3 of 3
+ 2004-08-04 07:56:42 216,576 ----a-w c:\windows\SYSTEM32\ieaksie.dll
- 2007-12-06 04:59:51 161,792 ----a-w c:\windows\SYSTEM32\ieakui.dll
+ 2002-08-29 10:00:00 221,184 ----a-w c:\windows\SYSTEM32\ieakui.dll
- 2007-12-07 02:21:45 384,512 ----a-w c:\windows\SYSTEM32\iedkcs32.dll
+ 2004-08-04 07:56:42 323,584 ----a-w c:\windows\SYSTEM32\iedkcs32.dll
- 2006-10-17 17:06:00 78,336 -c--a-w c:\windows\SYSTEM32\ieencode.dll
+ 2004-08-04 07:56:42 81,920 ----a-w c:\windows\SYSTEM32\ieencode.dll
- 2006-11-08 02:03:36 191,488 ----a-w c:\windows\SYSTEM32\iepeers.dll
+ 2006-10-23 15:34:20 251,904 ----a-w c:\windows\SYSTEM32\iepeers.dll
- 2007-12-07 02:21:46 44,544 ----a-w c:\windows\SYSTEM32\iernonce.dll
+ 2004-08-04 07:56:42 48,640 ----a-w c:\windows\SYSTEM32\iernonce.dll
- 2006-11-07 08:26:42 55,296 -c--a-w c:\windows\SYSTEM32\iesetup.dll
+ 2004-08-04 07:56:42 62,976 ----a-w c:\windows\SYSTEM32\iesetup.dll
- 2007-12-06 11:00:58 13,824 ----a-w c:\windows\SYSTEM32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 ----a-w c:\windows\SYSTEM32\ieudinit.exe
- 2006-10-17 16:57:58 36,352 ----a-w c:\windows\SYSTEM32\imgutil.dll
+ 2004-08-04 07:56:42 35,840 ----a-w c:\windows\SYSTEM32\imgutil.dll
- 2007-08-21 06:15:44 683,520 ----a-w c:\windows\SYSTEM32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 ----a-w c:\windows\SYSTEM32\inetcomm.dll
- 2006-11-07 08:26:24 92,672 -c--a-w c:\windows\SYSTEM32\inseng.dll
+ 2006-10-23 15:34:20 96,256 ----a-w c:\windows\SYSTEM32\inseng.dll
+ 2008-08-30 20:14:28 99,568 ----a-w c:\windows\SYSTEM32\isafeif.dll
+ 2008-08-30 20:14:34 91,376 ----a-w c:\windows\SYSTEM32\isafprod.dll
- 2003-11-19 21:36:26 24,681 -c--a-w c:\windows\SYSTEM32\java.exe
+ 2009-02-04 14:11:42 144,792 ----a-w c:\windows\SYSTEM32\java.exe
- 2003-11-19 21:36:30 28,779 -c--a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-02-04 14:11:42 144,792 ----a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-02-04 14:11:42 148,888 ----a-w c:\windows\SYSTEM32\javaws.exe
- 2006-10-17 17:00:00 491,520 ----a-w c:\windows\SYSTEM32\jscript.dll
+ 2006-05-18 05:24:25 450,560 ----a-w c:\windows\SYSTEM32\jscript.dll
- 2007-12-07 02:21:47 27,648 ----a-w c:\windows\SYSTEM32\jsproxy.dll
+ 2006-10-23 15:34:20 15,872 ----a-w c:\windows\SYSTEM32\jsproxy.dll
+ 2002-08-29 10:00:00 2,000 ----a-w c:\windows\SYSTEM32\KEYBOARD.DRV
+ 2007-12-05 05:41:00 425,984 ----a-w c:\windows\SYSTEM32\keystone.exe
- 2006-10-17 17:05:10 40,960 -c--a-w c:\windows\SYSTEM32\licmgr10.dll
+ 2004-08-04 07:56:42 22,016 ----a-w c:\windows\SYSTEM32\licmgr10.dll
- 2006-10-19 00:03:58 100,864 -c--a-w c:\windows\SYSTEM32\logagent.exe
+ 2008-06-18 06:09:22 100,864 ----a-w c:\windows\SYSTEM32\logagent.exe
+ 2002-08-29 10:00:00 2,560 ----a-w c:\windows\SYSTEM32\LZ32.DLL
+ 2008-03-25 02:32:44 218,496 ----a-r c:\windows\SYSTEM32\Macromed\Flash\FlashUtil9f.exe
+ 2003-12-08 17:58:22 94,208 ----a-w c:\windows\SYSTEM32\Macromed\Flash\GetFlash.exe
+ 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\SYSTEM32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:04 235,936 ----a-w c:\windows\SYSTEM32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2007-07-21 01:37:39 48,749 ----a-w c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2008-10-08 12:41:19 74,137 ----a-w c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2008-12-18 15:12:20 84,661 ----a-w c:\windows\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
- 2004-03-22 22:17:05 24,816 ----a-w c:\windows\SYSTEM32\mdimon.dll
+ 2007-04-09 18:23:54 28,040 ----a-w c:\windows\SYSTEM32\mdimon.dll
+ 2002-08-29 10:00:00 2,032 ----a-w c:\windows\SYSTEM32\MOUSE.DRV
- 2005-06-29 01:46:00 74,240 ----a-w c:\windows\SYSTEM32\mscms.dll
+ 2008-06-24 16:23:05 74,240 ----a-w c:\windows\SYSTEM32\mscms.dll
- 2004-08-04 07:56:42 294,400 ----a-w c:\windows\SYSTEM32\msctf.dll
+ 2008-02-26 11:59:50 294,912 ----a-w c:\windows\SYSTEM32\msctf.dll
- 2004-08-04 07:56:43 512,029 -c--a-w c:\windows\SYSTEM32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w c:\windows\SYSTEM32\msexch40.dll
- 2004-08-04 07:56:43 319,517 -c--a-w c:\windows\SYSTEM32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w c:\windows\SYSTEM32\msexcl40.dll
- 2006-10-17 16:56:10 45,568 ----a-w c:\windows\SYSTEM32\mshta.exe
+ 2004-08-04 07:56:53 29,184 ----a-w c:\windows\SYSTEM32\mshta.exe
- 2007-12-08 05:21:48 3,592,192 ----a-w c:\windows\SYSTEM32\mshtml.dll
+ 2006-10-23 15:34:22 3,061,248 ----a-w c:\windows\SYSTEM32\mshtml.dll
- 2007-12-07 02:21:47 478,208 ----a-w c:\windows\SYSTEM32\mshtmled.dll
+ 2006-10-23 15:34:21 448,512 ----a-w c:\windows\SYSTEM32\mshtmled.dll
- 2006-10-17 16:28:56 48,128 -c--a-w c:\windows\SYSTEM32\mshtmler.dll
+ 2004-08-04 07:56:14 56,832 ----a-w c:\windows\SYSTEM32\mshtmler.dll
- 2004-08-04 07:56:43 1,507,356 ----a-w c:\windows\SYSTEM32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w c:\windows\SYSTEM32\msjet40.dll
- 2004-03-01 18:52:15 358,976 ----a-w c:\windows\SYSTEM32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w c:\windows\SYSTEM32\msjetoledb40.dll
- 2004-08-04 07:56:43 151,583 ----a-w c:\windows\SYSTEM32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 ----a-w c:\windows\SYSTEM32\msjint40.dll
- 2004-08-04 07:56:43 53,279 ----a-w c:\windows\SYSTEM32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w c:\windows\SYSTEM32\msjter40.dll
- 2004-08-04 07:56:43 241,693 ----a-w c:\windows\SYSTEM32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w c:\windows\SYSTEM32\msjtes40.dll
- 2006-11-08 02:03:36 156,160 ----a-w c:\windows\SYSTEM32\msls31.dll
+ 2002-08-29 10:00:00 146,432 ----a-w c:\windows\SYSTEM32\msls31.dll
- 2004-08-04 07:56:43 213,023 -c--a-w c:\windows\SYSTEM32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w c:\windows\SYSTEM32\msltus40.dll
- 2004-08-04 07:56:43 348,189 -c--a-w c:\windows\SYSTEM32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w c:\windows\SYSTEM32\mspbde40.dll
- 2007-12-07 02:21:48 193,024 ----a-w c:\windows\SYSTEM32\msrating.dll
+ 2006-10-23 15:34:21 146,432 ----a-w c:\windows\SYSTEM32\msrating.dll
- 2004-08-04 07:56:43 421,919 -c--a-w c:\windows\SYSTEM32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w c:\windows\SYSTEM32\msrd2x40.dll
- 2004-08-04 07:56:43 315,423 -c--a-w c:\windows\SYSTEM32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w c:\windows\SYSTEM32\msrd3x40.dll
- 2004-08-04 07:56:43 552,989 -c--a-w c:\windows\SYSTEM32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w c:\windows\SYSTEM32\msrepl40.dll
- 2004-08-04 07:56:43 258,077 -c--a-w c:\windows\SYSTEM32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w c:\windows\SYSTEM32\mstext40.dll
- 2007-12-07 02:21:48 671,232 ----a-w c:\windows\SYSTEM32\mstime.dll
+ 2006-10-23 15:34:21 532,480 ----a-w c:\windows\SYSTEM32\mstime.dll
- 2004-08-04 07:56:44 831,519 -c--a-w c:\windows\SYSTEM32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w c:\windows\SYSTEM32\mswdat10.dll
- 2004-08-04 07:56:44 245,248 ----a-w c:\windows\SYSTEM32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 ----a-w c:\windows\SYSTEM32\mswsock.dll
- 2004-08-04 07:56:44 614,429 ----a-w c:\windows\SYSTEM32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w c:\windows\SYSTEM32\mswstr10.dll
- 2004-08-04 07:56:44 348,189 -c--a-w c:\windows\SYSTEM32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w c:\windows\SYSTEM32\msxbde40.dll
- 2007-06-26 06:08:16 1,104,896 ----a-w c:\windows\SYSTEM32\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 ----a-w c:\windows\SYSTEM32\msxml3.dll
- 2007-05-08 19:03:04 1,275,392 ----a-w c:\windows\SYSTEM32\msxml4.dll
+ 2008-09-30 21:43:34 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
+ 2008-10-16 19:06:48 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
+ 2008-10-16 19:06:48 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
- 2006-08-17 12:28:27 332,288 ----a-w c:\windows\SYSTEM32\netapi32.dll
+ 2008-10-15 16:57:55 332,800 ----a-w c:\windows\SYSTEM32\netapi32.dll
- 2007-02-28 08:38:55 2,057,600 ----a-w c:\windows\SYSTEM32\ntkrnlpa.exe
+ 2008-08-14 09:22:13 2,057,728 ----a-w c:\windows\SYSTEM32\ntkrnlpa.exe
- 2007-02-28 09:10:57 2,180,352 ----a-w c:\windows\SYSTEM32\ntoskrnl.exe
+ 2008-08-14 10:00:45 2,180,352 ----a-w c:\windows\SYSTEM32\ntoskrnl.exe
- 2004-08-04 07:56:44 4,274,816 -c--a-w c:\windows\SYSTEM32\nv4_disp.dll
+ 2007-12-05 05:41:00 5,773,568 ----a-w c:\windows\SYSTEM32\nv4_disp.dll
+ 2007-12-05 05:41:00 385,024 ----a-w c:\windows\SYSTEM32\nvapi.dll
+ 2007-12-05 05:41:00 442,368 ----a-w c:\windows\SYSTEM32\nvappbar.exe
+ 2007-12-05 05:41:00 35,328 ----a-w c:\windows\SYSTEM32\nvcod.dll
+ 2007-12-05 05:41:00 35,328 ----a-w c:\windows\SYSTEM32\nvcodins.dll
+ 2007-12-05 05:41:00 147,456 ----a-w c:\windows\SYSTEM32\nvcolor.exe
+ 2007-12-05 05:41:00 8,523,776 ----a-w c:\windows\SYSTEM32\nvcpl.dll
+ 2007-12-05 05:41:00 753,664 ----a-w c:\windows\SYSTEM32\nvcplui.exe
+ 2007-12-05 05:41:00 1,073,152 ----a-w c:\windows\SYSTEM32\nvcpluir.dll
+ 2007-12-05 05:41:00 1,089,536 ----a-w c:\windows\SYSTEM32\nvcuda.dll
+ 2007-12-05 05:41:00 6,549,504 ----a-w c:\windows\SYSTEM32\nvdisps.dll
+ 2007-12-05 05:41:00 5,611,520 ----a-w c:\windows\SYSTEM32\nvdispsr.dll
+ 2007-12-05 05:41:00 1,339,392 ----a-w c:\windows\SYSTEM32\nvdspsch.exe
+ 2007-12-05 05:41:00 307,200 ----a-w c:\windows\SYSTEM32\nvexpbar.dll
+ 2007-12-05 05:41:00 3,420,160 ----a-w c:\windows\SYSTEM32\nvgames.dll
+ 2007-12-05 05:41:00 3,334,144 ----a-w c:\windows\SYSTEM32\nvgamesr.dll
+ 2005-12-10 07:06:00 573,440 ----a-w c:\windows\SYSTEM32\nvhwvid.dll
+ 2007-12-05 05:41:00 1,474,560 ----a-w c:\windows\SYSTEM32\nview.dll
+ 2007-12-05 05:41:00 229,376 ----a-w c:\windows\SYSTEM32\nvmccs.dll
+ 2007-12-05 05:41:00 45,056 ----a-w c:\windows\SYSTEM32\nvmccsrs.dll
+ 2007-12-05 05:41:00 188,416 ----a-w c:\windows\SYSTEM32\nvmccss.dll
+ 2007-12-05 05:41:00 458,752 ----a-w c:\windows\SYSTEM32\nvmccssr.dll
+ 2007-12-05 05:41:00 81,920 ----a-w c:\windows\SYSTEM32\nvmctray.dll
+ 2007-12-05 05:41:00 1,228,800 ----a-w c:\windows\SYSTEM32\nvmobls.dll
+ 2007-12-05 05:41:00 2,854,912 ----a-w c:\windows\SYSTEM32\nvmoblsr.dll
+ 2007-12-05 05:41:00 286,720 ----a-w c:\windows\SYSTEM32\nvnt4cpl.dll
+ 2007-12-05 05:41:00 6,901,760 ----a-w c:\windows\SYSTEM32\nvoglnt.dll
+ 2007-12-05 05:41:00 327,680 ----a-w c:\windows\SYSTEM32\nvrsar.dll
+ 2007-12-05 05:41:00 249,856 ----a-w c:\windows\SYSTEM32\nvrscs.dll
+ 2007-12-05 05:41:00 253,952 ----a-w c:\windows\SYSTEM32\nvrsda.dll
+ 2007-12-05 05:41:00 278,528 ----a-w c:\windows\SYSTEM32\nvrsde.dll
+ 2007-12-05 05:41:00 282,624 ----a-w c:\windows\SYSTEM32\nvrsel.dll
+ 2007-12-05 05:41:00 245,760 ----a-w c:\windows\SYSTEM32\nvrseng.dll
+ 2007-12-05 05:41:00 282,624 ----a-w c:\windows\SYSTEM32\nvrses.dll
+ 2007-12-05 05:41:00 274,432 ----a-w c:\windows\SYSTEM32\nvrsesm.dll
+ 2007-12-05 05:41:00 249,856 ----a-w c:\windows\SYSTEM32\nvrsfi.dll
+ 2007-12-05 05:41:00 282,624 ----a-w c:\windows\SYSTEM32\nvrsfr.dll
+ 2007-12-05 05:41:00 327,680 ----a-w c:\windows\SYSTEM32\nvrshe.dll
+ 2007-12-05 05:41:00 258,048 ----a-w c:\windows\SYSTEM32\nvrshu.dll
+ 2007-12-05 05:41:00 278,528 ----a-w c:\windows\SYSTEM32\nvrsit.dll
+ 2007-12-05 05:41:00 266,240 ----a-w c:\windows\SYSTEM32\nvrsja.dll
+ 2007-12-05 05:41:00 258,048 ----a-w c:\windows\SYSTEM32\nvrsko.dll
+ 2007-12-05 05:41:00 274,432 ----a-w c:\windows\SYSTEM32\nvrsnl.dll
+ 2007-12-05 05:41:00 253,952 ----a-w c:\windows\SYSTEM32\nvrsno.dll
+ 2007-12-05 05:41:00 253,952 ----a-w c:\windows\SYSTEM32\nvrspl.dll
+ 2007-12-05 05:41:00 274,432 ----a-w c:\windows\SYSTEM32\nvrspt.dll
+ 2007-12-05 05:41:00 266,240 ----a-w c:\windows\SYSTEM32\nvrsptb.dll
+ 2007-12-05 05:41:00 270,336 ----a-w c:\windows\SYSTEM32\nvrsru.dll
+ 2007-12-05 05:41:00 258,048 ----a-w c:\windows\SYSTEM32\nvrssk.dll
+ 2007-12-05 05:41:00 258,048 ----a-w c:\windows\SYSTEM32\nvrssl.dll
+ 2007-12-05 05:41:00 253,952 ----a-w c:\windows\SYSTEM32\nvrssv.dll
+ 2007-12-05 05:41:00 253,952 ----a-w c:\windows\SYSTEM32\nvrsth.dll
+ 2007-12-05 05:41:00 258,048 ----a-w c:\windows\SYSTEM32\nvrstr.dll
+ 2007-12-05 05:41:00 225,280 ----a-w c:\windows\SYSTEM32\nvrszhc.dll
+ 2007-12-05 05:41:00 126,976 ----a-w c:\windows\SYSTEM32\nvrszht.dll
+ 2007-12-05 05:41:00 466,944 ----a-w c:\windows\SYSTEM32\nvshell.dll
+ 2007-12-05 05:41:00 155,716 ----a-w c:\windows\SYSTEM32\nvsvc32.exe
+ 2007-12-05 05:41:00 356,352 ----a-w c:\windows\SYSTEM32\nvudisp.exe
+ 2008-05-16 15:48:14 446,464 ----a-w c:\windows\SYSTEM32\NVUNINST.EXE
+ 2007-12-05 05:41:00 3,710,976 ----a-w c:\windows\SYSTEM32\nvvitvs.dll
+ 2007-12-05 05:41:00 3,715,072 ----a-w c:\windows\SYSTEM32\nvvitvsr.dll
+ 2007-12-05 05:41:00 81,920 ----a-w c:\windows\SYSTEM32\nvwddi.dll
+ 2007-12-05 05:41:00 1,703,936 ----a-w c:\windows\SYSTEM32\nvwdmcpl.dll
+ 2007-12-05 05:41:00 1,019,904 ----a-w c:\windows\SYSTEM32\nvwimg.dll
+ 2007-12-05 05:41:00 282,624 ----a-w c:\windows\SYSTEM32\nvwrsar.dll
+ 2007-12-05 05:41:00 286,720 ----a-w c:\windows\SYSTEM32\nvwrscs.dll
+ 2007-12-05 05:41:00 294,912 ----a-w c:\windows\SYSTEM32\nvwrsda.dll
+ 2007-12-05 05:41:00 311,296 ----a-w c:\windows\SYSTEM32\nvwrsde.dll
+ 2007-12-05 05:41:00 335,872 ----a-w c:\windows\SYSTEM32\nvwrsel.dll
+ 2007-12-05 05:41:00 286,720 ----a-w c:\windows\SYSTEM32\nvwrseng.dll
+ 2007-12-05 05:41:00 335,872 ----a-w c:\windows\SYSTEM32\nvwrses.dll
+ 2007-12-05 05:41:00 327,680 ----a-w c:\windows\SYSTEM32\nvwrsesm.dll
+ 2007-12-05 05:41:00 303,104 ----a-w c:\windows\SYSTEM32\nvwrsfi.dll
+ 2007-12-05 05:41:00 327,680 ----a-w c:\windows\SYSTEM32\nvwrsfr.dll
+ 2007-12-05 05:41:00 278,528 ----a-w c:\windows\SYSTEM32\nvwrshe.dll
+ 2007-12-05 05:41:00 315,392 ----a-w c:\windows\SYSTEM32\nvwrshu.dll
+ 2007-12-05 05:41:00 323,584 ----a-w c:\windows\SYSTEM32\nvwrsit.dll
+ 2007-12-05 05:41:00 212,992 ----a-w c:\windows\SYSTEM32\nvwrsja.dll
+ 2007-12-05 05:41:00 196,608 ----a-w c:\windows\SYSTEM32\nvwrsko.dll
+ 2007-12-05 05:41:00 319,488 ----a-w c:\windows\SYSTEM32\nvwrsnl.dll
+ 2007-12-05 05:41:00 299,008 ----a-w c:\windows\SYSTEM32\nvwrsno.dll
+ 2007-12-05 05:41:00 294,912 ----a-w c:\windows\SYSTEM32\nvwrspl.dll
+ 2007-12-05 05:41:00 323,584 ----a-w c:\windows\SYSTEM32\nvwrspt.dll
+ 2007-12-05 05:41:00 319,488 ----a-w c:\windows\SYSTEM32\nvwrsptb.dll
+ 2007-12-05 05:41:00 315,392 ----a-w c:\windows\SYSTEM32\nvwrsru.dll
+ 2007-12-05 05:41:00 299,008 ----a-w c:\windows\SYSTEM32\nvwrssk.dll
+ 2007-12-05 05:41:00 303,104 ----a-w c:\windows\SYSTEM32\nvwrssl.dll
+ 2007-12-05 05:41:00 294,912 ----a-w c:\windows\SYSTEM32\nvwrssv.dll
+ 2007-12-05 05:41:00 290,816 ----a-w c:\windows\SYSTEM32\nvwrsth.dll
+ 2007-12-05 05:41:00 303,104 ----a-w c:\windows\SYSTEM32\nvwrstr.dll
+ 2007-12-05 05:41:00 163,840 ----a-w c:\windows\SYSTEM32\nvwrszhc.dll
+ 2007-12-05 05:41:00 167,936 ----a-w c:\windows\SYSTEM32\nvwrszht.dll
+ 2007-12-05 05:41:00 2,498,560 ----a-w c:\windows\SYSTEM32\nvwss.dll
+ 2007-12-05 05:41:00 2,519,040 ----a-w c:\windows\SYSTEM32\nvwssr.dll
+ 2007-12-05 05:41:00 1,626,112 ----a-w c:\windows\SYSTEM32\nwiz.exe
- 2007-12-07 02:21:48 102,912 ----a-w c:\windows\SYSTEM32\occache.dll
+ 2004-08-04 07:56:44 96,256 ----a-w c:\windows\SYSTEM32\occache.dll
- 2008-03-10 02:03:29 54,670 ----a-w c:\windows\SYSTEM32\PERFC009.DAT
+ 2009-03-11 23:33:07 54,670 ----a-w c:\windows\SYSTEM32\PERFC009.DAT
- 2008-03-10 02:03:29 385,450 ----a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-03-11 23:33:07 385,450 ----a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2003-10-02 04:00:00 413,696 ----a-w c:\windows\SYSTEM32\PICSDK.dll
- 2008-01-11 05:53:32 44,544 ----a-w c:\windows\SYSTEM32\pngfilt.dll
+ 2006-10-23 15:34:21 39,424 ----a-w c:\windows\SYSTEM32\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 ----a-w c:\windows\SYSTEM32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 ----a-w c:\windows\SYSTEM32\quartz.dll
- 2007-10-26 03:34:01 8,460,288 ----a-w c:\windows\SYSTEM32\shell32.dll
+ 2008-07-03 13:03:29 8,460,800 ----a-w c:\windows\SYSTEM32\shell32.dll
+ 2008-07-19 02:10:20 36,552 ----a-w c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-07-19 02:10:40 45,768 ----a-w c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
+ 2008-10-16 19:09:44 43,544 ----a-w c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2002-08-29 10:00:00 1,744 ----a-w c:\windows\SYSTEM32\SOUND.DRV
- 2006-12-10 18:10:02 14,640 ------w c:\windows\SYSTEM32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ------w c:\windows\SYSTEM32\spmsg.dll
- 2004-03-22 22:17:02 765,680 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdigraph.dll
+ 2007-04-09 18:24:04 758,664 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdigraph.dll
- 2004-03-22 22:17:08 42,224 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdiui.dll
+ 2007-04-09 18:23:58 46,472 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdiui.dll
- 2004-03-22 22:17:02 765,680 -c--a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdigraph.dll
+ 2007-04-09 18:24:04 758,664 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdigraph.dll
- 2004-03-22 22:17:08 42,224 -c--a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdiui.dll
+ 2007-04-09 18:23:58 46,472 ----a-w c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdiui.dll
- 2004-03-22 22:17:06 25,840 ----a-w c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
+ 2007-04-09 18:23:54 28,552 ----a-w c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
- 2005-06-10 23:53:32 57,856 ----a-w c:\windows\SYSTEM32\spoolsv.exe
+ 2004-08-04 07:56:57 57,856 ----a-w c:\windows\SYSTEM32\spoolsv.exe
- 2006-08-21 14:52:08 246,814 ----a-w c:\windows\SYSTEM32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ----a-w c:\windows\SYSTEM32\strmdll.dll
- 2007-11-13 11:31:11 60,416 ------w c:\windows\SYSTEM32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 ------w c:\windows\SYSTEM32\tzchange.exe
+ 2007-11-19 18:32:06 117,264 ----a-w c:\windows\SYSTEM32\UmxSbxExw.dll
+ 2007-11-19 18:32:06 256,528 ----a-w c:\windows\SYSTEM32\UmxSbxw.dll
+ 2007-05-18 18:30:00 79,368 ----a-w c:\windows\SYSTEM32\UmxWNP.dll
- 2007-12-07 02:21:48 105,984 ----a-w c:\windows\SYSTEM32\url.dll
+ 2004-08-04 07:56:46 37,888 ----a-w c:\windows\SYSTEM32\url.dll
- 2007-12-07 02:21:48 1,159,680 ----a-w c:\windows\SYSTEM32\urlmon.dll
+ 2006-10-23 15:34:22 615,936 ----a-w c:\windows\SYSTEM32\urlmon.dll
- 2006-11-08 02:03:36 413,696 ----a-w c:\windows\SYSTEM32\vbscript.dll
+ 2004-08-04 07:56:46 417,792 ----a-w c:\windows\SYSTEM32\vbscript.dll
+ 2008-08-30 20:14:38 83,256 ----a-w c:\windows\SYSTEM32\vetredir.dll
+ 2002-08-29 10:00:00 2,176 ----a-w c:\windows\SYSTEM32\VGA.DRV
- 2007-12-07 02:21:48 233,472 ----a-w c:\windows\SYSTEM32\webcheck.dll
+ 2004-08-04 07:56:46 276,480 ----a-w c:\windows\SYSTEM32\webcheck.dll
- 2007-03-08 13:47:48 1,843,584 ----a-w c:\windows\SYSTEM32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\SYSTEM32\win32k.sys
- 2007-12-07 02:21:48 824,832 ----a-w c:\windows\SYSTEM32\wininet.dll
+ 2006-10-23 15:34:22 664,576 ----a-w c:\windows\SYSTEM32\wininet.dll
+ 2002-08-29 10:00:00 2,864 ----a-w c:\windows\SYSTEM32\WINSOCK.DLL
+ 2002-08-29 10:00:00 2,112 ----a-w c:\windows\SYSTEM32\WINSPOOL.EXE
- 2006-10-19 01:47:20 937,984 ----a-w c:\windows\SYSTEM32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 ----a-w c:\windows\SYSTEM32\WMNetmgr.dll
- 2006-10-19 01:47:20 295,936 ------w c:\windows\SYSTEM32\wmpeffects.dll
+ 2008-06-24 22:12:58 295,936 ------w c:\windows\SYSTEM32\wmpeffects.dll
- 2006-10-19 01:47:22 2,450,944 ----a-w c:\windows\SYSTEM32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 ----a-w c:\windows\SYSTEM32\WMVCore.dll
+ 2002-08-29 10:00:00 2,736 ----a-w c:\windows\SYSTEM32\WOWDEB.EXE
- 2007-07-30 23:19:36 549,720 ----a-w c:\windows\SYSTEM32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
- 2007-07-30 23:19:16 53,080 ----a-w c:\windows\SYSTEM32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
- 2007-07-30 23:19:42 1,712,984 ----a-w c:\windows\SYSTEM32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
- 2007-07-30 23:19:32 325,976 ----a-w c:\windows\SYSTEM32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
- 2007-07-30 23:18:40 33,624 ----a-w c:\windows\SYSTEM32\wups.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
- 2007-07-30 23:19:12 43,352 ----a-w c:\windows\SYSTEM32\wups2.dll
+ 2008-10-16 19:09:44 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
- 2007-07-30 23:19:28 203,096 ----a-w c:\windows\SYSTEM32\wuweb.dll
+ 2008-10-16 19:13:40 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
- 2007-10-29 10:04:03 350,720 ----a-w c:\windows\SYSTEM32\xpsp3res.dll
+ 2008-02-15 09:06:21 351,744 ----a-w c:\windows\SYSTEM32\xpsp3res.dll
+ 2009-03-28 14:53:44 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_6fc.dat
+ 2000-08-31 12:00:00 49,152 ----a-w c:\windows\VFIND.exe
+ 2008-09-30 21:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 21:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2008-04-15 17:54:19 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
+ 2000-08-31 12:00:00 68,096 ----a-w c:\windows\zip.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-01-19 4670968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-23 181488]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-08-28 771312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-08-28 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-08-28 259312]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-08-30 234736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
c:\documents and settings\John\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-06-23 1373624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\hotComm.exe"=
"c:\\Program Files\\Mtrader mIRC - v2\\mirc32.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\SYSTEM32\\ftp.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall\\capfsem.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\cavrid.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\CA Website Inspector\\Light\\CAGlobalLight.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\cctray\\cctray.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall\\capfasem.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
"c:\\WINDOWS\\SYSTEM32\\taskmgr.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SDUpdate.exe"=
R0 KmxStart;KmxStart;c:\windows\SYSTEM32\DRIVERS\KmxStart.sys [2008-03-19 93712]
R0 PzWDM;PzWDM;c:\windows\SYSTEM32\DRIVERS\PzWDM.sys [2008-10-27 15172]
R1 KmxAgent;KmxAgent;c:\windows\SYSTEM32\DRIVERS\KmxAgent.sys [2008-03-21 63504]
R1 KmxFile;KmxFile;c:\windows\SYSTEM32\DRIVERS\KmxFile.sys [2008-03-21 45584]
R1 KmxFw;KmxFw;c:\windows\SYSTEM32\DRIVERS\KmxFw.sys [2008-03-19 115216]
R2 DLPortIO;DriverLINX Port I/O Driver;c:\windows\SYSTEM32\DRIVERS\DLPORTIO.sys [2005-03-20 3584]
R2 KmxCF;KmxCF;c:\windows\SYSTEM32\DRIVERS\KmxCF.sys [2008-06-04 134648]
R2 KmxSbx;KmxSbx;c:\windows\SYSTEM32\DRIVERS\KmxSbx.sys [2008-03-21 66576]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2007-04-17 12992]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys [2007-07-09 46112]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-04-15 281104]
R3 KmxCfg;KmxCfg;c:\windows\SYSTEM32\DRIVERS\KmxCfg.sys [2008-05-30 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-10-27 185584]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
--- Other Services/Drivers In Memory ---
*Deregistered* - project
.
Contents of the 'Scheduled Tasks' folder
2004-09-15 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2004-08-04 03:56]
.
- - - - ORPHANS REMOVED - - - -
BHO-{894a3b2b-6942-4b9f-af8d-3c39b5a4a230} - c:\windows\system32\uwthqn.dll
BHO-{9b738f2f-1299-4289-83b5-1d6579a27c82} - (no file)
BHO-{f44c12ab-a9e5-43c0-be43-f9dab699e2e1} - c:\windows\system32\yudedawo.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-RegistryMechanic - (no file)
HKU-Default-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil9d.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\windows\system32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\5hbvpu1b.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login_verify2?&.src=ym
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\Firefox\components\CallingIDLinkAdvisorGecko.dll
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\Firefox\components\CIDDomFx3.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-28 10:54:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1192)
c:\windows\system32\LMIRfsClientNP.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SYSTEM32\nvsvc32.exe
c:\windows\SYSTEM32\StkASv2K.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\CA\CA Internet Security Suite\ccupdate\ccupdate.exe
.
**************************************************************************
.
Completion time: 2009-03-28 11:01:14 - machine was rebooted [John]
ComboFix-quarantined-files.txt 2009-03-28 15:01:10
ComboFix2.txt 2008-03-22 03:55:24
Pre-Run: 10,809,163,776 bytes free
Post-Run: 10,896,277,504 bytes free
1741 --- E O F --- 2009-02-26 08:00:37
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:06:35 AM, on 3/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\StkASv2K.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: {032a4a5b-93c3-d8fa-f9b4-2496b2b3a498} - {894a3b2b-6942-4b9f-af8d-3c39b5a4a230} - C:\WINDOWS\system32\uwthqn.dll
O2 - BHO: (no name) - {9b738f2f-1299-4289-83b5-1d6579a27c82} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {f44c12ab-a9e5-43c0-be43-f9dab699e2e1} - C:\WINDOWS\system32\yudedawo.dll (file missing)
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - (no file)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [kililuvedu] Rundll32.exe "C:\WINDOWS\system32\gakejuha.dll",s
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CPMab9b1d26] Rundll32.exe "c:\windows\system32\kafuyora.dll",a
O4 - HKLM\..\Run: [a8a82eba] rundll32.exe "C:\WINDOWS\system32\bebidatu.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7921] command.com /c del "c:\windows\system32\gupureje.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4166] cmd.exe /c del "c:\windows\system32\gupureje.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9401] command.com /c del "C:\WINDOWS\system32\mayonibe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC504] cmd.exe /c del "C:\WINDOWS\system32\mayonibe.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\Run: [kililuvedu] Rundll32.exe "C:\WINDOWS\system32\morahove.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [kililuvedu] Rundll32.exe "C:\WINDOWS\system32\morahove.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3841567307-4091171729-3825519540-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jean')
O4 - HKUS\S-1-5-21-3841567307-4091171729-3825519540-1009\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Guest01')
O4 - HKUS\S-1-5-21-3841567307-4091171729-3825519540-1012\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'LogMeInRemoteUser')
O4 - HKUS\S-1-5-21-3841567307-4091171729-3825519540-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O20 - AppInit_DLLs: uwthqn.dll c:\windows\system32\kafuyora.dll,C:\WINDOWS\system32\nagefipi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kafuyora.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kafuyora.dll
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (file missing)
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Syntek STK1150 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Unknown owner - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (file missing)
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (file missing)
--
End of file - 7991 bytes
Also:
- removed unused programs
- loaded PSI
- upgraded adobe flash player active x 9.0.124.0
- upgraded adobe flash player 10 plugin 10.0.22.87
- removed adobe reader 8.1.2
- load foxit reader
- remove java 5.0 and 1.4.2
- load java 6.11
- removed spybot 1.3
- loaded spybot 1.6.2 and immunized
-