-30-2008\Users\00000002\UsrClass.dat
- 2005-10-21 00:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
- 2005-10-21 00:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2008-03-01 13:06:20 124,928 -c—-w c:\windows\ie7updates\KB950759-IE7\advpack.dll
+ 2008-03-01 13:06:21 347,136 -c—-w c:\windows\ie7updates\KB950759-IE7\dxtmsft.dll
+ 2008-03-01 13:06:21 214,528 -c—-w c:\windows\ie7updates\KB950759-IE7\dxtrans.dll
+ 2008-03-01 13:06:21 133,120 -c—-w c:\windows\ie7updates\KB950759-IE7\extmgr.dll
+ 2008-03-01 13:06:21 63,488 -c—-w c:\windows\ie7updates\KB950759-IE7\icardie.dll
+ 2008-02-29 08:55:23 70,656 -c—-w c:\windows\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2008-03-01 13:06:21 153,088 -c—-w c:\windows\ie7updates\KB950759-IE7\ieakeng.dll
+ 2008-03-01 13:06:21 230,400 -c—-w c:\windows\ie7updates\KB950759-IE7\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 -c—-w c:\windows\ie7updates\KB950759-IE7\ieakui.dll
+ 2008-03-01 13:06:22 383,488 -c—-w c:\windows\ie7updates\KB950759-IE7\ieapfltr.dll
+ 2008-03-01 13:06:22 384,512 -c—-w c:\windows\ie7updates\KB950759-IE7\iedkcs32.dll
+ 2008-03-01 13:06:24 6,066,176 -c—-w c:\windows\ie7updates\KB950759-IE7\ieframe.dll
+ 2008-03-01 13:06:24 44,544 -c—-w c:\windows\ie7updates\KB950759-IE7\iernonce.dll
+ 2008-03-01 13:06:25 267,776 -c—-w c:\windows\ie7updates\KB950759-IE7\iertutil.dll
+ 2008-02-22 10:00:51 13,824 -c—-w c:\windows\ie7updates\KB950759-IE7\ieudinit.exe
+ 2008-02-29 08:55:46 625,664 -c—-w c:\windows\ie7updates\KB950759-IE7\iexplore.exe
+ 2008-03-01 13:06:25 27,648 -c—-w c:\windows\ie7updates\KB950759-IE7\jsproxy.dll
+ 2008-03-01 13:06:26 459,264 -c—-w c:\windows\ie7updates\KB950759-IE7\msfeeds.dll
+ 2008-03-01 13:06:26 52,224 -c—-w c:\windows\ie7updates\KB950759-IE7\msfeedsbs.dll
+ 2008-03-01 22:36:30 3,591,680 -c—-w c:\windows\ie7updates\KB950759-IE7\mshtml.dll
+ 2008-03-01 13:06:28 478,208 -c—-w c:\windows\ie7updates\KB950759-IE7\mshtmled.dll
+ 2008-03-01 13:06:28 193,024 -c—-w c:\windows\ie7updates\KB950759-IE7\msrating.dll
+ 2008-03-01 13:06:29 671,232 -c—-w c:\windows\ie7updates\KB950759-IE7\mstime.dll
+ 2008-03-01 13:06:29 102,912 -c—-w c:\windows\ie7updates\KB950759-IE7\occache.dll
+ 2008-03-01 13:06:29 44,544 -c—-w c:\windows\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB950759-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB950759-IE7\spuninst\updspapi.dll
+ 2008-03-01 13:06:29 105,984 -c—-w c:\windows\ie7updates\KB950759-IE7\url.dll
+ 2008-03-01 13:06:30 1,159,680 -c—-w c:\windows\ie7updates\KB950759-IE7\urlmon.dll
+ 2008-03-01 13:06:30 233,472 -c—-w c:\windows\ie7updates\KB950759-IE7\webcheck.dll
+ 2008-03-01 13:06:31 826,368 -c—-w c:\windows\ie7updates\KB950759-IE7\wininet.dll
+ 2008-04-23 04:16:28 124,928 -c—-w c:\windows\ie7updates\KB953838-IE7\advpack.dll
+ 2008-04-23 04:16:28 347,136 -c—-w c:\windows\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2008-04-23 04:16:28 214,528 -c—-w c:\windows\ie7updates\KB953838-IE7\dxtrans.dll
+ 2008-04-23 04:16:28 133,120 -c—-w c:\windows\ie7updates\KB953838-IE7\extmgr.dll
+ 2008-04-23 04:16:28 63,488 -c—-w c:\windows\ie7updates\KB953838-IE7\icardie.dll
+ 2008-04-22 07:39:58 70,656 -c—-w c:\windows\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2008-04-23 04:16:28 153,088 -c—-w c:\windows\ie7updates\KB953838-IE7\ieakeng.dll
+ 2008-04-23 04:16:28 230,400 -c—-w c:\windows\ie7updates\KB953838-IE7\ieaksie.dll
+ 2008-04-20 05:07:51 161,792 -c—-w c:\windows\ie7updates\KB953838-IE7\ieakui.dll
+ 2008-04-23 04:16:28 383,488 -c—-w c:\windows\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2008-04-23 04:16:28 384,512 -c—-w c:\windows\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2008-04-23 04:16:28 6,066,176 -c—-w c:\windows\ie7updates\KB953838-IE7\ieframe.dll
+ 2008-04-23 04:16:28 44,544 -c—-w c:\windows\ie7updates\KB953838-IE7\iernonce.dll
+ 2008-04-23 04:16:28 267,776 -c—-w c:\windows\ie7updates\KB953838-IE7\iertutil.dll
+ 2008-04-22 07:39:58 13,824 -c—-w c:\windows\ie7updates\KB953838-IE7\ieudinit.exe
+ 2008-04-22 07:40:18 625,664 -c—-w c:\windows\ie7updates\KB953838-IE7\iexplore.exe
+ 2008-04-23 04:16:28 27,648 -c—-w c:\windows\ie7updates\KB953838-IE7\jsproxy.dll
+ 2008-04-23 04:16:28 459,264 -c—-w c:\windows\ie7updates\KB953838-IE7\msfeeds.dll
+ 2008-04-23 04:16:28 52,224 -c—-w c:\windows\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2008-04-24 02:16:30 3,591,680 -c—-w c:\windows\ie7updates\KB953838-IE7\mshtml.dll
+ 2008-04-23 04:16:28 478,208 -c—-w c:\windows\ie7updates\KB953838-IE7\mshtmled.dll
+ 2008-04-23 04:16:28 193,024 -c—-w c:\windows\ie7updates\KB953838-IE7\msrating.dll
+ 2008-04-23 04:16:28 671,232 -c—-w c:\windows\ie7updates\KB953838-IE7\mstime.dll
+ 2008-04-23 04:16:28 102,912 -c—-w c:\windows\ie7updates\KB953838-IE7\occache.dll
+ 2008-04-23 04:16:28 44,544 -c—-w c:\windows\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2008-04-23 04:16:28 105,984 -c—-w c:\windows\ie7updates\KB953838-IE7\url.dll
+ 2008-04-23 04:16:29 1,159,680 -c—-w c:\windows\ie7updates\KB953838-IE7\urlmon.dll
+ 2008-04-23 04:16:29 233,472 -c—-w c:\windows\ie7updates\KB953838-IE7\webcheck.dll
+ 2008-04-23 04:16:29 826,368 -c—-w c:\windows\ie7updates\KB953838-IE7\wininet.dll
+ 2008-06-23 16:57:27 124,928 -c—-w c:\windows\ie7updates\KB956390-IE7\advpack.dll
+ 2008-06-23 16:57:27 347,136 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll
+ 2008-06-23 16:57:27 214,528 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll
+ 2008-06-23 16:57:27 133,120 -c—-w c:\windows\ie7updates\KB956390-IE7\extmgr.dll
+ 2008-06-23 16:57:28 63,488 -c—-w c:\windows\ie7updates\KB956390-IE7\icardie.dll
+ 2008-06-23 09:20:25 70,656 -c—-w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe
+ 2008-06-23 16:57:29 153,088 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll
+ 2008-06-23 16:57:29 230,400 -c—-w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll
+ 2008-06-21 05:23:54 161,792 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakui.dll
+ 2008-06-23 16:57:29 383,488 -c—-w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll
+ 2008-06-23 16:57:29 384,512 -c—-w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll
+ 2008-06-23 16:57:33 6,066,176 -c—-w c:\windows\ie7updates\KB956390-IE7\ieframe.dll
+ 2008-06-23 16:57:33 44,544 -c—-w c:\windows\ie7updates\KB956390-IE7\iernonce.dll
+ 2008-06-23 16:57:34 267,776 -c—-w c:\windows\ie7updates\KB956390-IE7\iertutil.dll
+ 2008-06-23 09:20:26 13,824 -c—-w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe
+ 2008-06-23 09:20:52 625,664 -c—-w c:\windows\ie7updates\KB956390-IE7\iexplore.exe
+ 2008-06-23 16:57:35 27,648 -c—-w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll
+ 2008-06-23 16:57:36 459,264 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll
+ 2008-06-23 16:57:36 52,224 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll
+ 2008-06-24 14:57:40 3,592,192 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtml.dll
+ 2008-06-23 16:57:39 477,696 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll
+ 2008-06-23 16:57:39 193,024 -c—-w c:\windows\ie7updates\KB956390-IE7\msrating.dll
+ 2008-06-23 16:57:40 671,232 -c—-w c:\windows\ie7updates\KB956390-IE7\mstime.dll
+ 2008-06-23 16:57:40 102,912 -c—-w c:\windows\ie7updates\KB956390-IE7\occache.dll
+ 2008-06-23 16:57:40 44,544 -c—-w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll
+ 2008-06-23 16:57:40 105,984 -c—-w c:\windows\ie7updates\KB956390-IE7\url.dll
+ 2008-06-23 16:57:40 1,159,680 -c—-w c:\windows\ie7updates\KB956390-IE7\urlmon.dll
+ 2008-06-23 16:57:41 233,472 -c—-w c:\windows\ie7updates\KB956390-IE7\webcheck.dll
+ 2008-06-23 16:57:41 826,368 -c—-w c:\windows\ie7updates\KB956390-IE7\wininet.dll
- 2007-06-27 03:10:26 317,440 —-a-w c:\windows\inf\unregmp2.exe
+ 2007-06-27 02:10:26 317,440 —-a-w c:\windows\inf\unregmp2.exe
+ 2008-11-13 08:00:41 32,768 —-a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 1998-10-29 21:45:06 306,688 —-a-w c:\windows\IsUninst.exe
+ 1998-10-29 13:45:06 306,688 —-a-w c:\windows\IsUninst.exe
- 2000-08-31 12:00:00 28,160 —-a-w c:\windows\Nircmd.exe
+ 2000-08-31 13:00:00 28,672 —-a-w c:\windows\Nircmd.exe
- 2006-03-15 20:00:00 158,208 —-a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
+ 2008-03-03 05:24:10 158,208 —-a-w c:\windows\pchealth\helpctr\binaries\MSConfig.exe
- 2000-08-31 12:00:00 161,792 —-a-w c:\windows\swreg.exe
+ 2000-08-31 13:00:00 161,792 —-a-w c:\windows\swreg.exe
- 2008-03-01 13:06:20 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
- 2006-10-19 02:47:08 7,168 —-a-w c:\windows\system32\asferror.dll
+ 2006-10-19 01:47:08 7,168 —-a-w c:\windows\system32\asferror.dll
- 1999-08-09 19:39:20 14,832 —-a-w c:\windows\system32\asfsipc.dll
+ 2001-03-03 00:52:40 15,360 —-a-w c:\windows\system32\asfsipc.dll
+ 2005-02-24 18:10:10 2,084,864 —-a-w c:\windows\system32\AudDesign.dll
+ 2005-02-24 18:10:30 417,792 —-a-w c:\windows\system32\AudDisplay.dll
+ 2005-03-11 23:37:10 1,986,560 —-a-w c:\windows\system32\AudFile.dll
- 2006-10-19 02:47:08 276,992 —-a-w c:\windows\system32\audiodev.dll
+ 2006-10-19 01:47:08 276,992 —-a-w c:\windows\system32\audiodev.dll
+ 2005-02-24 18:11:06 1,212,416 —-a-w c:\windows\system32\AudioInfos.dll
+ 2005-03-10 22:00:30 454,656 —-a-w c:\windows\system32\AudioRecord.dll
+ 2005-02-24 18:11:56 479,232 —-a-w c:\windows\system32\AudioVisu.dll
+ 2005-02-24 21:21:12 458,752 —-a-w c:\windows\system32\AudPlayer.dll
- 2006-10-19 02:47:10 542,720 —-a-w c:\windows\system32\blackbox.dll
+ 2006-10-19 01:47:10 542,720 —-a-w c:\windows\system32\blackbox.dll
- 2007-07-31 00:19:20 92,504 —-a-w c:\windows\system32\cdm.dll
+ 2008-10-16 19:09:44 92,696 —-a-w c:\windows\system32\cdm.dll
- 2006-10-19 02:47:10 229,376 —-a-w c:\windows\system32\cewmdm.dll
+ 2006-10-19 01:47:10 229,376 —-a-w c:\windows\system32\cewmdm.dll
+ 1998-07-13 01:00:00 32,768 —-a-w c:\windows\system32\CMDLGFR.DLL
- 2006-10-27 16:37:08 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-04 19:58:21 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-04 18:52:13 16,384 –sha-w c:\windows\system32\config\systemprofile\History\History.IE5\index.dat
- 2006-10-27 16:37:08 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-04 19:58:21 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-04 18:52:22 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090420080905\index.dat
+ 2008-09-04 18:52:23 78,924 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
- 2006-10-27 16:37:08 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-04 19:58:21 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-04 18:52:13 32,768 –sha-w c:\windows\system32\config\systemprofile\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-18 08:10:56 15,360 —-a-w c:\windows\system32\ctfmon.exe
+ 2008-04-19 21:27:14 15,360 —-a-w c:\windows\system32\ctfmon.exe
- 2008-03-01 13:06:20 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-08-26 07:24:28 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-08-14 09:51:43 138,368 ——w c:\windows\system32\dllcache\afd.sys
+ 2008-06-13 13:10:50 272,128 ——w c:\windows\system32\dllcache\bthport.sys
- 2007-07-31 00:19:20 92,504 —-a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 19:09:44 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
- 2008-04-18 08:10:56 15,360 —-a-w c:\windows\system32\dllcache\ctfmon.exe
+ 2008-04-19 21:27:14 15,360 —-a-w c:\windows\system32\dllcache\ctfmon.exe
+ 2008-03-25 04:50:25 554,008 ——w c:\windows\system32\dllcache\dao360.dll
- 2008-02-20 05:32:43 148,992 ——w c:\windows\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 —-a-w c:\windows\system32\dllcache\dnsapi.dll
- 2008-03-01 13:06:21 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-07-07 20:32:22 253,952 ——w c:\windows\system32\dllcache\es.dll
- 2008-03-01 13:06:21 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
- 2008-03-01 13:06:21 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-08-26 07:24:28 63,488 ——w c:\windows\system32\dllcache\icardie.dll
- 2008-02-29 08:55:23 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
- 2008-03-01 13:06:21 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
- 2008-02-15 05:44:25 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
- 2008-03-01 13:06:22 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-08-26 07:24:28 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-03-01 13:06:22 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-03-01 13:06:24 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-03 17:41:15 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
- 2008-03-01 13:06:24 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
- 2008-03-01 13:06:25 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-08-26 07:24:29 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
- 2008-02-22 10:00:51 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
- 2008-02-29 08:55:46 625,664 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-08-23 05:56:15 635,848 ——w c:\windows\system32\dllcache\iexplore.exe
- 2007-08-21 06:15:44 683,520 ——w c:\windows\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 ——w c:\windows\system32\dllcache\inetcomm.dll
- 2008-03-01 13:06:25 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
- 2006-05-05 09:41:45 453,120 ——w c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-10-24 11:10:42 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-05-01 14:30:33 331,776 ——w c:\windows\system32\dllcache\msadce.dll
+ 2008-06-24 16:23:05 74,240 ——w c:\windows\system32\dllcache\mscms.dll
- 2006-03-15 20:00:00 158,208 —-a-w c:\windows\system32\dllcache\msconfig.exe
+ 2008-03-03 05:24:10 158,208 —-a-w c:\windows\system32\dllcache\msconfig.exe
+ 2008-02-26 11:59:50 294,912 ——w c:\windows\system32\dllcache\msctf.dll
+ 2008-03-25 04:50:28 518,944 ——w c:\windows\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:30 326,432 ——w c:\windows\system32\dllcache\msexcl40.dll
- 2008-03-01 13:06:26 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-08-26 07:24:30 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
- 2008-03-01 13:06:26 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-08-26 07:24:30 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-03-01 22:36:30 3,591,680 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2008-08-27 08:24:32 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
- 2008-03-01 13:06:28 478,208 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-03-25 04:50:34 1,516,568 ——w c:\windows\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:40 355,112 ——w c:\windows\system32\dllcache\msjetol1.dll
+ 2008-03-27 08:12:54 151,583 ——w c:\windows\system32\dllcache\msjint40.dll
+ 2008-03-25 04:50:42 60,192 ——w c:\windows\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 248,608 ——w c:\windows\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:44 219,936 ——w c:\windows\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:45 355,104 ——w c:\windows\system32\dllcache\mspbde40.dll
- 2008-03-01 13:06:28 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-03-25 04:50:47 432,928 ——w c:\windows\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 ——w c:\windows\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 ——w c:\windows\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:55 264,992 ——w c:\windows\system32\dllcache\mstext40.dll
- 2008-03-01 13:06:29 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-03-25 04:50:57 838,432 ——w c:\windows\system32\dllcache\mswdat10.dll
+ 2008-06-20 17:41:10 245,248 ——w c:\windows\system32\dllcache\mswsock.dll
+ 2008-03-25 04:50:58 621,344 ——w c:\windows\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 355,104 ——w c:\windows\system32\dllcache\msxbde40.dll
- 2007-06-26 06:08:16 1,104,896 ——w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
- 2006-08-17 12:28:27 332,288 ——w c:\windows\system32\dllcache\netapi32.dll
+ 2008-10-15 16:57:55 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
- 2007-02-28 09:53:04 2,137,600 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-08-14 09:55:01 2,142,720 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
- 2007-02-28 09:15:56 2,059,392 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-08-14 09:18:44 2,062,976 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
- 2007-02-28 09:15:59 2,017,280 ——w c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-08-14 09:18:46 2,020,864 ——w c:\windows\system32\dllcache\ntkrpamp.exe
- 2007-02-28 09:55:14 2,182,144 ——w c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-08-14 09:57:20 2,185,984 ——w c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-03-01 13:06:29 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\dllcache\occache.dll
- 2008-03-01 13:06:29 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-29 22:35:13 1,287,680 ——w c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 ——w c:\windows\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 ——w c:\windows\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 ——w c:\windows\system32\dllcache\rmcast.sys
- 2006-08-14 10:34:41 332,928 ——w c:\windows\system32\dllcache\srv.sys
+ 2008-08-28 10:04:17 333,056 ——w c:\windows\system32\dllcache\srv.sys
- 2007-10-30 17:20:55 360,064 ——w c:\windows\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 —-a-w c:\windows\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 ——w c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 —-a-w c:\windows\system32\dllcache\tcpip6.sys
- 2008-03-01 13:06:29 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-08-26 07:24:30 105,984 ——w c:\windows\system32\dllcache\url.dll
- 2008-03-01 13:06:30 1,159,680 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ——w c:\windows\system32\dllcache\urlmon.dll
- 2008-03-01 13:06:30 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
- 2008-03-19 09:47:00 1,845,248 ——w c:\windows\system32\dllcache\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
- 2008-03-01 13:06:31 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-08-26 07:24:31 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2007-06-12 04:51:12 10,834,944 —-a-w c:\windows\system32\dllcache\wmp.dll
- 2007-07-31 00:19:36 549,720 —-a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-31 00:19:16 53,080 —-a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 —-a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-31 00:19:32 325,976 —-a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 19:12:22 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-31 00:18:40 33,624 —-a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-31 00:19:28 203,096 —-a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 19:13:40 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
- 2008-02-20 05:32:43 148,992 —-a-w c:\windows\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 —-a-w c:\windows\system32\dnsapi.dll
- 2006-03-16 04:00:00 138,496 —-a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 —-a-w c:\windows\system32\drivers\afd.sys
+ 2008-06-13 13:10:50 272,128 ——w c:\windows\system32\drivers\bthport.sys
- 2006-07-13 08:48:58 202,240 —-a-w c:\windows\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 —-a-w c:\windows\system32\drivers\rmcast.sys
- 2006-08-14 10:34:41 332,928 —-a-w c:\windows\system32\drivers\srv.sys
+ 2008-08-28 10:04:17 333,056 —-a-w c:\windows\system32\drivers\srv.sys
- 2007-10-30 17:20:55 360,064 —-a-w c:\windows\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 —-a-w c:\windows\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 —-a-w c:\windows\system32\drivers\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 —-a-w c:\windows\system32\drivers\tcpip6.sys
- 2006-10-19 02:47:22 671,232 ——w c:\windows\system32\drivers\UMDF\wpdmtpdr.dll
+ 2006-10-19 01:47:22 671,232 ——w c:\windows\system32\drivers\UMDF\wpdmtpdr.dll
- 2006-10-19 01:00:00 38,528 —-a-w c:\windows\system32\drivers\wpdusb.sys
+ 2006-10-19 00:00:00 38,528 —-a-w c:\windows\system32\drivers\wpdusb.sys
- 2006-10-19 01:00:46 249,856 —-a-w c:\windows\system32\drmupgds.exe
+ 2006-10-19 00:00:46 249,856 —-a-w c:\windows\system32\drmupgds.exe
- 2006-10-19 02:47:10 991,744 —-a-w c:\windows\system32\drmv2clt.dll
+ 2006-10-19 01:47:10 991,744 —-a-w c:\windows\system32\drmv2clt.dll
- 2008-03-01 13:06:21 347,136 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2005-07-26 04:39:45 243,200 —-a-w c:\windows\system32\es.dll
+ 2008-07-07 20:32:22 253,952 —-a-w c:\windows\system32\es.dll
- 2008-03-01 13:06:21 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-04-09 07:11:46 382,424 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-10-16 07:07:51 382,424 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-03-01 13:06:21 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-02-29 08:55:23 70,656 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-03-01 13:06:21 230,400 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-02-15 05:44:25 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-03-01 13:06:22 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-03-01 13:06:22 384,512 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-03-01 13:06:24 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-10-03 17:41:15 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-03-01 13:06:24 44,544 —-a-w c:\windows\system32\iernonce.dll
+ 2008-08-26 07:24:29 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-03-01 13:06:25 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-08-26 07:24:29 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-02-22 10:00:51 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2007-08-21 06:15:44 683,520 —-a-w c:\windows\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 —-a-w c:\windows\system32\inetcomm.dll
+ 1998-07-13 05:00:00 15,360 —-a-w c:\windows\system32\inetfr.DLL
- 2008-03-01 13:06:25 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2008-03-29 13:57:56 1,890 –sha-w c:\windows\system32\KGyGaAvL.sys
+ 2008-11-25 12:25:09 1,890 –sha-w c:\windows\system32\KGyGaAvL.sys
+ 2003-08-07 21:01:50 237,568 —-a-w c:\windows\system32\lame_enc.dll
- 2006-10-19 02:47:14 11,264 —-a-w c:\windows\system32\LAPRXY.dll
+ 2006-10-19 01:47:14 11,264 —-a-w c:\windows\system32\LAPRXY.dll
- 2006-10-19 01:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2006-10-19 00:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
- 2006-10-19 02:47:14 212,992 —-a-w c:\windows\system32\MFPLAT.dll
+ 2006-10-19 01:47:14 212,992 —-a-w c:\windows\system32\MFPLAT.dll
- 2006-10-19 02:47:14 259,072 —-a-w c:\windows\system32\MP43DECD.dll
+ 2006-10-19 01:47:14 259,072 ——w c:\windows\system32\MP43DECD.dll
- 2006-10-19 02:47:14 4,096 —-a-w c:\windows\system32\MP43DMOD.dll
+ 2006-10-19 01:47:14 4,096 —-a-w c:\windows\system32\MP43DMOD.dll
- 2006-10-19 02:47:14 317,440 —-a-w c:\windows\system32\MP4SDECD.dll
+ 2006-10-19 01:47:14 317,440 ——w c:\windows\system32\MP4SDECD.dll
- 2006-10-19 02:47:14 4,096 —-a-w c:\windows\system32\MP4SDMOD.dll
+ 2006-10-19 01:47:14 4,096 —-a-w c:\windows\system32\MP4SDMOD.dll
- 2006-10-19 02:47:14 259,072 —-a-w c:\windows\system32\MPG4DECD.dll
+ 2006-10-19 01:47:14 259,072 ——w c:\windows\system32\MPG4DECD.dll
- 2006-10-19 02:47:14 4,096 —-a-w c:\windows\system32\MPG4DMOD.dll
+ 2006-10-19 01:47:14 4,096 —-a-w c:\windows\system32\MPG4DMOD.dll
+ 1998-07-13 05:00:00 59,904 —-a-w c:\windows\system32\Mscc2fr.dll
+ 1998-07-13 05:00:00 141,312 —-a-w c:\windows\system32\MSCMCFR.DLL
- 2005-06-29 09:46:00 74,240 —-a-w c:\windows\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 —-a-w c:\windows\system32\mscms.dll
- 2006-03-16 04:00:00 294,400 —-a-w c:\windows\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 —-a-w c:\windows\system32\msctf.dll
- 2006-03-16 04:00:00 512,029 —-a-w c:\windows\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 —-a-w c:\windows\system32\msexch40.dll
- 2006-03-16 04:00:00 319,517 —-a-w c:\windows\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 —-a-w c:\windows\system32\msexcl40.dll
- 2008-03-01 13:06:26 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-03-01 13:06:26 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-03-01 22:36:30 3,591,680 —-a-w c:\windows\system32\mshtml.dll
+ 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-03-01 13:06:28 478,208 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2006-03-16 04:00:00 1,507,356 —-a-w c:\windows\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 —-a-w c:\windows\system32\msjet40.dll
- 2006-03-16 04:00:00 358,976 —-a-w c:\windows\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 —-a-w c:\windows\system32\msjetoledb40.dll
- 2006-03-16 04:00:00 151,583 —-a-w c:\windows\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 —-a-w c:\windows\system32\msjint40.dll
- 2006-03-16 04:00:00 53,279 —-a-w c:\windows\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 —-a-w c:\windows\system32\msjter40.dll
- 2006-03-16 04:00:00 241,693 —-a-w c:\windows\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 —-a-w c:\windows\system32\msjtes40.dll
- 2006-03-16 04:00:00 213,023 —-a-w c:\windows\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 —-a-w c:\windows\system32\msltus40.dll
- 2006-10-19 02:47:16 179,712 —-a-w c:\windows\system32\msnetobj.dll
+ 2006-10-19 01:47:16 179,712 —-a-w c:\windows\system32\msnetobj.dll
- 2006-03-16 04:00:00 348,189 —-a-w c:\windows\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 —-a-w c:\windows\system32\mspbde40.dll
- 2006-10-19 02:47:16 27,136 —-a-w c:\windows\system32\mspmsnsv.dll
+ 2006-10-19 01:47:16 27,136 —-a-w c:\windows\system32\mspmsnsv.dll
- 2006-10-19 02:47:16 175,616 —-a-w c:\windows\system32\mspmsp.dll
+ 2006-10-19 01:47:16 175,616 —-a-w c:\windows\system32\mspmsp.dll
- 2008-03-01 13:06:28 193,024 —-a-w c:\windows\system32\msrating.dll
+ 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\msrating.dll
- 2006-03-16 04:00:00 421,919 —-a-w c:\windows\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 —-a-w c:\windows\system32\msrd2x40.dll
- 2006-03-16 04:00:00 315,423 —-a-w c:\windows\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 —-a-w c:\windows\system32\msrd3x40.dll
- 2006-03-16 04:00:00 552,989 —-a-w c:\windows\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 —-a-w c:\windows\system32\msrepl40.dll
- 2006-12-04 21:21:50 414,720 —-a-w c:\windows\system32\msscp.dll
+ 2006-12-04 20:21:50 414,720 —-a-w c:\windows\system32\msscp.dll
- 2006-03-16 04:00:00 258,077 —-a-w c:\windows\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 —-a-w c:\windows\system32\mstext40.dll
- 2008-03-01 13:06:29 671,232 —-a-w c:\windows\system32\mstime.dll
+ 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\mstime.dll
- 2006-03-16 04:00:00 1,392,671 —-a-w c:\windows\system32\msvbvm60.dll
+ 2004-02-24 01:42:40 1,386,496 —-a-w c:\windows\system32\msvbvm60.dll
+ 1998-06-17 05:00:00 516,173 —-a-w c:\windows\system32\MSVCP60D.DLL
- 2006-03-16 04:00:00 831,519 —-a-w c:\windows\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 —-a-w c:\windows\system32\mswdat10.dll
- 2006-10-19 02:47:16 321,536 —-a-w c:\windows\system32\mswmdm.dll
+ 2006-10-19 01:47:16 321,536 —-a-w c:\windows\system32\mswmdm.dll
- 2006-03-16 04:00:00 245,248 —-a-w c:\windows\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 —-a-w c:\windows\system32\mswsock.dll
- 2006-03-16 04:00:00 614,429 —-a-w c:\windows\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 —-a-w c:\windows\system32\mswstr10.dll
- 2006-03-16 04:00:00 348,189 —-a-w c:\windows\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 —-a-w c:\windows\system32\msxbde40.dll
- 2007-06-26 06:08:16 1,104,896 —-a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 —-a-w c:\windows\system32\msxml3.dll
- 2007-05-08 20:03:04 1,275,392 —-a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 21:43:34 1,286,152 —-a-w c:\windows\system32\msxml4.dll
- 2007-05-15 20:43:10 1,320,800 —-a-w c:\windows\system32\msxml6.dll
+ 2008-08-30 01:06:44 1,350,664 —-a-w c:\windows\system32\msxml6.dll
- 2006-08-17 12:28:27 332,288 —-a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:57:55 332,800 —-a-w c:\windows\system32\netapi32.dll
+ 2001-03-03 00:52:42 8,704 —-a-w c:\windows\system32\npwmsdrm.dll
- 2007-02-28 09:15:59 2,017,280 —-a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 09:18:46 2,020,864 —-a-w c:\windows\system32\ntkrnlpa.exe
- 2007-02-28 09:53:04 2,137,600 —-a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 09:55:01 2,142,720 —-a-w c:\windows\system32\ntoskrnl.exe
- 2008-03-01 13:06:29 102,912 —-a-w c:\windows\system32\occache.dll
+ 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\occache.dll
- 2008-04-11 07:03:17 75,512 —-a-w c:\windows\system32\perfc009.dat
+ 2008-11-10 05:19:10 76,030 —-a-w c:\windows\system32\perfc009.dat
- 2008-04-11 07:03:17 455,816 —-a-w c:\windows\system32\perfh009.dat
+ 2008-11-10 05:19:10 456,692 —-a-w c:\windows\system32\perfh009.dat
- 2008-03-01 13:06:29 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2006-10-19 02:47:18 284,160 —-a-w c:\windows\system32\PortableDeviceApi.dll
+ 2006-10-19 01:47:18 284,160 ——w c:\windows\system32\PortableDeviceApi.dll
- 2006-10-19 02:47:18 101,888 —-a-w c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 01:47:18 101,888 ——w c:\windows\system32\PortableDeviceClassExtension.dll
- 2006-10-19 02:47:18 166,912 —-a-w c:\windows\system32\PortableDeviceTypes.dll
+ 2006-10-19 01:47:18 166,912 ——w c:\windows\system32\PortableDeviceTypes.dll
- 2006-10-19 02:47:18 132,096 —-a-w c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 01:47:18 132,096 ——w c:\windows\system32\PortableDeviceWiaCompat.dll
- 2006-10-19 02:47:18 199,168 —-a-w c:\windows\system32\PortableDeviceWMDRM.dll
+ 2006-10-19 01:47:18 199,168 ——w c:\windows\system32\PortableDeviceWMDRM.dll
- 2006-10-19 02:47:18 211,456 —-a-w c:\windows\system32\qasf.dll
+ 2006-10-19 01:47:18 211,456 —-a-w c:\windows\system32\qasf.dll
- 2007-10-29 22:35:13 1,287,680 —-a-w c:\windows\system32\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 —-a-w c:\windows\system32\quartz.dll
- 2008-04-19 15:09:30 3,099,976 —-a-w c:\windows\system32\Restore\rstrlog.dat
+ 2008-05-03 12:17:47 1,113,344 —-a-w c:\windows\system32\Restore\rstrlog.dat
+ 2008-07-19 02:10:20 36,552 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-07-19 02:10:40 45,768 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2006-10-16 21:10:58 14,640 —-a-w c:\windows\system32\spmsg.dll
+ 2008-07-08 13:02:01 17,272 ——w c:\windows\system32\spmsg.dll
+ 1998-07-13 05:00:00 21,504 —-a-w c:\windows\system32\TABCTFR.DLL
- 2007-11-13 11:31:11 60,416 —-a-w c:\windows\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2008-03-01 13:06:29 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
- 2008-03-01 13:06:30 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 —-a-w c:\windows\system32\urlmon.dll
- 2006-10-19 02:58:00 8,704 —-a-w c:\windows\system32\uwdf.exe
+ 2006-10-19 01:58:00 8,704 —-a-w c:\windows\system32\uwdf.exe
+ 2000-10-02 01:00:00 119,568 —-a-w c:\windows\system32\VB6FR.DLL
+ 1999-03-26 01:00:00 101,888 —-a-w c:\windows\system32\VB6STKIT.DLL
- 2006-10-19 02:47:18 4,096 —-a-w c:\windows\system32\wdfapi.dll
+ 2006-10-19 01:47:18 4,096 —-a-w c:\windows\system32\wdfapi.dll
- 2006-10-19 02:58:00 8,704 —-a-w c:\windows\system32\wdfmgr.exe
+ 2006-10-19 01:58:00 8,704 —-a-w c:\windows\system32\wdfmgr.exe
- 2008-03-01 13:06:30 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-08-26 07:24:31 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-03-19 09:47:00 1,845,248 —-a-w c:\windows\system32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 —-a-w c:\windows\system32\win32k.sys
- 2008-03-01 13:06:31 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-08-26 07:24:31 826,368 —-a-w c:\windows\system32\wininet.dll
- 2006-10-19 02:47:18 757,248 —-a-w c:\windows\system32\WMADMOD.dll
+ 2006-10-19 01:47:18 757,248 —-a-w c:\windows\system32\WMADMOD.dll
- 2006-10-19 02:47:18 1,117,696 —-a-w c:\windows\system32\WMADMOE.dll
+ 2006-10-19 01:47:18 1,117,696 —-a-w c:\windows\system32\WMADMOE.dll
+ 2005-02-24 17:51:38 348,160 —-a-w c:\windows\system32\WMAFile.dll
- 2007-10-27 22:40:30 222,720 —-a-w c:\windows\system32\wmasf.dll
+ 2007-10-27 21:40:30 222,720 —-a-w c:\windows\system32\wmasf.dll
- 2006-10-19 02:47:18 33,792 —-a-w c:\windows\system32\wmdmlog.dll
+ 2006-10-19 01:47:18 33,792 —-a-w c:\windows\system32\wmdmlog.dll
- 2006-10-19 02:47:18 37,376 —-a-w c:\windows\system32\wmdmps.dll
+ 2006-10-19 01:47:18 37,376 —-a-w c:\windows\system32\wmdmps.dll
- 2006-10-19 02:47:18 429,056 —-a-w c:\windows\system32\wmdrmdev.dll
+ 2006-10-19 01:47:18 429,056 —-a-w c:\windows\system32\wmdrmdev.dll
- 2006-10-19 02:47:20 348,672 —-a-w c:\windows\system32\wmdrmnet.dll
+ 2006-10-19 01:47:20 348,672 —-a-w c:\windows\system32\wmdrmnet.dll
- 2006-10-19 02:47:20 535,040 —-a-w c:\windows\system32\wmdrmsdk.dll
+ 2006-10-19 01:47:20 535,040 —-a-w c:\windows\system32\wmdrmsdk.dll
- 2006-10-19 02:47:20 227,328 —-a-w c:\windows\system32\wmerror.dll
+ 2006-10-19 01:47:20 227,328 —-a-w c:\windows\system32\wmerror.dll
- 2006-10-19 02:47:20 157,184 —-a-w c:\windows\system32\wmidx.dll
+ 2006-10-19 01:47:20 157,184 —-a-w c:\windows\system32\wmidx.dll
- 2006-10-19 02:47:20 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
+ 2006-10-19 01:47:20 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
- 2007-06-12 04:51:12 10,834,944 —-a-w c:\windows\system32\wmp.dll
+ 2007-06-12 03:51:12 10,834,944 —-a-w c:\windows\system32\wmp.dll
- 2006-10-19 02:47:20 242,688 —-a-w c:\windows\system32\wmpasf.dll
+ 2006-10-19 01:47:20 242,688 —-a-w c:\windows\system32\wmpasf.dll
- 2006-10-19 02:47:20 314,880 —-a-w c:\windows\system32\wmpdxm.dll
+ 2006-10-19 01:47:20 314,880 —-a-w c:\windows\system32\wmpdxm.dll
- 2006-10-19 02:47:20 295,936 —-a-w c:\windows\system32\wmpeffects.dll
+ 2008-06-24 22:12:58 295,936 ——w c:\windows\system32\wmpeffects.dll
- 2006-10-19 02:47:20 1,661,440 —-a-w c:\windows\system32\wmpencen.dll
+ 2006-10-19 01:47:20 1,661,440 —-a-w c:\windows\system32\wmpencen.dll
- 2006-10-19 02:47:20 8,231,936 —-a-w c:\windows\system32\wmploc.dll
+ 2006-10-19 01:47:20 8,231,936 —-a-w c:\windows\system32\wmploc.dll
- 2006-10-19 02:47:20 613,376 —-a-w c:\windows\system32\wmpmde.dll
+ 2006-10-19 01:47:20 613,376 ——w c:\windows\system32\wmpmde.dll
- 2006-10-19 02:47:20 130,048 —-a-w c:\windows\system32\wmpps.dll
+ 2006-10-19 01:47:20 130,048 ——w c:\windows\system32\wmpps.dll
- 2006-10-19 02:47:20 99,840 —-a-w c:\windows\system32\wmpshell.dll
+ 2006-10-19 01:47:20 99,840 —-a-w c:\windows\system32\wmpshell.dll
- 2006-10-19 02:47:20 204,288 —-a-w c:\windows\system32\wmpsrcwp.dll
+ 2006-10-19 01:47:20 204,288 —-a-w c:\windows\system32\wmpsrcwp.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\wmsdmod.dll
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\wmsdmod.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\wmsdmoe2.dll
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\wmsdmoe2.dll
- 2006-10-19 02:47:22 603,648 —-a-w c:\windows\system32\WMSPDMOD.dll
+ 2006-10-19 01:47:22 603,648 —-a-w c:\windows\system32\WMSPDMOD.dll
- 2006-10-19 02:47:22 1,329,152 —-a-w c:\windows\system32\WMSPDMOE.dll
+ 2006-10-19 01:47:22 1,329,152 —-a-w c:\windows\system32\WMSPDMOE.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\WMVADVD.dll
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\WMVADVD.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\WMVADVE.DLL
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\WMVADVE.DLL
- 2006-10-19 02:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2006-10-19 01:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
- 2006-10-19 02:47:22 1,543,680 —-a-w c:\windows\system32\WMVDECOD.dll
+ 2006-10-19 01:47:22 1,543,680 ——w c:\windows\system32\WMVDECOD.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\wmvdmod.dll
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\wmvdmod.dll
- 2006-10-19 02:47:22 4,096 —-a-w c:\windows\system32\wmvdmoe2.dll
+ 2006-10-19 01:47:22 4,096 —-a-w c:\windows\system32\wmvdmoe2.dll
- 2006-10-19 02:47:22 1,574,912 —-a-w c:\windows\system32\WMVENCOD.dll
+ 2006-10-19 01:47:22 1,574,912 ——w c:\windows\system32\WMVENCOD.dll
- 2006-10-19 02:47:22 1,382,912 —-a-w c:\windows\system32\WMVSDECD.dll
+ 2006-10-19 01:47:22 1,382,912 ——w c:\windows\system32\WMVSDECD.dll
- 2006-10-19 02:47:22 767,488 —-a-w c:\windows\system32\WMVSENCD.dll
+ 2006-10-19 01:47:22 767,488 ——w c:\windows\system32\WMVSENCD.dll
- 2006-10-19 02:47:22 656,896 —-a-w c:\windows\system32\WMVXENCD.dll
+ 2006-10-19 01:47:22 656,896 ——w c:\windows\system32\WMVXENCD.dll
- 2006-10-19 02:47:22 629,760 —-a-w c:\windows\system32\wpd_ci.dll
+ 2006-10-19 01:47:22 629,760 —-a-w c:\windows\system32\wpd_ci.dll
- 2006-10-19 02:47:22 35,840 —-a-w c:\windows\system32\wpdconns.dll
+ 2006-10-19 01:47:22 35,840 —-a-w c:\windows\system32\wpdconns.dll
- 2006-10-19 02:47:22 154,624 —-a-w c:\windows\system32\wpdmtp.dll
+ 2006-10-19 01:47:22 154,624 —-a-w c:\windows\system32\wpdmtp.dll
- 2006-10-19 02:47:22 63,488 —-a-w c:\windows\system32\wpdmtpus.dll
+ 2006-10-19 01:47:22 63,488 —-a-w c:\windows\system32\wpdmtpus.dll
- 2006-10-19 02:47:22 2,603,008 —-a-w c:\windows\system32\WpdShext.dll
+ 2006-10-19 01:47:22 2,603,008 ——w c:\windows\system32\WpdShext.dll
- 2006-10-19 01:00:14 17,408 —-a-w c:\windows\system32\wpdshextautoplay.exe
+ 2006-10-19 00:00:14 17,408 ——w c:\windows\system32\wpdshextautoplay.exe
- 2006-10-19 02:47:22 38,400 —-a-w c:\windows\system32\wpdshextres.dll
+ 2006-10-19 01:47:22 38,400 ——w c:\windows\system32\wpdshextres.dll
- 2006-10-19 02:47:22 133,632 —-a-w c:\windows\system32\WPDShServiceObj.dll
+ 2006-10-19 01:47:22 133,632 ——w c:\windows\system32\WPDShServiceObj.dll
- 2006-10-19 02:47:22 356,352 —-a-w c:\windows\system32\wpdsp.dll
+ 2006-10-19 01:47:22 356,352 —-a-w c:\windows\system32\wpdsp.dll
- 2007-07-31 00:19:36 549,720 —-a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\windows\system32\wuapi.dll
- 2007-07-31 00:19:16 53,080 —-a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 —-a-w c:\windows\system32\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
- 2007-07-31 00:19:32 325,976 —-a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 —-a-w c:\windows\system32\wucltui.dll
- 2007-07-31 00:18:40 33,624 —-a-w c:\windows\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\wups.dll
- 2007-07-31 00:19:12 43,352 —-a-w c:\windows\system32\wups2.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\wups2.dll
- 2007-07-31 00:19:28 203,096 —-a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 19:13:40 202,776 —-a-w c:\windows\system32\wuweb.dll
+ 2008-09-30 21:42:08 1,286,152 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 21:45:12 91,656 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2008-04-15 17:54:19 1,724,416 —-a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-19 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-04-19 1443072]
"MsmqIntCert"="mqrt.dll" [2007-07-06 c:\windows\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-01 c:\windows\system32\CHDAudPropShortcut.exe]
"nwiz"="nwiz.exe" [2006-08-18 c:\windows\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotSnD"="c:\program files\Spybot\SpybotSD.exe" [2008-07-07 4891472]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=c:\windows\pss\Last.fm Helper.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-19 16:27 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
–a—— 2008-03-02 13:34 1365504 c:\program files\Rainlendar2\Rainlendar2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 12:16 1833296 c:\program files\Spybot\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2006-06-21 12:14 35328 c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-08-18 03:00 1617920 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
S2 OpenCASE Media Agent;OpenCASE Media Agent;"c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe" [2007-12-06 810632]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\Drivers\5U870CAP.sys [2006-06-06 61952]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1cb024e-67f7-11dc-8d53-00163688606a}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{a93de238-14ac-46b8-9d6d-6e2a28c6eb27} - c:\windows\system32\sajuyaya.dll
MSConfigStartUp-MMTray - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
MSConfigStartUp-RocketDock - c:\program files\RocketDock\RocketDock.exe
MSConfigStartUp-Veoh - c:\program files\Veoh Networks\Veoh\VeohClient.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\laura\Application Data\Mozilla\Firefox\Profiles\51j58qrl.Laura\
FireFox -: prefs.js - STARTUP.HOMEPAGE - nytimes.com
FF -: plugin - c:\documents and settings\laura\Application Data\Mozilla\Firefox\Profiles\51j58qrl.Laura\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-30 23:11:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\msdtc.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\mqsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-30 23:15:52 - machine was rebooted [laura]
ComboFix-quarantined-files.txt 2008-12-01 04:15:49
ComboFix2.txt 2008-04-21 20:01:07
ComboFix3.txt 2008-04-20 23:56:39

Pre-Run: 76,512,346,112 bytes free
Post-Run: 76,772,016,128 bytes free

1145 — E O F — 2008-11-13 08:01:46


Here is my new hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:16:17 PM, on 11/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\seek.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

–
End of file - 6200 bytes
Hi frankswildyears,

Doesn't look too bad now. Teatimer is still running, please try to disable it again. Here's a more detailed set of instructions
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.)

You have old vulnerable java install. You will need a newer version for the next scan.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 10…allows end-users to run Java applications".
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u10-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs:
  • Uninstall the old versions of Sun Java, Java JRE, or similar.
  • Do not uninstall Java TM 6 Update 10 if found! :yeah:
Reboot your computer.

  • Double-click on the saved file to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.
Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
  • Spyware, Adware, Dialers, and other potentially dangerous programs
  • Archives
  • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HijackThis log.
Let me know how things are now.

Thanks
For what its worth, my computer has stopped making pop-ups.

Here is the Kaspersky scan result:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, December 1, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 01, 2008 12:15:56
Records in database: 1429020
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 107638
Threat name: 17
Infected objects: 39
Suspicious objects: 0
Duration of the scan: 02:23:46


File name / Threat name / Threats count
C:\home\kyle\BootZilla420\BZ 4.2.0\BZ\Malware\SmitfraudfixSFX.exe Infected: Hoax.Win32.Renos.vasi 1
C:\home\kyle\BootZilla420\BZ 4.2.0\BZ\Malware\SmitfraudfixSFX.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\home\kyle\BootZilla420\BZ 4.2.0\BZ\Utils\RegScanner\RegScanner.exe Infected: not-a-virus:PSWTool.Win32.ProductKey.p 1
C:\home\kyle\BootZilla420\BZ 4.2.0\bzsnapshot.zip Infected: not-a-virus:PSWTool.Win32.ProductKey.p 1
C:\home\kyle\BootZilla420\BZ 4.2.0\bzsnapshot.zip Infected: Hoax.Win32.Renos.vasi 1
C:\home\kyle\BootZilla420\BZ 4.2.0\bzsnapshot.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\QooBox\Quarantine\C\WINDOWS\system32\aaoxlejd.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\bfgnekvw.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\bljtqhdh.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\bosotozo.dll.vir Infected: Trojan-Spy.Win32.Agent.fdp 1
C:\QooBox\Quarantine\C\WINDOWS\system32\bxganqfu.dll.vir Infected: Trojan.Win32.Monder.ck 1
C:\QooBox\Quarantine\C\WINDOWS\system32\esqumede.dll.vir Infected: Trojan.Win32.Monder.ch 1
C:\QooBox\Quarantine\C\WINDOWS\system32\fltubryb.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ijaisyud.dll.vir Infected: Trojan.Win32.Monder.at 1
C:\QooBox\Quarantine\C\WINDOWS\system32\jbxijlpp.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\jcubaomn.dll.vir Infected: Trojan.Win32.Monder.ap 1
C:\QooBox\Quarantine\C\WINDOWS\system32\jutovofa.dll.vir Infected: Trojan.Win32.Monder.aamw 1
C:\QooBox\Quarantine\C\WINDOWS\system32\kfroadoy.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\kjqjqkso.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qvq 1
C:\QooBox\Quarantine\C\WINDOWS\system32\migitiho.dll.vir Infected: Trojan.Win32.Monder.aamw 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mnmbxxpd.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nxurltkx.dll.vir Infected: Trojan.Win32.Monder.bh 1
C:\QooBox\Quarantine\C\WINDOWS\system32\puvcesxt.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rcnhnmsr.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\swbrewra.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\tulfeilf.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\vxbuhodq.dll.vir Infected: Trojan.Win32.Monder.ao 1
C:\QooBox\Quarantine\C\WINDOWS\system32\wqfvxypv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qvq 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ygfcdcii.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ysajcgwv.dll.vir Infected: Trojan.Win32.Monder.cg 1
C:\QooBox\Quarantine\catchme2008-04-20_194554.73.zip Infected: Trojan.Win32.Monder.gen 1
C:\VundoFix Backups\bpgdsqhi.dll.bad Infected: Trojan.Win32.Monder.bt 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[1].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[2].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[3].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[4].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[5].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M4ZC2Q36\ac[6].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\RCX4C0.tmp Infected: Virus.Win32.Trats.d 1

The selected area was scanned.

And here is the new Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:01 PM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Trend Micro\HijackThis\seek.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

–
End of file - 6542 bytes
There is a new issue that isn't that big of a problem, but I was wondering if you know how to fix it. When I went into Add/Remove programs to remove my old Java, I think I may have removed something Java related that I perhaps shouldn't have. Certain websites are now loading oddly, such as certain forums displaying in an out of the ordinary way. The format with the margins and such isn't working properly. If I am not describing things sensibly, that is alright because it isn't a huge functional problem and it is something I can probably figure out.
Hi frankswildyears,

Let's remove Combofix.

Click your Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

Please re-run ATF, then do a scan with MalwareBytes Antimalware.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

Start MBAM
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

RE: java

I take it you are using Firefox

Make sure java is enabled. At the top of FireFox
  • Click Tools, Options, Content
  • Check all 4 boxes in the top section
  • Click the advanced button, check the first box "Move or resize existing window"
  • Click Ok, OK
You can also try hitting the Ctrl key and the F5 key at the same time when on a page that isn't displaying properly. This should refresh the page to the correct state.

Please post the MBAM log and a new HJT log.

Thanks
Thank you so much for your help. The perceived Java problem no longer happens and I am also not having any pop up problems.

This is my MBAM log (it came up clean):

Malwarebytes' Anti-Malware 1.30
Database version: 1452
Windows 5.1.2600 Service Pack 2

12/2/2008 11:22:12 PM
mbam-log-2008-12-02 (23-22-12).txt

Scan type: Quick Scan
Objects scanned: 55721
Time elapsed: 3 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


And this is my new Hijcakthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:22:34 PM, on 12/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\seek.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe

–
End of file - 6531 bytes


My computer doesn't seem to be having any more problems. If you don't see anything else wrong, I just want to thank you again for helping me out.

edit: Oh my goodness, as soon as I did these things, my perceived Java problem came back, how odd. Let me go back into my Firefox settings and make sure everything is right.

edit 2: Yeah, that problem is still around. I am not sure if you have used the site Facebook, but a lot of the functions on that site are also not working. The links and buttons and whatnot don't react when I click on them. It seemed to happen after I uninstalled Combofix. Should I reinstall it?

edit 3: For some reason my Folder settings have also changed? It is very weird; I went into the folder options and now all of the sudden it is back to default settings.
I cleared my Java cache, but it is still not working properly in Firefox. I attached two images of the same page. The one labeled ie is how it looks in Internet Explorer and how it used to look in Firefox. The one labeled ff is how a lot of websites look in Firefox now.
Hi frankswildyears,

To set your folder options to what you prefer
  • Click the views icon or button
  • Select your preference
  • Next click the Tools button
  • Click the View tab
  • In the folders Views section click Apply to all folders
  • Ok the popup
  • Click apply, click OK
These are the settings I have for firefox. They are on the Tools, Options, Content tab. the first is under the Advanced button.
[attachment removed]

The second is under the Fonts Advanced button
[attachment removed]

Does using Cntrl F5 help? Do this a couple of times when viewing the page that won't display correctly. It should force a refresh. This does happen sometimes with FF when the caches are cleared. At worse, a reinstall of FireFox will fix it. Try the Cntl F5 keys at the same first.

Thanks
Hi frankswildyears,

Good to hear. Now we'll finish cleaning up and reset your restore points, and I'll give you some tips.

Open HJT, run a system scan only, check mark these lines if present

O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll (file missing) (HKCU)


Close all other browsers/windows, click fix checked, close HJT

You can delete any notepads or that may have been created and are on your desktop.

I suggest you keep ATF and MBAM. Keep MBAM updated and use it as an on demand scanner. ATF is a good cleaner, now that you know the Ctrl F5 trick, use it to clean the caches.

Now that your system has been cleaned, we'll remove all old infected System Restore points.

Turn OFF System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Restart your computer.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore.
  • Click Apply, and then click OK.
System Restore will now be active again.

* Updates and Upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

Some Recommendations and prevention tips

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

* If you are behind a router, Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

This thread will be kept open for a few days. If you have any problems, please continue to post in this thread.

:adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI