Sorry I havnt replied sooner..Work has been Keeping me busy..Here are the results.
Jotti Scan...
Filename: DAFE9F2F8D.dll
Status: Scan finished. 0 out of 21 scanners reported malware.
Scan taken on: Mon 29 Jun 2009 23:35:04 (CET)
ComboFix Log...
ComboFix 09-06-29.02 - Compaq_Owner 06/29/2009 16:53.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.680 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Owner\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Personal Firewall *enabled* {825036E0-9F94-4752-8789-8B92454AF49B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\system32\dllcache\wininet.dll --> c:\windows\SoftwareDistribution\Download\115be7432752f1eec2b0cdd6ef406571\sp2gdr\wininet.dll
c:\windows\system32\dllcache\wininet.dll --> c:\windows\SoftwareDistribution\Download\115be7432752f1eec2b0cdd6ef406571\sp2qfe\wininet.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.
2009-06-29 21:28 . 2009-06-29 21:28 -------- d-----w- c:\program files\MSXML 4.0
2009-06-28 22:12 . 2009-06-29 00:54 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-06-28 22:09 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-28 22:09 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-06-28 22:09 . 2009-02-06 17:22 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-28 22:09 . 2009-02-06 17:24 2180480 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-28 22:09 . 2009-02-06 16:49 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-28 22:09 . 2009-02-06 16:49 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-06-27 11:21 . 2009-06-27 11:21 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-06-27 11:21 . 2009-06-17 16:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-27 11:21 . 2009-06-27 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-27 11:21 . 2009-06-27 13:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-27 11:21 . 2009-06-17 16:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-24 22:10 . 2009-06-24 22:10 -------- d-----w- c:\program files\Trend Micro
2009-06-19 23:06 . 2009-06-19 23:06 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-09 22:43 . 2009-06-09 22:43 -------- d--h--r- C:\MSOCache
2009-06-07 14:43 . 2009-06-07 14:43 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Octoshape
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 21:30 . 2004-08-10 23:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-27 11:15 . 2006-01-15 00:24 -------- d-----w- c:\program files\Azureus
2009-06-04 22:04 . 2007-01-16 01:17 -------- d-----w- c:\program files\World of Warcraft
2009-05-07 15:44 . 2004-08-09 04:28 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-02 20:49 . 2009-05-02 20:49 -------- d-----w- c:\program files\Bytescout XLS Viewer
2009-05-02 20:46 . 2009-05-02 20:46 1078 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_294823.exe
2009-05-02 20:46 . 2009-05-02 20:46 1078 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{F58E04CD-6E76-43C8-AAF1-482225C2910E}\_18be6784.exe
2009-05-02 20:46 . 2009-05-02 20:46 -------- d-----w- c:\program files\MindFusion Limited
2009-04-29 04:56 . 2004-08-09 04:28 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-09 04:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2004-08-09 04:28 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-09 04:28 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2005-05-13 23:12 . 2005-05-13 23:12 217073 -csha-r- c:\windows\meta4.exe
2005-10-24 17:13 . 2005-10-24 17:13 66560 -csha-r- c:\windows\MOTA113.exe
2005-10-14 03:27 . 2005-10-14 03:27 422400 -csha-r- c:\windows\x2.64.exe
2005-10-08 01:14 . 2005-10-08 01:14 308224 --sha-r- c:\windows\system32\avisynth.dll
2005-07-14 18:31 . 2005-07-14 18:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll
2005-06-26 21:32 . 2005-06-26 21:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-22 04:37 . 2005-06-22 04:37 45568 --sha-r- c:\windows\system32\cygz.dll
2006-01-01 01:56 . 2006-01-01 01:54 80 --sh--r- c:\windows\system32\DAFE9F2F8D.dll
2004-01-25 06:00 . 2004-01-25 06:00 70656 --sha-r- c:\windows\system32\i420vfw.dll
2006-04-27 16:24 . 2006-04-27 16:24 2945024 --sha-r- c:\windows\system32\Smab.dll
2005-02-28 19:16 . 2005-02-28 19:16 240128 --sha-r- c:\windows\system32\x.264.exe
2004-01-25 06:00 . 2004-01-25 06:00 70656 --sha-r- c:\windows\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-28_21.46.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-30 21:45 . 2008-09-30 21:45 91656 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2009-06-29 21:43 . 2009-06-29 21:43 16384 c:\windows\Temp\Perflib_Perfdata_5f4.dat
+ 2005-05-26 10:16 . 2008-10-16 19:09 43544 c:\windows\system32\wups2.dll
+ 2004-08-09 05:43 . 2008-10-16 19:08 34328 c:\windows\system32\wups.dll
+ 2004-08-09 05:43 . 2008-10-16 19:09 51224 c:\windows\system32\wuauclt.exe
+ 2008-10-22 09:47 . 2008-10-22 09:47 62976 c:\windows\system32\tzchange.exe
+ 2005-11-24 21:30 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
+ 2009-01-13 23:22 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2009-06-28 22:03 . 2008-10-16 19:09 43544 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2009-06-28 22:03 . 2008-10-16 19:08 34328 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2006-11-02 07:23 . 2006-11-20 08:42 33280 c:\windows\system32\snmp.exe
+ 2004-08-09 04:28 . 2009-02-03 20:08 55808 c:\windows\system32\secur32.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 55808 c:\windows\system32\secur32.dll
+ 2005-11-24 21:10 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe
- 2004-08-09 04:28 . 2006-10-17 17:58 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 44544 c:\windows\system32\pngfilt.dll
- 2004-08-09 04:28 . 2009-04-06 20:51 63016 c:\windows\system32\perfc009.dat
+ 2004-08-09 04:28 . 2009-06-29 21:48 63016 c:\windows\system32\perfc009.dat
+ 2004-08-09 05:41 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
- 2004-08-09 04:28 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
+ 2004-08-09 04:28 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
+ 2006-11-08 03:03 . 2009-04-29 04:55 52224 c:\windows\system32\msfeedsbs.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
- 2004-08-09 05:41 . 2004-08-04 19:00 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-09 04:28 . 2008-06-24 16:23 74240 c:\windows\system32\mscms.dll
- 2004-08-09 04:28 . 2005-06-29 01:46 74240 c:\windows\system32\mscms.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 27648 c:\windows\system32\jsproxy.dll
+ 2006-11-07 09:26 . 2009-04-28 09:05 13824 c:\windows\system32\ieudinit.exe
+ 2004-08-09 04:28 . 2009-04-29 04:55 44544 c:\windows\system32\iernonce.dll
+ 2004-08-09 04:28 . 2009-04-28 09:05 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 17:58 . 2009-04-29 04:55 63488 c:\windows\system32\icardie.dll
+ 2004-08-09 05:43 . 2008-10-16 19:08 34328 c:\windows\system32\dllcache\wups.dll
+ 2004-08-09 05:43 . 2008-10-16 19:09 51224 c:\windows\system32\dllcache\wuauclt.exe
+ 2006-11-02 07:23 . 2006-11-20 08:42 33280 c:\windows\system32\dllcache\snmp.exe
- 2004-08-09 04:28 . 2004-08-04 19:00 55808 c:\windows\system32\dllcache\secur32.dll
+ 2004-08-09 04:28 . 2009-02-03 20:08 55808 c:\windows\system32\dllcache\secur32.dll
+ 2005-11-24 21:10 . 2009-02-06 16:54 35328 c:\windows\system32\dllcache\sc.exe
+ 2004-08-09 04:28 . 2009-04-29 04:56 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2004-08-09 04:28 . 2006-10-17 17:58 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
- 2004-08-09 04:28 . 2006-03-01 19:42 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2004-08-09 04:28 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2009-04-29 04:55 . 2009-04-29 04:55 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-09 05:41 . 2004-08-04 19:00 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-09 04:28 . 2005-06-29 01:46 74240 c:\windows\system32\dllcache\mscms.dll
+ 2004-08-09 04:28 . 2008-06-24 16:23 74240 c:\windows\system32\dllcache\mscms.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-04-28 09:05 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-09 04:28 . 2009-04-29 04:55 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-09 04:28 . 2006-10-17 18:06 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-09 04:28 . 2009-04-28 09:05 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-04-29 04:55 . 2009-04-29 04:55 63488 c:\windows\system32\dllcache\icardie.dll
+ 2004-08-09 04:28 . 2008-10-16 19:09 92696 c:\windows\system32\dllcache\cdm.dll
+ 2004-08-09 04:28 . 2008-10-16 19:09 92696 c:\windows\system32\cdm.dll
+ 2004-07-15 06:34 . 2004-07-15 06:34 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_PerfCounter.dll
+ 2003-02-21 09:09 . 2003-02-21 09:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_mscorsn.dll
+ 2004-07-15 06:32 . 2004-07-15 06:32 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_CORPerfMonExt.dll
+ 2007-01-15 21:11 . 2007-01-15 21:11 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
- 2003-02-21 09:09 . 2003-02-21 09:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-14 01:58 . 2007-04-14 01:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-14 01:57 . 2007-04-14 01:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2003-02-21 09:09 . 2003-02-21 09:09 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-14 01:57 . 2007-04-14 01:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2004-07-15 06:32 . 2004-07-15 06:32 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2007-04-14 02:30 . 2007-04-14 02:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-15 07:49 . 2004-07-15 07:49 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2009-06-29 21:28 . 2009-06-29 21:28 32768 c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2009-06-29 21:29 . 2006-10-17 17:58 44544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 50688 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 27136 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll
+ 2009-06-29 21:29 . 2006-11-07 09:26 13312 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-06-29 21:29 . 2006-11-07 09:26 43008 c:\windows\ie7updates\KB969897-IE7\iernonce.dll
+ 2009-06-29 21:29 . 2006-10-17 18:06 78336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll
+ 2009-06-29 21:29 . 2006-11-07 09:26 54784 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe
+ 2009-06-29 21:29 . 2006-10-17 17:58 61952 c:\windows\ie7updates\KB969897-IE7\icardie.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 10240 c:\windows\assembly\NativeImages1_v1.1.4322\VJSWfcBrowserStubLib\1.0.5000.0__b03f5f7f11d50a3a_3f0cbd73\VJSWfcBrowserStubLib.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 32768 c:\windows\assembly\NativeImages1_v1.1.4322\vjslibcw\1.0.5000.0__b03f5f7f11d50a3a_e33d8987\vjslibcw.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 69632 c:\windows\assembly\NativeImages1_v1.1.4322\VJSharpCodeProvider\7.0.5000.0__b03f5f7f11d50a3a_1da86e94\VJSharpCodeProvider.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 20480 c:\windows\assembly\NativeImages1_v1.1.4322\vjscor\1.0.5000.0__b03f5f7f11d50a3a_0fce8aa0\vjscor.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_b924cb2b\System.Drawing.Design.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_ab089005\CustomMarshalers.dll
- 2005-09-23 13:29 . 2005-09-23 13:29 6144 c:\windows\system32\mui\0409\mscorees.dll
+ 2006-12-22 18:02 . 2006-12-22 18:02 6144 c:\windows\system32\mui\0409\mscorees.dll
+ 2005-05-17 00:25 . 2009-04-15 09:24 351744 c:\windows\system32\xpsp3res.dll
+ 2004-08-09 05:43 . 2008-10-16 19:13 202776 c:\windows\system32\wuweb.dll
+ 2004-08-09 05:43 . 2008-10-16 19:12 323608 c:\windows\system32\wucltui.dll
+ 2004-08-09 05:43 . 2008-10-16 19:12 561688 c:\windows\system32\wuapi.dll
- 2006-10-19 03:47 . 2006-10-19 03:47 295936 c:\windows\system32\wmpeffects.dll
+ 2006-10-19 03:47 . 2008-06-24 23:12 295936 c:\windows\system32\wmpeffects.dll
+ 2004-08-09 04:29 . 2008-06-18 10:03 938496 c:\windows\system32\WMNetmgr.dll
+ 2004-08-09 04:29 . 2007-10-27 22:40 222720 c:\windows\system32\wmasf.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 351232 c:\windows\system32\winhttp.dll
+ 2004-08-09 04:28 . 2008-12-16 12:47 351232 c:\windows\system32\winhttp.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 233472 c:\windows\system32\webcheck.dll
+ 2004-08-09 05:41 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-09 05:41 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-09 05:41 . 2009-02-09 10:20 473088 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 105984 c:\windows\system32\url.dll
- 2004-08-09 04:28 . 2006-10-17 18:05 105984 c:\windows\system32\url.dll
+ 2004-08-09 04:29 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll
+ 2004-08-09 04:28 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe
- 2004-08-09 04:28 . 2004-08-04 19:00 144896 c:\windows\system32\schannel.dll
+ 2004-08-09 04:28 . 2008-12-05 07:12 144896 c:\windows\system32\schannel.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 399360 c:\windows\system32\rpcss.dll
- 2004-08-09 04:28 . 2009-04-06 20:51 402406 c:\windows\system32\perfh009.dat
+ 2004-08-09 04:28 . 2009-06-29 21:48 402406 c:\windows\system32\perfh009.dat
+ 2004-08-09 04:28 . 2009-03-06 14:44 283648 c:\windows\system32\pdh.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 283648 c:\windows\system32\pdh.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 102912 c:\windows\system32\occache.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 714752 c:\windows\system32\ntdll.dll
+ 2004-08-09 04:28 . 2008-10-15 16:57 332800 c:\windows\system32\netapi32.dll
+ 2004-08-09 04:28 . 2008-06-20 17:41 245248 c:\windows\system32\mswsock.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 245248 c:\windows\system32\mswsock.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 671232 c:\windows\system32\mstime.dll
+ 2004-08-09 04:29 . 2006-12-04 21:21 414720 c:\windows\system32\msscp.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 193024 c:\windows\system32\msrating.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 477696 c:\windows\system32\mshtmled.dll
+ 2006-11-08 03:03 . 2009-04-29 04:55 459264 c:\windows\system32\msfeeds.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
+ 2006-12-22 17:28 . 2006-12-22 17:28 271360 c:\windows\system32\mscoree.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 723456 c:\windows\system32\lsasrv.dll
+ 2004-08-09 04:29 . 2008-06-18 06:09 100864 c:\windows\system32\logagent.exe
- 2004-08-09 04:29 . 2006-10-19 02:03 100864 c:\windows\system32\logagent.exe
+ 2004-08-09 04:28 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
+ 2004-08-09 05:43 . 2008-04-11 18:50 683520 c:\windows\system32\inetcomm.dll
+ 2006-10-17 17:57 . 2009-04-29 04:55 268288 c:\windows\system32\iertutil.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 385024 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 17:27 . 2009-04-29 04:55 383488 c:\windows\system32\ieapfltr.dll
+ 2005-11-24 21:08 . 2009-04-25 05:26 161792 c:\windows\system32\ieakui.dll
- 2005-11-24 21:08 . 2006-11-07 09:25 161792 c:\windows\system32\ieakui.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-09 04:28 . 2008-10-23 13:01 283648 c:\windows\system32\gdi32.dll
+ 2004-08-08 22:36 . 2009-06-29 21:43 191384 c:\windows\system32\FNTCACHE.DAT
- 2004-08-08 22:36 . 2007-01-15 00:33 191384 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-09 04:28 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll
+ 2004-08-09 04:28 . 2008-07-07 20:32 253952 c:\windows\system32\es.dll
- 2004-08-09 04:28 . 2006-10-17 17:57 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-09 04:28 . 2008-06-20 09:52 225920 c:\windows\system32\drivers\tcpip6.sys
+ 2004-08-09 04:28 . 2008-06-20 10:45 360320 c:\windows\system32\drivers\tcpip.sys
+ 2004-08-09 04:28 . 2008-12-11 11:57 333184 c:\windows\system32\drivers\srv.sys
+ 2005-11-24 21:10 . 2008-05-08 12:28 202752 c:\windows\system32\drivers\rmcast.sys
+ 2004-08-09 04:28 . 2008-10-24 11:10 453632 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-09 04:28 . 2008-08-14 09:51 138368 c:\windows\system32\drivers\afd.sys
+ 2004-08-09 04:28 . 2008-06-20 17:41 148992 c:\windows\system32\dnsapi.dll
+ 2004-08-09 05:43 . 2008-10-16 19:13 202776 c:\windows\system32\dllcache\wuweb.dll
+ 2004-08-09 05:43 . 2008-10-16 19:12 323608 c:\windows\system32\dllcache\wucltui.dll
+ 2004-08-09 05:43 . 2008-10-16 19:12 561688 c:\windows\system32\dllcache\wuapi.dll
+ 2004-08-09 05:41 . 2008-04-21 10:02 215552 c:\windows\system32\dllcache\wordpad.exe
+ 2004-08-09 04:29 . 2008-06-18 10:03 938496 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2004-08-09 05:41 . 2009-02-06 16:39 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2004-08-09 05:41 . 2009-02-09 10:20 453120 c:\windows\system32\dllcache\wmiprvsd.dll
+ 2004-08-09 04:29 . 2007-10-27 22:40 222720 c:\windows\system32\dllcache\wmasf.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-09 04:28 . 2008-12-16 12:47 351232 c:\windows\system32\dllcache\winhttp.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-09 05:43 . 2006-11-08 03:03 765952 c:\windows\system32\dllcache\vgx.dll
+ 2004-08-09 05:43 . 2008-05-27 17:23 765952 c:\windows\system32\dllcache\vgx.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 105984 c:\windows\system32\dllcache\url.dll
- 2004-08-09 04:28 . 2006-10-17 18:05 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-09 04:29 . 2007-06-27 03:10 317440 c:\windows\system32\dllcache\unregmp2.exe
+ 2004-08-09 04:28 . 2008-06-20 09:52 225920 c:\windows\system32\dllcache\tcpip6.sys
+ 2004-08-09 04:28 . 2008-06-20 10:45 360320 c:\windows\system32\dllcache\tcpip.sys
+ 2004-08-09 04:29 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2004-08-09 04:28 . 2008-12-11 11:57 333184 c:\windows\system32\dllcache\srv.sys
+ 2004-08-09 04:28 . 2009-02-06 17:14 110592 c:\windows\system32\dllcache\services.exe
+ 2004-08-09 04:28 . 2008-12-05 07:12 144896 c:\windows\system32\dllcache\schannel.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 144896 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 399360 c:\windows\system32\dllcache\rpcss.dll
+ 2004-08-09 04:28 . 2009-04-15 15:11 584192 c:\windows\system32\dllcache\rpcrt4.dll
+ 2005-11-24 21:10 . 2008-05-08 12:28 202752 c:\windows\system32\dllcache\rmcast.sys
+ 2004-08-09 04:28 . 2009-03-06 14:44 283648 c:\windows\system32\dllcache\pdh.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 283648 c:\windows\system32\dllcache\pdh.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-09 04:28 . 2008-10-15 16:57 332800 c:\windows\system32\dllcache\netapi32.dll
+ 2004-08-09 04:28 . 2008-06-20 17:41 245248 c:\windows\system32\dllcache\mswsock.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-09 04:29 . 2006-12-04 21:21 414720 c:\windows\system32\dllcache\msscp.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-04-29 04:55 . 2009-04-29 04:55 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2004-08-09 05:43 . 2008-05-01 14:30 331776 c:\windows\system32\dllcache\msadce.dll
- 2004-08-09 05:43 . 2004-08-04 19:00 331776 c:\windows\system32\dllcache\msadce.dll
+ 2006-05-05 09:41 . 2008-10-24 11:10 453632 c:\windows\system32\dllcache\mrxsmb.sys
+ 2004-08-09 04:28 . 2009-02-09 10:20 723456 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-09 04:29 . 2008-06-18 06:09 100864 c:\windows\system32\dllcache\logagent.exe
- 2004-08-09 04:29 . 2006-10-19 02:03 100864 c:\windows\system32\dllcache\logagent.exe
+ 2004-08-09 04:28 . 2009-05-07 15:44 344064 c:\windows\system32\dllcache\localspl.dll
+ 2004-08-09 04:28 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-09 05:43 . 2008-04-11 18:50 683520 c:\windows\system32\dllcache\inetcomm.dll
+ 2004-08-09 05:43 . 2009-04-25 05:27 636088 c:\windows\system32\dllcache\iexplore.exe
+ 2009-04-29 04:55 . 2009-04-29 04:55 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-04-29 04:55 . 2009-04-29 04:55 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2005-11-24 21:08 . 2006-11-07 09:25 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2005-11-24 21:08 . 2009-04-25 05:26 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-09 04:28 . 2008-10-23 13:01 283648 c:\windows\system32\dllcache\gdi32.dll
+ 2004-08-09 05:41 . 2009-02-09 10:20 473088 c:\windows\system32\dllcache\fastprox.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-09 04:28 . 2008-07-07 20:32 253952 c:\windows\system32\dllcache\es.dll
- 2004-08-09 04:28 . 2006-10-17 17:57 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-09 04:28 . 2008-06-20 17:41 148992 c:\windows\system32\dllcache\dnsapi.dll
+ 2004-08-09 04:28 . 2008-08-14 09:51 138368 c:\windows\system32\dllcache\afd.sys
+ 2004-08-09 04:28 . 2009-04-29 04:55 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 616960 c:\windows\system32\dllcache\advapi32.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 616960 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-09 04:28 . 2009-04-29 04:55 124928 c:\windows\system32\advpack.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 616960 c:\windows\system32\advapi32.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 616960 c:\windows\system32\advapi32.dll
+ 2003-02-21 18:42 . 2003-02-21 18:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_msvcr71.dll
+ 2004-07-15 06:25 . 2004-07-15 06:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_mscorjit.dll
+ 2004-07-15 06:24 . 2004-07-15 06:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_fusion.dll
+ 2004-07-15 07:49 . 2004-07-15 07:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_aspnet_isapi.dll
- 2004-07-15 06:33 . 2004-07-15 06:33 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 01:58 . 2007-04-14 01:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 01:56 . 2007-04-14 01:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-15 06:25 . 2004-07-15 06:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-14 02:30 . 2007-04-14 02:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2004-07-15 07:49 . 2004-07-15 07:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2004-08-09 04:29 . 2007-06-27 03:10 317440 c:\windows\inf\unregmp2.exe
+ 2009-06-29 21:29 . 2006-11-08 03:03 818688 c:\windows\ie7updates\KB969897-IE7\wininet.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 231424 c:\windows\ie7updates\KB969897-IE7\webcheck.dll
+ 2009-06-29 21:29 . 2006-10-17 18:05 105984 c:\windows\ie7updates\KB969897-IE7\url.dll
+ 2009-06-29 21:29 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-06-29 21:29 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-06-29 21:29 . 2006-10-17 18:04 101376 c:\windows\ie7updates\KB969897-IE7\occache.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 670720 c:\windows\ie7updates\KB969897-IE7\mstime.dll
+ 2009-06-29 21:29 . 2006-10-17 18:05 192000 c:\windows\ie7updates\KB969897-IE7\msrating.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 475648 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 458752 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll
+ 2009-06-29 21:29 . 2006-10-17 18:04 622080 c:\windows\ie7updates\KB969897-IE7\iexplore.exe
+ 2009-06-29 21:29 . 2006-10-17 17:57 266752 c:\windows\ie7updates\KB969897-IE7\iertutil.dll
+ 2009-06-29 21:29 . 2006-11-07 09:27 382976 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll
+ 2009-06-29 21:29 . 2006-10-17 17:27 380928 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll
+ 2009-06-29 21:29 . 2006-11-07 09:25 161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll
+ 2009-06-29 21:29 . 2006-11-07 09:27 229376 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll
+ 2009-06-29 21:29 . 2006-11-07 09:26 152064 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 131584 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-06-29 21:29 . 2006-10-17 17:57 214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll
+ 2009-06-29 21:29 . 2006-10-17 17:58 346624 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll
+ 2009-06-29 21:29 . 2006-11-07 09:26 123904 c:\windows\ie7updates\KB969897-IE7\advpack.dll
+ 2009-06-29 21:38 . 2006-11-08 03:03 765952 c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2009-06-29 21:38 . 2007-03-06 01:23 371424 c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2009-06-29 21:38 . 2007-03-06 01:22 213216 c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2005-01-19 04:26 . 2008-10-24 11:10 453632 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-06-28 22:09 . 2008-06-13 13:10 272128 c:\windows\Driver Cache\i386\bthport.sys
+ 2009-06-29 21:36 . 2009-06-29 21:36 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_664592b4\System.Drawing.dll
+ 2009-06-28 22:08 . 2008-04-15 17:54 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
+ 2008-09-30 21:42 . 2008-09-30 21:42 1286152 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2004-08-09 05:43 . 2008-10-16 19:13 1809944 c:\windows\system32\wuaueng.dll
+ 2004-08-09 04:29 . 2008-06-18 10:03 2458112 c:\windows\system32\WMVCore.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 1159680 c:\windows\system32\urlmon.dll
+ 2004-08-09 04:28 . 2008-07-03 13:16 8454656 c:\windows\system32\shell32.dll
+ 2004-08-09 04:28 . 2008-12-20 22:43 1287680 c:\windows\system32\quartz.dll
+ 2004-08-09 04:28 . 2009-02-06 17:24 2180480 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 05:59 . 2009-02-06 16:49 2057728 c:\windows\system32\ntkrnlpa.exe
+ 2008-09-30 21:43 . 2008-09-30 21:43 1286152 c:\windows\system32\msxml4.dll
+ 2004-08-09 04:28 . 2008-09-04 16:42 1106944 c:\windows\system32\msxml3.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 3596288 c:\windows\system32\mshtml.dll
+ 2006-11-08 03:03 . 2009-04-29 04:55 6066176 c:\windows\system32\ieframe.dll
+ 2006-09-06 05:01 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
+ 2004-08-09 05:43 . 2008-10-16 19:13 1809944 c:\windows\system32\dllcache\wuaueng.dll
+ 2004-08-09 04:29 . 2008-06-18 10:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2004-08-09 04:28 . 2009-04-17 09:58 1846656 c:\windows\system32\dllcache\win32k.sys
+ 2004-08-09 04:28 . 2009-04-29 04:56 1159680 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-09 04:28 . 2008-07-03 13:16 8454656 c:\windows\system32\dllcache\shell32.dll
+ 2004-08-09 04:28 . 2008-12-20 22:43 1287680 c:\windows\system32\dllcache\quartz.dll
+ 2004-08-09 04:28 . 2008-09-04 16:42 1106944 c:\windows\system32\dllcache\msxml3.dll
+ 2004-08-09 04:28 . 2009-04-29 04:56 3596288 c:\windows\system32\dllcache\mshtml.dll
+ 2009-04-29 04:55 . 2009-04-29 04:55 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2008-07-09 14:25 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2007-04-14 02:35 . 2007-04-14 02:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-14 02:35 . 2007-04-14 02:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2004-07-15 06:28 . 2004-07-15 06:28 2502656 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_mscorwks.dll
+ 2004-07-15 06:26 . 2004-07-15 06:26 2510848 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_mscorsvr.dll
+ 2004-07-15 20:29 . 2004-07-15 20:29 2138112 c:\windows\Microsoft.NET\Framework\v1.1.4322\SHADOW2984\_mscorlib.dll
+ 2007-04-14 01:57 . 2007-04-14 01:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-14 01:57 . 2007-04-14 01:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-14 01:50 . 2007-04-14 01:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 1162240 c:\windows\ie7updates\KB969897-IE7\urlmon.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 3577856 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
+ 2009-06-29 21:29 . 2006-11-08 03:03 6049280 c:\windows\ie7updates\KB969897-IE7\ieframe.dll
+ 2009-06-29 21:29 . 2006-09-06 05:01 2451824 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat
+ 2004-08-09 05:49 . 2006-08-21 20:57 1077321 c:\windows\Help\SBSI\Training\orun32.exe
+ 2005-03-02 00:59 . 2009-02-06 17:24 2180480 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-03-02 00:34 . 2009-02-06 16:49 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2005-03-02 00:34 . 2009-02-06 16:49 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2005-03-02 00:57 . 2009-02-06 17:22 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-06-29 21:36 . 2009-06-29 21:36 4468736 c:\windows\assembly\NativeImages1_v1.1.4322\vjslib\1.0.5000.0__b03f5f7f11d50a3a_f4fdb070\vjslib.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_3f4063c7\System.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_9dcb8cc1\System.Xml.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_1f49b5a2\System.Windows.Forms.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_2b5dbf90\System.Design.dll
+ 2009-06-29 21:36 . 2009-06-29 21:36 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5b088979\mscorlib.dll
+ 2009-06-29 21:35 . 2009-06-29 21:35 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-06-29 21:35 . 2009-06-29 21:35 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2004-08-09 04:29 . 2008-11-11 23:34 10838016 c:\windows\system32\wmp.dll
+ 2004-08-09 04:29 . 2008-11-11 23:34 10838016 c:\windows\system32\dllcache\wmp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 71328]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-13 98304]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-11-24 95960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
RCA Detective.lnk - c:\documents and settings\Compaq_Owner\My Documents\RCA Detective\RCADetective.exe [2009-1-13 1069056]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Neverwinter Nights_ Platinum Edition Registration.lnk]
path=c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\Neverwinter Nights_ Platinum Edition Registration.lnk
backup=c:\windows\pss\Neverwinter Nights_ Platinum Edition Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"AOL ACS"=2 (0x2)
"TapiSrv"=2 (0x2)
"ose"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:TCP"= 6881:TCP:Bittorrent
"6881:UDP"= 6881:UDP:Bittorrent2
S3 SaiH0109;SaiH0109;c:\windows\system32\drivers\SaiH0109.sys [11/27/2005 11:06 AM 55936]
S3 SaiU0109;SaiU0109;c:\windows\system32\drivers\SaiU0109.sys [11/27/2005 11:06 AM 19456]
.
Contents of the 'Scheduled Tasks' folder
2009-06-27 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Compaq_Owner.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-06-05 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-29 16:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(608)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3052)
c:\windows\system32\msi.dll
c:\windows\system32\mshtml.dll
.
Completion time: 2009-06-29 17:00
ComboFix-quarantined-files.txt 2009-06-29 21:59
ComboFix2.txt 2009-06-28 21:48
Pre-Run: 4,866,027,520 bytes free
Post-Run: 4,845,645,824 bytes free
470 --- E O F --- 2009-06-29 21:39
Kapersky Scan Results...
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, July 1, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, July 01, 2009 13:11:30
Records in database: 2411096
--------------------------------------------------------------------------------
Infected: :
Scan using the following database: extended
Scan archives: no
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan statistics:
Files scanned: 95105
Threat name: 3
Infected objects: 9
Suspicious objects: 0
Infected: : 01:09:14
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETrvbqjwqx.dll.vir Infected: Trojan.Win32.Small.bzc 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073399.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073400.exe Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073401.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073404.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073406.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073408.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP724\A0073416.dll Infected: not-a-virus:WebToolbar.Win32.Zango.bd 1
C:\System Volume Information\_restore{A85EC1FF-58D4-4723-A09B-E5784A945816}\RP779\A0075876.dll Infected: Trojan.Win32.Small.bzc 1
The selected area was scanned.