Sorry to take so long to get back, I've been on vacation.
ComboFix Log
ComboFix 09-01-01.02 - Zeus '08 2009-01-02 16:37:41.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.159 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Zeus '08\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\3Q02VX20.exe.a_a
f:\recycler\Desktop.ini
f:\recycler\restore.exe
—– BITS: Possible infected sites —–
hxxp://sus.net.tamu.edu
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 16:28 . 2009-01-02 16:34 47,616 –a—— c:\windows\sqlserver.dll
2008-12-27 09:32 . 2008-12-27 09:32 d——– c:\windows\BBSTORE
2008-12-27 09:32 . 2008-12-27 09:32 d——– c:\program files\The Learning Company
2008-12-27 09:32 . 2008-12-27 09:35 30 –a—— c:\windows\RESULT.QTW
2008-12-20 22:39 . 2008-12-21 12:33 6,089 –a—— c:\windows\system32\winexec
2008-12-20 18:53 . 2008-12-21 07:59 153,610 –a—— c:\windows\service32.exe
2008-12-20 18:44 . 2008-12-20 18:44 34,826 –a—— c:\windows\system32\winexec.exe
2008-12-15 13:47 . 2008-09-29 08:07 67,904 –a—— c:\windows\system32\mfevtps.exe
2008-12-15 13:47 . 2008-09-29 08:07 64,432 –a—— c:\windows\system32\drivers\mferkdet.sys
2008-12-15 12:18 . 2008-06-10 02:32 73,728 –a—— c:\windows\system32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 01:03 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-15 18:18 ——— d—–w c:\program files\Java
2008-11-29 04:25 ——— d—–w c:\documents and settings\Zeus '08\Application Data\Uniblue
2008-11-29 02:58 ——— d—–w c:\program files\Motorola Phone Tools
2008-11-29 02:56 ——— d—–w c:\program files\Motorola
2008-11-27 16:16 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-27 16:07 ——— d—–w c:\program files\Avanquest update
2008-11-23 16:47 ——— d—–w c:\program files\iTunes
2008-11-23 16:47 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-23 16:46 ——— d—–w c:\program files\iPod
2008-11-23 16:46 ——— d—–w c:\program files\Common Files\Apple
2008-11-23 16:43 ——— d—–w c:\program files\QuickTime
2008-11-12 13:38 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-11 18:37 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-11 16:14 ——— d—–w c:\program files\Google
2008-11-10 02:52 ——— d—–w c:\program files\Common Files\Adobe
2008-09-26 23:34 0 ——w c:\documents and settings\Zeus '08\jre-6u7-windows-i586-p.exe
2008-09-26 23:33 382,352 —-a-w c:\documents and settings\Zeus '08\jre-6u7-windows-i586-p-iftw.exe
2008-09-26 23:31 0 —-a-w c:\documents and settings\Zeus '08\jre-6u7-windows-i586-p.exe.bak2
2007-02-26 22:17 92,064 —-a-w c:\documents and settings\Zeus '08\mqdmmdm.sys
2007-02-26 22:17 9,232 —-a-w c:\documents and settings\Zeus '08\mqdmmdfl.sys
2007-02-26 22:17 79,328 —-a-w c:\documents and settings\Zeus '08\mqdmserd.sys
2007-02-26 22:17 66,656 —-a-w c:\documents and settings\Zeus '08\mqdmbus.sys
2007-02-26 22:17 6,208 —-a-w c:\documents and settings\Zeus '08\mqdmcmnt.sys
2007-02-26 22:17 5,936 —-a-w c:\documents and settings\Zeus '08\mqdmwhnt.sys
2007-02-26 22:17 4,048 —-a-w c:\documents and settings\Zeus '08\mqdmcr.sys
2007-02-26 22:17 25,600 —-a-w c:\documents and settings\Zeus '08\usbsermptxp.sys
2007-02-26 22:17 22,768 —-a-w c:\documents and settings\Zeus '08\usbsermpt.sys
2008-09-29 14:07 22,576 —-a-w c:\program files\mozilla firefox\components\Scriptff.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-01_19.58.15.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB938464\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB938464\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB938464\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 —-a-w c:\windows\$hf_mig$\KB938464\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB938464\update\updspapi.dll
+ 2008-02-20 05:19:35 147,968 —-a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:49:36 45,568 —-a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 —-a-w c:\windows\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB945553\update\updspapi.dll
+ 2008-05-02 13:30:08 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP2QFE\msgsc.dll
+ 2008-05-02 14:01:49 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP3GDR\msgsc.dll
+ 2008-05-02 13:42:10 83,968 —-a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 —-a-w c:\windows\$hf_mig$\KB946648\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
+ 2008-02-20 06:52:43 282,624 —-a-w c:\windows\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:22:36 14,048 —-a-w c:\windows\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w c:\windows\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w c:\windows\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 —-a-w c:\windows\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB948590\update\updspapi.dll
+ 2008-03-25 04:50:25 554,008 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2008-03-25 04:50:28 518,944 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2008-03-25 04:50:30 326,432 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2008-03-25 04:50:34 1,516,568 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2008-03-25 04:50:40 355,112 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-26 08:09:15 151,583 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2008-03-25 04:50:42 60,192 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2008-03-25 04:50:42 248,608 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2008-03-25 16:20:46 219,936 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2008-03-25 04:50:45 355,104 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2008-03-25 04:50:47 432,928 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2008-03-25 04:50:55 264,992 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2008-03-25 04:50:57 838,432 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2008-03-25 04:50:58 621,344 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2008-03-25 04:50:58 355,104 —-a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:22:33 14,048 —-a-w c:\windows\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:22:39 213,216 —-a-w c:\windows\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:22:31 22,752 —-a-w c:\windows\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w c:\windows\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w c:\windows\$hf_mig$\KB950749\update\updspapi.dll
+ 2008-05-08 12:14:51 203,008 —-a-w c:\windows\$hf_mig$\KB950762\SP2QFE\rmcast.sys
+ 2008-05-08 14:02:52 203,136 —-a-w c:\windows\$hf_mig$\KB950762\SP3GDR\rmcast.sys
+ 2008-05-08 13:58:17 203,136 —-a-w c:\windows\$hf_mig$\KB950762\SP3QFE\rmcast.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB950762\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB950762\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB950762\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB950762\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB950762\update\updspapi.dll
+ 2008-07-07 20:06:43 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
+ 2008-07-07 20:26:58 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
+ 2008-07-07 20:23:18 253,952 —-a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-04-11 18:39:39 683,520 —-a-w c:\windows\$hf_mig$\KB951066\SP2QFE\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 —-a-w c:\windows\$hf_mig$\KB951066\SP3GDR\inetcomm.dll
+ 2008-04-12 06:22:26 691,712 —-a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
+ 2007-12-03 15:25:31 755,576 —-a-w c:\windows\$hf_mig$\KB951066\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
+ 2008-07-14 11:03:00 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
+ 2008-07-11 12:42:28 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
+ 2008-07-11 12:51:51 62,976 —-a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-13 09:52:16 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys
+ 2008-06-13 11:05:51 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys
+ 2008-06-13 11:27:43 272,128 —-a-w c:\windows\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951376-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951376-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB951376-v2\update\updspapi.dll
+ 2008-05-07 04:55:40 1,288,192 —-a-w c:\windows\$hf_mig$\KB951698\SP2QFE\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 —-a-w c:\windows\$hf_mig$\KB951698\SP3GDR\quartz.dll
+ 2008-05-07 05:04:15 1,288,192 —-a-w c:\windows\$hf_mig$\KB951698\SP3QFE\quartz.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB951698\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB951698\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB951698\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB951698\update\update.exe
+ 2007-12-04 02:55:32 382,840 —-a-w c:\windows\$hf_mig$\KB951698\update\updspapi.dll
+ 2006-08-16 12:08:32 100,352 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\6to4svc.dll
+ 2008-06-20 10:44:08 138,368 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\afd.sys
+ 2008-06-20 17:36:11 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\dnsapi.dll
+ 2008-06-20 17:36:11 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
+ 2008-06-20 10:44:42 360,960 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
+ 2008-06-20 09:32:39 225,920 —-a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip6.sys
+ 2008-06-20 11:40:08 138,496 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\afd.sys
+ 2008-06-20 17:46:57 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\dnsapi.dll
+ 2008-06-20 17:46:57 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
+ 2008-06-20 11:51:12 361,600 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
+ 2008-06-20 11:08:27 225,856 —-a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip6.sys
+ 2008-06-20 11:48:03 138,496 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys
+ 2008-06-20 17:43:05 147,968 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
+ 2008-06-20 17:43:05 245,248 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
+ 2008-06-20 11:59:02 361,600 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
+ 2008-06-20 11:16:44 225,856 —-a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB951748\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB951748\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB951748\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB951748\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB951748\update\updspapi.dll
+ 2008-05-01 15:04:00 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP2QFE\msadce.dll
+ 2008-05-01 14:33:02 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP3GDR\msadce.dll
+ 2008-05-01 14:38:05 331,776 —-a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2008-06-24 16:28:00 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP2QFE\mscms.dll
+ 2008-06-24 16:43:16 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP3GDR\mscms.dll
+ 2008-06-24 16:53:10 74,240 —-a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-09-15 12:17:07 1,846,912 —-a-w c:\windows\$hf_mig$\KB954211\SP2QFE\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 —-a-w c:\windows\$hf_mig$\KB954211\SP3GDR\win32k.sys
+ 2008-09-15 12:25:27 1,846,912 —-a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB954211\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-08-14 09:48:52 138,368 —-a-w c:\windows\$hf_mig$\KB956803\SP2QFE\afd.sys
+ 2008-08-14 10:04:36 138,496 —-a-w c:\windows\$hf_mig$\KB956803\SP3GDR\afd.sys
+ 2008-08-14 10:34:26 138,496 —-a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-08-14 09:55:01 2,142,720 —-a-w c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlmp.exe
+ 2008-08-14 09:18:44 2,062,976 —-a-w c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
+ 2008-08-14 09:18:46 2,020,864 —-a-w c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrpamp.exe
+ 2008-08-14 09:57:20 2,185,984 —-a-w c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
+ 2008-08-14 10:09:26 2,145,280 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlmp.exe
+ 2008-08-14 09:33:16 2,066,048 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,023,936 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrpamp.exe
+ 2008-08-14 10:11:02 2,189,184 —-a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
+ 2008-08-14 10:39:28 2,145,280 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
+ 2008-08-14 21:39:46 2,066,048 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
+ 2008-08-14 10:09:44 2,023,936 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
+ 2008-08-14 22:11:10 2,189,184 —-a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB956841\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
+ 2008-08-28 10:35:33 333,056 —-a-w c:\windows\$hf_mig$\KB957095\SP2QFE\srv.sys
+ 2008-09-08 10:41:42 333,824 —-a-w c:\windows\$hf_mig$\KB957095\SP3GDR\srv.sys
+ 2008-09-08 11:37:19 333,824 —-a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
+ 2008-10-15 16:53:28 339,456 —-a-w c:\windows\$hf_mig$\KB958644\SP2QFE\netapi32.dll
+ 2008-10-15 16:34:24 337,408 —-a-w c:\windows\$hf_mig$\KB958644\SP3GDR\netapi32.dll
+ 2008-10-15 16:25:53 339,456 —-a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:51 382,840 —-a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB938464$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB938464$\spuninst\updspapi.dll
+ 2004-08-04 07:56:42 45,568 -c—-w c:\windows\$NtUninstallKB945553$\dnsrslvr.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\$NtUninstallKB945553$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\$NtUninstallKB945553$\spuninst\updspapi.dll
+ 2004-08-04 07:56:43 82,944 -c—-w c:\windows\$NtUninstallKB946648$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB946648$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB946648$\spuninst\updspapi.dll
+ 2007-06-19 13:31:19 282,112 -c—-w c:\windows\$NtUninstallKB948590$\gdi32.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\$NtUninstallKB948590$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\$NtUninstallKB948590$\spuninst\updspapi.dll
+ 2004-08-04 07:56:42 561,179 -c—-w c:\windows\$NtUninstallKB950749$\dao360.dll
+ 2004-08-04 07:56:43 512,029 -c—-w c:\windows\$NtUninstallKB950749$\msexch40.dll
+ 2004-08-04 07:56:43 319,517 -c—-w c:\windows\$NtUninstallKB950749$\msexcl40.dll
+ 2004-08-04 07:56:43 1,507,356 -c—-w c:\windows\$NtUninstallKB950749$\msjet40.dll
+ 2004-07-17 18:34:46 358,976 -c—-w c:\windows\$NtUninstallKB950749$\msjetoledb40.dll
+ 2004-08-04 07:56:43 151,583 -c—-w c:\windows\$NtUninstallKB950749$\msjint40.dll
+ 2004-08-04 07:56:43 53,279 -c—-w c:\windows\$NtUninstallKB950749$\msjter40.dll
+ 2004-08-04 07:56:43 241,693 -c—-w c:\windows\$NtUninstallKB950749$\msjtes40.dll
+ 2004-08-04 07:56:43 213,023 -c—-w c:\windows\$NtUninstallKB950749$\msltus40.dll
+ 2004-08-04 07:56:43 348,189 -c—-w c:\windows\$NtUninstallKB950749$\mspbde40.dll
+ 2004-08-04 07:56:43 421,919 -c—-w c:\windows\$NtUninstallKB950749$\msrd2x40.dll
+ 2004-08-04 07:56:43 315,423 -c—-w c:\windows\$NtUninstallKB950749$\msrd3x40.dll
+ 2004-08-04 07:56:43 552,989 -c—-w c:\windows\$NtUninstallKB950749$\msrepl40.dll
+ 2004-08-04 07:56:43 258,077 -c—-w c:\windows\$NtUninstallKB950749$\mstext40.dll
+ 2004-08-04 07:56:44 831,519 -c—-w c:\windows\$NtUninstallKB950749$\mswdat10.dll
+ 2004-08-04 07:56:44 614,429 -c—-w c:\windows\$NtUninstallKB950749$\mswstr10.dll
+ 2004-08-04 07:56:44 348,189 -c—-w c:\windows\$NtUninstallKB950749$\msxbde40.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\$NtUninstallKB950749$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\$NtUninstallKB950749$\spuninst\updspapi.dll
+ 2006-07-13 08:48:58 202,240 -c—-w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB950762$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB950762$\spuninst\updspapi.dll
+ 2005-07-26 04:39:45 243,200 -c—-w c:\windows\$NtUninstallKB950974$\es.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB950974$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB950974$\spuninst\updspapi.dll
+ 2007-08-21 06:15:44 683,520 -c—-w c:\windows\$NtUninstallKB951066$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB951066$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB951066$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951072-v2$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB951072-v2$\spuninst\updspapi.dll
+ 2007-11-13 11:31:11 60,416 -c—-w c:\windows\$NtUninstallKB951072-v2$\tzchange.exe
+ 2004-08-04 06:10:37 274,304 -c—-w c:\windows\$NtUninstallKB951376-v2$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951376-v2$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB951376-v2$\spuninst\updspapi.dll
+ 2007-10-29 22:43:03 1,287,680 -c—-w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB951698$\spuninst\spuninst.exe
+ 2007-12-04 02:55:32 382,840 -c—-w c:\windows\$NtUninstallKB951698$\spuninst\updspapi.dll
+ 2004-08-04 06:14:14 138,496 -c—-w c:\windows\$NtUninstallKB951748$\afd.sys
+ 2006-06-26 17:37:10 148,480 -c—-w c:\windows\$NtUninstallKB951748$\dnsapi.dll
+ 2004-08-04 07:56:44 245,248 -c—-w c:\windows\$NtUninstallKB951748$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB951748$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB951748$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c—-w c:\windows\$NtUninstallKB951748$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c—-w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-04 07:56:42 331,776 -c—-w c:\windows\$NtUninstallKB952287$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB952287$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB952287$\spuninst\updspapi.dll
+ 2005-06-29 01:46:00 74,240 -c—-w c:\windows\$NtUninstallKB952954$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB952954$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB952954$\spuninst\updspapi.dll
+ 2007-07-27 16:41:48 231,288 -c—-w c:\windows\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe
+ 2007-07-27 16:41:48 382,840 -c—-w c:\windows\$NtUninstallKB954154_WM11$\spuninst\updspapi.dll
+ 2006-10-19 03:47:20 295,936 -c—-w c:\windows\$NtUninstallKB954154_WM11$\wmpeffects.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB954211$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB954211$\spuninst\updspapi.dll
+ 2007-03-08 13:47:48 1,843,584 -c—-w c:\windows\$NtUninstallKB954211$\win32k.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB956391$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB956391$\spuninst\updspapi.dll
+ 2008-06-20 10:44:38 138,368 -c—-w c:\windows\$NtUninstallKB956803$\afd.sys
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB956803$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB956803$\spuninst\updspapi.dll
+ 2007-02-28 09:08:48 2,136,064 -c—-w c:\windows\$NtUninstallKB956841$\ntkrnlmp.exe
+ 2007-02-28 08:38:55 2,057,600 -c—-w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
+ 2007-02-28 08:38:57 2,015,744 -c—-w c:\windows\$NtUninstallKB956841$\ntkrpamp.exe
+ 2007-02-28 09:10:57 2,180,352 -c—-w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB956841$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w c:\windows\$NtUninstallKB956841$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB957095$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB957095$\spuninst\updspapi.dll
+ 2006-08-14 10:34:41 332,928 -c—-w c:\windows\$NtUninstallKB957095$\srv.sys
+ 2006-08-17 12:28:27 332,288 -c—-w c:\windows\$NtUninstallKB958644$\netapi32.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB958644$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\windows\$NtUninstallKB958644$\spuninst\updspapi.dll
- 2008-01-22 05:09:52 251,272 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2008-11-11 18:27:56 250,928 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2008-06-13 13:10:50 272,128 ——w c:\windows\Driver Cache\i386\bthport.sys
- 2007-02-28 09:08:48 2,136,064 ——w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 09:58:27 2,136,064 ——w c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 ——w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 ——w c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 ——w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:22:14 2,015,744 ——w c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 ——w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 ——w c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2006-10-27 01:55:38 138,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-10-27 20:16:36 46,864 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
+ 2007-08-29 05:38:10 500,648 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\MORPH9.DLL
+ 2007-09-15 03:45:58 16,901,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 05:38:46 9,584,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\MSPUB.EXE
+ 2007-08-29 06:19:24 1,654,648 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-29 06:49:28 606,120 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONBTTNIE.DLL
+ 2007-08-29 05:43:30 1,022,840 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONENOTE.EXE
+ 2007-08-24 10:45:42 101,784 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONENOTEM.EXE
+ 2007-08-24 10:45:42 75,144 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONFILTER.DLL
+ 2007-08-24 10:45:46 1,167,744 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONLIBS.DLL
+ 2007-10-13 03:08:52 6,588,968 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\ONMAIN.DLL
+ 2007-08-29 05:06:16 467,840 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\POWERPNT.EXE
+ 2007-08-29 05:06:44 7,990,144 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\PPCORE.DLL
+ 2008-01-22 05:09:52 251,272 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\PPTPIA.DLL
+ 2007-08-24 09:43:28 138,648 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\PRTF9.DLL
+ 2007-08-29 05:39:14 625,560 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\PTXT9.DLL
+ 2007-08-24 09:43:36 593,296 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\PUBCONV.DLL
+ 2007-08-29 05:16:00 350,064 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2007-09-07 00:03:02 4,280,176 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\WRD12CNV.DLL
+ 2007-08-29 06:07:58 24,928 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\WRD12EXE.EXE
+ 2007-09-06 23:56:32 17,490,800 —-a-r c:\windows\Installer\$PatchCache$\Managed\
00002119030000000000000000F01FEC\12.0.6215\WWLIB.DLL
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2008-11-11 16:15:35 26,694 —-a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
+ 2008-11-23 16:47:51 102,400 —-a-r c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2008-10-22 13:43:48 86,016 —-a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
- 2008-03-16 23:10:28 1,165,584 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-11-11 18:37:14 1,165,584 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-03-16 23:10:29 20,240 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-11-11 18:37:15 20,240 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-03-16 23:10:28 159,504 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-11-11 18:37:14 159,504 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-03-16 23:10:28 184,080 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-11-11 18:37:14 184,080 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-03-16 23:10:29 217,864 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-11-11 18:37:15 217,864 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-03-16 23:10:29 18,704 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-11-11 18:37:15 18,704 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-03-16 23:10:29 35,088 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-11-11 18:37:15 35,088 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-03-16 23:10:28 845,584 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-11-11 18:37:14 845,584 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-03-16 23:10:28 922,384 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-11-11 18:37:15 922,384 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-03-16 23:10:29 272,648 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-11-11 18:37:15 272,648 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-03-16 23:10:29 888,080 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-11-11 18:37:15 888,080 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-03-16 23:10:28 1,172,240 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-11-11 18:37:14 1,172,240 —-a-r c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-11-29 02:57:18 22,486 —-a-r c:\windows\Installer\{922D9CCA-4317-425F-9AA5-94829DF8BA6D}\_6FEFF9B68218417F98F549.exe
+ 2008-11-29 02:57:18 22,486 —-a-r c:\windows\Installer\{922D9CCA-4317-425F-9AA5-94829DF8BA6D}\_768193AF48B27FC9C5F817.exe
+ 2008-11-29 02:57:18 22,486 —-a-r c:\windows\Installer\{922D9CCA-4317-425F-9AA5-94829DF8BA6D}\_C8733E494AEB6988C093CB.exe
+ 2008-12-15 19:44:57 10,134 —-a-r c:\windows\Installer\{A638557B-1F13-40A0-9627-C892FBCA6960}\ARPPRODUCTICON.exe
+ 2008-11-10 02:52:43 295,606 —-a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
- 2000-08-31 13:00:00 161,792 —-a-w c:\windows\SWREG.exe
+ 2000-08-31 14:00:00 161,792 —-a-w c:\windows\SWREG.exe
- 2007-07-31 00:19:20 92,504 —-a-w c:\windows\system32\cdm.dll
+ 2008-01-24 00:35:00 95,064 —-a-w c:\windows\system32\cdm.dll
+ 2008-08-14 09:51:43 138,368 -c—-w c:\windows\system32\dllcache\afd.sys
+ 2008-06-13 13:10:50 272,128 -c—-w c:\windows\system32\dllcache\bthport.sys
- 2007-07-31 00:19:20 92,504 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-01-24 00:35:00 95,064 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-03-25 04:50:25 554,008 -c—-w c:\windows\system32\dllcache\dao360.dll
- 2006-06-26 17:37:10 148,480 -c—-w c:\windows\system32\dllcache\dnsapi.dll
+ 2008-06-21 05:11:12 148,992 -c–a-w c:\windows\system32\dllcache\dnsapi.dll
+ 2008-02-20 05:32:43 45,568 -c—-w c:\windows\system32\dllcache\dnsrslvr.dll
+ 2008-07-07 20:32:22 253,952 -c—-w c:\windows\system32\dllcache\es.dll
- 2007-06-19 13:31:19 282,112 -c—-w c:\windows\system32\dllcache\gdi32.dll
+ 2008-02-20 06:51:05 282,624 -c—-w c:\windows\system32\dllcache\gdi32.dll
- 2007-08-21 06:15:44 683,520 -c—-w c:\windows\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 -c—-w c:\windows\system32\dllcache\inetcomm.dll
+ 2008-05-01 14:30:33 331,776 -c—-w c:\windows\system32\dllcache\msadce.dll
+ 2008-06-24 16:23:05 74,240 -c—-w c:\windows\system32\dllcache\mscms.dll
+ 2008-03-25 04:50:28 518,944 -c—-w c:\windows\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:30 326,432 -c—-w c:\windows\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:34 1,516,568 -c—-w c:\windows\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:40 355,112 -c—-w c:\windows\system32\dllcache\msjetol1.dll
+ 2008-03-26 08:09:15 151,583 -c—-w c:\windows\system32\dllcache\msjint40.dll
+ 2008-03-25 04:50:42 60,192 -c—-w c:\windows\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 248,608 -c—-w c:\windows\system32\dllcache\msjtes40.dll
+ 2008-03-25 16:20:46 219,936 -c—-w c:\windows\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:45 355,104 -c—-w c:\windows\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:47 432,928 -c—-w c:\windows\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 -c—-w c:\windows\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 -c—-w c:\windows\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:55 264,992 -c—-w c:\windows\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:57 838,432 -c—-w c:\windows\system32\dllcache\mswdat10.dll
+ 2008-06-20 17:41:10 245,248 -c—-w c:\windows\system32\dllcache\mswsock.dll
+ 2008-03-25 04:50:58 621,344 -c—-w c:\windows\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 355,104 -c—-w c:\windows\system32\dllcache\msxbde40.dll
- 2006-08-17 12:28:27 332,288 -c—-w c:\windows\system32\dllcache\netapi32.dll
+ 2008-10-15 16:57:55 332,800 -c—-w c:\windows\system32\dllcache\netapi32.dll
- 2007-02-28 09:08:48 2,136,064 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-08-14 09:58:27 2,136,064 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 -c—-w c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 -c—-w c:\windows\system32\dllcache\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-08-14 09:22:14 2,015,744 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
- 2007-10-29 22:43:03 1,287,680 -c—-w c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c—-w c:\windows\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c–a-w c:\windows\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c–a-w c:\windows\system32\dllcache\rmcast.sys
- 2006-08-14 10:34:41 332,928 -c—-w c:\windows\system32\dllcache\srv.sys
+ 2008-08-28 10:04:17 333,056 -c—-w c:\windows\system32\dllcache\srv.sys
- 2007-10-30 17:20:55 360,064 -c—-w c:\windows\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c–a-w c:\windows\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c—-w c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 21:22:08 225,920 -c–a-w c:\windows\system32\dllcache\tcpip6.sys
- 2007-03-08 13:47:48 1,843,584 -c—-w c:\windows\system32\dllcache\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 -c—-w c:\windows\system32\dllcache\win32k.sys
- 2007-07-31 00:19:36 549,720 -c–a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-01-24 00:35:24 556,376 -c–a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-31 00:19:16 53,080 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-01-24 00:34:52 53,592 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-01-24 00:35:30 1,743,704 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-31 00:19:32 325,976 -c–a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-01-24 00:35:20 325,464 -c–a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-31 00:18:40 33,624 -c–a-w c:\windows\system32\dllcache\wups.dll
+ 2008-01-24 00:34:24 36,184 -c–a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-31 00:19:46 203,096 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-01-24 00:35:12 204,120 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-08-29 15:18:58 87,336 —-a-w c:\windows\system32\dns-sd.exe
- 2006-06-26 17:37:10 148,480 —-a-w c:\windows\system32\dnsapi.dll
+ 2008-06-21 05:11:12 148,992 —-a-w c:\windows\system32\dnsapi.dll
- 2004-08-04 07:56:42 45,568 —-a-w c:\windows\system32\dnsrslvr.dll
+ 2008-02-20 05:32:43 45,568 —-a-w c:\windows\system32\dnsrslvr.dll
+ 2008-08-29 14:53:50 61,440 —-a-w c:\windows\system32\dnssd.dll
- 2004-08-04 06:14:14 138,496 —-a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 —-a-w c:\windows\system32\drivers\afd.sys
- 2004-08-04 06:10:37 274,304 ——w c:\windows\system32\drivers\bthport.sys
+ 2008-06-13 13:10:50 272,128 ——w c:\windows\system32\drivers\bthport.sys
- 2008-01-29 17:01:28 16,168 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 18:12:54 15,464 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
- 2006-11-30 14:50:00 64,360 —-a-w c:\windows\system32\drivers\mfeapfk.sys
+ 2008-09-29 14:07:00 74,648 —-a-w c:\windows\system32\drivers\mfeapfk.sys
- 2006-11-30 14:50:00 72,264 —-a-w c:\windows\system32\drivers\mfeavfk.sys
+ 2008-09-29 14:07:00 90,360 —-a-w c:\windows\system32\drivers\mfeavfk.sys
- 2006-11-30 14:50:00 34,152 —-a-w c:\windows\system32\drivers\mfebopk.sys
+ 2008-09-29 14:07:00 42,424 —-a-w c:\windows\system32\drivers\mfebopk.sys
- 2007-02-23 02:50:00 170,408 —-a-w c:\windows\system32\drivers\mfehidk.sys
+ 2008-09-29 14:07:00 340,592 —-a-w c:\windows\system32\drivers\mfehidk.sys
- 2006-11-30 14:50:00 52,136 —-a-w c:\windows\system32\drivers\mfetdik.sys
+ 2008-09-29 14:07:00 62,704 —-a-w c:\windows\system32\drivers\mfetdik.sys
- 2007-02-27 19:31:28 21,504 —-a-w c:\windows\system32\drivers\motmodem.sys
+ 2007-06-18 20:18:26 23,680 —-a-w c:\windows\system32\drivers\motmodem.sys
- 2006-07-13 08:48:58 202,240 —-a-w c:\windows\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 —-a-w c:\windows\system32\drivers\rmcast.sys
- 2006-08-14 10:34:41 332,928 —-a-w c:\windows\system32\drivers\srv.sys
+ 2008-08-28 10:04:17 333,056 —-a-w c:\windows\system32\drivers\srv.sys
- 2007-10-30 17:20:55 360,064 —-a-w c:\windows\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 —-a-w c:\windows\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 —-a-w c:\windows\system32\drivers\tcpip6.sys
+ 2008-06-20 21:22:08 225,920 —-a-w c:\windows\system32\drivers\tcpip6.sys
- 2008-07-10 14:35:22 32,000 —-a-w c:\windows\system32\drivers\usbaapl.sys
+ 2008-10-01 18:01:28 32,000 —-a-w c:\windows\system32\drivers\usbaapl.sys
+ 2008-04-17 18:12:54 107,368 -c–a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 18:12:54 15,464 -c–a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
+ 2008-08-22 00:49:22 18,688 -c–a-w c:\windows\system32\DRVSTORE\motccgp_4B8D9AB3A82A683595609FFF880F0EDF6139A96D\motccgp.sys
+ 2008-08-22 00:49:56 8,320 -c–a-w c:\windows\system32\DRVSTORE\motccgp_4B8D9AB3A82A683595609FFF880F0EDF6139A96D\motccgpfl.sys
+ 2007-11-02 21:51:28 6,400 -c–a-w c:\windows\system32\DRVSTORE\motccgp_4B8D9AB3A82A683595609FFF880F0EDF6139A96D\motswch.sys
+ 2006-11-13 21:45:54 1,419,232 -c–a-w c:\windows\system32\DRVSTORE\motccgp_4B8D9AB3A82A683595609FFF880F0EDF6139A96D\wdfcoinstaller01005.dll
+ 2007-06-18 21:18:26 23,680 -c–a-w c:\windows\system32\DRVSTORE\motmodem_8AAFC1213735C79BDDFE23749C53BFC0F01512CA\motmodem.sys
+ 2006-11-13 21:45:54 1,419,232 -c–a-w c:\windows\system32\DRVSTORE\motmodem_8AAFC1213735C79BDDFE23749C53BFC0F01512CA\wdfcoinstaller01005.dll
+ 2006-07-28 14:10:08 6,144 -c–a-w c:\windows\system32\DRVSTORE\motodrv_EBD40518FA36F6DD08A0EAF14AED13D857D9FFFC\mot_ci.dll
+ 2007-10-10 23:41:50 42,112 -c–a-w c:\windows\system32\DRVSTORE\motodrv_EBD40518FA36F6DD08A0EAF14AED13D857D9FFFC\motodrv.sys
+ 2007-01-24 04:36:20 6,016 -c–a-w c:\windows\system32\DRVSTORE\motousbnet_45605EBE166919E5AE82CE7DE5B7BB04045B4427\motfilt.sys
+ 2008-03-03 22:03:10 23,296 -c–a-w c:\windows\system32\DRVSTORE\motousbnet_45605EBE166919E5AE82CE7DE5B7BB04045B4427\Motousbnet.sys
+ 2007-11-02 21:51:28 6,400 -c–a-w c:\windows\system32\DRVSTORE\motousbnet_45605EBE166919E5AE82CE7DE5B7BB04045B4427\motswch.sys
+ 2006-11-13 21:45:54 1,419,232 -c–a-w c:\windows\system32\DRVSTORE\motousbnet_45605EBE166919E5AE82CE7DE5B7BB04045B4427\wdfcoinstaller01005.dll
+ 2007-06-18 21:18:26 23,680 -c–a-w c:\windows\system32\DRVSTORE\motport_50487F381F70FF5572305B1B459E22B860F1D8C7\motport.sys
+ 2006-11-13 21:45:54 1,419,232 -c–a-w c:\windows\system32\DRVSTORE\motport_50487F381F70FF5572305B1B459E22B860F1D8C7\wdfcoinstaller01005.dll
+ 2008-10-01 18:01:28 32,000 -c–a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
- 2005-07-26 04:39:45 243,200 —-a-w c:\windows\system32\es.dll
+ 2008-07-07 20:32:22 253,952 —-a-w c:\windows\system32\es.dll
- 2008-04-22 11:34:49 272,576 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-11-12 13:38:21 272,576 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2007-06-19 13:31:19 282,112 —-a-w c:\windows\system32\gdi32.dll
+ 2008-02-20 06:51:05 282,624 —-a-w c:\windows\system32\gdi32.dll
- 2008-01-29 17:02:30 107,368 —-a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-17 18:12:54 107,368 —-a-w c:\windows\system32\GEARAspi.dll
- 2007-08-21 06:15:44 683,520 —-a-w c:\windows\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 —-a-w c:\windows\system32\inetcomm.dll
- 2008-06-10 06:21:01 135,168 —-a-w c:\windows\system32\java.exe
+ 2008-06-10 07:21:01 135,168 —-a-w c:\windows\system32\java.exe
- 2008-06-10 06:21:04 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2008-06-10 07:21:04 135,168 —-a-w c:\windows\system32\javaw.exe
- 2008-06-10 07:32:34 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2008-06-10 08:32:34 139,264 —-a-w c:\windows\system32\javaws.exe
- 2007-11-21 00:52:38 2,884,992 —-a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 —-a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
- 2007-11-21 00:52:40 218,496 —-a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-05 03:24:04 235,936 —-a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2008-02-15 16:53:18 70,264 —-a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-12-15 18:08:32 84,661 —-a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-09-29 14:07:00 19,480 —-a-w c:\windows\system32\MFEOtlk.dll
- 2008-01-02 16:21:38 17,642,616 —-a-w c:\windows\system32\MRT.exe
+ 2008-10-07 18:19:42 16,721,856 —-a-w c:\windows\system32\MRT.exe
- 2005-06-29 01:46:00 74,240 —-a-w c:\windows\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 —-a-w c:\windows\system32\mscms.dll
- 2004-08-04 07:56:43 512,029 —-a-w c:\windows\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 —-a-w c:\windows\system32\msexch40.dll
- 2004-08-04 07:56:43 319,517 —-a-w c:\windows\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 —-a-w c:\windows\system32\msexcl40.dll
- 2004-08-04 07:56:43 1,507,356 —-a-w c:\windows\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 —-a-w c:\windows\system32\msjet40.dll
- 2004-07-17 18:34:46 358,976 —-a-w c:\windows\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 —-a-w c:\windows\system32\msjetoledb40.dll
- 2004-08-04 07:56:43 151,583 —-a-w c:\windows\system32\msjint40.dll
+ 2008-03-26 08:09:15 151,583 —-a-w c:\windows\system32\msjint40.dll
- 2004-08-04 07:56:43 53,279 —-a-w c:\windows\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 —-a-w c:\windows\system32\msjter40.dll
- 2004-08-04 07:56:43 241,693 —-a-w c:\windows\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 —-a-w c:\windows\system32\msjtes40.dll
- 2004-08-04 07:56:43 213,023 —-a-w c:\windows\system32\msltus40.dll
+ 2008-03-25 16:20:46 219,936 —-a-w c:\windows\system32\msltus40.dll
- 2004-08-04 07:56:43 348,189 —-a-w c:\windows\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 —-a-w c:\windows\system32\mspbde40.dll
- 2004-08-04 07:56:43 421,919 —-a-w c:\windows\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 —-a-w c:\windows\system32\msrd2x40.dll
- 2004-08-04 07:56:43 315,423 —-a-w c:\windows\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 —-a-w c:\windows\system32\msrd3x40.dll
- 2004-08-04 07:56:43 552,989 —-a-w c:\windows\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 —-a-w c:\windows\system32\msrepl40.dll
- 2004-08-04 07:56:43 258,077 —-a-w c:\windows\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 —-a-w c:\windows\system32\mstext40.dll
- 2004-08-04 07:56:44 831,519 —-a-w c:\windows\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 —-a-w c:\windows\system32\mswdat10.dll
- 2004-08-04 07:56:44 245,248 —-a-w c:\windows\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 —-a-w c:\windows\system32\mswsock.dll
- 2004-08-04 07:56:44 614,429 —-a-w c:\windows\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 —-a-w c:\windows\system32\mswstr10.dll
- 2004-08-04 07:56:44 348,189 —-a-w c:\windows\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 —-a-w c:\windows\system32\msxbde40.dll
- 2006-08-17 12:28:27 332,288 —-a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:57:55 332,800 —-a-w c:\windows\system32\netapi32.dll
- 2007-02-28 08:38:55 2,057,600 —-a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
- 2007-02-28 09:10:57 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
- 2008-09-06 18:11:56 66,777 —-a-w c:\windows\system32\nvModes.dat
+ 2008-12-31 23:28:02 66,777 —-a-w c:\windows\system32\nvModes.dat
- 2008-09-30 13:31:39 80,280 —-a-w c:\windows\system32\perfc009.dat
+ 2008-11-26 04:08:31 80,280 —-a-w c:\windows\system32\perfc009.dat
- 2008-09-30 13:31:39 467,482 —-a-w c:\windows\system32\perfh009.dat
+ 2008-11-26 04:08:31 467,482 —-a-w c:\windows\system32\perfh009.dat
- 2007-10-29 22:43:03 1,287,680 —-a-w c:\windows\system32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 —-a-w c:\windows\system32\quartz.dll
- 2007-10-31 20:09:14 30,464 —-a-w c:\windows\system32\ReinstallBackups\
0017\DriverFiles\usbaapl.sys
+ 2008-10-01 18:01:28 32,000 —-a-w c:\windows\system32\ReinstallBackups\
0017\DriverFiles\usbaapl.sys
+ 2008-01-24 00:34:24 36,184 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.1.6001.65\wups.dll
+ 2008-01-24 00:34:52 44,888 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.1.6001.65\wups2.dll
- 2007-11-13 11:31:11 60,416 ——w c:\windows\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 ——w c:\windows\system32\tzchange.exe
- 2007-03-08 13:47:48 1,843,584 —-a-w c:\windows\system32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 —-a-w c:\windows\system32\win32k.sys
- 2006-10-19 03:47:20 295,936 ——w c:\windows\system32\wmpeffects.dll
+ 2008-06-25 00:12:58 295,936 ——w c:\windows\system32\wmpeffects.dll
- 2007-07-31 00:19:36 549,720 —-a-w c:\windows\system32\wuapi.dll
+ 2008-01-24 00:35:24 556,376 —-a-w c:\windows\system32\wuapi.dll
- 2007-07-31 00:19:16 53,080 —-a-w c:\windows\system32\wuauclt.exe
+ 2008-01-24 00:34:52 53,592 —-a-w c:\windows\system32\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-01-24 00:35:30 1,743,704 —-a-w c:\windows\system32\wuaueng.dll
- 2007-07-31 00:19:32 325,976 —-a-w c:\windows\system32\wucltui.dll
+ 2008-01-24 00:35:20 325,464 —-a-w c:\windows\system32\wucltui.dll
- 2007-07-31 00:18:40 33,624 —-a-w c:\windows\system32\wups.dll
+ 2008-01-24 00:34:24 36,184 —-a-w c:\windows\system32\wups.dll
- 2007-07-31 00:19:12 43,352 —-a-w c:\windows\system32\wups2.dll
+ 2008-01-24 00:34:52 44,888 —-a-w c:\windows\system32\wups2.dll
- 2007-07-31 00:19:46 203,096 —-a-w c:\windows\system32\wuweb.dll
+ 2008-01-24 00:35:12 204,120 —-a-w c:\windows\system32\wuweb.dll
+ 2009-01-02 22:34:51 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_430.dat
+ 2008-04-15 17:54:19 1,724,416 —-a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="c:\documents and settings\Zeus '08\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-06 133104]
"gStart"="c:\garmin\gStart.exe" [2007-08-23 1891416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-10-26 4632576]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-06-25 294998]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-02 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-03 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2006-01-17 135168]
"mmtask"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe" [2006-01-17 53248]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\udaterui.exe" [2008-03-14 136512]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"CitiVAN"="c:\program files\Citi Virtual Account Numbers\CitiVAN.exe" [2004-08-12 192512]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"sydate"="c:\windows\system32\winexec.exe" [2008-12-20 34826]
"serviceload"="c:\windows\service32.exe" [2008-12-21 153610]
"nwiz"="nwiz.exe" [2004-10-26 c:\windows\system32\nwiz.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
c:\documents and settings\Zeus '08\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2007-08-25 1078]
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2007-05-15 6144]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\MATLAB_SV7\\bin\\win32\\MATLAB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 McAfeeEngineService;McAfee Engine Service;"c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe" [2008-09-29 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2008-12-15 67904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2008-12-15 64432]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2c1c242-44df-11db-b59a-806d6172696f}]
\Shell\AutoRun\command - setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Maya]
c:\windows\maya.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\serviceload]
c:\windows\service32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6424712-DC88-861A-31B1-04240DD4FA6A}]
c:\windows\system32\winexec.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-23 c:\windows\Tasks\At1.job
- c:\windows\system32\33w387rr.exe []
2008-12-26 c:\windows\Tasks\At10.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At11.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At12.job
- c:\windows\system32\33w387rr.exe []
2008-12-31 c:\windows\Tasks\At13.job
- c:\windows\system32\33w387rr.exe []
2008-12-26 c:\windows\Tasks\At14.job
- c:\windows\system32\33w387rr.exe []
2009-01-01 c:\windows\Tasks\At15.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At16.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At17.job
- c:\windows\system32\33w387rr.exe []
2009-01-01 c:\windows\Tasks\At18.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At19.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At2.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At20.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At21.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At22.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At23.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At24.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At25.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At26.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At27.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At28.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At29.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At3.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At30.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At31.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At32.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At33.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-26 c:\windows\Tasks\At34.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At35.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At36.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-31 c:\windows\Tasks\At37.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-26 c:\windows\Tasks\At38.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-01 c:\windows\Tasks\At39.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At4.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\At40.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At41.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-01 c:\windows\Tasks\At42.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At43.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At44.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At45.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At46.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At47.job
- c:\windows\system32\3Q02VX20.exe []
2009-01-02 c:\windows\Tasks\At48.job
- c:\windows\system32\3Q02VX20.exe []
2008-12-23 c:\windows\Tasks\At5.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At6.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At7.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At8.job
- c:\windows\system32\33w387rr.exe []
2008-12-23 c:\windows\Tasks\At9.job
- c:\windows\system32\33w387rr.exe []
2009-01-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-706699826-1343024091-1004.job
- c:\documents and settings\Zeus '08\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 19:22]
2009-01-02 c:\windows\Tasks\User_Feed_Synchronization-{4DEB9CBE-063B-4194-B2AB-DA44A856A865}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-System configuration backup - c:\recycler\S-1-5-21-4396444862-8592557575-204344651-7730\sysdate.exe
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\Manager.exe - c:\windows\Downloaded Program Files\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 16:45:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
sydate = c:\windows\system32\winexec.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-02 16:49:57
ComboFix-quarantined-files.txt 2009-01-02 22:49:13
ComboFix2.txt 2008-10-05 01:32:11
ComboFix3.txt 2008-10-02 00:59:16
Pre-Run: 1,768,947,712 bytes free
Post-Run: 2,722,656,256 bytes free
845 — E O F — 2008-11-11 18:37:26
NEW HijackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:03 PM, on 1/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\WINDOWS\Logi_MwX.Exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Network Associates\Common Framework\udaterui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Zeus '08\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Garmin\gStart.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Zeus '08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Zeus '08\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\system32\BhoCitUS.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [sydate] C:\WINDOWS\system32\winexec.exe
O4 - HKLM\..\Run: [serviceload] C:\WINDOWS\service32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Zeus '08\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: LaunchU3.exe.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) -
http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1190851696280
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1190851659587
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: OpcEnum - Unknown owner - C:\WINDOWS\system32\OpcEnum.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 11118 bytes