DeepThought
2008-03-06, 19:02
Well, I never thought I'd see a virus that lets your computer basically run normally, but shuts out all your defenses and resists eradication so strongly...there are some choice things I would like to do to the creators of this ATM...
So, I got a blue screen "stop error", while doing some normal tasks, and it's been he** in a handbasket since. I had no Internet for a while, a call to Dell revealed my Trend Micro PCCillin had been corrupted and had to be uninstalled. The virus had disabled it anyway, and also System Restore.
BitDefender and Panda Activescan have confirmed a Win32.Bagle, I got it somehow from Emule, I naively didn't even realize I had a suspicious file. I don't know precisely what file it was, but have an idea and deleted the suspects. I had been having bad notifications though anyway for ages of "b152.exe" or"b***.exe" from PCCillin - that program never could get rid of those files. :/
Since getting internet back up, I have done considerable cleanup in fits and starts from reading various forums - I got ComboFix to run by renaming it, and and HijackThis to run only as part of the MGTools package. I was able to get CCleaner to run eventually and nuked a lot there, but that's as far as I got - Spybot and various other things still get the error "not a valid Win32 application".
Here is a ComboFix log (it hung before spitting out the log, but I went and found it):
ComboFix 08-03-05.1 - Greta 2008-03-05 21:58:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1552 [GMT -6:00]
Running from: C:\Documents and Settings\Greta\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\kernel
C:\Program Files\Temporary
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\1002984.exe
C:\WINDOWS\system32\drivers\down\1010718.exe
C:\WINDOWS\system32\drivers\down\105203.exe
C:\WINDOWS\system32\drivers\down\109609.exe
C:\WINDOWS\system32\drivers\down\1158421.exe
C:\WINDOWS\system32\drivers\down\118312.exe
C:\WINDOWS\system32\drivers\down\141000.exe
C:\WINDOWS\system32\drivers\down\14756968.exe
C:\WINDOWS\system32\drivers\down\14758093.exe
C:\WINDOWS\system32\drivers\down\14759750.exe
C:\WINDOWS\system32\drivers\down\14761578.exe
C:\WINDOWS\system32\drivers\down\14798968.exe
C:\WINDOWS\system32\drivers\down\148015.exe
C:\WINDOWS\system32\drivers\down\14842062.exe
C:\WINDOWS\system32\drivers\down\14844203.exe
C:\WINDOWS\system32\drivers\down\14852093.exe
C:\WINDOWS\system32\drivers\down\14857593.exe
C:\WINDOWS\system32\drivers\down\14865703.exe
C:\WINDOWS\system32\drivers\down\14870640.exe
C:\WINDOWS\system32\drivers\down\14871281.exe
C:\WINDOWS\system32\drivers\down\14872125.exe
C:\WINDOWS\system32\drivers\down\14895921.exe
C:\WINDOWS\system32\drivers\down\14900468.exe
C:\WINDOWS\system32\drivers\down\14955687.exe
C:\WINDOWS\system32\drivers\down\151968.exe
C:\WINDOWS\system32\drivers\down\158031.exe
C:\WINDOWS\system32\drivers\down\159875.exe
C:\WINDOWS\system32\drivers\down\169359.exe
C:\WINDOWS\system32\drivers\down\171828.exe
C:\WINDOWS\system32\drivers\down\172125.exe
C:\WINDOWS\system32\drivers\down\174062.exe
C:\WINDOWS\system32\drivers\down\175031.exe
C:\WINDOWS\system32\drivers\down\177656.exe
C:\WINDOWS\system32\drivers\down\185593.exe
C:\WINDOWS\system32\drivers\down\186484.exe
C:\WINDOWS\system32\drivers\down\192125.exe
C:\WINDOWS\system32\drivers\down\193718.exe
C:\WINDOWS\system32\drivers\down\194625.exe
C:\WINDOWS\system32\drivers\down\195265.exe
C:\WINDOWS\system32\drivers\down\195593.exe
C:\WINDOWS\system32\drivers\down\197953.exe
C:\WINDOWS\system32\drivers\down\200062.exe
C:\WINDOWS\system32\drivers\down\200125.exe
C:\WINDOWS\system32\drivers\down\202765.exe
C:\WINDOWS\system32\drivers\down\204578.exe
C:\WINDOWS\system32\drivers\down\205937.exe
C:\WINDOWS\system32\drivers\down\206843.exe
C:\WINDOWS\system32\drivers\down\207703.exe
C:\WINDOWS\system32\drivers\down\216156.exe
C:\WINDOWS\system32\drivers\down\219140.exe
C:\WINDOWS\system32\drivers\down\232578.exe
C:\WINDOWS\system32\drivers\down\232656.exe
C:\WINDOWS\system32\drivers\down\238593.exe
C:\WINDOWS\system32\drivers\down\239265.exe
C:\WINDOWS\system32\drivers\down\245312.exe
C:\WINDOWS\system32\drivers\down\247140.exe
C:\WINDOWS\system32\drivers\down\249687.exe
C:\WINDOWS\system32\drivers\down\252031.exe
C:\WINDOWS\system32\drivers\down\253687.exe
C:\WINDOWS\system32\drivers\down\256015.exe
C:\WINDOWS\system32\drivers\down\256906.exe
C:\WINDOWS\system32\drivers\down\265218.exe
C:\WINDOWS\system32\drivers\down\269000.exe
C:\WINDOWS\system32\drivers\down\271078.exe
C:\WINDOWS\system32\drivers\down\271953.exe
C:\WINDOWS\system32\drivers\down\272828.exe
C:\WINDOWS\system32\drivers\down\278859.exe
C:\WINDOWS\system32\drivers\down\280015.exe
C:\WINDOWS\system32\drivers\down\280796.exe
C:\WINDOWS\system32\drivers\down\280968.exe
C:\WINDOWS\system32\drivers\down\281203.exe
C:\WINDOWS\system32\drivers\down\282906.exe
C:\WINDOWS\system32\drivers\down\293390.exe
C:\WINDOWS\system32\drivers\down\29387453.exe
C:\WINDOWS\system32\drivers\down\29389984.exe
C:\WINDOWS\system32\drivers\down\29394906.exe
C:\WINDOWS\system32\drivers\down\29396843.exe
C:\WINDOWS\system32\drivers\down\29438390.exe
C:\WINDOWS\system32\drivers\down\29450031.exe
C:\WINDOWS\system32\drivers\down\294515.exe
C:\WINDOWS\system32\drivers\down\29464031.exe
C:\WINDOWS\system32\drivers\down\29467250.exe
C:\WINDOWS\system32\drivers\down\29496093.exe
C:\WINDOWS\system32\drivers\down\29500156.exe
C:\WINDOWS\system32\drivers\down\29501781.exe
C:\WINDOWS\system32\drivers\down\29502421.exe
C:\WINDOWS\system32\drivers\down\29506671.exe
C:\WINDOWS\system32\drivers\down\29508250.exe
C:\WINDOWS\system32\drivers\down\29544312.exe
C:\WINDOWS\system32\drivers\down\295500.exe
C:\WINDOWS\system32\drivers\down\300484.exe
C:\WINDOWS\system32\drivers\down\316281.exe
C:\WINDOWS\system32\drivers\down\341140.exe
C:\WINDOWS\system32\drivers\down\349859.exe
C:\WINDOWS\system32\drivers\down\43973281.exe
C:\WINDOWS\system32\drivers\down\43979031.exe
C:\WINDOWS\system32\drivers\down\43981156.exe
C:\WINDOWS\system32\drivers\down\43983562.exe
C:\WINDOWS\system32\drivers\down\44023156.exe
C:\WINDOWS\system32\drivers\down\44030234.exe
C:\WINDOWS\system32\drivers\down\44039500.exe
C:\WINDOWS\system32\drivers\down\44044953.exe
C:\WINDOWS\system32\drivers\down\44056703.exe
C:\WINDOWS\system32\drivers\down\44061515.exe
C:\WINDOWS\system32\drivers\down\44063265.exe
C:\WINDOWS\system32\drivers\down\44064437.exe
C:\WINDOWS\system32\drivers\down\44074812.exe
C:\WINDOWS\system32\drivers\down\44076671.exe
C:\WINDOWS\system32\drivers\down\44116078.exe
C:\WINDOWS\system32\drivers\down\58556093.exe
C:\WINDOWS\system32\drivers\down\58565578.exe
C:\WINDOWS\system32\drivers\down\58567328.exe
C:\WINDOWS\system32\drivers\down\58569000.exe
C:\WINDOWS\system32\drivers\down\58570953.exe
C:\WINDOWS\system32\drivers\down\585765.exe
C:\WINDOWS\system32\drivers\down\58607953.exe
C:\WINDOWS\system32\drivers\down\58615015.exe
C:\WINDOWS\system32\drivers\down\58621437.exe
C:\WINDOWS\system32\drivers\down\58623875.exe
C:\WINDOWS\system32\drivers\down\58632812.exe
C:\WINDOWS\system32\drivers\down\58636843.exe
C:\WINDOWS\system32\drivers\down\58637562.exe
C:\WINDOWS\system32\drivers\down\58638140.exe
C:\WINDOWS\system32\drivers\down\58645296.exe
C:\WINDOWS\system32\drivers\down\58647125.exe
C:\WINDOWS\system32\drivers\down\58683781.exe
C:\WINDOWS\system32\drivers\down\605328.exe
C:\WINDOWS\system32\drivers\down\60543015.exe
C:\WINDOWS\system32\drivers\down\60555875.exe
C:\WINDOWS\system32\drivers\down\60558359.exe
C:\WINDOWS\system32\drivers\down\60560062.exe
C:\WINDOWS\system32\drivers\down\60577921.exe
C:\WINDOWS\system32\drivers\down\60616968.exe
C:\WINDOWS\system32\drivers\down\60658421.exe
C:\WINDOWS\system32\drivers\down\60662203.exe
C:\WINDOWS\system32\drivers\down\60666484.exe
C:\WINDOWS\system32\drivers\down\60669078.exe
C:\WINDOWS\system32\drivers\down\60698281.exe
C:\WINDOWS\system32\drivers\down\60707640.exe
C:\WINDOWS\system32\drivers\down\60708687.exe
C:\WINDOWS\system32\drivers\down\60711656.exe
C:\WINDOWS\system32\drivers\down\60729703.exe
C:\WINDOWS\system32\drivers\down\60732296.exe
C:\WINDOWS\system32\drivers\down\60770578.exe
C:\WINDOWS\system32\drivers\down\625984.exe
C:\WINDOWS\system32\drivers\down\683953.exe
C:\WINDOWS\system32\drivers\down\69953.exe
C:\WINDOWS\system32\drivers\down\73157625.exe
C:\WINDOWS\system32\drivers\down\73174234.exe
C:\WINDOWS\system32\drivers\down\73182031.exe
C:\WINDOWS\system32\drivers\down\73190578.exe
C:\WINDOWS\system32\drivers\down\73193437.exe
C:\WINDOWS\system32\drivers\down\73261062.exe
C:\WINDOWS\system32\drivers\down\73312046.exe
C:\WINDOWS\system32\drivers\down\73334078.exe
C:\WINDOWS\system32\drivers\down\73338515.exe
C:\WINDOWS\system32\drivers\down\73381781.exe
C:\WINDOWS\system32\drivers\down\73395046.exe
C:\WINDOWS\system32\drivers\down\73396843.exe
C:\WINDOWS\system32\drivers\down\73401890.exe
C:\WINDOWS\system32\drivers\down\73411765.exe
C:\WINDOWS\system32\drivers\down\73418625.exe
C:\WINDOWS\system32\drivers\down\73475093.exe
C:\WINDOWS\system32\drivers\down\75226703.exe
C:\WINDOWS\system32\drivers\down\75230296.exe
C:\WINDOWS\system32\drivers\down\75232671.exe
C:\WINDOWS\system32\drivers\down\75234625.exe
C:\WINDOWS\system32\drivers\down\75236843.exe
C:\WINDOWS\system32\drivers\down\75263687.exe
C:\WINDOWS\system32\drivers\down\75278234.exe
C:\WINDOWS\system32\drivers\down\75280234.exe
C:\WINDOWS\system32\drivers\down\75293718.exe
C:\WINDOWS\system32\drivers\down\75298406.exe
C:\WINDOWS\system32\drivers\down\75306125.exe
C:\WINDOWS\system32\drivers\down\75309984.exe
C:\WINDOWS\system32\drivers\down\75310609.exe
C:\WINDOWS\system32\drivers\down\75311375.exe
C:\WINDOWS\system32\drivers\down\75314906.exe
C:\WINDOWS\system32\drivers\down\75316625.exe
C:\WINDOWS\system32\drivers\down\75352140.exe
C:\WINDOWS\system32\drivers\down\770453.exe
C:\WINDOWS\system32\drivers\down\794984.exe
C:\WINDOWS\system32\drivers\down\804796.exe
C:\WINDOWS\system32\drivers\down\827578.exe
C:\WINDOWS\system32\drivers\down\830312.exe
C:\WINDOWS\system32\drivers\down\868484.exe
C:\WINDOWS\system32\drivers\down\89781656.exe
C:\WINDOWS\system32\drivers\down\89788593.exe
C:\WINDOWS\system32\drivers\down\89791234.exe
C:\WINDOWS\system32\drivers\down\89797765.exe
C:\WINDOWS\system32\drivers\down\89801000.exe
C:\WINDOWS\system32\drivers\down\89821968.exe
C:\WINDOWS\system32\drivers\down\89850296.exe
C:\WINDOWS\system32\drivers\down\89877359.exe
C:\WINDOWS\system32\drivers\down\89883062.exe
C:\WINDOWS\system32\drivers\down\89895171.exe
C:\WINDOWS\system32\drivers\down\89899687.exe
C:\WINDOWS\system32\drivers\down\89902031.exe
C:\WINDOWS\system32\drivers\down\89902906.exe
C:\WINDOWS\system32\drivers\down\89908671.exe
C:\WINDOWS\system32\drivers\down\89910906.exe
C:\WINDOWS\system32\drivers\down\89959328.exe
C:\WINDOWS\system32\drivers\down\90468.exe
C:\WINDOWS\system32\drivers\down\908203.exe
C:\WINDOWS\system32\drivers\down\910656.exe
C:\WINDOWS\system32\drivers\down\914687.exe
C:\WINDOWS\system32\drivers\down\93218.exe
C:\WINDOWS\system32\drivers\down\95171.exe
C:\WINDOWS\system32\drivers\down\96031.exe
C:\WINDOWS\system32\drivers\down\976927859.exe
C:\WINDOWS\system32\drivers\down\976980468.exe
C:\WINDOWS\system32\drivers\down\976993265.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
K:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.
2008-03-05 04:24 . 2008-03-05 09:01 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-03-05 04:12 . 2005-01-13 21:41 11,254 --a------ C:\WINDOWS\system32\locate.com
2008-03-05 04:11 . 2008-03-05 04:17 <DIR> d-------- C:\MGtools
2008-03-05 04:11 . 2008-03-05 04:17 101,748 --a------ C:\MGlogs.zip
2008-03-04 15:43 . 2008-03-04 15:43 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-03-04 14:15 . 2008-03-04 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-04 14:14 . 2008-03-04 14:14 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-04 14:14 . 2008-03-04 14:14 <DIR> d-------- C:\Documents and Settings\Greta\Application Data\SUPERAntiSpyware.com
2008-03-04 14:13 . 2008-03-04 14:13 1,238,736 --a------ C:\MGtools.exe
2008-03-04 14:11 . 2008-03-04 14:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-04 14:11 . 2008-03-04 14:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-04 14:08 . 2008-03-05 22:06 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-04 14:08 . 2008-03-04 14:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-03 23:06 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-03 23:04 . 2008-03-03 23:05 7,237,978 --a------ C:\Temp\Free3GPVideoConverter.exe
2008-03-03 22:54 . 2008-03-03 22:54 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-03 17:03 . 2008-03-03 23:28 <DIR> d-------- C:\Program Files\INAC
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-03 10:13 . 2008-03-03 10:13 <DIR> d-------- C:\websymbols
2008-03-03 10:10 . 2008-03-03 10:13 <DIR> d-------- C:\Program Files\Debugging Tools for Windows
2008-03-03 10:06 . 2008-03-03 10:06 <DIR> d-------- C:\Program Files\Citrix
2008-03-03 10:01 . 2008-03-03 10:01 60,968 --a------ C:\Documents and Settings\Greta\GoToAssistDownloadHelper.exe
2008-02-27 02:20 . 2008-02-27 02:20 <DIR> d-------- C:\Program Files\Native Instruments
2008-02-27 02:20 . 2006-05-19 16:54 393,216 --a------ C:\WINDOWS\system32\NI_IRC_1_1.dll
2008-02-27 02:20 . 2005-04-04 18:00 393,216 --a------ C:\WINDOWS\system32\NI_IRC_1_0_3.dll
2008-02-27 02:20 . 2006-07-11 16:16 61,440 --a------ C:\WINDOWS\system32\NI_DFD_1_4.dll
2008-02-27 02:19 . 2008-02-27 02:22 <DIR> d-------- C:\Program Files\Finale GPO 2.0
2008-02-27 02:19 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-02-27 02:17 . 2008-02-27 02:35 <DIR> d-------- C:\Program Files\Finale 2007
2008-02-10 16:32 . 2008-02-10 16:32 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-02-09 14:18 . 2008-02-09 14:22 <DIR> d-------- C:\Program Files\SecondLifeReleaseCandidate
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 03:44 --------- d-----w C:\Program Files\Yahoo!
2008-03-06 03:28 --------- d-----w C:\Program Files\Soulseek
2008-03-05 00:15 --------- d-----w C:\Program Files\iTunes
2008-03-04 20:13 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-04 05:06 --------- d-----w C:\Program Files\Java
2008-03-04 04:27 --------- d-----w C:\Program Files\WildTangent
2008-03-04 04:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-03 06:29 --------- d-----w C:\Documents and Settings\Greta\Application Data\foobar2000
2008-03-01 07:29 --------- d-----w C:\Program Files\Trend Micro
2008-02-29 23:07 --------- d-----w C:\Program Files\eMule
2008-02-28 08:26 164,280 ----a-w C:\Documents and Settings\Greta\Application Data\GDIPFONTCACHEV1.DAT
2008-02-27 08:16 --------- d-----w C:\Program Files\BitComet
2008-02-10 07:10 --------- d-----w C:\Program Files\myFairTunes
2008-02-09 04:25 --------- d-----w C:\Program Files\Solveig Multimedia
2008-02-09 04:25 --------- d-----w C:\Program Files\Common Files\Solveig Multimedia
2008-02-09 04:25 --------- d-----w C:\Program Files\Common Files\Elecard
2008-02-04 03:39 --------- d-----w C:\Program Files\Creative
2008-02-04 03:19 --------- d-----w C:\Program Files\Macromedia
2008-02-04 03:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 03:17 --------- d-----w C:\Program Files\ListMaker
2008-02-04 03:17 --------- d-----w C:\Program Files\eMusic Download Manager
2008-02-04 00:32 --------- d-----w C:\Program Files\NCH Swift Sound
2008-02-04 00:06 --------- d-----w C:\Program Files\SecondLife
2008-02-04 00:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-02-03 23:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-03 23:52 --------- d-----w C:\Program Files\QuickPar
2008-02-03 23:52 --------- d-----w C:\Program Files\NetWaiting
2008-02-03 23:52 --------- d-----w C:\Program Files\Modem Helper
2008-02-03 23:52 --------- d-----w C:\Program Files\GemMaster
2008-02-03 23:52 --------- d-----w C:\Program Files\FLAC
2008-02-03 23:52 --------- d-----w C:\Program Files\ESPNMotion
2008-02-03 23:52 --------- d-----w C:\Program Files\EnglishOtto
2008-02-03 23:52 --------- d-----w C:\Program Files\DivX
2008-02-03 23:52 --------- d-----w C:\Program Files\ClocX
2008-02-03 23:52 --------- d-----w C:\Program Files\AoA Audio Extractor
2008-01-30 12:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-22 02:30 --------- d-----w C:\Program Files\WinSCP
2008-01-21 05:30 --------- d-----w C:\Program Files\iPod
2008-01-21 05:20 --------- d-----w C:\Program Files\QuickTime
2008-01-21 05:20 --------- d-----w C:\Program Files\MediaMonkey
2008-01-20 07:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-19 18:41 --------- d-----w C:\Program Files\CUE Splitter
2008-01-17 08:41 --------- d-----w C:\Documents and Settings\Greta\Application Data\Apple Computer
2008-01-16 04:50 --------- d-----w C:\Documents and Settings\Greta\Application Data\AccurateRip
2008-01-12 19:31 --------- d-----w C:\Program Files\Audible
2008-01-12 19:23 --------- d-----w C:\Documents and Settings\Greta\Application Data\Creative
2008-01-12 05:42 --------- d--h--w C:\Program Files\Creative Installation Information
2008-01-12 05:42 --------- d-----w C:\Program Files\Common Files\Creative
2008-01-10 01:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-10 01:08 --------- d-----w C:\Program Files\AIM6
2008-01-09 21:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2008-01-06 18:59 --------- d-----w C:\Program Files\Last.fm
2007-11-26 08:53 604 ---ha-w C:\Program Files\STLL Notifier
2004-08-10 11:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-10 11:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2007-04-04 06:32 1,264 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2004-08-10 11:00 1,028,096 --sh--w C:\WINDOWS\system32\mfc42.dll
2004-08-10 11:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-10 11:00 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2004-08-10 11:00 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-10 11:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.
So, I got a blue screen "stop error", while doing some normal tasks, and it's been he** in a handbasket since. I had no Internet for a while, a call to Dell revealed my Trend Micro PCCillin had been corrupted and had to be uninstalled. The virus had disabled it anyway, and also System Restore.
BitDefender and Panda Activescan have confirmed a Win32.Bagle, I got it somehow from Emule, I naively didn't even realize I had a suspicious file. I don't know precisely what file it was, but have an idea and deleted the suspects. I had been having bad notifications though anyway for ages of "b152.exe" or"b***.exe" from PCCillin - that program never could get rid of those files. :/
Since getting internet back up, I have done considerable cleanup in fits and starts from reading various forums - I got ComboFix to run by renaming it, and and HijackThis to run only as part of the MGTools package. I was able to get CCleaner to run eventually and nuked a lot there, but that's as far as I got - Spybot and various other things still get the error "not a valid Win32 application".
Here is a ComboFix log (it hung before spitting out the log, but I went and found it):
ComboFix 08-03-05.1 - Greta 2008-03-05 21:58:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1552 [GMT -6:00]
Running from: C:\Documents and Settings\Greta\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\kernel
C:\Program Files\Temporary
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\1002984.exe
C:\WINDOWS\system32\drivers\down\1010718.exe
C:\WINDOWS\system32\drivers\down\105203.exe
C:\WINDOWS\system32\drivers\down\109609.exe
C:\WINDOWS\system32\drivers\down\1158421.exe
C:\WINDOWS\system32\drivers\down\118312.exe
C:\WINDOWS\system32\drivers\down\141000.exe
C:\WINDOWS\system32\drivers\down\14756968.exe
C:\WINDOWS\system32\drivers\down\14758093.exe
C:\WINDOWS\system32\drivers\down\14759750.exe
C:\WINDOWS\system32\drivers\down\14761578.exe
C:\WINDOWS\system32\drivers\down\14798968.exe
C:\WINDOWS\system32\drivers\down\148015.exe
C:\WINDOWS\system32\drivers\down\14842062.exe
C:\WINDOWS\system32\drivers\down\14844203.exe
C:\WINDOWS\system32\drivers\down\14852093.exe
C:\WINDOWS\system32\drivers\down\14857593.exe
C:\WINDOWS\system32\drivers\down\14865703.exe
C:\WINDOWS\system32\drivers\down\14870640.exe
C:\WINDOWS\system32\drivers\down\14871281.exe
C:\WINDOWS\system32\drivers\down\14872125.exe
C:\WINDOWS\system32\drivers\down\14895921.exe
C:\WINDOWS\system32\drivers\down\14900468.exe
C:\WINDOWS\system32\drivers\down\14955687.exe
C:\WINDOWS\system32\drivers\down\151968.exe
C:\WINDOWS\system32\drivers\down\158031.exe
C:\WINDOWS\system32\drivers\down\159875.exe
C:\WINDOWS\system32\drivers\down\169359.exe
C:\WINDOWS\system32\drivers\down\171828.exe
C:\WINDOWS\system32\drivers\down\172125.exe
C:\WINDOWS\system32\drivers\down\174062.exe
C:\WINDOWS\system32\drivers\down\175031.exe
C:\WINDOWS\system32\drivers\down\177656.exe
C:\WINDOWS\system32\drivers\down\185593.exe
C:\WINDOWS\system32\drivers\down\186484.exe
C:\WINDOWS\system32\drivers\down\192125.exe
C:\WINDOWS\system32\drivers\down\193718.exe
C:\WINDOWS\system32\drivers\down\194625.exe
C:\WINDOWS\system32\drivers\down\195265.exe
C:\WINDOWS\system32\drivers\down\195593.exe
C:\WINDOWS\system32\drivers\down\197953.exe
C:\WINDOWS\system32\drivers\down\200062.exe
C:\WINDOWS\system32\drivers\down\200125.exe
C:\WINDOWS\system32\drivers\down\202765.exe
C:\WINDOWS\system32\drivers\down\204578.exe
C:\WINDOWS\system32\drivers\down\205937.exe
C:\WINDOWS\system32\drivers\down\206843.exe
C:\WINDOWS\system32\drivers\down\207703.exe
C:\WINDOWS\system32\drivers\down\216156.exe
C:\WINDOWS\system32\drivers\down\219140.exe
C:\WINDOWS\system32\drivers\down\232578.exe
C:\WINDOWS\system32\drivers\down\232656.exe
C:\WINDOWS\system32\drivers\down\238593.exe
C:\WINDOWS\system32\drivers\down\239265.exe
C:\WINDOWS\system32\drivers\down\245312.exe
C:\WINDOWS\system32\drivers\down\247140.exe
C:\WINDOWS\system32\drivers\down\249687.exe
C:\WINDOWS\system32\drivers\down\252031.exe
C:\WINDOWS\system32\drivers\down\253687.exe
C:\WINDOWS\system32\drivers\down\256015.exe
C:\WINDOWS\system32\drivers\down\256906.exe
C:\WINDOWS\system32\drivers\down\265218.exe
C:\WINDOWS\system32\drivers\down\269000.exe
C:\WINDOWS\system32\drivers\down\271078.exe
C:\WINDOWS\system32\drivers\down\271953.exe
C:\WINDOWS\system32\drivers\down\272828.exe
C:\WINDOWS\system32\drivers\down\278859.exe
C:\WINDOWS\system32\drivers\down\280015.exe
C:\WINDOWS\system32\drivers\down\280796.exe
C:\WINDOWS\system32\drivers\down\280968.exe
C:\WINDOWS\system32\drivers\down\281203.exe
C:\WINDOWS\system32\drivers\down\282906.exe
C:\WINDOWS\system32\drivers\down\293390.exe
C:\WINDOWS\system32\drivers\down\29387453.exe
C:\WINDOWS\system32\drivers\down\29389984.exe
C:\WINDOWS\system32\drivers\down\29394906.exe
C:\WINDOWS\system32\drivers\down\29396843.exe
C:\WINDOWS\system32\drivers\down\29438390.exe
C:\WINDOWS\system32\drivers\down\29450031.exe
C:\WINDOWS\system32\drivers\down\294515.exe
C:\WINDOWS\system32\drivers\down\29464031.exe
C:\WINDOWS\system32\drivers\down\29467250.exe
C:\WINDOWS\system32\drivers\down\29496093.exe
C:\WINDOWS\system32\drivers\down\29500156.exe
C:\WINDOWS\system32\drivers\down\29501781.exe
C:\WINDOWS\system32\drivers\down\29502421.exe
C:\WINDOWS\system32\drivers\down\29506671.exe
C:\WINDOWS\system32\drivers\down\29508250.exe
C:\WINDOWS\system32\drivers\down\29544312.exe
C:\WINDOWS\system32\drivers\down\295500.exe
C:\WINDOWS\system32\drivers\down\300484.exe
C:\WINDOWS\system32\drivers\down\316281.exe
C:\WINDOWS\system32\drivers\down\341140.exe
C:\WINDOWS\system32\drivers\down\349859.exe
C:\WINDOWS\system32\drivers\down\43973281.exe
C:\WINDOWS\system32\drivers\down\43979031.exe
C:\WINDOWS\system32\drivers\down\43981156.exe
C:\WINDOWS\system32\drivers\down\43983562.exe
C:\WINDOWS\system32\drivers\down\44023156.exe
C:\WINDOWS\system32\drivers\down\44030234.exe
C:\WINDOWS\system32\drivers\down\44039500.exe
C:\WINDOWS\system32\drivers\down\44044953.exe
C:\WINDOWS\system32\drivers\down\44056703.exe
C:\WINDOWS\system32\drivers\down\44061515.exe
C:\WINDOWS\system32\drivers\down\44063265.exe
C:\WINDOWS\system32\drivers\down\44064437.exe
C:\WINDOWS\system32\drivers\down\44074812.exe
C:\WINDOWS\system32\drivers\down\44076671.exe
C:\WINDOWS\system32\drivers\down\44116078.exe
C:\WINDOWS\system32\drivers\down\58556093.exe
C:\WINDOWS\system32\drivers\down\58565578.exe
C:\WINDOWS\system32\drivers\down\58567328.exe
C:\WINDOWS\system32\drivers\down\58569000.exe
C:\WINDOWS\system32\drivers\down\58570953.exe
C:\WINDOWS\system32\drivers\down\585765.exe
C:\WINDOWS\system32\drivers\down\58607953.exe
C:\WINDOWS\system32\drivers\down\58615015.exe
C:\WINDOWS\system32\drivers\down\58621437.exe
C:\WINDOWS\system32\drivers\down\58623875.exe
C:\WINDOWS\system32\drivers\down\58632812.exe
C:\WINDOWS\system32\drivers\down\58636843.exe
C:\WINDOWS\system32\drivers\down\58637562.exe
C:\WINDOWS\system32\drivers\down\58638140.exe
C:\WINDOWS\system32\drivers\down\58645296.exe
C:\WINDOWS\system32\drivers\down\58647125.exe
C:\WINDOWS\system32\drivers\down\58683781.exe
C:\WINDOWS\system32\drivers\down\605328.exe
C:\WINDOWS\system32\drivers\down\60543015.exe
C:\WINDOWS\system32\drivers\down\60555875.exe
C:\WINDOWS\system32\drivers\down\60558359.exe
C:\WINDOWS\system32\drivers\down\60560062.exe
C:\WINDOWS\system32\drivers\down\60577921.exe
C:\WINDOWS\system32\drivers\down\60616968.exe
C:\WINDOWS\system32\drivers\down\60658421.exe
C:\WINDOWS\system32\drivers\down\60662203.exe
C:\WINDOWS\system32\drivers\down\60666484.exe
C:\WINDOWS\system32\drivers\down\60669078.exe
C:\WINDOWS\system32\drivers\down\60698281.exe
C:\WINDOWS\system32\drivers\down\60707640.exe
C:\WINDOWS\system32\drivers\down\60708687.exe
C:\WINDOWS\system32\drivers\down\60711656.exe
C:\WINDOWS\system32\drivers\down\60729703.exe
C:\WINDOWS\system32\drivers\down\60732296.exe
C:\WINDOWS\system32\drivers\down\60770578.exe
C:\WINDOWS\system32\drivers\down\625984.exe
C:\WINDOWS\system32\drivers\down\683953.exe
C:\WINDOWS\system32\drivers\down\69953.exe
C:\WINDOWS\system32\drivers\down\73157625.exe
C:\WINDOWS\system32\drivers\down\73174234.exe
C:\WINDOWS\system32\drivers\down\73182031.exe
C:\WINDOWS\system32\drivers\down\73190578.exe
C:\WINDOWS\system32\drivers\down\73193437.exe
C:\WINDOWS\system32\drivers\down\73261062.exe
C:\WINDOWS\system32\drivers\down\73312046.exe
C:\WINDOWS\system32\drivers\down\73334078.exe
C:\WINDOWS\system32\drivers\down\73338515.exe
C:\WINDOWS\system32\drivers\down\73381781.exe
C:\WINDOWS\system32\drivers\down\73395046.exe
C:\WINDOWS\system32\drivers\down\73396843.exe
C:\WINDOWS\system32\drivers\down\73401890.exe
C:\WINDOWS\system32\drivers\down\73411765.exe
C:\WINDOWS\system32\drivers\down\73418625.exe
C:\WINDOWS\system32\drivers\down\73475093.exe
C:\WINDOWS\system32\drivers\down\75226703.exe
C:\WINDOWS\system32\drivers\down\75230296.exe
C:\WINDOWS\system32\drivers\down\75232671.exe
C:\WINDOWS\system32\drivers\down\75234625.exe
C:\WINDOWS\system32\drivers\down\75236843.exe
C:\WINDOWS\system32\drivers\down\75263687.exe
C:\WINDOWS\system32\drivers\down\75278234.exe
C:\WINDOWS\system32\drivers\down\75280234.exe
C:\WINDOWS\system32\drivers\down\75293718.exe
C:\WINDOWS\system32\drivers\down\75298406.exe
C:\WINDOWS\system32\drivers\down\75306125.exe
C:\WINDOWS\system32\drivers\down\75309984.exe
C:\WINDOWS\system32\drivers\down\75310609.exe
C:\WINDOWS\system32\drivers\down\75311375.exe
C:\WINDOWS\system32\drivers\down\75314906.exe
C:\WINDOWS\system32\drivers\down\75316625.exe
C:\WINDOWS\system32\drivers\down\75352140.exe
C:\WINDOWS\system32\drivers\down\770453.exe
C:\WINDOWS\system32\drivers\down\794984.exe
C:\WINDOWS\system32\drivers\down\804796.exe
C:\WINDOWS\system32\drivers\down\827578.exe
C:\WINDOWS\system32\drivers\down\830312.exe
C:\WINDOWS\system32\drivers\down\868484.exe
C:\WINDOWS\system32\drivers\down\89781656.exe
C:\WINDOWS\system32\drivers\down\89788593.exe
C:\WINDOWS\system32\drivers\down\89791234.exe
C:\WINDOWS\system32\drivers\down\89797765.exe
C:\WINDOWS\system32\drivers\down\89801000.exe
C:\WINDOWS\system32\drivers\down\89821968.exe
C:\WINDOWS\system32\drivers\down\89850296.exe
C:\WINDOWS\system32\drivers\down\89877359.exe
C:\WINDOWS\system32\drivers\down\89883062.exe
C:\WINDOWS\system32\drivers\down\89895171.exe
C:\WINDOWS\system32\drivers\down\89899687.exe
C:\WINDOWS\system32\drivers\down\89902031.exe
C:\WINDOWS\system32\drivers\down\89902906.exe
C:\WINDOWS\system32\drivers\down\89908671.exe
C:\WINDOWS\system32\drivers\down\89910906.exe
C:\WINDOWS\system32\drivers\down\89959328.exe
C:\WINDOWS\system32\drivers\down\90468.exe
C:\WINDOWS\system32\drivers\down\908203.exe
C:\WINDOWS\system32\drivers\down\910656.exe
C:\WINDOWS\system32\drivers\down\914687.exe
C:\WINDOWS\system32\drivers\down\93218.exe
C:\WINDOWS\system32\drivers\down\95171.exe
C:\WINDOWS\system32\drivers\down\96031.exe
C:\WINDOWS\system32\drivers\down\976927859.exe
C:\WINDOWS\system32\drivers\down\976980468.exe
C:\WINDOWS\system32\drivers\down\976993265.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
K:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.
2008-03-05 04:24 . 2008-03-05 09:01 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-03-05 04:12 . 2005-01-13 21:41 11,254 --a------ C:\WINDOWS\system32\locate.com
2008-03-05 04:11 . 2008-03-05 04:17 <DIR> d-------- C:\MGtools
2008-03-05 04:11 . 2008-03-05 04:17 101,748 --a------ C:\MGlogs.zip
2008-03-04 15:43 . 2008-03-04 15:43 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-03-04 14:15 . 2008-03-04 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-04 14:14 . 2008-03-04 14:14 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-04 14:14 . 2008-03-04 14:14 <DIR> d-------- C:\Documents and Settings\Greta\Application Data\SUPERAntiSpyware.com
2008-03-04 14:13 . 2008-03-04 14:13 1,238,736 --a------ C:\MGtools.exe
2008-03-04 14:11 . 2008-03-04 14:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-04 14:11 . 2008-03-04 14:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-04 14:08 . 2008-03-05 22:06 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-04 14:08 . 2008-03-04 14:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-03 23:06 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-03 23:04 . 2008-03-03 23:05 7,237,978 --a------ C:\Temp\Free3GPVideoConverter.exe
2008-03-03 22:54 . 2008-03-03 22:54 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-03 17:03 . 2008-03-03 23:28 <DIR> d-------- C:\Program Files\INAC
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-03 10:13 . 2008-03-03 10:13 <DIR> d-------- C:\websymbols
2008-03-03 10:10 . 2008-03-03 10:13 <DIR> d-------- C:\Program Files\Debugging Tools for Windows
2008-03-03 10:06 . 2008-03-03 10:06 <DIR> d-------- C:\Program Files\Citrix
2008-03-03 10:01 . 2008-03-03 10:01 60,968 --a------ C:\Documents and Settings\Greta\GoToAssistDownloadHelper.exe
2008-02-27 02:20 . 2008-02-27 02:20 <DIR> d-------- C:\Program Files\Native Instruments
2008-02-27 02:20 . 2006-05-19 16:54 393,216 --a------ C:\WINDOWS\system32\NI_IRC_1_1.dll
2008-02-27 02:20 . 2005-04-04 18:00 393,216 --a------ C:\WINDOWS\system32\NI_IRC_1_0_3.dll
2008-02-27 02:20 . 2006-07-11 16:16 61,440 --a------ C:\WINDOWS\system32\NI_DFD_1_4.dll
2008-02-27 02:19 . 2008-02-27 02:22 <DIR> d-------- C:\Program Files\Finale GPO 2.0
2008-02-27 02:19 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-02-27 02:17 . 2008-02-27 02:35 <DIR> d-------- C:\Program Files\Finale 2007
2008-02-10 16:32 . 2008-02-10 16:32 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-02-09 14:18 . 2008-02-09 14:22 <DIR> d-------- C:\Program Files\SecondLifeReleaseCandidate
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 03:44 --------- d-----w C:\Program Files\Yahoo!
2008-03-06 03:28 --------- d-----w C:\Program Files\Soulseek
2008-03-05 00:15 --------- d-----w C:\Program Files\iTunes
2008-03-04 20:13 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-04 05:06 --------- d-----w C:\Program Files\Java
2008-03-04 04:27 --------- d-----w C:\Program Files\WildTangent
2008-03-04 04:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-03 06:29 --------- d-----w C:\Documents and Settings\Greta\Application Data\foobar2000
2008-03-01 07:29 --------- d-----w C:\Program Files\Trend Micro
2008-02-29 23:07 --------- d-----w C:\Program Files\eMule
2008-02-28 08:26 164,280 ----a-w C:\Documents and Settings\Greta\Application Data\GDIPFONTCACHEV1.DAT
2008-02-27 08:16 --------- d-----w C:\Program Files\BitComet
2008-02-10 07:10 --------- d-----w C:\Program Files\myFairTunes
2008-02-09 04:25 --------- d-----w C:\Program Files\Solveig Multimedia
2008-02-09 04:25 --------- d-----w C:\Program Files\Common Files\Solveig Multimedia
2008-02-09 04:25 --------- d-----w C:\Program Files\Common Files\Elecard
2008-02-04 03:39 --------- d-----w C:\Program Files\Creative
2008-02-04 03:19 --------- d-----w C:\Program Files\Macromedia
2008-02-04 03:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 03:17 --------- d-----w C:\Program Files\ListMaker
2008-02-04 03:17 --------- d-----w C:\Program Files\eMusic Download Manager
2008-02-04 00:32 --------- d-----w C:\Program Files\NCH Swift Sound
2008-02-04 00:06 --------- d-----w C:\Program Files\SecondLife
2008-02-04 00:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-02-03 23:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-03 23:52 --------- d-----w C:\Program Files\QuickPar
2008-02-03 23:52 --------- d-----w C:\Program Files\NetWaiting
2008-02-03 23:52 --------- d-----w C:\Program Files\Modem Helper
2008-02-03 23:52 --------- d-----w C:\Program Files\GemMaster
2008-02-03 23:52 --------- d-----w C:\Program Files\FLAC
2008-02-03 23:52 --------- d-----w C:\Program Files\ESPNMotion
2008-02-03 23:52 --------- d-----w C:\Program Files\EnglishOtto
2008-02-03 23:52 --------- d-----w C:\Program Files\DivX
2008-02-03 23:52 --------- d-----w C:\Program Files\ClocX
2008-02-03 23:52 --------- d-----w C:\Program Files\AoA Audio Extractor
2008-01-30 12:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-22 02:30 --------- d-----w C:\Program Files\WinSCP
2008-01-21 05:30 --------- d-----w C:\Program Files\iPod
2008-01-21 05:20 --------- d-----w C:\Program Files\QuickTime
2008-01-21 05:20 --------- d-----w C:\Program Files\MediaMonkey
2008-01-20 07:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-19 18:41 --------- d-----w C:\Program Files\CUE Splitter
2008-01-17 08:41 --------- d-----w C:\Documents and Settings\Greta\Application Data\Apple Computer
2008-01-16 04:50 --------- d-----w C:\Documents and Settings\Greta\Application Data\AccurateRip
2008-01-12 19:31 --------- d-----w C:\Program Files\Audible
2008-01-12 19:23 --------- d-----w C:\Documents and Settings\Greta\Application Data\Creative
2008-01-12 05:42 --------- d--h--w C:\Program Files\Creative Installation Information
2008-01-12 05:42 --------- d-----w C:\Program Files\Common Files\Creative
2008-01-10 01:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-10 01:08 --------- d-----w C:\Program Files\AIM6
2008-01-09 21:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2008-01-06 18:59 --------- d-----w C:\Program Files\Last.fm
2007-11-26 08:53 604 ---ha-w C:\Program Files\STLL Notifier
2004-08-10 11:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-10 11:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2007-04-04 06:32 1,264 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2004-08-10 11:00 1,028,096 --sh--w C:\WINDOWS\system32\mfc42.dll
2004-08-10 11:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-10 11:00 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2004-08-10 11:00 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-10 11:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.