Cid Highwind
2008-08-30, 16:33
I partially removed that "Antivirus XP 2008" Malware using Spybot S&D and Malwarebytes' Anti-Malware. Spybot didn't seem that successful in trying to remove it, it kept saying it got rid of the problems while it didn't.
Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:28:54 PM, on 8/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bexstefw.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cfghlpstr] C:\WINDOWS\system32\bexstefw.exe
O4 - HKCU\..\Run: [uicomapl] C:\WINDOWS\system32\fkbqzwzk.exe
O4 - HKCU\..\Run: [apichkmon] C:\WINDOWS\system32\vwzgtuhy.exe
O4 - HKCU\..\Run: [admmsg] C:\WINDOWS\system32\knwrynav.exe
O4 - HKLM\..\Policies\Explorer\Run: [dc7vryB54f] C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4812 bytes
And here is my Combofix Log:
ComboFix 08-08-29.02 - Hierophant Driud 2008-08-30 15:21:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3210 [GMT 2:00]
Running from: C:\Documents and Settings\Hierophant Driud\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-30 15:17 . 2008-08-30 15:17 86,016 --a------ C:\WINDOWS\system32\knwrynav.exe
2008-08-30 14:43 . 2008-08-30 14:43 86,016 --a------ C:\WINDOWS\system32\vwzgtuhy.exe
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-17 15:04 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-30 14:39 . 2008-08-17 15:04 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-30 14:22 . 2008-08-30 14:22 86,016 --a------ C:\WINDOWS\system32\fkbqzwzk.exe
2008-08-30 13:59 . 2008-08-30 13:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-30 13:59 . 2008-08-30 14:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 13:52 . 2008-08-30 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zevkxwds
2008-08-30 13:52 . 2008-08-30 13:52 86,016 --a------ C:\WINDOWS\system32\bexstefw.exe
2008-08-30 13:50 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-08-30 13:48 . 2008-08-30 13:55 <DIR> d-------- C:\Program Files\BitComet
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\vlc
2008-08-29 23:33 . 2008-08-30 14:20 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Contacts
2008-08-29 23:21 . 2008-08-29 23:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d-------- C:\Program Files\Windows Live
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-29 23:20 . 2008-08-29 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-29 22:12 . 2008-08-29 22:12 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Media Player Classic
2008-08-29 22:05 . 2008-08-29 22:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-08-29 22:05 . 2008-08-29 22:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-08-29 22:05 . 2008-08-29 22:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-08-29 20:39 . 2008-04-14 01:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-29 20:31 . 2008-08-29 20:31 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\InstallShield
2008-08-29 20:31 . 2006-11-07 12:28 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-08-29 20:31 . 2006-06-07 16:19 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-08-29 20:31 . 2006-10-19 07:06 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-08-29 20:31 . 2006-06-01 12:02 1,864 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-08-29 20:31 . 2006-10-05 10:37 1,428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\WINDOWS\nview
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-29 20:22 . 2008-05-16 09:18 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-08-29 20:22 . 2008-05-16 11:31 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-29 20:22 . 2008-08-30 15:16 186,097 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-29 20:22 . 2008-05-16 11:31 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-29 20:20 . 2008-08-29 20:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-29 20:12 . 2008-08-30 14:41 <DIR> d-------- C:\Documents and Settings\Hierophant Driud
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-08-29 20:05 . 2008-08-30 15:19 <DIR> d--hs---- C:\Documents and Settings\NetworkService
2008-08-29 20:05 . 2008-08-29 20:05 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-08-29 20:01 . 2008-08-29 20:01 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-08-29 20:01 . 2008-08-29 20:01 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-08-29 20:01 . 2008-08-29 20:01 0 --a------ C:\WINDOWS\control.ini
2008-08-29 20:00 . 2008-08-30 13:45 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-18 10:57 . 2008-08-18 10:57 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 10:49 . 2008-08-18 10:49 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 10:48 . 2008-08-18 10:48 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2008-07-12 21:24 . 2008-07-12 21:24 2,603,008 --a------ C:\WINDOWS\system32\wpdshext.dll
2008-07-12 21:20 . 2008-07-12 21:20 1,614,848 --a------ C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 21:09 . 2008-07-12 21:09 1,288,192 --a------ C:\WINDOWS\system32\quartz.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 19:56 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-29 19:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 19:56 --------- d-----w C:\Program Files\Realtek
2008-08-29 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-08-29 19:44 --------- d-----w C:\Program Files\Last.fm
2008-08-29 19:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-29 19:34 --------- d-----w C:\Documents and Settings\Hierophant Driud\Application Data\Winamp
2008-08-29 19:33 --------- d-----w C:\Program Files\Winamp
2008-08-29 19:30 --------- d-----w C:\Program Files\CCleaner
2008-08-29 19:28 --------- d-----w C:\Program Files\IZArc
2008-08-29 19:17 --------- d-----w C:\Program Files\ESET
2008-08-29 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-29 17:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-12 14:10 4,751,360 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-06 13:51 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-31 13:05 16,806,912 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-07-29 13:42 528,384 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:19 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\ALCWZRD.EXE
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.EXE
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\ALCMTR.EXE
2008-06-18 16:01 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"cfghlpstr"="C:\WINDOWS\system32\bexstefw.exe" [2008-08-30 13:52 86016]
"uicomapl"="C:\WINDOWS\system32\fkbqzwzk.exe" [2008-08-30 14:22 86016]
"apichkmon"="C:\WINDOWS\system32\vwzgtuhy.exe" [2008-08-30 14:43 86016]
"admmsg"="C:\WINDOWS\system32\knwrynav.exe" [2008-08-30 15:17 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 10:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 11:31 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 11:31 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 10:53 1447168]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 01:02 36352]
"nwiz"="nwiz.exe" [2008-05-16 11:31 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 15:05 16806912 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"dc7vryB54f"="C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe" [2008-08-30 13:52 69632]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14376:TCP"= 14376:TCP:BitComet 14376 TCP
"14376:UDP"= 14376:UDP:BitComet 14376 UDP
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-08-18 10:57]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Hierophant Driud\Application Data\Mozilla\Firefox\Profiles\qfim5rjr.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-30 15:21:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-30 15:22:17
ComboFix-quarantined-files.txt 2008-08-30 13:22:15
ComboFix2.txt 2008-08-30 13:19:35
Pre-Run: 49,871,171,584 bytes free
Post-Run: 49,860,231,168 bytes free
171
Sorry for the double post, but I didn't see an edit button, which made it hard not to double post for an edit.
I just would like to add that from the Antivirus 2008 almost every annoying thing is gone, except that Firewall warning that pops up every 5-10 minutes saying I am being attacked by something, and then an option to Enable it.
Apart from that Spybot S&D still keeps finding the popular Smitfraud-C.
Sorry for not properly introducing myself as well, and saying hi, this malware is just really annoying, I saw a lot of people that share my problem but according to the Introduction FAQs that I read it said that the solution the Mods post are almost always the solution for that specific person with his specific pc stats. So that's why I decided to post this topic.
New information: All files keep returning, and when Windows keeps starting up my Nod32 keeps saying it blocked and deleted a certain Trojan, but it keeps doing it whenever I restart so i'm quite confused with all this.
Thanks
-------------------------------------
Do NOT run 'FIXES' before helpers have analyzed HJT log (http://forums.spybot.info/showthread.php?t=16806 )
Cid Highwind
2008-09-01, 19:56
ComboFix 08-08-31.01 - Hierophant Driud 2008-09-01 18:44:04.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3107 [GMT 2:00]
Running from: C:\Documents and Settings\Hierophant Driud\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\blphclmmj0e9fe.scr
C:\WINDOWS\system32\lphclmmj0e9fe.exe
.
---- Previous Run -------
.
C:\WINDOWS\system32\blphclmmj0e9fe.scr
C:\WINDOWS\system32\lphclmmj0e9fe.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.
2008-09-01 18:40 . 2008-09-01 18:40 94,208 --a------ C:\WINDOWS\system32\yhwnsjgj.exe
2008-09-01 11:46 . 2008-09-01 11:46 94,208 --a------ C:\WINDOWS\system32\xmhklahk.exe
2008-09-01 00:40 . 2008-09-01 00:40 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Apple Computer
2008-09-01 00:40 . 2008-09-01 00:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-01 00:37 . 2008-09-01 18:31 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-01 00:37 . 2008-09-01 00:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-01 00:14 . 2008-09-01 08:07 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-08-31 19:20 . 2008-08-31 19:20 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-08-31 19:12 . 2008-08-31 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-08-31 19:11 . 2008-08-31 19:14 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-08-31 19:11 . 2008-08-31 19:14 <DIR> d-------- C:\Program Files\Autodesk
2008-08-31 19:07 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-08-31 19:07 . 2008-09-01 00:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-31 19:07 . 2008-08-31 19:07 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-31 19:04 . 2008-08-31 19:04 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Nero
2008-08-31 19:01 . 2008-08-31 19:01 <DIR> d-------- C:\Program Files\Nero
2008-08-31 19:01 . 2008-08-31 19:03 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-08-31 19:01 . 2008-08-31 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-08-31 18:53 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-08-31 18:52 . 2008-08-31 18:52 <DIR> d-------- C:\Program Files\MSBuild
2008-08-31 18:52 . 2008-08-31 18:52 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-31 18:48 . 2008-08-31 18:48 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-31 18:48 . 2008-08-31 18:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-31 18:47 . 2008-08-31 18:47 <DIR> dr-h----- C:\MSOCache
2008-08-31 18:47 . 2008-08-31 18:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-31 18:46 . 2008-08-31 18:46 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-08-31 18:46 . 2008-08-31 18:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-08-31 18:45 . 2008-08-31 18:45 <DIR> d-------- C:\Program Files\Macromedia
2008-08-31 18:42 . 2008-08-31 18:42 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-08-31 18:40 . 2008-08-31 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-08-31 18:27 . 2008-09-01 00:38 <DIR> d-------- C:\Program Files\QuickTime
2008-08-31 18:21 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-08-31 18:21 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-08-31 18:15 . 2008-08-31 18:15 <DIR> d-------- C:\Program Files\Bonjour
2008-08-31 18:11 . 2008-08-31 18:11 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-31 18:03 . 2008-08-31 18:03 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-08-31 17:16 . 2008-08-31 17:16 90,112 --a------ C:\WINDOWS\system32\jqrwbshg.exe
2008-08-31 12:52 . 2008-08-31 21:57 <DIR> d-------- C:\Program Files\Steam
2008-08-30 19:27 . 2008-08-30 19:27 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\DAEMON Tools
2008-08-30 19:27 . 2008-08-30 19:27 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-08-30 19:15 . 2008-08-31 18:08 <DIR> d-------- C:\Downloads
2008-08-30 19:08 . 2008-08-31 19:20 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-30 17:16 . 2008-08-30 17:16 81,920 --a------ C:\WINDOWS\system32\laxcnqje.exe
2008-08-30 15:45 . 2008-08-30 15:45 <DIR> d-------- C:\Program Files\Java
2008-08-30 15:45 . 2008-08-30 15:45 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-08-30 15:45 . 2008-08-30 15:45 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-30 15:28 . 2008-08-30 15:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-30 15:17 . 2008-08-30 15:17 86,016 --a------ C:\WINDOWS\system32\knwrynav.exe
2008-08-30 14:43 . 2008-08-30 14:43 86,016 --a------ C:\WINDOWS\system32\vwzgtuhy.exe
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-17 15:04 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-30 14:39 . 2008-08-17 15:04 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-30 14:22 . 2008-08-30 14:22 86,016 --a------ C:\WINDOWS\system32\fkbqzwzk.exe
2008-08-30 13:59 . 2008-08-31 23:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-30 13:59 . 2008-08-31 23:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 13:52 . 2008-08-30 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zevkxwds
2008-08-30 13:52 . 2008-08-30 13:52 86,016 --a------ C:\WINDOWS\system32\bexstefw.exe
2008-08-30 13:50 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\vlc
2008-08-29 23:33 . 2008-08-30 14:20 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Contacts
2008-08-29 23:21 . 2008-08-29 23:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d-------- C:\Program Files\Windows Live
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-29 23:20 . 2008-08-29 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-29 22:12 . 2008-08-29 22:12 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Media Player Classic
2008-08-29 22:05 . 2008-08-29 22:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-08-29 22:05 . 2008-08-29 22:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-08-29 22:05 . 2008-08-29 22:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-08-29 20:39 . 2008-04-14 01:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-29 20:31 . 2008-08-29 20:31 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\InstallShield
2008-08-29 20:31 . 2006-11-07 12:28 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-08-29 20:31 . 2006-06-07 16:19 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-08-29 20:31 . 2006-10-19 07:06 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-08-29 20:31 . 2006-06-01 12:02 1,864 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-08-29 20:31 . 2006-10-05 10:37 1,428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\WINDOWS\nview
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-29 20:22 . 2008-05-16 09:18 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-08-29 20:22 . 2008-05-16 11:31 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-29 20:22 . 2008-09-01 18:47 186,097 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-29 20:22 . 2008-05-16 11:31 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-29 20:20 . 2008-08-29 20:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-29 20:12 . 2008-09-01 00:26 <DIR> d-------- C:\Documents and Settings\Hierophant Driud
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-08-29 20:05 . 2008-09-01 14:42 <DIR> d--hs---- C:\Documents and Settings\NetworkService
2008-08-29 20:05 . 2008-08-29 20:05 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-08-29 20:01 . 2008-08-29 20:01 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-08-29 20:01 . 2008-08-29 20:01 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-08-29 20:01 . 2008-08-29 20:01 0 --a------ C:\WINDOWS\control.ini
2008-08-29 20:00 . 2008-08-30 13:45 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-18 10:57 . 2008-08-18 10:57 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 10:49 . 2008-08-18 10:49 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 10:48 . 2008-08-18 10:48 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-31 16:59 --------- d-----w C:\Documents and Settings\Hierophant Driud\Application Data\Winamp
2008-08-31 16:14 --------- d-----w C:\Program Files\Winamp
2008-08-29 19:56 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-29 19:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 19:56 --------- d-----w C:\Program Files\Realtek
2008-08-29 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-08-29 19:44 --------- d-----w C:\Program Files\Last.fm
2008-08-29 19:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-29 19:30 --------- d-----w C:\Program Files\CCleaner
2008-08-29 19:28 --------- d-----w C:\Program Files\IZArc
2008-08-29 19:17 --------- d-----w C:\Program Files\ESET
2008-08-29 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-29 17:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-12 14:10 4,751,360 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-06 13:51 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-31 13:05 16,806,912 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-07-29 13:42 528,384 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:20 1,614,848 ----a-w C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\ALCWZRD.EXE
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.EXE
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\ALCMTR.EXE
2008-06-18 16:01 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-08-30_15.19.23.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-31 17:10:41 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-08-31 17:10:47 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-08-31 17:10:48 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-08-31 17:10:48 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-08-31 17:10:46 2,878,976 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2008-08-31 17:10:39 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-08-31 17:10:39 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2008-08-31 17:10:51 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2008-08-31 17:10:43 5,025,792 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-08-31 17:10:41 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-08-31 17:10:38 503,808 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2008-08-31 17:10:39 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-08-31 17:10:46 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-08-31 17:10:47 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-08-31 17:10:47 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-08-31 17:10:40 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2008-08-31 17:10:40 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2008-08-31 17:10:40 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2008-08-31 17:10:40 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2008-08-31 17:10:39 745,472 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-08-31 17:10:52 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-08-31 17:10:52 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2008-08-31 17:10:37 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-08-31 17:10:51 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-08-31 17:10:53 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2008-08-31 17:10:38 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-08-31 17:10:38 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-08-31 17:10:38 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-08-31 17:10:49 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2008-08-31 17:10:42 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-08-31 17:10:50 389,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2008-08-31 17:10:48 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2008-08-31 17:10:39 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2008-08-31 17:10:46 5,050,368 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-08-31 17:10:42 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2008-08-31 17:10:42 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-08-31 17:10:42 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-08-31 17:10:50 700,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-08-31 17:10:49 368,640 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-08-31 17:10:50 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-08-31 17:10:49 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-08-31 17:10:49 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-08-31 17:10:41 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-08-31 17:10:43 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-08-31 17:10:51 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-08-31 17:10:44 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-08-31 17:10:44 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-08-31 17:10:45 5,320,704 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-08-31 17:10:45 2,035,712 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2008-08-31 17:10:50 3,018,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2008-08-31 18:32:16 26,624 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\b7c09cb78898a941a89b88249eb5ed40\Accessibility.ni.dll
+ 2008-08-31 18:32:18 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\4491d3e81c072640808854db59ec73f1\AspNetMMCExt.ni.dll
+ 2008-08-31 18:32:19 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\edf43234a86a9f4bbe69db9008d66474\CustomMarshalers.ni.dll
+ 2008-08-31 18:32:19 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\c509e76da3eb0e4980c7cb6c8b512975\dfsvc.ni.exe
+ 2008-08-31 18:32:21 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\19a6db2d80e31740b26bf30a4a49e6fb\Microsoft.Build.Engine.ni.dll
+ 2008-08-31 18:32:21 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\2bdaf28d10b0b048bf00deb5033be30b\Microsoft.Build.Framework.ni.dll
+ 2008-08-31 18:32:24 1,691,648 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\d65b90653a33a64aa7fe8a23a6a53ca0\Microsoft.Build.Tasks.ni.dll
+ 2008-08-31 18:32:24 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\1daed67be894a64eae15653e3d55f741\Microsoft.Build.Utilities.ni.dll
+ 2008-08-31 18:32:26 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9935258ef61e92458380499059b329a4\Microsoft.VisualBasic.ni.dll
+ 2008-08-31 17:09:14 11,411,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\a88ea1cfae9858458187c733dddd1fc2\mscorlib.ni.dll
+ 2008-08-31 18:32:28 962,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\67771a96ac2b9947a6eee6b6e107bd73\System.Configuration.ni.dll
+ 2008-08-31 17:09:51 6,688,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\d45d8fabcda7b149901d159d7df66a39\System.Data.ni.dll
+ 2008-08-31 18:32:29 1,712,128 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\c1325060928f814eb42ef74b54b44ae4\System.Deployment.ni.dll
+ 2008-08-31 17:11:38 10,723,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\78f2f461b7e186448f8c904d5938c942\System.Design.ni.dll
+ 2008-08-31 18:32:30 1,220,608 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\444ce86ca6e1954ab1612a75e3d45ffb\System.DirectoryServices.ni.dll
+ 2008-08-31 18:32:31 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\e20b47aa0c37e148a7a0b622ec67dad2\System.DirectoryServices.Protocols.ni.dll
+ 2008-08-31 17:11:42 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\34f8b68e94b94b4a93fbe85e6b317aff\System.Drawing.Design.ni.dll
+ 2008-08-31 17:09:27 1,626,112 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\ce3a48d26c079d46b2ad089460b77b3d\System.Drawing.ni.dll
+ 2008-08-31 18:32:32 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ea9e7062c6bec048a46bc316d77f84be\System.EnterpriseServices.ni.dll
+ 2008-08-31 18:32:32 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ea9e7062c6bec048a46bc316d77f84be\System.EnterpriseServices.Wrapper.dll
+ 2008-08-31 18:32:33 729,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\b6f6e953f248bd4a9e2db7442bab00fc\System.Security.ni.dll
+ 2008-08-31 18:32:34 684,032 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\721dba94e1c48f49aba184a3f573054c\System.Transactions.ni.dll
+ 2008-08-31 18:32:50 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\1e3e242472de6e40acf9c0e66ad63d19\System.Web.Mobile.ni.dll
+ 2008-08-31 18:32:51 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\bb94ca34817f424997a3b62468b512da\System.Web.RegularExpressions.ni.dll
+ 2008-08-31 18:32:53 1,945,600 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\0eeb7ea49fbf704cbd24a39ee3b3eefa\System.Web.Services.ni.dll
+ 2008-08-31 18:32:47 11,808,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\0468962716bab04fbccb08cecc95344d\System.Web.ni.dll
+ 2008-08-31 17:11:54 13,139,968 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\da1bba5cf0782e4ca1bb4a5fb9c5e48a\System.Windows.Forms.ni.dll
+ 2008-08-31 17:09:44 5,640,192 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\234cb60c8062174cb68683b53d6cc6e8\System.Xml.ni.dll
+ 2008-08-31 17:09:24 8,093,696 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\92ac362e84bb8a409b4adb78cef76979\System.ni.dll
+ 2008-08-31 10:52:37 27,648 ----a-r C:\WINDOWS\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
+ 2008-08-31 17:20:56 65,536 ----a-r C:\WINDOWS\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\ARPPRODUCTICON.exe
+ 2008-08-31 17:20:56 65,536 ----a-r C:\WINDOWS\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\AuditionCommonShortc_01CEC7E570FD4D068FADBF21DF0CC6DC.exe
+ 2008-08-31 17:20:56 65,536 ----a-r C:\WINDOWS\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut1_E3A4979EE8C048379F3D271B50BA9E7C_1.exe
+ 2008-08-31 17:20:56 65,536 ----a-r C:\WINDOWS\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut2_E3A4979EE8C048379F3D271B50BA9E7C_1.exe
+ 2008-08-31 17:20:56 65,536 ----a-r C:\WINDOWS\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut3_E3A4979EE8C048379F3D271B50BA9E7C.exe
+ 2008-08-31 22:40:31 27,136 ----a-r C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2008-08-31 16:21:49 65,536 ----a-r C:\WINDOWS\Installer\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}\ARPPRODUCTICON.exe
+ 2008-08-31 16:53:16 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-08-31 16:53:16 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-08-31 16:53:16 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-08-31 16:53:16 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-08-31 16:53:16 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-31 16:53:17 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-08-31 16:53:17 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-31 16:53:16 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-08-31 16:53:16 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-08-31 16:53:16 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-08-31 16:53:17 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-08-31 16:53:16 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-08-31 16:47:52 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-08-31 17:11:32 21,630 ----a-r C:\WINDOWS\Installer\{9A346205-EA92-4406-B1AB-50379DA3F057}\ARPPRODUCTICON.exe
+ 2008-08-31 17:11:32 21,630 ----a-r C:\WINDOWS\Installer\{9A346205-EA92-4406-B1AB-50379DA3F057}\NewShortcut1_9A346205EA924406B1AB50379DA3F057_1.exe
+ 2008-08-31 17:11:32 21,630 ----a-r C:\WINDOWS\Installer\{9A346205-EA92-4406-B1AB-50379DA3F057}\NewShortcut3_9A346205EA924406B1AB50379DA3F057.exe
+ 2008-08-31 17:07:01 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
+ 2008-08-31 17:07:02 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_3D.exe
+ 2008-08-31 17:07:02 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_Standard.exe
+ 2008-08-31 17:07:02 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Distiller.exe
+ 2008-08-31 17:07:02 7,278 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_ELEMENTS_DT.exe
+ 2008-08-31 17:07:01 23,558 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
+ 2008-08-31 17:03:45 25,214 ----a-r C:\WINDOWS\Installer\{B944FA21-81AF-4A77-8328-CE4F4CC51033}\ARPPRODUCTICON.exe
+ 2008-08-31 16:21:38 65,536 ----a-r C:\WINDOWS\Installer\{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}\ARPPRODUCTICON.exe
+ 2005-09-23 05:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_iehost.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2005-09-23 05:29:04 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.data.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_VsaVb7rt.dll
+ 2005-09-23 05:29:04 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2005-09-23 05:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
+ 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll
+ 2005-09-23 05:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2005-09-23 05:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2005-09-23 05:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2005-09-23 05:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2005-09-23 05:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2005-09-23 05:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2005-09-23 05:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2005-09-23 05:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2005-09-23 05:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2005-09-23 05:28:58 55,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2005-09-23 05:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2005-09-23 05:28:32 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2005-09-23 05:28:32 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2005-09-23 05:28:32 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2005-09-23 05:28:32 70,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2005-09-23 05:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2005-09-23 05:28:32 26,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2005-09-23 05:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2005-09-23 05:28:32 29,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2005-09-23 05:28:32 29,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2005-09-23 05:28:32 503,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2005-09-23 05:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2005-09-23 05:28:56 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2005-09-23 05:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2005-09-23 05:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2005-09-23 05:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2005-09-23 05:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2005-09-23 05:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2005-09-23 05:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2005-09-23 05:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2005-09-23 05:28:38 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2005-09-23 05:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2005-09-23 05:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2005-09-23 05:28:56 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2005-09-23 05:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2005-09-23 05:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2005-09-23 05:28:56 224,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2005-09-23 05:28:56 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2005-09-23 05:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2005-09-23 05:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2005-09-23 05:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2005-09-23 05:01:16 609,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
+ 2005-09-23 04:29:48 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll
+ 2005-09-23 04:32:24 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll
+ 2005-09-23 04:34:10 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll
+ 2005-09-23 04:34:12 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll
+ 2005-09-23 04:34:44 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll
+ 2005-09-23 04:36:24 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll
+ 2005-09-23 01:46:14 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll
+ 2005-09-23 04:38:26 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll
+ 2005-09-23 04:38:52 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll
+ 2005-09-23 04:40:30 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll
+ 2005-09-23 04:40:32 83,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll
+ 2005-09-23 04:40:56 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll
+ 2005-09-23 04:42:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll
+ 2005-09-23 04:44:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll
+ 2005-09-23 04:46:38 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll
+ 2005-09-23 04:46:38 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll
+ 2005-09-23 04:46:40 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll
+ 2005-09-23 04:47:04 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll
+ 2005-09-23 04:47:30 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll
+ 2005-09-23 04:47:32 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll
+ 2005-09-23 04:47:32 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll
+ 2005-09-23 04:30:18 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll
+ 2005-09-23 04:47:06 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll
+ 2005-09-23 04:29:50 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll
+ 2005-09-23 04:36:48 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll
+ 2005-09-23 05:57:06 245,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll
+ 2005-09-23 05:28:48 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2005-09-23 05:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2005-09-23 05:28:48 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2005-09-23 05:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2005-09-23 05:28:48 745,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2005-09-23 05:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2005-09-23 05:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2005-09-23 05:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2005-09-23 05:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2005-09-23 05:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2005-09-23 05:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2005-09-23 05:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2005-09-23 05:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2005-09-23 05:28:32 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2005-09-23 05:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2005-09-23 05:28:56 800,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2005-09-23 05:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2005-09-23 05:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2005-09-23 05:28:56 326,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2005-09-23 05:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2005-09-23 05:28:56 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2005-09-23 05:28:56 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2005-09-23 05:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2005-09-23 05:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2005-09-23 05:28:56 226,816 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2005-09-23 05:28:56 66,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2005-09-23 05:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2005-09-23 05:28:50 5,615,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2005-09-23 05:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2005-09-23 05:28:56 96,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2005-09-23 05:28:56 14,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2005-09-23 05:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2005-09-23 05:28:50 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2005-09-23 05:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2005-09-23 05:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2005-09-23 05:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2005-09-23 05:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2005-09-23 05:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2005-09-23 05:28:56 377,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2005-09-23 05:28:56 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
+ 2005-09-23 05:28:58 389,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2005-09-23 05:28:56 2,878,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2005-09-23 05:28:56 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2005-09-23 05:28:56 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2005-09-23 05:28:38 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2005-09-23 05:28:56 5,050,368 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2005-09-23 05:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2005-09-23 05:28:56 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2005-09-23 05:28:56 3,018,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2005-09-23 05:28:56 700,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2005-09-23 05:28:56 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2005-09-23 05:28:56 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2005-09-23 05:28:56 368,640 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2005-09-23 05:28:56 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2005-09-23 05:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2005-09-23 05:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2005-09-23 05:28:56 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2005-09-23 05:28:56 5,025,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2005-09-23 05:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2005-09-23 05:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2005-09-23 05:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2006-08-19 02:25:08 5,320,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2005-09-23 05:28:56 2,035,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2005-09-23 05:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2005-09-23 05:29:06 1,140,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2005-09-23 05:28:30 1,306,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2005-09-23 05:28:32 298,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2005-09-23 05:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
- 2008-08-29 18:01:13 86,327 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
+ 2008-08-30 19:14:57 86,327 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
- 2008-08-29 18:01:16 2,112 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2008-08-30 19:14:57 2,850 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2006-09-29 04:56:38 28,248 ----a-r C:\WINDOWS\system32\AdobePDF.dll
+ 2003-10-17 10:44:08 89,088 ----a-r C:\WINDOWS\system32\atl71.dll
+ 2005-12-05 16:09:18 2,323,664 ----a-w C:\WINDOWS\system32\d3dx9_28.dll
+ 2006-03-31 10:40:58 2,388,176 ----a-w C:\WINDOWS\system32\d3dx9_30.dll
+ 2005-09-23 05:28:38 83,456 ----a-w C:\WINDOWS\system32\dfshim.dll
+ 2006-02-28 10:41:34 61,440 ----a-w C:\WINDOWS\system32\dns-sd.exe
+ 2006-02-28 10:41:22 53,248 ----a-w C:\WINDOWS\system32\dnssd.dll
+ 2007-09-24 07:05:58 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
+ 2007-09-24 07:05:58 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
+ 2006-10-26 12:10:08 1,190,688 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2006-10-26 12:10:06 33,088 ----a-w C:\WINDOWS\system32\FM20ENU.DLL
- 2008-08-29 18:05:15 95,864 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-31 21:45:56 1,592,656 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2006-03-17 10:45:52 1,757,184 ----a-w C:\WINDOWS\system32\imagX7.dll
+ 2006-03-17 10:45:54 497,296 ----a-w C:\WINDOWS\system32\imagXpr7.dll
+ 2006-03-17 10:45:54 258,048 ----a-w C:\WINDOWS\system32\imagXR7.dll
+ 2006-03-17 10:45:54 802,816 ----a-w C:\WINDOWS\system32\imagXRA7.dll
+ 2006-10-26 11:45:04 207,360 ----a-w C:\WINDOWS\system32\INKED.DLL
+ 2008-08-30 13:45:07 139,264 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-08-30 13:45:07 139,264 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-08-30 13:45:07 143,360 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-02-20 13:34:06 190,696 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe
- 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2007-02-20 14:04:02 2,463,976 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-02-20 14:04:04 190,696 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2003-10-17 10:44:08 1,060,864 ----a-r C:\WINDOWS\system32\mfc71.dll
+ 2004-02-20 14:15:42 40,960 ----a-r C:\WINDOWS\system32\MFC71CHS.DLL
+ 2004-02-20 14:15:42 45,056 ----a-r C:\WINDOWS\system32\MFC71CHT.DLL
+ 2004-02-20 14:15:42 65,536 ----a-r C:\WINDOWS\system32\MFC71DEU.DLL
+ 2003-10-17 10:44:08 57,344 ----a-r C:\WINDOWS\system32\MFC71ENU.DLL
+ 2004-02-20 14:15:42 61,440 ----a-r C:\WINDOWS\system32\MFC71ESP.DLL
+ 2004-02-20 14:15:42 61,440 ----a-r C:\WINDOWS\system32\MFC71FRA.DLL
+ 2004-02-20 14:15:42 61,440 ----a-r C:\WINDOWS\system32\MFC71ITA.DLL
+ 2004-02-20 14:15:42 49,152 ----a-r C:\WINDOWS\system32\MFC71JPN.DLL
+ 2004-02-20 14:15:42 49,152 ----a-r C:\WINDOWS\system32\MFC71KOR.DLL
+ 2004-02-20 14:47:26 1,047,552 ----a-r C:\WINDOWS\system32\mfc71u.dll
+ 2005-09-23 05:28:52 270,848 ----a-w C:\WINDOWS\system32\mscoree.dll
+ 2005-09-23 05:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll
+ 2005-09-23 05:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll
+ 2007-03-12 12:02:26 947,472 ----a-w C:\WINDOWS\system32\msjava.dll
+ 2006-07-24 08:50:38 125,744 ----a-w C:\WINDOWS\system32\MSSTDFMT.DLL
+ 2003-10-17 10:44:08 499,712 ----a-r C:\WINDOWS\system32\msvcp71.dll
+ 2003-04-18 14:46:22 1,233,920 ----a-w C:\WINDOWS\system32\msxml4.dll
+ 2003-04-18 14:29:26 82,432 ----a-w C:\WINDOWS\system32\msxml4r.dll
+ 2005-09-23 05:29:00 6,144 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll
+ 2007-09-20 07:55:18 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
+ 2005-09-23 05:28:56 32,768 ----a-w C:\WINDOWS\system32\netfxperf.dll
- 2008-08-29 20:06:52 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-31 17:11:01 58,596 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-29 20:06:52 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-31 17:11:01 392,296 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2006-07-24 08:50:40 39,728 ----a-w C:\WINDOWS\system32\SCP32.DLL
+ 2007-05-10 21:13:07 24,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\ADREGP.DLL
+ 2007-05-10 21:13:22 190,072 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\ADUIGP.DLL
+ 2006-10-26 17:56:16 864,080 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 17:56:14 67,408 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2003-05-05 14:47:20 129,024 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\Ps5ui.dll
+ 2003-05-05 14:47:20 455,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL
+ 2007-05-10 21:13:07 24,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\AdReGP.dll
+ 2007-05-10 21:13:22 190,072 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\ADUIGP.dll
+ 2006-10-26 17:56:16 864,080 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 17:56:14 67,408 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\msonpui.dll
+ 2003-05-05 14:47:20 129,024 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\PS5UI.DLL
+ 2003-05-05 14:47:20 455,168 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\PSCRIPT5.DLL
+ 2006-10-26 17:56:12 33,104 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
+ 2007-03-21 18:54:16 77,312 ----a-w C:\WINDOWS\system32\TWAIN_32.DLL
+ 2006-03-17 13:49:46 368,640 ----a-w C:\WINDOWS\system32\TwnLib4.dll
+ 2007-03-21 18:54:16 48,560 ----a-w C:\WINDOWS\system32\TWUNK_16.EXE
+ 2007-03-21 18:54:16 69,632 ----a-w C:\WINDOWS\system32\TWUNK_32.EXE
+ 2006-07-24 08:50:40 47,920 ----a-w C:\WINDOWS\system32\VBAME.DLL
+ 2006-10-26 11:45:04 293,376 ----a-w C:\WINDOWS\system32\WISPTIS.EXE
+ 2008-09-01 16:47:18 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_4b4.dat
+ 2007-03-20 19:22:04 972,336 ----a-w C:\WINDOWS\UNNeroBackItUp.exe
+ 2007-09-20 07:55:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
+ 2007-02-28 14:41:02 972,336 ----a-w C:\WINDOWS\UNNeroShowTime.exe
+ 2007-03-21 19:02:12 972,336 ----a-w C:\WINDOWS\UNNeroVision.exe
+ 2007-09-20 07:59:24 972,072 ----a-w C:\WINDOWS\UNRecode.exe
+ 2008-08-31 16:55:55 1,233,920 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
+ 2008-08-31 16:55:54 82,432 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
+ 2006-10-26 11:40:34 95,744 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-12-01 20:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-10-26 11:40:36 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 11:40:36 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 11:40:36 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-12-01 20:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-06-05 13:47:40 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfc80.dll
+ 2006-06-05 13:47:48 1,080,320 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfc80u.dll
+ 2006-06-05 13:47:50 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfcm80.dll
+ 2006-06-05 13:47:50 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfcm80u.dll
+ 2006-10-26 11:40:36 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2006-10-26 11:40:36 1,079,808 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2006-10-26 11:40:36 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2006-10-26 11:40:36 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-12-01 22:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-01 22:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 22:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-01 22:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-06-05 13:28:32 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80CHS.dll
+ 2006-06-05 13:28:32 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80CHT.dll
+ 2006-06-05 13:28:32 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80DEU.dll
+ 2006-06-05 13:28:34 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ENU.dll
+ 2006-06-05 13:28:32 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ESP.dll
+ 2006-06-05 13:28:32 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80FRA.dll
+ 2006-06-05 13:28:32 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ITA.dll
+ 2006-06-05 13:28:32 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80JPN.dll
+ 2006-06-05 13:28:34 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80KOR.dll
+ 2006-10-26 11:40:36 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 11:40:36 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 11:40:36 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 11:40:36 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 11:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 11:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 11:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 11:40:36 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 11:40:36 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2006-12-01 22:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 22:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 22:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 22:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 22:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 22:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 22:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 22:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 22:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2005-09-22 23:35:10 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
+ 2006-12-01 22:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
+ 2008-08-31 17:10:39 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-08-31 17:10:39 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"cfghlpstr"="C:\WINDOWS\system32\bexstefw.exe" [2008-08-30 13:52 86016]
"uicomapl"="C:\WINDOWS\system32\fkbqzwzk.exe" [2008-08-30 14:22 86016]
"apichkmon"="C:\WINDOWS\system32\vwzgtuhy.exe" [2008-08-30 14:43 86016]
"admmsg"="C:\WINDOWS\system32\knwrynav.exe" [2008-08-30 15:17 86016]
"appsys"="C:\WINDOWS\system32\laxcnqje.exe" [2008-08-30 17:16 81920]
"smartsetact"="C:\WINDOWS\system32\jqrwbshg.exe" [2008-08-31 17:16 90112]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-08-08 14:11 490952]
"DscSysSet"="C:\WINDOWS\system32\xmhklahk.exe" [2008-09-01 11:46 94208]
"AdmApiEn"="C:\WINDOWS\system32\yhwnsjgj.exe" [2008-09-01 18:40 94208]
"cmdsrvsmart"="C:\WINDOWS\system32\rohkxibe.exe" [2008-09-01 18:48 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 10:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 11:31 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 11:31 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 10:53 1447168]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 01:02 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-08-30 15:45 144792]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"lphclmmj0e9fe"="C:\WINDOWS\system32\lphclmmj0e9fe.exe" [2008-09-01 18:48 203776]
"nwiz"="nwiz.exe" [2008-05-16 11:31 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 15:05 16806912 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"dc7vryB54f"="C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe" [2008-08-30 13:52 69632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
"NoDispScrSavPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
Cid Highwind
2008-09-02, 09:14
Combofix Log
ComboFix 08-09-01.01 - Hierophant Driud 2008-09-02 8:02:46.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3143 [GMT 2:00]
Running from: C:\Documents and Settings\Hierophant Driud\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Hierophant Driud\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\cvqtezin.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cvqtezin.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-02 to 2008-09-02 )))))))))))))))))))))))))))))))
.
2008-09-01 20:15 . 2008-09-01 20:15 <DIR> d-------- C:\WINDOWS\Sun
2008-09-01 20:00 . 2008-09-01 20:00 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-01 20:00 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-01 19:48 . 2008-09-01 19:50 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\.SunDownloadManager
2008-09-01 00:40 . 2008-09-01 00:40 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Apple Computer
2008-09-01 00:40 . 2008-09-01 00:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-01 00:37 . 2008-09-01 18:31 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-01 00:37 . 2008-09-01 00:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-01 00:14 . 2008-09-01 08:07 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-08-31 19:20 . 2008-08-31 19:20 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-08-31 19:12 . 2008-08-31 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-08-31 19:11 . 2008-08-31 19:14 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-08-31 19:11 . 2008-08-31 19:14 <DIR> d-------- C:\Program Files\Autodesk
2008-08-31 19:07 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-08-31 19:07 . 2008-09-01 00:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-31 19:07 . 2008-08-31 19:07 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-31 19:04 . 2008-08-31 19:04 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Nero
2008-08-31 19:01 . 2008-08-31 19:01 <DIR> d-------- C:\Program Files\Nero
2008-08-31 19:01 . 2008-08-31 19:03 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-08-31 19:01 . 2008-08-31 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-08-31 18:53 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-08-31 18:52 . 2008-08-31 18:52 <DIR> d-------- C:\Program Files\MSBuild
2008-08-31 18:52 . 2008-08-31 18:52 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-31 18:48 . 2008-08-31 18:48 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-31 18:48 . 2008-08-31 18:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-31 18:47 . 2008-08-31 18:47 <DIR> dr-h----- C:\MSOCache
2008-08-31 18:47 . 2008-08-31 18:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-31 18:46 . 2008-08-31 18:46 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-08-31 18:46 . 2008-08-31 18:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-08-31 18:45 . 2008-08-31 18:45 <DIR> d-------- C:\Program Files\Macromedia
2008-08-31 18:42 . 2008-08-31 18:42 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-08-31 18:40 . 2008-08-31 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-08-31 18:27 . 2008-09-01 00:38 <DIR> d-------- C:\Program Files\QuickTime
2008-08-31 18:21 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-08-31 18:21 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-08-31 18:15 . 2008-08-31 18:15 <DIR> d-------- C:\Program Files\Bonjour
2008-08-31 18:11 . 2008-08-31 18:11 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-31 18:03 . 2008-08-31 18:03 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-08-31 12:52 . 2008-08-31 21:57 <DIR> d-------- C:\Program Files\Steam
2008-08-30 19:27 . 2008-08-30 19:27 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\DAEMON Tools
2008-08-30 19:27 . 2008-08-30 19:27 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-08-30 19:15 . 2008-08-31 18:08 <DIR> d-------- C:\Downloads
2008-08-30 19:08 . 2008-08-31 19:20 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-30 15:45 . 2008-09-01 20:00 <DIR> d-------- C:\Program Files\Java
2008-08-30 15:45 . 2008-08-30 15:45 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-08-30 15:28 . 2008-08-30 15:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-17 15:04 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-30 14:39 . 2008-08-17 15:04 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-30 13:59 . 2008-08-31 23:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-30 13:59 . 2008-08-31 23:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 13:50 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\vlc
2008-08-29 23:33 . 2008-08-30 14:20 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Contacts
2008-08-29 23:21 . 2008-08-29 23:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d-------- C:\Program Files\Windows Live
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-29 23:20 . 2008-08-29 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-29 22:12 . 2008-08-29 22:12 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Media Player Classic
2008-08-29 22:05 . 2008-08-29 22:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-08-29 22:05 . 2008-08-29 22:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-08-29 22:05 . 2008-08-29 22:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-08-29 20:39 . 2008-04-14 01:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-29 20:31 . 2008-08-29 20:31 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\InstallShield
2008-08-29 20:31 . 2006-11-07 12:28 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-08-29 20:31 . 2006-06-07 16:19 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-08-29 20:31 . 2006-10-19 07:06 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-08-29 20:31 . 2006-06-01 12:02 1,864 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-08-29 20:31 . 2006-10-05 10:37 1,428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\WINDOWS\nview
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-29 20:22 . 2008-05-16 09:18 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-08-29 20:22 . 2008-05-16 11:31 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-29 20:22 . 2008-09-02 08:00 186,097 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-29 20:22 . 2008-05-16 11:31 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-29 20:20 . 2008-08-29 20:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-29 20:12 . 2008-09-01 19:48 <DIR> d-------- C:\Documents and Settings\Hierophant Driud
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-08-29 20:05 . 2008-09-01 14:42 <DIR> d--hs---- C:\Documents and Settings\NetworkService
2008-08-29 20:05 . 2008-08-29 20:05 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-08-29 20:01 . 2008-08-29 20:01 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-08-29 20:01 . 2008-08-29 20:01 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-08-29 20:01 . 2008-08-29 20:01 0 --a------ C:\WINDOWS\control.ini
2008-08-29 20:00 . 2008-08-30 13:45 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-18 10:57 . 2008-08-18 10:57 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 10:49 . 2008-08-18 10:49 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 10:48 . 2008-08-18 10:48 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-31 16:59 --------- d-----w C:\Documents and Settings\Hierophant Driud\Application Data\Winamp
2008-08-31 16:14 --------- d-----w C:\Program Files\Winamp
2008-08-29 19:56 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-29 19:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 19:56 --------- d-----w C:\Program Files\Realtek
2008-08-29 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-08-29 19:44 --------- d-----w C:\Program Files\Last.fm
2008-08-29 19:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-29 19:30 --------- d-----w C:\Program Files\CCleaner
2008-08-29 19:28 --------- d-----w C:\Program Files\IZArc
2008-08-29 19:17 --------- d-----w C:\Program Files\ESET
2008-08-29 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-29 17:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-12 14:10 4,751,360 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-06 13:51 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-31 13:05 16,806,912 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-07-29 13:42 528,384 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:20 1,614,848 ----a-w C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\ALCWZRD.EXE
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.EXE
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\ALCMTR.EXE
2008-06-18 16:01 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((( snapshot_2008-09-01_18.51.28.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-30 13:45:07 139,264 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-08-30 13:45:07 139,264 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2008-08-30 13:45:07 143,360 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-08-08 14:11 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 10:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 11:31 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 11:31 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 10:53 1447168]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 01:02 36352]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"nwiz"="nwiz.exe" [2008-05-16 11:31 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 15:05 16806912 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-08-18 10:57]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 08:05:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-02 8:05:52
ComboFix-quarantined-files.txt 2008-09-02 06:05:48
ComboFix2.txt 2008-09-01 18:14:06
ComboFix3.txt 2008-09-01 16:52:16
ComboFix4.txt 2008-08-30 13:22:17
ComboFix5.txt 2008-09-02 05:58:55
Pre-Run: 32,582,230,016 bytes free
Post-Run: 32,616,243,200 bytes free
232
Malware Log:
Malwarebytes' Anti-Malware 1.26
Database version: 1103
Windows 5.1.2600 Service Pack 3
9/2/2008 8:10:57 AM
mbam-log-2008-09-02 (08-10-57).txt
Scan type: Quick Scan
Objects scanned: 45085
Time elapsed: 1 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:11:31 AM, on 9/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9499 bytes