Results 1 to 10 of 20

Thread: Virtumonde and possibly more...

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Sep 2008
    Posts
    16

    Unhappy Virtumonde and possibly more...

    Hi
    So like the title of my thread says, I have Virtumonde and possibly other malware/adware etc. Spybot was able to get rid of the other issues except for of course Virtumonde and at least one other thing. Even after running VundoFix and ComboFix multiple times (as well as Spybot) in safe mode, and deleting the infected files I could find, I just can't seem to get rid of it... What might be worth mentioning is that twice Spybot ran and said there were no problems (once in safe mode and once after normal restart), but still I got pop-ups and my IE settings were changed.

    Anyway, here's my HijackThis log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:31:04 PM, on 2008-09-23
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\SiteAdvisor\6261\SAService.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\System32\WgaTray.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O2 - BHO: (no name) - {41b2d192-ea3a-4555-90a1-e50a9035fc09} - C:\WINDOWS\system32\sosoxx.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: {28fb0ffc-b290-2d09-49a4-9282285f2608} - {8062f582-2829-4a94-90d2-092bcff0bf82} - C:\WINDOWS\System32\trlhyf.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [90db8fbe] rundll32.exe "C:\WINDOWS\System32\aejohbji.dll",b
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames...o.cab55579.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...19/mcgdmgr.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames...p.cab56961.cab
    O18 - Protocol: bw+0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {E9A1120D-A99D-43BB-8D16-3A207402632E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O20 - AppInit_DLLs: sosoxx.dll trlhyf.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    --
    End of file - 25846 bytes

  2. #2
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
    "BEFORE you POST" (READ this Procedure before Requesting Assistance)
    http://forums.spybot.info/showthread.php?t=288
    All advice given is taken at your own risk.
    Please make sure you have read this information so we are on the same page.

    Make sure you read and follow the directions, anything else will slow the process and waste both of our time. I suggest you keep this computer offline except when troubleshooting, the junk may download more. If you have any tool I use, delete it and download it new from the link I provide. Read and follow the directions carefully, the tools will not work unless you do.
    The junk can be tough to remove, so do not expect fast or easy.

    1) Would you do both of us a favor and get rid of those 018 lines?
    For your information, all of the 018 items in the log are the result of the Logitech Desktop Messenger which gets installed along with another Logitech program because the EULA agreement is not read. Unless you know what it is and use it, it is a resource waster and can be removed in Add Remove programs, but make sure you uninstall only what I highlite in red, this is optional:
    C:\Program Files\Logitech\Desktop Messenger\ <<< uninstall only the program in red.
    After a restart those lines should be gone in the next HJT log...thanks

    2) We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
    * Run Spybot-S&D in Advanced Mode.
    * If it is not already set to do this Go to the Mode menu select "Advanced Mode"
    * On the left hand side, Click on Tools
    * Then click on the Resident Icon in the List
    * Uncheck "Resident TeaTimer" and OK any prompts.
    * Restart your computer.
    (leave TT disabled until we finish)

    3) A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.

    Tutorial
    http://www.bleepingcomputer.com/comb...o-use-combofix

    Remove any old copies of combofix before you proceed.

    Thanks to sUBs and anyone else who helped with this fix.

    It is important that it is saved directly to your Desktop.

    Download ComboFix from Here to your Desktop
    • Double click combofix.exe and follow the prompts.
    • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

    Note: Do not mouseclick combofix's window while its running. That may cause it to stall

    Post the combofix log and a new HJT log.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  3. #3
    Junior Member
    Join Date
    Sep 2008
    Posts
    16

    Default HijackThis log (new)

    Sorry it took me so long to respond - I really do appreciate you taking the time to reply.

    Here's the new HijackThis log, the ComboFix will be posted next.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:58:05 PM, on 2008-09-25
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\SiteAdvisor\6261\SAService.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\ctfmon.exe
    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [RJAALASR] %systemroot%\RJAALASR.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames...o.cab55579.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...19/mcgdmgr.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames...p.cab56961.cab
    O20 - AppInit_DLLs: sosoxx.dll trlhyf.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    --
    End of file - 7263 bytes

  4. #4
    Junior Member
    Join Date
    Sep 2008
    Posts
    16

    Default ComboFix log part 1

    ComboFix 08-09-20.05 - Administrator 2008-09-25 16:30:33.4 - NTFSx86 MINIMAL
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.286 [GMT -7:00]
    Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\B0.tmp
    C:\WINDOWS\system32\bitsprx.dll
    C:\WINDOWS\system32\blphc1h8j0end9.scr
    C:\WINDOWS\system32\cfgmgr3.dll
    C:\WINDOWS\system32\cmpbk3.dll
    C:\WINDOWS\system32\drivers\Winim50.sys
    C:\WINDOWS\system32\dwave.sys
    C:\WINDOWS\system32\k86.bin
    C:\WINDOWS\system32\lphc1h8j0end9.exe
    C:\WINDOWS\system32\winhelp.exe
    .
    ---- Previous Run -------
    .
    C:\WINDOWS\system32\5.tmp
    C:\WINDOWS\system32\blphc1h8j0end9.scr
    C:\WINDOWS\system32\cnbjmo.dll
    C:\WINDOWS\system32\E.tmp
    C:\WINDOWS\system32\ijbhojea.ini
    C:\WINDOWS\system32\k86.bin
    C:\WINDOWS\system32\lphc1h8j0end9.exe
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\phc1h8j0end9.bmp

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_RSVPCLIPSRV
    -------\Legacy_TCPSR
    -------\Legacy_WINIM50
    -------\Service_RSVPClipSrv
    -------\Service_Winim50


    ((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
    .

    2008-09-25 03:05 . 2008-09-25 03:05 23,552 --ahs---- C:\WINDOWS\SYSTEM32\$winnt$s.dll
    2008-09-25 03:05 . 2008-09-25 03:05 23,040 --ahs---- C:\WINDOWS\SYSTEM32\38a.dll
    2008-09-25 03:05 . 2008-09-25 03:05 16,384 --ahs---- C:\WINDOWS\SYSTEM32\4Fm.dll
    2008-09-25 02:27 . 2008-09-25 02:27 49,664 --a------ C:\4C.tmp
    2008-09-25 02:27 . 2008-09-25 02:27 18 --a------ C:\WINDOWS\SYSTEM32\4B.tmp
    2008-09-25 02:26 . 2008-09-25 02:26 131,198 --a------ C:\WINDOWS\SYSTEM32\43.tmp
    2008-09-25 02:26 . 2008-09-25 02:26 37,888 --a------ C:\WINDOWS\SYSTEM32\46.tmp
    2008-09-25 02:26 . 2008-09-25 02:26 312 --a------ C:\WINDOWS\SYSTEM32\41.tmp
    2008-09-25 01:54 . 2008-09-25 01:54 49,664 --a------ C:\3D.tmp
    2008-09-25 01:53 . 2008-09-25 01:53 131,198 --a------ C:\WINDOWS\SYSTEM32\35.tmp
    2008-09-25 01:53 . 2008-09-25 01:53 37,888 --a------ C:\WINDOWS\SYSTEM32\38.tmp
    2008-09-25 01:53 . 2008-09-25 01:53 312 --a------ C:\WINDOWS\SYSTEM32\33.tmp
    2008-09-25 01:53 . 2008-09-25 01:53 18 --a------ C:\WINDOWS\SYSTEM32\3C.tmp
    2008-09-25 01:37 . 2008-09-25 15:42 32,256 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ati1ydxx.sys
    2008-09-25 01:36 . 2008-09-25 01:36 131,198 --a------ C:\WINDOWS\SYSTEM32\E.tmp
    2008-09-25 01:36 . 2008-09-25 01:36 49,664 --a------ C:\1E.tmp
    2008-09-25 01:36 . 2008-09-25 01:36 37,888 --a------ C:\WINDOWS\SYSTEM32\17.tmp
    2008-09-25 01:36 . 2008-09-25 01:36 312 --a------ C:\WINDOWS\SYSTEM32\5.tmp
    2008-09-25 01:36 . 2008-09-25 01:36 29 --a------ C:\WINDOWS\SYSTEM32\dpwuursd.tmp
    2008-09-25 01:36 . 2008-09-25 01:36 18 --a------ C:\WINDOWS\SYSTEM32\1D.tmp
    2008-09-25 01:32 . 2008-09-25 01:32 172,032 --a------ C:\WINDOWS\RJAALASR.exe
    2008-09-25 01:32 . 2008-09-25 01:32 32,256 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ati2wbxx.sys
    2008-09-25 01:31 . 2008-09-25 01:31 172,032 --a------ C:\WINDOWS\SYSTEM32\B1.tmp
    2008-09-25 01:31 . 2008-09-25 01:31 131,198 --a------ C:\WINDOWS\SYSTEM32\AD.tmp
    2008-09-25 01:31 . 2008-09-25 01:32 49,664 --a------ C:\B6.tmp
    2008-09-25 01:31 . 2008-09-25 01:36 30,208 --a------ C:\WINDOWS\SYSTEM32\rs32net.exe
    2008-09-25 01:31 . 2008-09-25 04:05 641 --a-s---- C:\WINDOWS\SYSTEM32\1799622569.dat
    2008-09-25 01:31 . 2008-09-25 01:31 312 --a------ C:\WINDOWS\SYSTEM32\AC.tmp
    2008-09-25 01:31 . 2008-09-25 01:32 18 --a------ C:\WINDOWS\SYSTEM32\B5.tmp
    2008-09-25 00:06 . 2008-09-25 00:06 44 --a------ C:\WINDOWS\SYSTEM32\7E.tmp
    2008-09-25 00:06 . 2008-09-25 00:06 18 --a------ C:\WINDOWS\SYSTEM32\87.tmp
    2008-09-24 23:29 . 2008-09-24 23:29 18 --a------ C:\WINDOWS\SYSTEM32\4D.tmp
    2008-09-24 23:27 . 2008-09-24 23:28 88 --a------ C:\WINDOWS\SYSTEM32\4A.tmp
    2008-09-24 23:02 . 2008-09-24 23:02 186,368 --a------ C:\WINDOWS\SYSTEM32\13.tmp
    2008-09-24 23:02 . 2008-09-24 23:02 88 --a------ C:\WINDOWS\SYSTEM32\F.tmp
    2008-09-24 23:02 . 2008-09-24 23:02 18 --a------ C:\WINDOWS\SYSTEM32\1B.tmp
    2008-09-24 22:42 . 2008-09-24 22:42 186,368 --a------ C:\WINDOWS\SYSTEM32\14.tmp
    2008-09-24 22:42 . 2008-09-24 22:42 88 --a------ C:\WINDOWS\SYSTEM32\12.tmp
    2008-09-24 22:42 . 2008-09-24 22:42 18 --a------ C:\WINDOWS\SYSTEM32\18.tmp
    2008-09-24 22:42 . 2008-09-24 22:42 0 --a------ C:\WINDOWS\SYSTEM32\XDva016.sys

  5. #5
    Junior Member
    Join Date
    Sep 2008
    Posts
    16

    Default combofix log part 2

    2008-09-24 22:42 . 2008-09-24 22:42 0 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wATV03nt.sys
    2008-09-24 22:42 . 2008-09-24 22:42 0 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys
    2008-09-24 22:42 . 2008-09-24 22:42 0 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys
    2008-09-24 22:42 . 2008-09-24 22:42 0 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\el90xbc5.sys
    2008-09-24 22:33 . 2008-09-24 22:33 36,452 --a------ C:\WINDOWS\SYSTEM32\10.tmp
    2008-09-24 22:33 . 2008-09-24 22:33 88 --a------ C:\WINDOWS\SYSTEM32\C.tmp
    2008-09-24 22:33 . 2008-09-24 22:33 18 --a------ C:\WINDOWS\SYSTEM32\11.tmp
    2008-09-24 22:16 . 2008-09-24 22:16 0 --a------ C:\WINDOWS\SYSTEM32\D.tmp
    2008-09-24 22:15 . 2008-09-24 22:16 88 --a------ C:\WINDOWS\SYSTEM32\B.tmp
    2008-09-24 22:10 . 2008-09-24 22:10 88 --a------ C:\WINDOWS\SYSTEM32\7.tmp
    2008-09-24 22:10 . 2008-09-24 22:10 0 --a------ C:\WINDOWS\SYSTEM32\9.tmp
    2008-09-24 22:05 . 2008-09-24 22:05 88 --a------ C:\WINDOWS\SYSTEM32\4.tmp
    2008-09-24 22:05 . 2008-09-24 22:05 18 --a------ C:\WINDOWS\SYSTEM32\8.tmp
    2008-09-24 22:01 . 2008-09-24 22:01 186,368 --a------ C:\WINDOWS\SYSTEM32\6A.tmp
    2008-09-24 22:01 . 2008-09-24 22:01 36,452 --a------ C:\WINDOWS\SYSTEM32\6B.tmp
    2008-09-24 22:01 . 2008-09-24 22:01 88 --a------ C:\WINDOWS\SYSTEM32\68.tmp
    2008-09-24 22:01 . 2008-09-24 22:01 0 --a------ C:\WINDOWS\SYSTEM32\6C.tmp
    2008-09-24 21:50 . 2008-09-25 00:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\CatRoot_bak
    2008-09-24 21:31 . 2008-09-24 23:29 8,592 --a------ C:\WINDOWS\SYSTEM32\dplx.sys
    2008-09-24 21:31 . 2008-09-24 21:31 88 --a------ C:\WINDOWS\SYSTEM32\6.tmp
    2008-09-24 21:31 . 2008-09-24 21:32 18 --a------ C:\WINDOWS\SYSTEM32\A.tmp
    2008-09-23 19:29 . 2006-08-14 03:34 332,928 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
    2008-09-23 19:28 . 2006-06-21 22:06 1,435,648 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\query.dll
    2008-09-23 19:28 . 2006-06-21 22:06 69,120 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\ciodm.dll
    2008-09-23 19:22 . 2006-07-13 06:33 8,453,632 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
    2008-09-23 19:21 . 2006-04-20 04:51 359,808 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
    2008-09-23 19:18 . 2006-08-25 08:45 617,472 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\comctl32.dll
    2008-09-23 18:53 . 2004-08-04 00:56 380,416 --------- C:\WINDOWS\SYSTEM32\irprops.cpl
    2008-09-23 18:34 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\002622_.tmp
    2008-09-23 17:28 . 2008-09-24 18:18 4,566 --a------ C:\WINDOWS\imsins.BAK
    2008-09-23 16:14 . 2008-09-23 16:14 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-22 22:07 . 2006-05-05 02:41 453,120 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\mrxsmb.sys
    2008-09-22 22:07 . 2006-05-05 02:47 174,592 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\rdbss.sys
    2008-09-22 19:06 . 2008-09-22 19:06 <DIR> d-------- C:\VundoFix Backups
    2008-09-22 18:12 . 2003-07-16 13:50 48,256 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\w32.dll
    2008-09-22 18:12 . 2003-07-16 13:51 41,600 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\weitekp9.dll
    2008-09-22 18:12 . 2003-07-16 13:51 31,232 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\weitekp9.sys
    2008-09-22 18:10 . 2004-08-03 22:31 482,304 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\pintlgnt.ime
    2008-09-22 18:10 . 2003-07-16 13:33 92,416 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\mga.sys
    2008-09-22 18:10 . 2003-07-16 13:33 92,032 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\mga.dll
    2008-09-22 18:10 . 2003-07-16 13:23 67,584 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\pmigrate.dll
    2008-09-22 18:10 . 2001-08-17 23:36 65,536 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_mailmsg.dll
    2008-09-22 18:10 . 2001-08-17 23:36 38,912 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_ntfsdrv.dll
    2008-09-22 18:10 . 2003-07-16 13:41 6,144 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\pmxgl.dll
    2008-09-22 18:09 . 2003-07-16 13:22 10,096,640 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\hwxcht.dll
    2008-09-22 18:09 . 2001-08-17 23:36 43,520 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_fcachdll.dll
    2008-09-22 18:09 . 2003-07-16 13:31 18,432 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\jupiw.dll
    2008-09-22 18:07 . 2001-08-17 23:36 2,134,528 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_smtpsnap.dll
    2008-09-22 18:07 . 2001-08-17 23:36 175,104 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_smtpadm.dll
    2008-09-22 17:56 . 2008-09-22 17:56 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
    2008-09-22 17:56 . 2008-09-22 17:56 749 -rah----- C:\WINDOWS\SYSTEM32\wuaucpl.cpl.manifest
    2008-09-22 17:56 . 2008-09-22 17:56 749 -rah----- C:\WINDOWS\SYSTEM32\sapi.cpl.manifest
    2008-09-22 17:56 . 2008-09-22 17:56 749 -rah----- C:\WINDOWS\SYSTEM32\ncpa.cpl.manifest
    2008-09-22 17:56 . 2008-09-22 17:56 488 -rah----- C:\WINDOWS\SYSTEM32\logonui.exe.manifest
    2008-09-22 17:52 . 2008-07-18 22:09 1,811,656 --a------ C:\WINDOWS\SYSTEM32\wuaueng.dll
    2008-09-22 17:51 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dmusic.sys
    2008-09-22 17:51 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\splitter.sys
    2008-09-22 17:50 . 2004-08-03 22:59 57,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\redbook.sys
    2008-09-22 17:33 . 2004-08-04 00:56 130,048 --a------ C:\WINDOWS\SYSTEM32\ksproxy.ax
    2008-09-22 17:33 . 2004-08-04 00:56 4,096 --a------ C:\WINDOWS\SYSTEM32\ksuser.dll
    2008-09-22 17:32 . 2004-08-04 01:01 40,840 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\termdd.sys
    2008-09-22 17:29 . 2003-07-16 13:39 1,086,182 -ra------ C:\WINDOWS\SETA8.tmp
    2008-09-22 17:29 . 2003-07-16 13:39 797,189 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\NT5IIS.CAT
    2008-09-22 17:29 . 2003-07-16 13:32 399,645 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\MAPIMIG.CAT
    2008-09-22 17:29 . 2003-07-16 13:37 37,484 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\MW770.CAT
    2008-09-22 17:29 . 2003-07-16 13:30 13,608 -ra------ C:\WINDOWS\SETB4.tmp
    2008-09-22 17:29 . 2003-07-16 13:29 13,472 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\HPCRDP.CAT
    2008-09-22 17:29 . 2003-07-16 13:29 8,574 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\IASNT4.CAT
    2008-09-22 17:29 . 2003-07-16 13:54 7,046 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\OEMBIOS.CAT
    2008-09-22 17:29 . 2003-07-16 13:54 7,046 -ra------ C:\WINDOWS\SETC6.tmp
    2008-09-22 17:26 . 2008-09-22 17:26 119,808 --a------ C:\WINDOWS\SYSTEM32\trlhyf.dll
    2008-09-22 17:26 . 2008-09-22 17:26 119,808 --a------ C:\WINDOWS\SYSTEM32\sngykdjv.dll
    2008-09-22 17:23 . 2008-09-22 17:23 82,944 --a------ C:\WINDOWS\SYSTEM32\aejohbji.dll
    2008-09-22 17:20 . 2008-07-18 22:09 215,752 --a------ C:\WINDOWS\SYSTEM32\wuaucpl.cpl
    2008-09-22 09:20 . 2008-09-22 09:20 <DIR> d-------- C:\WINDOWS\java
    2008-09-22 09:20 . 2008-09-25 01:35 535,920,640 --a------ C:\WINDOWS\MEMORY.DMP
    2008-09-21 14:58 . 2008-09-21 16:51 1,738 --a------ C:\WINDOWS\setupapi.old
    2008-09-21 14:51 . 2008-09-21 14:51 <DIR> d-------- C:\Program Files\Safer Networking
    2008-09-21 14:13 . 2008-09-21 14:14 <DIR> d-------- C:\Program Files\CCleaner
    2008-09-21 14:03 . 2008-09-21 14:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-09-21 14:03 . 2008-09-23 21:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-09-21 13:56 . 2004-03-15 15:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
    2008-09-21 13:56 . 2004-03-15 16:01 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
    2008-09-21 13:56 . 2008-09-21 14:38 <DIR> d-------- C:\Documents and Settings\Administrator
    2008-09-21 12:58 . 2008-09-21 12:58 119,808 --a------ C:\WINDOWS\SYSTEM32\sosoxx.dll

  6. #6
    Junior Member
    Join Date
    Sep 2008
    Posts
    16

    Default combofix log part 3

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-24 01:38 --------- d-----w C:\Program Files\Canon
    2008-09-24 01:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
    2008-09-24 01:33 --------- d-----w C:\Program Files\Dell Support Center
    2008-09-24 01:31 --------- d-----w C:\Program Files\Common Files\supportsoft
    2008-09-24 01:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-09-24 01:19 --------- d-----w C:\Program Files\Dell
    2008-09-20 22:47 --------- d-----w C:\Documents and Settings\Cindy\Application Data\MSN6
    2008-09-20 22:16 --------- d-----w C:\Documents and Settings\Steve\Application Data\MSN6
    2008-09-12 17:20 --------- d-----w C:\Program Files\McAfee
    2008-08-31 05:55 --------- d-----w C:\Program Files\iTunes
    2008-08-31 05:54 --------- d-----w C:\Program Files\iPod
    2008-08-31 05:50 --------- d-----w C:\Program Files\QuickTime
    2008-08-26 04:08 --------- d-----w C:\Program Files\MSN Messenger
    2008-08-19 16:51 --------- d-----w C:\Program Files\NOS
    2008-08-19 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
    2008-08-19 03:41 --------- d-----w C:\Program Files\Common Files\Adobe AIR
    2008-08-19 03:40 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-08-14 09:17 --------- d-----w C:\Program Files\GameSpy Arcade
    2008-08-14 08:47 --------- d-----w C:\Documents and Settings\Sarah\Application Data\MSN6
    2008-08-14 04:21 --------- d-----w C:\Program Files\Apple Software Update
    .

    ------- Sigcheck -------

    2003-07-16 13:47 20480 2f9b3fab88427319ae1c623da7657e85 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
    2004-08-04 00:56 22016 b44a9ec9ffcc580e175b192a27f106fa C:\WINDOWS\ServicePackFiles\i386\svchost.exe
    2004-08-04 00:56 22016 b1172999c9889f1f7063d773109da2fb C:\WINDOWS\SYSTEM32\svchost.exe

    2005-05-25 12:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
    2006-01-13 10:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
    2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    2003-07-16 13:47 332928 244a2f9816bc9b593957281ef577d976 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
    2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
    2005-05-25 12:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
    2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
    2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
    2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
    2004-08-03 23:14 359040 1745b00fc1141404b28f4b94f69a8871 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
    2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\tcpip.sys
    2006-04-20 04:38 340480 b8158e2a6112c0a5ca67bc158fc70218 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP1QFE\tcpip.sys
    2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP2GDR\tcpip.sys
    2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP2QFE\tcpip.sys
    2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys
    2006-04-20 04:51 359808 021415ad071ef3944c27dc9597ed2214 C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
    2006-04-20 04:51 359808 021415ad071ef3944c27dc9597ed2214 C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys

    2004-08-04 00:56 1039872 3e72e8cddb0430b8da6717ab1f238480 C:\WINDOWS\explorer.exe
    2007-06-13 04:26 1040896 c47f62e3d79f33fd859eeafd4521d5e1 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
    2003-07-16 13:28 1011712 cabc6acc2d07f54e1438646615b21426 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
    2004-08-04 00:56 1039872 f23ea6bdeec01ab844aa9cfc31ba19d3 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
    2004-08-04 00:56 1039872 0ffeb1097e917d3bd8a7d505e7294941 C:\WINDOWS\ServicePackFiles\i386\explorer.exe

    2003-07-16 13:26 20992 954470ebd89bc3e43f7e2d7434bbaeaf C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
    2004-08-04 00:56 23040 c574ee9ca8966e4e3d7547ebb59ea688 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
    2004-08-04 00:56 23040 83b48f42a37030bb871fa1300a9f0af6 C:\WINDOWS\SYSTEM32\ctfmon.exe

    2005-06-10 17:17 65536 ff913e82962cbfd4f4dd7b628288a72f C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
    2003-07-16 13:46 58880 b8790eb2d8c296e2186c6eab56f91a81 C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
    2004-08-04 00:56 65536 7579e9061203ff730f554938850b43ae C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
    2004-08-04 00:56 65536 3716cf3f78414231daa51e532b38f430 C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
    2005-06-10 16:55 60928 4b2f0031e4c687f8f2088c84ed8c532c C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\spoolsv.exe
    2005-06-10 16:55 60928 8129ec1fde55bf2764d0c71772703130 C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp1qfe\spoolsv.exe
    2005-06-10 16:53 65536 0083f79e822bfac7876bf6220c4ecc0a C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe
    2005-06-10 17:17 65536 ff913e82962cbfd4f4dd7b628288a72f C:\WINDOWS\SoftwareDistribution\Download\0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe
    2005-06-10 16:53 65536 0083f79e822bfac7876bf6220c4ecc0a C:\WINDOWS\SYSTEM32\spoolsv.exe

    2003-07-16 13:49 29696 eb1eac537a334ec8de64dca283ba1923 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
    2004-08-04 00:56 32256 e5e057208f1120dfb7a451c1feafa22c C:\WINDOWS\ServicePackFiles\i386\userinit.exe
    2004-08-04 00:56 32256 8b369bcff0ac9d7cab3d1ca2217cb022 C:\WINDOWS\SYSTEM32\userinit.exe
    .
    ((((((((((((((((((((((((((((( snapshot@2008-09-22_20.38.59.34 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2004-11-30 22:46:38 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\spmsg.dll
    + 2004-11-30 21:46:38 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\spmsg.dll
    - 2004-12-01 04:22:42 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\spuninst.exe
    + 2004-12-01 03:22:42 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\spuninst.exe
    - 2004-12-01 04:22:40 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\update\spcustom.dll
    + 2004-12-01 03:22:40 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\update\spcustom.dll
    - 2004-11-30 22:46:40 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\update\update.exe
    + 2004-11-30 21:46:40 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB873333\update\update.exe
    - 2004-10-14 18:34:52 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\spmsg.dll
    + 2004-10-14 17:34:52 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\spmsg.dll
    - 2004-10-14 18:36:18 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\spuninst.exe
    + 2004-10-14 17:36:18 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\spuninst.exe
    - 2004-10-14 18:36:16 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\update\spcustom.dll
    + 2004-10-14 17:36:16 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\update\spcustom.dll
    - 2004-10-14 18:34:54 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\update\update.exe
    + 2004-10-14 17:34:54 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB873339\update\update.exe
    - 2004-10-14 19:34:52 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\spmsg.dll
    + 2004-10-14 18:34:52 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\spmsg.dll
    - 2004-10-14 19:36:18 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\spuninst.exe
    + 2004-10-14 18:36:18 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\spuninst.exe
    - 2004-10-14 19:36:16 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\update\spcustom.dll
    + 2004-10-14 18:36:16 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\update\spcustom.dll
    - 2004-10-14 19:34:54 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\update\update.exe
    + 2004-10-14 18:34:54 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB885835\update\update.exe
    - 2004-10-14 19:34:52 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\spmsg.dll
    + 2004-10-14 18:34:46 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\spmsg.dll
    - 2004-10-14 19:36:18 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\spuninst.exe
    - 2004-10-14 19:36:16 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\update\spcustom.dll
    + 2004-10-14 18:36:06 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\update\spcustom.dll
    - 2004-10-14 19:34:54 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\update\update.exe
    + 2004-10-14 18:34:48 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB885836\update\update.exe
    - 2004-11-30 22:46:38 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\spmsg.dll
    + 2004-10-14 18:34:46 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\spmsg.dll
    - 2004-12-01 04:22:42 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\spuninst.exe
    - 2004-12-01 04:22:40 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\update\spcustom.dll
    + 2004-10-14 18:36:06 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\update\spcustom.dll
    - 2004-11-30 22:46:40 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\update\update.exe
    + 2004-10-14 18:34:48 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB888302\update\update.exe
    - 2004-11-30 22:46:38 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\spmsg.dll
    + 2004-10-14 18:34:46 7,168 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\spmsg.dll
    - 2004-12-01 04:22:42 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\spuninst.exe
    - 2004-12-01 04:22:40 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\update\spcustom.dll
    + 2004-10-14 18:36:06 21,504 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\update\spcustom.dll
    - 2004-11-30 22:46:40 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\update\update.exe
    + 2004-10-14 18:21:58 662,528 -c--a-w C:\WINDOWS\$hf_mig$\KB891781\update\update.exe
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\spuninst.exe
    - 2005-07-08 02:27:08 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\arpidfix.exe
    + 2005-07-08 02:27:06 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\arpidfix.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB893756\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\spuninst.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896358\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\spuninst.exe
    - 2005-06-29 23:54:32 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe
    + 2005-06-29 23:54:30 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896423\update\updspapi.dll
    - 2005-02-25 04:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\spmsg.dll
    + 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\spmsg.dll
    - 2005-02-25 04:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\spuninst.exe
    + 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\spuninst.exe
    - 2005-10-06 00:39:46 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\arpidfix.exe
    + 2005-10-05 23:39:46 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\arpidfix.exe
    - 2005-02-25 04:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\spcustom.dll
    + 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\spcustom.dll
    - 2005-02-25 04:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\update.exe
    + 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\update.exe
    - 2005-02-25 04:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\updspapi.dll
    + 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896424\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\spuninst.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB896428\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\spuninst.exe
    - 2005-06-29 23:54:32 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\arpidfix.exe
    + 2005-06-29 23:54:30 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\arpidfix.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB899587\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\spmsg.dll
    + 2005-07-13 01:08:08 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\spuninst.exe
    + 2005-07-13 01:08:09 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\spuninst.exe
    - 2005-09-09 23:26:26 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\arpidfix.exe
    + 2005-09-09 23:26:25 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\arpidfix.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\spcustom.dll
    + 2005-07-13 01:08:08 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\updspapi.dll
    + 2005-07-13 01:08:17 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB901017\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB901190\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB901190\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB901190\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB901190\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\spuninst.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB901214\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\spmsg.dll
    + 2005-10-12 23:12:25 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\spuninst.exe
    + 2005-10-12 23:12:26 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\spuninst.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\spcustom.dll
    + 2005-10-12 23:12:25 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\update.exe
    + 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\updspapi.dll
    + 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB904706\update\updspapi.dll
    - 2005-02-25 03:35:06 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\spmsg.dll
    + 2005-02-25 03:35:05 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\spmsg.dll
    - 2005-02-25 03:35:06 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\spuninst.exe
    - 2005-08-23 01:01:30 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\arpidfix.exe
    + 2005-08-23 01:01:28 38,400 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\arpidfix.exe
    - 2005-02-25 03:35:06 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\spcustom.dll
    + 2005-02-25 03:35:05 22,240 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\spcustom.dll
    - 2005-02-25 03:35:06 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\update.exe
    + 2005-02-25 03:35:05 718,048 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\update.exe
    - 2005-02-25 03:35:08 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c--a-w C:\WINDOWS\$hf_mig$\KB905749\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB908519\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB908519\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB908519\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB908519\update\updspapi.dll
    - 2006-05-14 08:48:18 180,736 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\SP2QFE\rasmans.dll
    + 2006-06-22 10:36:52 180,736 ----a-w C:\WINDOWS\$hf_mig$\KB911280\SP2QFE\rasmans.dll
    - 2005-10-12 23:16:49 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\spmsg.dll
    + 2005-10-12 23:12:25 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\spmsg.dll
    - 2005-10-12 23:16:49 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\spuninst.exe
    + 2005-10-12 23:12:26 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\spuninst.exe
    - 2005-10-12 23:16:49 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\spcustom.dll
    + 2005-10-12 23:12:25 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\spcustom.dll
    - 2005-10-12 23:16:51 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\update.exe
    + 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\update.exe
    - 2005-10-12 23:16:56 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\updspapi.dll
    + 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB911280\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB911927\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB911927\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB911927\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB911927\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB912919\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB912919\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB912919\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB912919\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB914389\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB914389\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB914389\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB914389\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB917953\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB917953\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB917953\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB917953\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB919007\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB919007\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB919007\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB919007\update\updspapi.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB920685\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB920685\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB920685\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB920685\update\updspapi.dll
    - 2005-10-12 23:12:26 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\spuninst.exe
    + 2006-01-19 19:29:21 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\spuninst.exe
    - 2005-10-12 23:12:25 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\spcustom.dll
    + 2006-01-19 19:29:20 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\spcustom.dll
    - 2005-10-12 23:12:29 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\update.exe
    + 2006-01-19 19:29:21 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\update.exe
    - 2005-10-12 23:12:34 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB921398\update\updspapi.dll
    - 2005-10-12 23:16:49 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\spmsg.dll
    + 2005-10-12 23:12:25 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\spmsg.dll
    - 2005-10-12 23:16:49 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\spuninst.exe
    + 2005-10-12 23:12:26 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\spuninst.exe
    - 2005-10-12 23:16:49 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\spcustom.dll
    + 2005-10-12 23:12:25 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\spcustom.dll
    - 2005-10-12 23:16:51 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\update.exe
    + 2005-10-12 23:12:28 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\update.exe
    - 2005-10-12 23:16:56 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\updspapi.dll
    + 2005-10-12 23:12:33 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB923414\update\updspapi.dll
    - 2002-08-29 11:00:00 8,192 -c----w C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe
    + 2002-08-29 11:00:00 15,872 -c----w C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe
    - 2002-08-29 11:00:00 742,400 -c----w C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
    + 2002-08-29 11:00:00 750,080 -c----w C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
    - 2002-08-29 11:00:00 221,696 -c----w C:\WINDOWS\$NtUninstallKB842773$\qmgr.dll
    + 2003-07-16 20:42:27 221,696 -c----w C:\WINDOWS\$NtUninstallKB842773$\qmgr.dll
    - 2002-08-29 11:00:00 17,408 -c----w C:\WINDOWS\$NtUninstallKB842773$\qmgrprxy.dll
    + 2003-07-16 20:42:28 17,408 -c----w C:\WINDOWS\$NtUninstallKB842773$\qmgrprxy.dll
    - 2002-08-29 11:00:00 310,272 -c----w C:\WINDOWS\$NtUninstallKB842773$\winhttp.dll
    + 2003-07-16 20:51:36 310,272 -c----w C:\WINDOWS\$NtUninstallKB842773$\winhttp.dll
    - 2004-08-04 07:56:44 1,281,536 -c----w C:\WINDOWS\$NtUninstallKB873333$\ole32.dll
    + 2004-08-04 07:56:46 1,281,536 -c----w C:\WINDOWS\$NtUninstallKB873333$\ole32.dll
    - 2002-08-29 11:00:00 68,608 -c----w C:\WINDOWS\$NtUninstallKB873333$\olecli32.dll
    + 2003-07-16 20:40:36 68,608 -c----w C:\WINDOWS\$NtUninstallKB873333$\olecli32.dll
    - 2002-08-29 11:00:00 34,304 -c----w C:\WINDOWS\$NtUninstallKB873333$\olecnv32.dll
    + 2003-07-16 20:40:37 34,304 -c----w C:\WINDOWS\$NtUninstallKB873333$\olecnv32.dll
    - 2004-08-04 07:56:44 395,776 -c----w C:\WINDOWS\$NtUninstallKB873333$\rpcss.dll
    + 2004-08-04 07:56:46 395,776 -c----w C:\WINDOWS\$NtUninstallKB873333$\rpcss.dll
    + 2004-12-01 04:22:40 21,504 -c----w C:\WINDOWS\$NtUninstallKB873333$\spcustom.dll
    + 2004-11-30 22:46:38 7,168 -c----w C:\WINDOWS\$NtUninstallKB873333$\spmsg.dll
    + 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB873333$\spuninst.exe
    - 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
    + 2004-12-01 03:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
    + 2004-11-30 22:46:40 662,528 -c----w C:\WINDOWS\$NtUninstallKB873333$\update.exe
    - 2004-08-04 07:56:42 345,088 -c----w C:\WINDOWS\$NtUninstallKB873339$\hypertrm.dll
    + 2004-08-04 07:56:44 345,088 -c----w C:\WINDOWS\$NtUninstallKB873339$\hypertrm.dll
    + 2004-10-14 18:36:16 21,504 -c----w C:\WINDOWS\$NtUninstallKB873339$\spcustom.dll
    + 2004-10-14 18:34:52 7,168 -c----w C:\WINDOWS\$NtUninstallKB873339$\spmsg.dll
    + 2004-10-14 18:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB873339$\spuninst.exe
    - 2004-10-14 18:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
    + 2004-10-14 17:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
    + 2004-10-14 18:34:54 662,528 -c----w C:\WINDOWS\$NtUninstallKB873339$\update.exe
    - 2004-08-04 07:56:42 721,920 -c----w C:\WINDOWS\$NtUninstallKB885835$\lsasrv.dll
    + 2004-08-04 07:56:44 721,920 -c----w C:\WINDOWS\$NtUninstallKB885835$\lsasrv.dll
    + 2004-10-14 19:36:16 21,504 -c----w C:\WINDOWS\$NtUninstallKB885835$\spcustom.dll
    + 2004-10-14 19:34:52 7,168 -c----w C:\WINDOWS\$NtUninstallKB885835$\spmsg.dll
    + 2004-10-14 19:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB885835$\spuninst.exe
    - 2004-10-14 19:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
    + 2004-10-14 18:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
    + 2004-10-14 19:34:54 662,528 -c----w C:\WINDOWS\$NtUninstallKB885835$\update.exe
    + 2004-10-14 19:36:16 21,504 -c----w C:\WINDOWS\$NtUninstallKB885836$\spcustom.dll
    + 2004-10-14 19:34:52 7,168 -c----w C:\WINDOWS\$NtUninstallKB885836$\spmsg.dll
    + 2004-10-14 19:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB885836$\spuninst.exe
    - 2004-10-14 19:36:18 177,664 -c----w C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c----w C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
    + 2004-10-14 19:34:54 662,528 -c----w C:\WINDOWS\$NtUninstallKB885836$\update.exe
    + 2004-12-01 04:22:40 21,504 -c----w C:\WINDOWS\$NtUninstallKB888302$\spcustom.dll
    + 2004-11-30 22:46:38 7,168 -c----w C:\WINDOWS\$NtUninstallKB888302$\spmsg.dll
    + 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB888302$\spuninst.exe
    - 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c----w C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
    - 2004-08-04 07:56:45 96,768 -c----w C:\WINDOWS\$NtUninstallKB888302$\srvsvc.dll
    + 2004-08-04 07:56:46 96,768 -c----w C:\WINDOWS\$NtUninstallKB888302$\srvsvc.dll
    + 2004-11-30 22:46:40 662,528 -c----w C:\WINDOWS\$NtUninstallKB888302$\update.exe
    - 2004-08-04 07:56:41 58,880 -c----w C:\WINDOWS\$NtUninstallKB890046$\agentdpv.dll
    + 2004-08-04 07:56:42 58,880 -c----w C:\WINDOWS\$NtUninstallKB890046$\agentdpv.dll
    + 2005-02-25 03:35:06 22,240 -c----w C:\WINDOWS\$NtUninstallKB890046$\spcustom.dll
    + 2005-02-25 03:35:06 14,048 -c----w C:\WINDOWS\$NtUninstallKB890046$\spmsg.dll
    + 2005-02-25 03:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB890046$\spuninst.exe
    + 2005-02-25 03:35:06 718,048 -c----w C:\WINDOWS\$NtUninstallKB890046$\update.exe
    + 2005-02-25 03:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB890046$\updspapi.dll
    - 2004-08-04 07:56:41 56,832 -c----w C:\WINDOWS\$NtUninstallKB890859$\authz.dll
    + 2004-08-04 07:56:42 56,832 -c----w C:\WINDOWS\$NtUninstallKB890859$\authz.dll
    - 2004-08-04 05:58:58 2,056,832 -c----w C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
    + 2004-08-04 05:59:00 2,056,832 -c----w C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
    - 2004-08-04 06:19:59 2,180,992 -c----w C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
    + 2004-08-04 06:20:00 2,180,992 -c----w C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
    + 2005-02-25 02:35:06 22,240 -c----w C:\WINDOWS\$NtUninstallKB890859$\spcustom.dll
    + 2005-02-25 02:35:06 14,048 -c----w C:\WINDOWS\$NtUninstallKB890859$\spmsg.dll
    + 2005-02-25 02:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB890859$\spuninst.exe
    + 2005-02-25 02:35:06 718,048 -c----w C:\WINDOWS\$NtUninstallKB890859$\update.exe
    + 2005-02-25 02:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB890859$\updspapi.dll
    - 2004-08-04 07:56:46 577,024 -c----w C:\WINDOWS\$NtUninstallKB890859$\user32.dll
    + 2004-08-04 07:56:48 577,024 -c----w C:\WINDOWS\$NtUninstallKB890859$\user32.dll
    - 2004-08-04 06:17:40 1,835,904 -c----w C:\WINDOWS\$NtUninstallKB890859$\win32k.sys
    + 2004-08-04 06:17:42 1,835,904 -c----w C:\WINDOWS\$NtUninstallKB890859$\win32k.sys
    - 2004-08-04 07:56:46 290,816 -c----w C:\WINDOWS\$NtUninstallKB890859$\winsrv.dll
    + 2004-08-04 07:56:48 290,816 -c----w C:\WINDOWS\$NtUninstallKB890859$\winsrv.dll
    + 2004-12-01 04:22:40 21,504 -c----w C:\WINDOWS\$NtUninstallKB891781$\spcustom.dll
    + 2004-11-30 22:46:38 7,168 -c----w C:\WINDOWS\$NtUninstallKB891781$\spmsg.dll
    + 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB891781$\spuninst.exe
    - 2004-12-01 04:22:42 177,664 -c----w C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
    + 2004-10-14 18:36:07 177,664 -c----w C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
    + 2004-11-30 22:46:40 662,528 -c----w C:\WINDOWS\$NtUninstallKB891781$\update.exe
    + 2005-07-08 02:27:08 38,400 -c----w C:\WINDOWS\$NtUninstallKB893756$\arpidfix.exe
    + 2005-02-25 03:35:06 22,240 -c----w C:\WINDOWS\$NtUninstallKB893756$\spcustom.dll
    + 2005-02-25 03:35:06 14,048 -c----w C:\WINDOWS\$NtUninstallKB893756$\spmsg.dll
    + 2005-02-25 03:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB893756$\spuninst.exe
    - 2005-02-25 03:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c----w C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe
    - 2005-02-25 03:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB893756$\spuninst\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c----w C:\WINDOWS\$NtUninstallKB893756$\spuninst\updspapi.dll
    - 2004-08-04 07:56:46 246,272 -c----w C:\WINDOWS\$NtUninstallKB893756$\tapisrv.dll
    + 2004-08-04 07:56:48 246,272 -c----w C:\WINDOWS\$NtUninstallKB893756$\tapisrv.dll
    + 2005-02-25 03:35:06 718,048 -c----w C:\WINDOWS\$NtUninstallKB893756$\update.exe
    + 2005-02-25 03:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB893756$\updspapi.dll
    - 2004-08-04 07:56:50 18,432 -c----w C:\WINDOWS\$NtUninstallKB896358$\hh.exe
    + 2004-08-04 07:56:52 18,432 -c----w C:\WINDOWS\$NtUninstallKB896358$\hh.exe
    - 2004-08-04 07:56:42 38,912 -c----w C:\WINDOWS\$NtUninstallKB896358$\hhsetup.dll
    + 2004-08-04 07:56:44 38,912 -c----w C:\WINDOWS\$NtUninstallKB896358$\hhsetup.dll
    - 2004-08-04 07:56:42 143,872 -c----w C:\WINDOWS\$NtUninstallKB896358$\itircl.dll
    + 2004-08-04 07:56:44 143,872 -c----w C:\WINDOWS\$NtUninstallKB896358$\itircl.dll
    - 2004-08-04 07:56:42 134,144 -c----w C:\WINDOWS\$NtUninstallKB896358$\itss.dll
    + 2004-08-04 07:56:44 134,144 -c----w C:\WINDOWS\$NtUninstallKB896358$\itss.dll
    + 2005-02-25 03:35:06 22,240 -c----w C:\WINDOWS\$NtUninstallKB896358$\spcustom.dll
    + 2005-02-25 03:35:06 14,048 -c----w C:\WINDOWS\$NtUninstallKB896358$\spmsg.dll
    + 2005-02-25 03:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB896358$\spuninst.exe
    - 2005-02-25 03:35:06 209,632 -c----w C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe
    + 2005-02-25 03:35:05 209,632 -c----w C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe
    - 2005-02-25 03:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB896358$\spuninst\updspapi.dll
    + 2005-02-25 03:35:06 371,936 -c----w C:\WINDOWS\$NtUninstallKB896358$\spuninst\updspapi.dll
    + 2005-02-25 03:35:06 718,048 -c----w C:\WINDOWS\$NtUninstallKB896358$\update.exe
    + 2005-02-25 03:35:08 371,936 -c----w C:\WINDOWS\$NtUninstallKB896358$\updspapi.dll
    + 2005-06-29 23:54:32 38,400 -c----w C:\WINDOWS\$NtUninstallKB896423$\arpidfix.exe

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •