offline
- Pridružio: 28 Jun 2008
- Poruke: 61
|
Evo nakon što je odradio combo,dobio sam ovo:
ComboFix 08-06-20.4 - xx 2008-06-28 14:14:56.11 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.271 [GMT 2:00]
Running from: D:\Documents and Settings\xx\Desktop\ATF CLEANER\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\All Users\Application Data\Starware349
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\FindIt.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\FindItHot.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\findithotxp.png
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\finditxp.png
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Free_Credit_Score0.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Free_Music0.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Horoscopes0.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\logo.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\logoxp.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Reference.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\ReferenceHot.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\referencehotxp.png
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\referencexp.png
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Ringtones0.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\Weather.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\WeatherHot.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\weatherhotxp.png
D:\Documents and Settings\All Users\Application Data\Starware349\buttons\weatherxp.png
D:\Documents and Settings\All Users\Application Data\Starware349\contexts\error.xml
D:\Documents and Settings\All Users\Application Data\Starware349\contexts\Related.xml
D:\Documents and Settings\All Users\Application Data\Starware349\contexts\Travel.xml
D:\Documents and Settings\All Users\Application Data\Starware349\images\walertXP.bmp
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\ProductMessagingConfig.xml
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\ProductMessagingConfig.xml.backup
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\SimpleUpdateConfig.xml
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\SimpleUpdateConfig.xml.backup
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\TimerManagerConfig.xml
D:\Documents and Settings\All Users\Application Data\Starware349\SimpleUpdate\TimerManagerConfig.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349
D:\Documents and Settings\xx\Application Data\Starware349\BrowserSearch\BrowserSearch.xml
D:\Documents and Settings\xx\Application Data\Starware349\BrowserSearch\BrowserSearch.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Configurator\Configurator.xml
D:\Documents and Settings\xx\Application Data\Starware349\Configurator\Configurator.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\ErrorSearch\ErrorSearchOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\ErrorSearch\ErrorSearchOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Free_Credit_Score\Free_Credit_ScoreOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Free_Credit_Score\Free_Credit_ScoreOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Free_Music\Free_MusicOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Free_Music\Free_MusicOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Horoscopes\HoroscopesOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Horoscopes\HoroscopesOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Layouts\ToolbarLayout.xml
D:\Documents and Settings\xx\Application Data\Starware349\Layouts\ToolbarLayout.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Manager\ManagerOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Manager\ManagerOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Reference\ReferenceOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Reference\ReferenceOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\RelatedSearch\RelatedSearchOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\RelatedSearch\RelatedSearchOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Ringtones\RingtonesOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Ringtones\RingtonesOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Toolbar\TBProductsOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Toolbar\TBProductsOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\ToolbarLogo\ToolbarLogoOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\ToolbarLogo\ToolbarLogoOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\ToolbarSearch\ToolbarSearchOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\ToolbarSearch\ToolbarSearchOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\TravelSearch\TravelSearchOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\TravelSearch\TravelSearchOptions.xml.backup
D:\Documents and Settings\xx\Application Data\Starware349\Weather\AlertArchive.xml
D:\Documents and Settings\xx\Application Data\Starware349\Weather\WeatherOptions.xml
D:\Documents and Settings\xx\Application Data\Starware349\Weather\WeatherOptions.xml.backup
D:\WINDOWS\svchost.exe
D:\WINDOWS\system32\cologsver.exe
D:\WINDOWS\system32\google.dll
D:\WINDOWS\system32\lsprst7.dll
D:\WINDOWS\system32\msnserv.exe
I:\autorun.bat
I:\autorun.inf
I:\autorun.vbs
I:\Knight.exe
.
---- Previous Run -------
.
D:\WINDOWS\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_POWERMANAGER
-------\Service_PowerManager
-------\Legacy_POWERMANAGER
-------\Service_PowerManager
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-28 )))))))))))))))))))))))))))))))
.
2008-06-27 19:34 . 2008-06-27 19:34 <DIR> d-------- D:\Program Files\Electronic Arts
2008-06-19 18:09 . 2008-06-19 18:09 268 --ah----- D:\sqmdata01.sqm
2008-06-19 18:09 . 2008-06-19 18:09 244 --ah----- D:\sqmnoopt01.sqm
2008-06-18 23:02 . 2008-06-18 23:02 268 --ah----- D:\sqmdata00.sqm
2008-06-18 23:02 . 2008-06-18 23:02 244 --ah----- D:\sqmnoopt00.sqm
2008-06-17 22:42 . 2008-06-17 22:42 <DIR> d-------- D:\Program Files\InstallShield Installation Information
2008-06-11 17:02 . 2008-06-11 17:02 <DIR> d-------- D:\Program Files\Fifa Master
2008-06-11 16:29 . 2008-06-11 16:29 <DIR> dr-h----- D:\Documents and Settings\xx\Application Data\SecuROM
2008-06-11 15:03 . 2008-06-13 15:10 272,128 --------- D:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 15:03 . 2008-06-13 15:10 272,128 -----c--- D:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 01:11 . 2008-06-10 01:11 <DIR> d-------- D:\Program Files\Davilex
2008-06-09 13:44 . 2008-06-09 13:44 <DIR> d-------- D:\Documents and Settings\xx\.spss
2008-06-09 13:35 . 2008-06-09 13:35 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
2008-06-09 13:31 . 2008-06-09 13:31 <DIR> d-------- D:\Program Files\Common Files\SPSS
2008-06-09 13:31 . 2008-06-09 13:31 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SPSS
2008-06-09 13:30 . 2008-06-09 13:30 1,025 --a------ D:\WINDOWS\system32\sysprs7.tgz
2008-06-09 13:30 . 2008-06-09 13:30 1,025 --a------ D:\WINDOWS\system32\sysprs7.dll
2008-06-09 13:30 . 2008-06-09 13:30 16 ---h----- D:\WINDOWS\system32\servdat.slm
2008-06-07 11:49 . 2008-06-07 11:49 <DIR> d--hs---- D:\WINDOWS\ftpcache
2008-05-31 15:27 . 2008-06-03 17:31 <DIR> d-a------ D:\Documents and Settings\All Users\Application Data\TEMP
2008-05-31 15:26 . 2008-06-17 15:35 <DIR> d-------- D:\Program Files\Neuro-Programmer 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 12:22 23,890,976 --sha-w D:\WINDOWS\system32\drivers\fidbox.dat
2008-06-28 12:22 1,654,560 --sha-w D:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-28 12:21 323,108 --sha-w D:\WINDOWS\system32\drivers\fidbox.idx
2008-06-28 12:21 158,228 --sha-w D:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-28 07:34 4,192 ----a-w D:\WINDOWS\system32\ealregsnapshot1.reg
2008-06-28 07:31 --------- d-----w D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-24 17:07 --------- d-----w D:\Documents and Settings\xx\Application Data\temp
2008-06-17 14:17 --------- d-----w D:\Program Files\Winamp
2008-06-17 14:12 223,128 ----a-w D:\WINDOWS\system32\drivers\vaxscsi.sys
2008-06-17 13:37 --------- d-----w D:\Program Files\LHM2006
2008-06-17 13:36 --------- d-----w D:\Program Files\XoftSpySE
2008-06-17 13:35 --------- d-----w D:\Program Files\Windows Live Toolbar
2008-06-17 13:35 --------- d-----w D:\Program Files\bfgclient
2008-05-30 13:58 --------- d-----w D:\Program Files\Common Files\Adobe
2008-05-11 15:14 1,292,470 ----a-w D:\Documents and Settings\xx\ddram.exe
2008-05-08 12:28 202,752 ----a-w D:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w D:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w D:\WINDOWS\system32\wininet.dll
2008-04-12 09:44 286,720 ------w D:\WINDOWS\Setup1.exe
2007-11-03 14:45 13 ----a-w D:\Documents and Settings\xx\Verinfo.dat
2007-11-03 14:44 1,024 ----a-w D:\Documents and Settings\xx\Config.dat
2004-08-03 22:56 221,532 --sh--r D:\WINDOWS\system32\lxkchkv.exe
.
------- Sigcheck -------
md5deep: D:\WINDOWS\svchost.exe: No such file or directory
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 D:\WINDOWS\system32\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 D:\WINDOWS\system32\dllcache\svchost.exe
2007-03-08 17:36 577536 b409909f6e2e8a7067076ed748abf1e7 D:\WINDOWS\SoftwareDistribution\Download\4d9d678c0d8af22c04a4a7fc7f1ff86c\sp2gdr\user32.dll
2007-03-08 17:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b D:\WINDOWS\SoftwareDistribution\Download\4d9d678c0d8af22c04a4a7fc7f1ff86c\sp2qfe\user32.dll
2005-03-02 20:09 577024 de2db164bbb35db061af0997e4499054 D:\WINDOWS\system32\user32.dll
2005-03-02 20:09 577024 de2db164bbb35db061af0997e4499054 D:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 D:\WINDOWS\system32\ws2_32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 D:\WINDOWS\system32\dllcache\ws2_32.dll
2007-10-30 19:20 360064 90caff4b094573449a0872a0f919b178 D:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 19:20 360064 90caff4b094573449a0872a0f919b178 D:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe D:\WINDOWS\system32\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe D:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e D:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e D:\WINDOWS\system32\drivers\ndis.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 D:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 D:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-02 02:34 2056832 81013f36b21c7f72cf784cc6731e0002 D:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 10:38 2057600 515d30e2c90a3665a2739309334c9283 D:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntkrnlpa.exe
2007-02-28 11:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba D:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2qfe\ntkrnlpa.exe
2005-03-02 02:34 2056832 81013f36b21c7f72cf784cc6731e0002 D:\WINDOWS\system32\ntkrnlpa.exe
2005-03-02 02:59 2179328 4d4cf2c14550a4b7718e94a6e581856e D:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2007-02-28 11:10 2180352 582a8dbaa58c3b1f176eb2817daee77c D:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntoskrnl.exe
2007-02-28 11:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 D:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2qfe\ntoskrnl.exe
2005-03-02 02:59 2179328 4d4cf2c14550a4b7718e94a6e581856e D:\WINDOWS\system32\ntoskrnl.exe
2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 D:\WINDOWS\explorer.exe
2008-03-01 19:10 1033216 97bd6515465659ff8f3b7be375b2ea87 D:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2008-03-01 21:00 1033216 7712df0cdde3a5ac89843e61cd5b3658 D:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 D:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 D:\WINDOWS\system32\services.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 D:\WINDOWS\system32\dllcache\services.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 D:\WINDOWS\system32\lsass.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 D:\WINDOWS\system32\dllcache\lsass.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 D:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 D:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( snapshot_2008-05-06_21.59.11.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-23 04:56:21 554,008 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-27 07:39:13 151,583 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-12-10 12:41:14 621,344 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 ----a-w D:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:22:36 14,048 ----a-w D:\WINDOWS\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w D:\WINDOWS\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w D:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w D:\WINDOWS\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w D:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll
+ 2008-05-07 04:55:40 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP2QFE\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP3GDR\quartz.dll
+ 2008-05-07 05:04:15 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP3QFE\quartz.dll
+ 2007-11-30 11:18:51 17,272 ----a-w D:\WINDOWS\$hf_mig$\KB951698\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w D:\WINDOWS\$hf_mig$\KB951698\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\updspapi.dll
+ 2004-08-03 22:56:44 561,179 -c----w D:\WINDOWS\$NtUninstallKB950749$\dao360.dll
+ 2004-08-03 22:56:44 512,029 -c----w D:\WINDOWS\$NtUninstallKB950749$\msexch40.dll
+ 2004-08-03 22:56:44 319,517 -c----w D:\WINDOWS\$NtUninstallKB950749$\msexcl40.dll
+ 2004-08-03 22:56:44 1,507,356 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjet40.dll
+ 2004-07-17 09:34:48 358,976 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjetol1.dll
+ 2004-07-17 09:34:48 358,976 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjetoledb40.dll
+ 2004-08-03 22:56:44 151,583 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjint40.dll
+ 2004-08-03 22:56:44 53,279 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjter40.dll
+ 2004-08-03 22:56:44 241,693 -c----w D:\WINDOWS\$NtUninstallKB950749$\msjtes40.dll
+ 2004-08-03 22:56:44 213,023 -c----w D:\WINDOWS\$NtUninstallKB950749$\msltus40.dll
+ 2004-08-03 22:56:44 348,189 -c----w D:\WINDOWS\$NtUninstallKB950749$\mspbde40.dll
+ 2004-08-03 22:56:44 421,919 -c----w D:\WINDOWS\$NtUninstallKB950749$\msrd2x40.dll
+ 2004-08-03 22:56:44 315,423 -c----w D:\WINDOWS\$NtUninstallKB950749$\msrd3x40.dll
+ 2004-08-03 22:56:44 552,989 -c----w D:\WINDOWS\$NtUninstallKB950749$\msrepl40.dll
+ 2004-08-03 22:56:44 258,077 -c----w D:\WINDOWS\$NtUninstallKB950749$\mstext40.dll
+ 2004-08-03 22:56:46 831,519 -c----w D:\WINDOWS\$NtUninstallKB950749$\mswdat10.dll
+ 2004-08-03 22:56:46 614,429 -c----w D:\WINDOWS\$NtUninstallKB950749$\mswstr10.dll
+ 2004-08-03 22:56:46 348,189 -c----w D:\WINDOWS\$NtUninstallKB950749$\msxbde40.dll
+ 2007-03-06 01:22:41 213,216 -c----w D:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w D:\WINDOWS\$NtUninstallKB950749$\spuninst\updspapi.dll
- 2008-03-16 14:41:23 53,248 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-06-11 13:46:10 53,248 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-03-16 14:41:28 12,800 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-06-11 13:46:10 12,800 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-03-16 14:41:32 473,600 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-06-11 13:46:11 473,600 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-03-16 14:40:32 2,676,224 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:02 2,676,224 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:40:45 2,846,720 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:03 2,846,720 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:40:52 563,712 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:04 563,712 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:40:59 567,296 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:05 567,296 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:41:05 576,000 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:05 576,000 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-08 21:38:53 577,024 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:06 577,024 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-08 21:38:55 577,536 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:07 577,536 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-08 21:38:56 577,536 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:07 577,536 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-08 21:38:57 578,560 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:08 578,560 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:41:37 578,560 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-11 13:46:11 578,560 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-03-16 14:41:41 145,920 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-06-11 13:46:12 145,920 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-03-16 14:41:45 159,232 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-06-11 13:46:12 159,232 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-03-16 14:41:50 364,544 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-06-11 13:46:12 364,544 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-03-16 14:41:55 178,176 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-06-11 13:46:13 178,176 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-03-16 14:41:18 223,232 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-06-11 13:46:09 223,232 ----a-w D:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2008-05-06 19:53:43 2,048 --s-a-w D:\WINDOWS\bootstat.dat
+ 2008-06-28 12:22:17 2,048 --s-a-w D:\WINDOWS\bootstat.dat
+ 2008-06-13 13:10:50 272,128 ------w D:\WINDOWS\Driver Cache\i386\bthport.sys
- 2000-08-31 06:00:00 73,728 ----a-w D:\WINDOWS\fdsv.exe
+ 2000-08-31 06:00:00 89,504 ----a-w D:\WINDOWS\fdsv.exe
+ 2008-03-01 13:06:20 124,928 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
+ 2008-03-01 13:06:21 347,136 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
+ 2008-03-01 13:06:21 214,528 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
+ 2008-03-01 13:06:21 133,120 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
+ 2008-03-01 13:06:21 63,488 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
+ 2008-02-29 08:55:23 70,656 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2008-03-01 13:06:21 153,088 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
+ 2008-03-01 13:06:21 230,400 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
+ 2008-03-01 13:06:22 383,488 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
+ 2008-03-01 13:06:22 384,512 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
+ 2008-03-01 13:06:24 6,066,176 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
+ 2008-03-01 13:06:24 44,544 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
+ 2008-03-01 13:06:25 267,776 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
+ 2008-02-22 10:00:51 13,824 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
+ 2008-02-29 08:55:46 625,664 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
+ 2008-03-01 13:06:25 27,648 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
+ 2008-03-01 13:06:26 459,264 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
+ 2008-03-01 13:06:26 52,224 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
+ 2008-03-01 16:36:30 3,591,680 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
+ 2008-03-01 13:06:28 478,208 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
+ 2008-03-01 13:06:28 193,024 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
+ 2008-03-01 13:06:29 671,232 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
+ 2008-03-01 13:06:29 102,912 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
+ 2008-03-01 13:06:29 44,544 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
+ 2008-03-01 13:06:29 105,984 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\url.dll
+ 2008-03-01 13:06:30 1,159,680 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
+ 2008-03-01 13:06:30 233,472 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
+ 2008-03-01 13:06:31 826,368 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
+ 2008-06-03 19:21:48 21,342 ----a-r D:\WINDOWS\Installer\{015983A5-EAD2-4D06-8AA3-A5E3E8DDE815}\ARPPRODUCTICON.exe
+ 2008-06-03 19:21:48 61,440 ----a-r D:\WINDOWS\Installer\{015983A5-EAD2-4D06-8AA3-A5E3E8DDE815}\NewShortcut3_F3536A0AB5814C33A03D5A508BFBEB89.exe
+ 2008-06-03 19:21:48 61,440 ----a-r D:\WINDOWS\Installer\{015983A5-EAD2-4D06-8AA3-A5E3E8DDE815}\NewShortcut4_5E4862AFBE9C4B18A47FD3EF3DF92F06.exe
+ 2008-06-03 19:21:48 61,440 ----a-r D:\WINDOWS\Installer\{015983A5-EAD2-4D06-8AA3-A5E3E8DDE815}\NewShortcut5_1D96F5E278E84C218CB266CBB748EB31.exe
+ 2008-06-27 17:34:21 6,318 ----a-r D:\WINDOWS\Installer\{1D171963-9063-4423-898B-8EC4F1F190B7}\ARPPRODUCTICON.exe
+ 2008-06-27 17:34:22 6,318 ----a-r D:\WINDOWS\Installer\{1D171963-9063-4423-898B-8EC4F1F190B7}\NewShortcut1_1D17196390634423898B8EC4F1F190B7_1.exe
+ 2008-06-27 17:34:21 6,318 ----a-r D:\WINDOWS\Installer\{1D171963-9063-4423-898B-8EC4F1F190B7}\NewShortcut2_1D17196390634423898B8EC4F1F190B7.exe
+ 2008-06-09 11:35:00 45,056 ----a-r D:\WINDOWS\Installer\{9A657E90-E2B7-44DE-8929-055948162595}\ARPPRODUCTICON.exe
+ 2008-06-09 11:35:00 45,056 ----a-r D:\WINDOWS\Installer\{9A657E90-E2B7-44DE-8929-055948162595}\BaseShortcut_621025AE3510478EBC271A647150976F.exe
+ 2008-05-30 13:59:36 295,606 ----a-r D:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
- 2000-08-31 06:00:00 28,160 ----a-w D:\WINDOWS\Nircmd.exe
+ 2000-08-31 06:00:00 28,672 ----a-w D:\WINDOWS\Nircmd.exe
+ 2008-06-28 07:36:30 6,974 ----a-w D:\WINDOWS\SoftwareDistribution\EventCache\{E0572FBD-713F-44BF-A39A-0FFB6580855A}.bin
- 2008-03-01 13:06:20 124,928 ----a-w D:\WINDOWS\system32\advpack.dll
+ 2008-04-23 04:16:28 124,928 ----a-w D:\WINDOWS\system32\advpack.dll
+ 2006-05-13 03:06:02 696,320 ----a-w D:\WINDOWS\system32\dk\calling.com
+ 2003-03-16 13:49:00 33,792 ----a-w D:\WINDOWS\system32\dk\d.dll
+ 2007-09-05 09:02:02 61,440 ----a-w D:\WINDOWS\system32\dk\lam1.exe
+ 2007-09-05 09:02:02 90,112 ----a-w D:\WINDOWS\system32\dk\lam2.exe
+ 2007-09-05 09:02:04 19,968 ----a-w D:\WINDOWS\system32\dk\lam3.exe
+ 2007-09-05 09:02:06 17,408 ----a-w D:\WINDOWS\system32\dk\lam4.exe
+ 2007-09-05 09:02:08 31,744 ----a-w D:\WINDOWS\system32\dk\lam5.exe
+ 2007-11-25 01:16:46 35,542 ----a-w D:\WINDOWS\system32\dk\lmz.exe
+ 2006-03-15 19:51:32 18,432 ----a-w D:\WINDOWS\system32\dk\msn.dll
+ 2003-04-19 09:43:12 86,016 ----a-w D:\WINDOWS\system32\dk\reg.dll
+ 2002-08-27 16:03:14 29,184 ----a-w D:\WINDOWS\system32\dk\systemac.dll
- 2008-03-01 13:06:20 124,928 -c--a-w D:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-04-23 04:16:28 124,928 -c--a-w D:\WINDOWS\system32\dllcache\advpack.dll
- 2004-08-03 22:56:44 561,179 -c--a-w D:\WINDOWS\system32\dllcache\dao360.dll
+ 2008-03-25 04:50:25 554,008 -c--a-w D:\WINDOWS\system32\dllcache\dao360.dll
- 2008-03-01 13:06:21 347,136 -c--a-w D:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 -c--a-w D:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 -c--a-w D:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 -c--a-w D:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-03-01 13:06:21 133,120 -c--a-w D:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-23 04:16:28 133,120 -c--a-w D:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-03-01 13:06:21 63,488 -c----w D:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-04-23 04:16:28 63,488 -c----w D:\WINDOWS\system32\dllcache\icardie.dll
- 2008-02-29 08:55:23 70,656 -c--a-w D:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 -c--a-w D:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 -c--a-w D:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 -c--a-w D:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-03-01 13:06:21 230,400 -c--a-w D:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 -c--a-w D:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-02-15 05:44:25 161,792 -c--a-w D:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-04-20 05:07:51 161,792 -c--a-w D:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-03-01 13:06:22 383,488 -c----w D:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-04-23 04:16:28 383,488 -c----w D:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-03-01 13:06:22 384,512 -c--a-w D:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 -c--a-w D:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-03-01 13:06:24 6,066,176 -c----w D:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-04-23 04:16:28 6,066,176 -c----w D:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-03-01 13:06:24 44,544 -c--a-w D:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-04-23 04:16:28 44,544 -c--a-w D:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-03-01 13:06:25 267,776 -c----w D:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-04-23 04:16:28 267,776 -c----w D:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-02-22 10:00:51 13,824 -c----w D:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-04-22 07:39:58 13,824 -c----w D:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-02-29 08:55:46 625,664 -c--a-w D:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-04-22 07:40:18 625,664 -c--a-w D:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-03-01 13:06:25 27,648 -c--a-w D:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 -c--a-w D:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-08-03 22:56:44 294,400 -c--a-w D:\WINDOWS\system32\dllcache\msctf.dll
+ 2008-02-26 11:59:50 294,912 -c--a-w D:\WINDOWS\system32\dllcache\msctf.dll
- 2004-08-03 22:56:44 512,029 -c--a-w D:\WINDOWS\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:28 518,944 -c--a-w D:\WINDOWS\system32\dllcache\msexch40.dll
- 2004-08-03 22:56:44 319,517 -c--a-w D:\WINDOWS\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 -c--a-w D:\WINDOWS\system32\dllcache\msexcl40.dll
- 2008-03-01 13:06:26 459,264 -c----w D:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-04-23 04:16:28 459,264 -c----w D:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-03-01 13:06:26 52,224 -c----w D:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-04-23 04:16:28 52,224 -c----w D:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-03-01 16:36:30 3,591,680 -c--a-w D:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-23 20:16:30 3,591,680 -c--a-w D:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-03-01 13:06:28 478,208 -c--a-w D:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 -c--a-w D:\WINDOWS\system32\dllcache\mshtmled.dll
- 2004-08-03 22:56:44 1,507,356 -c--a-w D:\WINDOWS\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 -c--a-w D:\WINDOWS\system32\dllcache\msjet40.dll
- 2004-07-17 09:34:48 358,976 -c--a-w D:\WINDOWS\system32\dllcache\msjetol1.dll
+ 2008-03-25 04:50:40 355,112 -c--a-w D:\WINDOWS\system32\dllcache\msjetol1.dll
- 2004-08-03 22:56:44 151,583 -c--a-w D:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-03-27 08:12:54 151,583 -c--a-w D:\WINDOWS\system32\dllcache\msjint40.dll
- 2004-08-03 22:56:44 53,279 -c--a-w D:\WINDOWS\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 60,192 -c--a-w D:\WINDOWS\system32\dllcache\msjter40.dll
- 2004-08-03 22:56:44 241,693 -c--a-w D:\WINDOWS\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 -c--a-w D:\WINDOWS\system32\dllcache\msjtes40.dll
- 2004-08-03 22:56:44 213,023 -c--a-w D:\WINDOWS\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:44 219,936 -c--a-w D:\WINDOWS\system32\dllcache\msltus40.dll
- 2004-08-03 22:56:44 348,189 -c--a-w D:\WINDOWS\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 -c--a-w D:\WINDOWS\system32\dllcache\mspbde40.dll
- 2008-03-01 13:06:28 193,024 -c--a-w D:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-23 04:16:28 193,024 -c--a-w D:\WINDOWS\system32\dllcache\msrating.dll
- 2004-08-03 22:56:44 421,919 -c--a-w D:\WINDOWS\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 -c--a-w D:\WINDOWS\system32\dllcache\msrd2x40.dll
- 2004-08-03 22:56:44 315,423 -c--a-w D:\WINDOWS\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 -c--a-w D:\WINDOWS\system32\dllcache\msrd3x40.dll
- 2004-08-03 22:56:44 552,989 -c--a-w D:\WINDOWS\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 -c--a-w D:\WINDOWS\system32\dllcache\msrepl40.dll
- 2004-08-03 22:56:44 258,077 -c--a-w D:\WINDOWS\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:55 264,992 -c--a-w D:\WINDOWS\system32\dllcache\mstext40.dll
- 2008-03-01 13:06:29 671,232 -c--a-w D:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-23 04:16:28 671,232 -c--a-w D:\WINDOWS\system32\dllcache\mstime.dll
- 2004-08-03 22:56:46 831,519 -c--a-w D:\WINDOWS\system32\dllcache\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 -c--a-w D:\WINDOWS\system32\dllcache\mswdat10.dll
- 2004-08-03 22:56:46 614,429 -c--a-w D:\WINDOWS\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 -c--a-w D:\WINDOWS\system32\dllcache\mswstr10.dll
- 2004-08-03 22:56:46 348,189 -c--a-w D:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 -c--a-w D:\WINDOWS\system32\dllcache\msxbde40.dll
- 2008-03-01 13:06:29 102,912 -c--a-w D:\WINDOWS\system32\dllcache\occache.dll
+ 2008-04-23 04:16:28 102,912 -c--a-w D:\WINDOWS\system32\dllcache\occache.dll
- 2008-03-01 13:06:29 44,544 -c--a-w D:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 -c--a-w D:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 -c--a-w D:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c--a-w D:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c--a-w D:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w D:\WINDOWS\system32\dllcache\rmcast.sys
- 2008-03-01 13:06:29 105,984 -c--a-w D:\WINDOWS\system32\dllcache\url.dll
+ 2008-04-23 04:16:28 105,984 -c--a-w D:\WINDOWS\system32\dllcache\url.dll
- 2008-03-01 13:06:30 1,159,680 -c--a-w D:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 -c--a-w D:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-03-01 13:06:30 233,472 -c--a-w D:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-04-23 04:16:29 233,472 -c--a-w D:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-03-01 13:06:31 826,368 -c--a-w D:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-04-23 04:16:29 826,368 -c--a-w D:\WINDOWS\system32\dllcache\wininet.dll
- 2008-03-01 13:06:21 347,136 ----a-w D:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 ----a-w D:\WINDOWS\system32\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 ----a-w D:\WINDOWS\system32\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 ----a-w D:\WINDOWS\system32\dxtrans.dll
- 2008-03-01 13:06:21 133,120 ----a-w D:\WINDOWS\system32\extmgr.dll
+ 2008-04-23 04:16:28 133,120 ----a-w D:\WINDOWS\system32\extmgr.dll
- 2008-04-13 21:16:03 259,840 ----a-w D:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-06-12 08:10:04 264,616 ----a-w D:\WINDOWS\system32\FNTCACHE.DAT
- 2008-03-01 13:06:21 63,488 ----a-w D:\WINDOWS\system32\icardie.dll
+ 2008-04-23 04:16:28 63,488 ----a-w D:\WINDOWS\system32\icardie.dll
- 2008-02-29 08:55:23 70,656 ----a-w D:\WINDOWS\system32\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 ----a-w D:\WINDOWS\system32\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 ----a-w D:\WINDOWS\system32\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 ----a-w D:\WINDOWS\system32\ieakeng.dll
- 2008-03-01 13:06:21 230,400 ----a-w D:\WINDOWS\system32\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 ----a-w D:\WINDOWS\system32\ieaksie.dll
- 2008-02-15 05:44:25 161,792 ----a-w D:\WINDOWS\system32\ieakui.dll
+ 2008-04-20 05:07:51 161,792 ----a-w D:\WINDOWS\system32\ieakui.dll
- 2008-03-01 13:06:22 383,488 ----a-w D:\WINDOWS\system32\ieapfltr.dll
+ 2008-04-23 04:16:28 383,488 ----a-w D:\WINDOWS\system32\ieapfltr.dll
- 2008-03-01 13:06:22 384,512 ----a-w D:\WINDOWS\system32\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 ----a-w D:\WINDOWS\system32\iedkcs32.dll
- 2008-03-01 13:06:24 6,066,176 ----a-w D:\WINDOWS\system32\ieframe.dll
+ 2008-04-23 04:16:28 6,066,176 ----a-w D:\WINDOWS\system32\ieframe.dll
- 2008-03-01 13:06:24 44,544 ----a-w D:\WINDOWS\system32\iernonce.dll
+ 2008-04-23 04:16:28 44,544 ----a-w D:\WINDOWS\system32\iernonce.dll
- 2008-03-01 13:06:25 267,776 ----a-w D:\WINDOWS\system32\iertutil.dll
+ 2008-04-23 04:16:28 267,776 ----a-w D:\WINDOWS\system32\iertutil.dll
- 2008-02-22 10:00:51 13,824 ----a-w D:\WINDOWS\system32\ieudinit.exe
+ 2008-04-22 07:39:58 13,824 ----a-w D:\WINDOWS\system32\ieudinit.exe
- 2008-03-01 13:06:25 27,648 ----a-w D:\WINDOWS\system32\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 ----a-w D:\WINDOWS\system32\jsproxy.dll
- 2004-08-03 22:56:44 294,400 ----a-w D:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 ----a-w D:\WINDOWS\system32\msctf.dll
- 2004-08-03 22:56:44 512,029 ----a-w D:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w D:\WINDOWS\system32\msexch40.dll
- 2004-08-03 22:56:44 319,517 ----a-w D:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w D:\WINDOWS\system32\msexcl40.dll
- 2008-03-01 13:06:26 459,264 ----a-w D:\WINDOWS\system32\msfeeds.dll
+ 2008-04-23 04:16:28 459,264 ----a-w D:\WINDOWS\system32\msfeeds.dll
- 2008-03-01 13:06:26 52,224 ----a-w D:\WINDOWS\system32\msfeedsbs.dll
+ 2008-04-23 04:16:28 52,224 ----a-w D:\WINDOWS\system32\msfeedsbs.dll
- 2008-03-01 16:36:30 3,591,680 ----a-w D:\WINDOWS\system32\mshtml.dll
+ 2008-04-23 20:16:30 3,591,680 ----a-w D:\WINDOWS\system32\mshtml.dll
- 2008-03-01 13:06:28 478,208 ----a-w D:\WINDOWS\system32\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 ----a-w D:\WINDOWS\system32\mshtmled.dll
- 2004-08-03 22:56:44 1,507,356 ----a-w D:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w D:\WINDOWS\system32\msjet40.dll
- 2004-07-17 09:34:48 358,976 ----a-w D:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w D:\WINDOWS\system32\msjetoledb40.dll
- 2004-08-03 22:56:44 151,583 ----a-w D:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 ----a-w D:\WINDOWS\system32\msjint40.dll
- 2004-08-03 22:56:44 53,279 ----a-w D:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w D:\WINDOWS\system32\msjter40.dll
- 2004-08-03 22:56:44 241,693 ----a-w D:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w D:\WINDOWS\system32\msjtes40.dll
- 2004-08-03 22:56:44 213,023 ----a-w D:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w D:\WINDOWS\system32\msltus40.dll
- 2004-08-03 22:56:44 348,189 ----a-w D:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w D:\WINDOWS\system32\mspbde40.dll
- 2008-03-01 13:06:28 193,024 ----a-w D:\WINDOWS\system32\msrating.dll
+ 2008-04-23 04:16:28 193,024 ----a-w D:\WINDOWS\system32\msrating.dll
- 2004-08-03 22:56:44 421,919 ----a-w D:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w D:\WINDOWS\system32\msrd2x40.dll
- 2004-08-03 22:56:44 315,423 ----a-w D:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w D:\WINDOWS\system32\msrd3x40.dll
- 2004-08-03 22:56:44 552,989 ----a-w D:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w D:\WINDOWS\system32\msrepl40.dll
- 2004-08-03 22:56:44 258,077 ----a-w D:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w D:\WINDOWS\system32\mstext40.dll
- 2008-03-01 13:06:29 671,232 ----a-w D:\WINDOWS\system32\mstime.dll
+ 2008-04-23 04:16:28 671,232 ----a-w D:\WINDOWS\system32\mstime.dll
- 2004-08-03 22:56:46 831,519 ----a-w D:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w D:\WINDOWS\system32\mswdat10.dll
- 2004-08-03 22:56:46 614,429 ----a-w D:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w D:\WINDOWS\system32\mswstr10.dll
- 2004-08-03 22:56:46 348,189 ----a-w D:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w D:\WINDOWS\system32\msxbde40.dll
+ 2008-03-01 17:17:23 176,128 ----a-w D:\WINDOWS\system32\nvudisp.exe
- 2008-03-01 13:06:29 102,912 ----a-w D:\WINDOWS\system32\occache.dll
+ 2008-04-23 04:16:28 102,912 ----a-w D:\WINDOWS\system32\occache.dll
- 2008-03-01 13:06:29 44,544 ----a-w D:\WINDOWS\system32\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 ----a-w D:\WINDOWS\system32\pngfilt.dll
- 2006-12-10 13:10:02 14,640 ------w D:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w D:\WINDOWS\system32\spmsg.dll
- 2008-03-01 13:06:29 105,984 ----a-w D:\WINDOWS\system32\url.dll
+ 2008-04-23 04:16:28 105,984 ----a-w D:\WINDOWS\system32\url.dll
- 2008-03-01 13:06:30 1,159,680 ----a-w D:\WINDOWS\system32\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 ----a-w D:\WINDOWS\system32\urlmon.dll
- 2008-03-01 13:06:30 233,472 ----a-w D:\WINDOWS\system32\webcheck.dll
+ 2008-04-23 04:16:29 233,472 ----a-w D:\WINDOWS\system32\webcheck.dll
+ 2005-09-22 21:49:12 95,744 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-12-01 20:56:00 96,256 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-01 20:54:32 479,232 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2005-09-22 23:16:02 1,093,632 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-22 23:16:06 1,079,808 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-22 23:16:08 69,632 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-22 23:16:10 57,344 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-12-01 22:25:52 1,101,824 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-01 22:25:56 1,093,120 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 22:25:58 69,632 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-01 22:26:00 57,856 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 22:08:00 40,960 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 22:08:00 45,056 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 22:08:00 65,536 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 22:08:00 57,344 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 22:08:00 61,440 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 22:08:00 61,440 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 22:08:00 61,440 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 22:08:00 49,152 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 22:08:00 49,152 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-01 22:46:44 65,536 ----a-w D:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-23 21:38 68856]
"ares"="D:\Program Files\Ares\Ares.exe" [2007-07-16 23:54 961536]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"EA Core"="D:\Program Files\Electronic Arts\EA Downloader\Core.exe" [2006-08-16 12:33 1826816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"DAEMON Tools-1033"="D:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-23 19:18 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=D:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 10:50 155648 D:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"D:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\WINDOWS\\system32\\lxkchkv.exe"=
"D:\\WINDOWS\\system32\\dk\\calling.com"=
"C:\\SPSS\\spss.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17380:TCP"= 17380:TCP:NortonAV
"13806:TCP"= 13806:TCP:NortonAV
"15789:TCP"= 15789:TCP:NortonAV
R2 acedrv10;acedrv10;D:\WINDOWS\system32\drivers\acedrv10.sys [2007-07-24 09:45]
R2 acehlp10;acehlp10;D:\WINDOWS\system32\drivers\acehlp10.sys [2007-07-11 10:20]
R2 PowerManager;Power Manager;D:\WINDOWS\svchost.exe []
R3 klim5;Kaspersky Anti-Virus NDIS Filter;D:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;D:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 23:04]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"D:\Program Files\MSN Messenger\usnsvc.exe" [2007-01-19 13:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0693c984-53cc-11dc-97c0-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c66ad34-5006-11dc-9bda-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1b0244f4-55f5-11dc-bcb3-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a94f570-7038-11dc-ac81-971d5fe1e1d2}]
\Shell\AutoOpen\command - J:\.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
\Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3aa86754-5574-11dc-b7bc-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{693805c0-65fd-11dc-8ec8-a8783cb692d6}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9b802e4-6c38-11dc-8921-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9b802e5-6c38-11dc-8921-806d6172696f}]
\Shell\AutoRun\command - H:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ddb9ccf0-4f1f-11dc-a32d-c62ea26f04d2}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e72a6ba4-5394-11dc-9fce-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed8d4574-5175-11dc-a4e0-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee1772d0-813a-11dc-ac9b-cb6bcd068dd0}]
\Shell\AutoOpen\command - J:\.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
\Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe2abfc4-56b2-11dc-b76a-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
*Newly Created Service* - POWERMANAGER
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{72637363-7069-7374-652E-336D65747300}]
D:\WINDOWS\system32\cscripts.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-28 11:59:13 D:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- D:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-27 16:00:00 D:\WINDOWS\Tasks\Norton Security Scan.job"
- D:\Program Files\Norton Security Scan\Nss.exe
"2008-06-28 12:22:53 D:\WINDOWS\Tasks\XoftSpySE 2.job"
- D:\Program Files\XoftSpySE\XoftSpy.exe
"2008-06-28 01:04:14 D:\WINDOWS\Tasks\XoftSpySE.job"
- D:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-06-28 14:24:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
D:\WINDOWS\system32\WgaTray.exe
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-28 14:29:36 - machine was rebooted [xx]
ComboFix-quarantined-files.txt 2008-06-28 12:29:19
ComboFix2.txt 2008-04-13 21:38:35
ComboFix3.txt 2008-04-12 12:52:38
ComboFix4.txt 2008-03-16 12:11:16
ComboFix5.txt 2008-03-15 19:38:59
Pre-Run: 612,585,472 bytes free
Post-Run: 703,475,712 bytes free
657 --- E O F --- 2008-06-28 01:22:11
|