هذا التقرير
ComboFix 09-03-02.03 - user 03/03/2009 21:39:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.446.168 [GMT 3:00]
Running from: c:\documents and settings\user\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-02-03 to 2009-03-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-03 18:42 --------- d-----w c:\documents and settings\user\Application Data\DMCache
2009-03-03 14:56 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-03 12:42 663,584 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-03 12:42 5,444 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-03 12:41 40,444 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-03 12:41 4,770,336 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-02 15:46 --------- d-----w c:\documents and settings\user\Application Data\IDM
2009-03-02 15:42 --------- d-----w c:\program files\Internet Download Manager
2009-02-26 08:51 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 18:37 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 18:37 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-01-14 19:30 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-14 19:30 --------- d-----w c:\program files\mpegable
2009-01-14 16:10 --------- d-----w c:\documents and settings\user\Application Data\CyberLink
2009-01-03 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
.
((((((((((((((((((((((((((((( snapshot_Sun 10-26-2008_22.36.55.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-14 15:52:22 121,856 ----a-w c:\windows\$hf_mig$\KB915865\SP2QFE\xmllite.dll
+ 2005-10-12 23:12:25 14,048 ----a-w c:\windows\$hf_mig$\KB915865\spmsg.dll
+ 2005-10-12 23:12:26 213,216 ----a-w c:\windows\$hf_mig$\KB915865\spuninst.exe
+ 2005-10-12 23:12:25 22,752 ----a-w c:\windows\$hf_mig$\KB915865\update\spcustom.dll
+ 2005-10-12 23:12:28 716,000 ----a-w c:\windows\$hf_mig$\KB915865\update\update.exe
+ 2005-10-12 23:12:33 371,424 ----a-w c:\windows\$hf_mig$\KB915865\update\updspapi.dll
+ 2007-07-12 23:28:07 765,952 ----a-w c:\windows\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 00:57:34 14,560 ----a-w c:\windows\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 00:57:39 213,216 ----a-w c:\windows\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 00:57:32 22,752 ----a-w c:\windows\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 00:57:56 712,928 ----a-w c:\windows\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 00:58:46 369,376 ----a-w c:\windows\$hf_mig$\KB938127-IE7\update\updspapi.dll
+ 2008-05-27 17:31:17 765,952 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\SP2QFE\vgx.dll
+ 2007-03-06 00:57:33 14,560 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\spmsg.dll
+ 2007-03-06 00:57:38 213,216 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\spuninst.exe
+ 2007-03-06 00:57:32 22,752 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\spcustom.dll
+ 2007-03-06 00:57:55 712,928 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\update.exe
+ 2007-03-06 00:58:46 369,376 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\updspapi.dll
+ 2008-10-03 09:56:58 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP2QFE\strmdll.dll
+ 2008-10-03 10:03:03 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP3GDR\strmdll.dll
+ 2008-10-03 09:49:34 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP3QFE\strmdll.dll
+ 2007-11-30 12:39:01 17,784 ----a-w c:\windows\$hf_mig$\KB954600\spmsg.dll
+ 2007-11-30 12:39:01 231,288 ----a-w c:\windows\$hf_mig$\KB954600\spuninst.exe
+ 2007-11-30 12:39:01 26,488 ----a-w c:\windows\$hf_mig$\KB954600\update\spcustom.dll
+ 2007-11-30 12:39:03 752,504 ----a-w c:\windows\$hf_mig$\KB954600\update\update.exe
+ 2007-11-30 12:39:04 380,792 ----a-w c:\windows\$hf_mig$\KB954600\update\updspapi.dll
+ 2008-09-04 16:33:03 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP2QFE\msxml3.dll
+ 2008-09-04 17:15:18 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3GDR\msxml3.dll
+ 2008-09-04 17:12:05 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:18:09 17,784 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:18:09 231,288 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:18:09 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 12:39:03 752,504 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 10:04:32 380,792 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-10-22 09:47:25 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP2QFE\tzchange.exe
+ 2008-10-23 10:06:59 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3GDR\tzchange.exe
+ 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:01 17,784 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:01 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:01 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:03 752,504 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:04 380,792 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-10-23 12:50:15 284,160 ----a-w c:\windows\$hf_mig$\KB956802\SP2QFE\gdi32.dll
+ 2008-10-23 12:36:22 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3GDR\gdi32.dll
+ 2008-10-23 12:42:41 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 12:58:08 17,784 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 12:58:09 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 12:58:08 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:34:22 752,504 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:34:30 380,792 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-10-24 11:25:29 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP2QFE\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ----a-w c:\windows\$hf_mig$\KB957097\SP3GDR\mrxsmb.sys
+ 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 12:58:08 17,784 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 12:58:09 231,288 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 12:58:08 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 12:58:12 752,504 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 12:58:19 380,792 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-10-16 19:31:55 124,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\advpack.dll
+ 2008-10-16 19:31:55 347,136 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtmsft.dll
+ 2008-10-16 19:31:55 214,528 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtrans.dll
+ 2008-10-16 19:31:55 132,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\extmgr.dll
+ 2008-10-16 19:31:55 63,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\icardie.dll
+ 2008-10-16 12:46:08 70,656 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ie4uinit.exe
+ 2008-10-16 19:31:55 153,088 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakeng.dll
+ 2008-10-16 19:31:55 230,400 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieaksie.dll
+ 2008-10-15 06:33:26 161,792 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dat
+ 2008-10-16 19:31:55 380,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dll
+ 2008-10-16 19:31:56 388,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-16 19:31:57 6,068,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieframe.dll
+ 2008-10-16 19:31:57 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iernonce.dll
+ 2008-10-16 19:31:57 267,776 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iertutil.dll
+ 2008-10-16 12:46:08 13,824 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieudinit.exe
+ 2008-10-15 06:34:58 633,632 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
+ 2008-10-16 19:31:58 27,648 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\jsproxy.dll
+ 2008-10-16 19:31:58 459,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeeds.dll
+ 2008-10-16 19:31:58 52,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeedsbs.dll
+ 2008-10-16 19:32:01 3,595,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
+ 2008-10-16 19:32:02 477,696 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtmled.dll
+ 2008-10-16 19:32:02 193,024 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msrating.dll
+ 2008-10-16 19:32:02 671,232 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mstime.dll
+ 2008-10-16 19:32:02 102,912 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\occache.dll
+ 2008-10-16 19:32:02 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\pngfilt.dll
+ 2008-10-16 19:32:02 105,984 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\url.dll
+ 2008-10-16 19:32:03 1,163,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\urlmon.dll
+ 2008-10-16 19:32:03 233,472 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\webcheck.dll
+ 2008-10-16 19:32:03 827,904 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
+ 2007-03-06 00:57:33 14,560 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spmsg.dll
+ 2007-03-06 00:57:38 213,216 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spuninst.exe
+ 2007-03-06 00:57:32 22,752 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\spcustom.dll
+ 2007-03-06 00:57:56 712,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\update.exe
+ 2007-03-06 00:58:46 369,376 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\updspapi.dll
+ 2008-10-16 10:22:42 1,024,000 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\browseui.dll
+ 2008-10-16 10:22:33 151,040 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\cdfview.dll
+ 2008-10-16 10:22:35 1,053,696 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\danim.dll
+ 2008-10-16 10:22:35 357,888 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\dxtmsft.dll
+ 2008-10-16 10:22:36 205,312 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\dxtrans.dll
+ 2008-10-16 10:22:36 55,808 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\extmgr.dll
+ 2008-10-15 14:18:21 18,432 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\iedw.exe
+ 2008-10-16 10:22:36 251,392 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\iepeers.dll
+ 2008-10-16 10:22:36 96,256 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\inseng.dll
+ 2008-10-16 10:22:40 16,384 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\jsproxy.dll
+ 2008-10-16 10:22:45 3,088,384 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\mshtml.dll
+ 2008-10-16 10:22:40 449,024 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\mshtmled.dll
+ 2008-10-16 10:22:37 146,432 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\msrating.dll
+ 2008-10-16 10:22:37 532,480 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\mstime.dll
+ 2008-10-16 10:22:37 39,424 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\pngfilt.dll
+ 2008-10-16 10:22:39 1,499,136 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\shdocvw.dll
+ 2008-10-16 10:22:41 474,112 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\shlwapi.dll
+ 2008-10-15 17:05:22 690,176 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\spru0401.dll
+ 2008-10-16 10:22:43 617,984 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\urlmon.dll
+ 2008-10-16 10:22:40 666,112 ----a-w c:\windows\$hf_mig$\KB958215\SP2QFE\wininet.dll
+ 2008-10-16 01:00:24 3,088,896 ----a-w c:\windows\$hf_mig$\KB958215\SP3GDR\mshtml.dll
+ 2008-10-16 01:00:22 1,499,136 ----a-w c:\windows\$hf_mig$\KB958215\SP3GDR\shdocvw.dll
+ 2008-10-16 01:00:23 617,472 ----a-w c:\windows\$hf_mig$\KB958215\SP3GDR\urlmon.dll
+ 2008-10-16 01:00:23 664,576 ----a-w c:\windows\$hf_mig$\KB958215\SP3GDR\wininet.dll
+ 2008-10-16 03:33:22 3,088,896 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\mshtml.dll
+ 2008-10-16 01:03:19 1,499,136 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\shdocvw.dll
+ 2008-10-16 01:03:19 617,984 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\urlmon.dll
+ 2008-10-16 01:03:19 665,600 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
+ 2007-11-30 12:39:01 17,784 ----a-w c:\windows\$hf_mig$\KB958215\spmsg.dll
+ 2007-11-30 12:39:01 231,288 ----a-w c:\windows\$hf_mig$\KB958215\spuninst.exe
+ 2007-11-30 12:39:01 26,488 ----a-w c:\windows\$hf_mig$\KB958215\update\spcustom.dll
+ 2007-11-30 11:18:13 752,504 ----a-w c:\windows\$hf_mig$\KB958215\update\update.exe
+ 2008-07-09 07:34:30 380,792 ----a-w c:\windows\$hf_mig$\KB958215\update\updspapi.dll
+ 2008-12-11 10:24:44 333,184 ----a-w c:\windows\$hf_mig$\KB958687\SP2QFE\srv.sys
+ 2008-12-11 10:57:09 333,952 ----a-w c:\windows\$hf_mig$\KB958687\SP3GDR\srv.sys
+ 2008-12-11 12:33:59 333,952 ----a-w c:\windows\$hf_mig$\KB958687\SP3QFE\srv.sys
+ 2007-11-30 12:39:01 17,784 ----a-w c:\windows\$hf_mig$\KB958687\spmsg.dll
+ 2007-11-30 12:39:01 231,288 ----a-w c:\windows\$hf_mig$\KB958687\spuninst.exe
+ 2007-11-30 12:39:01 26,488 ----a-w c:\windows\$hf_mig$\KB958687\update\spcustom.dll
+ 2007-11-30 12:39:03 752,504 ----a-w c:\windows\$hf_mig$\KB958687\update\update.exe
+ 2007-11-30 12:39:04 380,792 ----a-w c:\windows\$hf_mig$\KB958687\update\updspapi.dll
+ 2008-12-13 06:27:09 3,594,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
+ 2007-03-06 00:57:33 14,560 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spmsg.dll
+ 2007-03-06 00:57:38 213,216 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spuninst.exe
+ 2007-03-06 00:57:32 22,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\spcustom.dll
+ 2007-03-06 00:57:55 712,928 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\update.exe
+ 2007-03-06 00:58:46 369,376 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\updspapi.dll
+ 2008-12-12 17:27:59 3,088,384 ----a-w c:\windows\$hf_mig$\KB960714\SP2QFE\mshtml.dll
+ 2008-12-12 17:00:59 3,088,896 ----a-w c:\windows\$hf_mig$\KB960714\SP3GDR\mshtml.dll
+ 2008-12-12 17:14:16 3,088,896 ----a-w c:\windows\$hf_mig$\KB960714\SP3QFE\mshtml.dll
+ 2007-11-30 12:39:01 17,784 ----a-w c:\windows\$hf_mig$\KB960714\spmsg.dll
+ 2007-11-30 12:39:01 231,288 ----a-w c:\windows\$hf_mig$\KB960714\spuninst.exe
+ 2007-11-30 12:39:01 26,488 ----a-w c:\windows\$hf_mig$\KB960714\update\spcustom.dll
+ 2008-07-09 07:34:22 752,504 ----a-w c:\windows\$hf_mig$\KB960714\update\update.exe
+ 2007-11-30 12:39:04 380,792 ----a-w c:\windows\$hf_mig$\KB960714\update\updspapi.dll
+ 2008-07-09 07:34:18 17,784 ----a-w c:\windows\$hf_mig$\KB960715\spmsg.dll
+ 2008-07-09 07:34:19 231,288 ----a-w c:\windows\$hf_mig$\KB960715\spuninst.exe
+ 2008-07-09 07:34:18 26,488 ----a-w c:\windows\$hf_mig$\KB960715\update\spcustom.dll
+ 2008-11-15 17:17:36 752,504 ----a-w c:\windows\$hf_mig$\KB960715\update\update.exe
+ 2008-07-09 07:34:30 380,792 ----a-w c:\windows\$hf_mig$\KB960715\update\updspapi.dll
+ 2008-07-03 13:02:34 8,446,464 ----a-w c:\windows\$hf_mig$\KB967715\SP2QFE\shell32.dll
+ 2008-02-15 22:03:08 690,176 ----a-w c:\windows\$hf_mig$\KB967715\SP2QFE\spru0401.dll
+ 2008-06-17 19:01:29 8,446,976 ----a-w c:\windows\$hf_mig$\KB967715\SP3GDR\shell32.dll
+ 2008-06-17 19:03:58 8,447,488 ----a-w c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:34:18 17,784 ----a-w c:\windows\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:34:19 231,288 ----a-w c:\windows\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:34:18 26,488 ----a-w c:\windows\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:34:22 752,504 ----a-w c:\windows\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:34:30 380,792 ----a-w c:\windows\$hf_mig$\KB967715\update\updspapi.dll
+ 2006-05-25 07:29:04 213,216 -c----w c:\windows\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe
+ 2006-05-25 07:29:04 371,424 -c----w c:\windows\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\updspapi.dll
+ 2006-05-24 09:32:48 213,216 -c----w c:\windows\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe
+ 2006-05-24 09:32:48 371,424 -c----w c:\windows\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\updspapi.dll
+ 2005-10-12 23:12:26 213,216 -c----w c:\windows\$NtUninstallKB915865$\spuninst\spuninst.exe
+ 2005-10-12 23:12:33 371,424 -c----w c:\windows\$NtUninstallKB915865$\spuninst\updspapi.dll
+ 2005-06-28 07:23:28 213,216 -c----w c:\windows\$NtUninstallKB939683$\spuninst\spuninst.exe
+ 2005-06-28 07:23:54 371,424 -c----w c:\windows\$NtUninstallKB939683$\spuninst\updspapi.dll
+ 2006-12-01 09:03:18 316,416 -c----w c:\windows\$NtUninstallKB939683$\unregmp2.exe
+ 2006-10-18 17:03:58 100,864 -c----w c:\windows\$NtUninstallKB952069_WM9$\logagent.exe
+ 2007-07-27 06:42:32 231,288 -c----w c:\windows\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe
+ 2007-07-27 06:41:48 382,840 -c----w c:\windows\$NtUninstallKB952069_WM9$\spuninst\updspapi.dll
+ 2006-10-18 18:47:20 937,984 -c----w c:\windows\$NtUninstallKB952069_WM9$\wmnetmgr.dll
+ 2006-10-18 18:47:22 2,450,944 -c----w c:\windows\$NtUninstallKB952069_WM9$\wmvcore.dll
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB954600$\spuninst\spuninst.exe
+ 2007-11-30 12:39:04 380,792 -c----w c:\windows\$NtUninstallKB954600$\spuninst\updspapi.dll
+ 2004-08-03 21:55:54 246,302 -c----w c:\windows\$NtUninstallKB954600$\strmdll.dll
+ 2004-08-03 21:55:46 1,236,480 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
+ 2007-11-30 11:18:09 231,288 -c----w c:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe
+ 2008-07-09 10:04:32 380,792 -c----w c:\windows\$NtUninstallKB955069$\spuninst\updspapi.dll
+ 2007-11-30 12:39:01 26,488 -c----w c:\windows\$NtUninstallKB955839$\spcustom.dll
+ 2007-11-30 12:39:01 17,784 -c----w c:\windows\$NtUninstallKB955839$\spmsg.dll
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB955839$\spuninst.exe
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB955839$\spuninst\spuninst.exe
+ 2007-11-30 12:39:04 380,792 -c----w c:\windows\$NtUninstallKB955839$\spuninst\updspapi.dll
+ 2007-11-30 12:39:03 752,504 -c----w c:\windows\$NtUninstallKB955839$\update.exe
+ 2007-11-30 12:39:04 380,792 -c----w c:\windows\$NtUninstallKB955839$\updspapi.dll
+ 2004-08-03 21:55:38 278,016 -c----w c:\windows\$NtUninstallKB956802$\gdi32.dll
+ 2008-07-08 12:58:09 231,288 -c----w c:\windows\$NtUninstallKB956802$\spuninst\spuninst.exe
+ 2008-07-09 07:34:30 380,792 -c----w c:\windows\$NtUninstallKB956802$\spuninst\updspapi.dll
+ 2004-08-03 20:15:18 451,456 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
+ 2008-07-08 12:58:09 231,288 -c----w c:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe
+ 2008-07-08 12:58:19 380,792 -c----w c:\windows\$NtUninstallKB957097$\spuninst\updspapi.dll
+ 2008-08-20 05:36:15 1,023,488 -c----w c:\windows\$NtUninstallKB958215$\browseui.dll
+ 2008-08-20 05:36:11 151,040 -c----w c:\windows\$NtUninstallKB958215$\cdfview.dll
+ 2008-08-20 05:36:11 1,053,696 -c----w c:\windows\$NtUninstallKB958215$\danim.dll
+ 2008-08-20 05:36:11 357,888 -c----w c:\windows\$NtUninstallKB958215$\dxtmsft.dll
+ 2008-08-20 05:36:12 205,312 -c----w c:\windows\$NtUninstallKB958215$\dxtrans.dll
+ 2008-08-20 05:36:12 55,808 -c----w c:\windows\$NtUninstallKB958215$\extmgr.dll
+ 2008-08-19 09:30:39 18,432 -c----w c:\windows\$NtUninstallKB958215$\iedw.exe
+ 2008-08-20 05:36:12 250,880 -c----w c:\windows\$NtUninstallKB958215$\iepeers.dll
+ 2008-08-20 05:36:12 96,256 -c----w c:\windows\$NtUninstallKB958215$\inseng.dll
+ 2008-08-20 05:36:14 16,384 -c----w c:\windows\$NtUninstallKB958215$\jsproxy.dll
+ 2008-08-20 05:36:17 3,081,216 -c----w c:\windows\$NtUninstallKB958215$\mshtml.dll
+ 2008-08-20 05:36:14 449,024 -c----w c:\windows\$NtUninstallKB958215$\mshtmled.dll
+ 2008-08-20 05:36:12 146,432 -c----w c:\windows\$NtUninstallKB958215$\msrating.dll
+ 2008-08-20 05:36:12 532,480 -c----w c:\windows\$NtUninstallKB958215$\mstime.dll
+ 2008-08-20 05:36:12 39,424 -c----w c:\windows\$NtUninstallKB958215$\pngfilt.dll
+ 2008-08-20 05:36:13 1,494,528 -c----w c:\windows\$NtUninstallKB958215$\shdocvw.dll
+ 2008-08-20 05:36:14 474,112 -c----w c:\windows\$NtUninstallKB958215$\shlwapi.dll
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB958215$\spuninst\spuninst.exe
+ 2008-07-09 07:34:30 380,792 -c----w c:\windows\$NtUninstallKB958215$\spuninst\updspapi.dll
+ 2008-08-20 05:36:15 614,912 -c----w c:\windows\$NtUninstallKB958215$\urlmon.dll
+ 2008-08-20 05:36:13 657,920 -c----w c:\windows\$NtUninstallKB958215$\wininet.dll
+ 2008-08-19 12:21:32 690,176 -c----w c:\windows\$NtUninstallKB958215$\xpsp3res.dll
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB958687$\spuninst\spuninst.exe
+ 2007-11-30 12:39:04 380,792 -c----w c:\windows\$NtUninstallKB958687$\spuninst\updspapi.dll
+ 2008-08-28 10:04:17 333,056 -c----w c:\windows\$NtUninstallKB958687$\srv.sys
+ 2008-10-16 10:37:28 3,080,704 -c----w c:\windows\$NtUninstallKB960714$\mshtml.dll
+ 2007-11-30 12:39:01 231,288 -c----w c:\windows\$NtUninstallKB960714$\spuninst\spuninst.exe
+ 2007-11-30 12:39:04 380,792 -c----w c:\windows\$NtUninstallKB960714$\spuninst\updspapi.dll
+ 2008-07-09 07:34:19 231,288 -c----w c:\windows\$NtUninstallKB960715$\spuninst\spuninst.exe
+ 2008-07-09 07:34:30 380,792 -c----w c:\windows\$NtUninstallKB960715$\spuninst\updspapi.dll
+ 2004-08-03 21:55:52 8,369,664 -c----w c:\windows\$NtUninstallKB967715$\shell32.dll
+ 2008-07-09 07:34:19 231,288 -c----w c:\windows\$NtUninstallKB967715$\spuninst\spuninst.exe
+ 2008-07-09 07:34:30 380,792 -c----w c:\windows\$NtUninstallKB967715$\spuninst\updspapi.dll
+ 2004-08-03 21:56:08 98,304 -c----w c:\windows\$NtUninstallscripten$\cscript.exe
+ 2001-09-19 12:00:00 45,083 -c----w c:\windows\$NtUninstallscripten$\dispex.dll
+ 2007-08-13 15:38:04 491,520 -c----w c:\windows\$NtUninstallscripten$\jscript.dll
+ 2004-08-03 21:55:50 159,744 -c----w c:\windows\$NtUninstallscripten$\scrobj.dll
+ 2004-08-03 21:55:50 151,552 -c----w c:\windows\$NtUninstallscripten$\scrrun.dll
+ 2005-06-28 07:23:26 213,216 -c----w c:\windows\$NtUninstallscripten$\spuninst\spuninst.exe
+ 2005-06-28 07:23:54 371,424 -c----w c:\windows\$NtUninstallscripten$\spuninst\updspapi.dll
+ 2007-08-13 15:54:10 413,696 -c----w c:\windows\$NtUninstallscripten$\vbscript.dll
+ 2004-08-03 21:56:36 114,688 -c----w c:\windows\$NtUninstallscripten$\wscript.exe
+ 2004-08-03 21:56:00 28,672 -c----w c:\windows\$NtUninstallscripten$\wshcon.dll
+ 2004-08-03 21:56:00 65,536 -c----w c:\windows\$NtUninstallscripten$\wshext.dll
+ 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2004-08-03 21:55:32 61,440 -c--a-w c:\windows\ie7\admparse.dll
+ 2004-08-03 21:55:32 99,840 -c--a-w c:\windows\ie7\advpack.dll
+ 2004-08-03 21:55:34 35,328 -c--a-w c:\windows\ie7\corpol.dll
+ 2004-08-03 21:55:34 28,672 -c--a-w c:\windows\ie7\custsat.dll
+ 2008-10-16 10:37:23 357,888 -c--a-w c:\windows\ie7\dxtmsft.dll
+ 2008-10-16 10:37:23 205,312 -c--a-w c:\windows\ie7\dxtrans.dll
+ 2008-10-16 10:37:23 55,808 -c--a-w c:\windows\ie7\extmgr.dll
+ 2004-08-03 21:55:38 38,912 -c--a-w c:\windows\ie7\hmmapi.dll
+ 2004-08-03 21:56:16 34,304 -c--a-w c:\windows\ie7\ie4uinit.exe
+ 2004-08-03 21:55:38 139,264 -c--a-w c:\windows\ie7\ieakeng.dll
+ 2004-08-03 21:55:38 216,064 -c--a-w c:\windows\ie7\ieaksie.dll
+ 2001-09-19 12:00:00 221,184 -c--a-w c:\windows\ie7\ieakui.dll
+ 2004-08-03 21:55:38 323,584 -c--a-w c:\windows\ie7\iedkcs32.dll
+ 2008-10-15 09:45:01 18,432 -c--a-w c:\windows\ie7\iedw.exe
+ 2004-08-03 21:55:38 81,920 -c--a-w c:\windows\ie7\ieencode.dll
+ 2008-10-16 10:37:24 250,880 -c--a-w c:\windows\ie7\iepeers.dll
+ 2004-08-03 21:55:38 48,128 -c--a-w c:\windows\ie7\iernonce.dll
+ 2004-08-03 21:55:38 62,976 -c--a-w c:\windows\ie7\iesetup.dll
+ 2004-08-03 21:56:16 93,184 -c--a-w c:\windows\ie7\iexplore.exe
+ 2004-08-03 21:55:38 35,840 -c--a-w c:\windows\ie7\imgutil.dll
+ 2008-10-16 10:37:24 96,256 -c--a-w c:\windows\ie7\inseng.dll
+ 2007-12-18 14:41:00 450,560 -c--a-w c:\windows\ie7\jscript.dll
+ 2008-10-16 10:37:26 16,384 -c--a-w c:\windows\ie7\jsproxy.dll
+ 2004-08-03 21:55:40 22,016 -c--a-w c:\windows\ie7\licmgr10.dll
+ 2004-08-03 21:56:22 29,184 -c--a-w c:\windows\ie7\mshta.exe
+ 2008-12-12 17:33:22 3,081,216 -c--a-w c:\windows\ie7\mshtml.dll
+ 2008-10-16 10:37:26 449,024 -c--a-w c:\windows\ie7\mshtmled.dll
+ 2004-08-03 21:53:52 56,832 -c--a-w c:\windows\ie7\mshtmler.dll
+ 2001-09-19 12:00:00 146,432 -c--a-w c:\windows\ie7\msls31.dll
+ 2008-10-16 10:37:24 146,432 -c--a-w c:\windows\ie7\msrating.dll
+ 2008-10-16 10:37:24 532,480 -c--a-w c:\windows\ie7\mstime.dll
+ 2004-08-03 21:55:46 96,256 -c--a-w c:\windows\ie7\occache.dll
+ 2008-10-16 10:37:24 39,424 -c--a-w c:\windows\ie7\pngfilt.dll
+ 2007-09-27 14:23:42 32,960 -c--a-w c:\windows\ie7\spuninst\iecustom.dll
+ 2007-09-27 14:21:34 66,048 -c--a-w c:\windows\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 14:42:02 213,216 -c--a-w c:\windows\ie7\spuninst\spuninst.exe
+ 2006-09-06 14:42:02 369,376 -c--a-w c:\windows\ie7\spuninst\updspapi.dll
+ 2004-08-03 21:55:54 48,640 -c--a-w c:\windows\ie7\url.dll
+ 2008-10-16 10:37:27 614,912 -c--a-w c:\windows\ie7\urlmon.dll
+ 2007-12-18 14:41:00 417,792 -c--a-w c:\windows\ie7\vbscript.dll
+ 2004-08-03 21:55:54 848,384 -c--a-w c:\windows\ie7\vgx.dll
+ 2004-08-03 21:55:58 276,480 -c--a-w c:\windows\ie7\webcheck.dll
+ 2008-10-16 10:37:25 657,920 -c--a-w c:\windows\ie7\wininet.dll
+ 2007-03-06 00:57:39 213,216 -c----w c:\windows\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 00:58:46 369,376 -c----w c:\windows\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-13 15:54:10 765,952 -c----w c:\windows\ie7updates\KB938127-IE7\vgx.dll
+ 2007-03-06 00:57:38 213,216 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2007-03-06 00:58:46 369,376 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2007-07-12 23:30:57 765,952 -c----w c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2007-08-13 15:39:00 123,904 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2007-08-13 15:35:46 346,624 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2007-08-13 15:35:38 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2007-08-13 15:54:10 131,584 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2007-08-13 15:36:26 61,952 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2007-08-13 15:39:06 54,784 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2007-08-13 15:39:26 152,064 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2007-08-13 15:39:54 229,376 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2007-08-13 14:56:54 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2007-02-12 13:10:12 2,451,312 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dat
+ 2007-07-11 09:27:48 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2007-08-13 15:39:50 382,976 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2007-08-13 15:54:10 6,049,280 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2007-08-13 15:39:10 43,008 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2007-08-13 15:34:04 266,752 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2007-08-13 15:39:10 13,312 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2007-08-13 15:43:56 622,080 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2007-08-13 15:54:10 27,136 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2007-08-13 15:54:10 458,752 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2007-08-13 15:54:10 50,688 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2007-08-13 15:54:10 475,648 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2007-08-13 15:44:26 192,000 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2007-08-13 15:54:10 670,720 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2007-08-13 15:44:06 101,376 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2007-08-13 15:36:12 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 00:57:38 213,216 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 00:58:46 369,376 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2007-08-13 15:44:30 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2007-08-13 15:54:10 1,162,240 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2007-08-13 15:54:10 231,424 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2007-08-13 15:54:10 818,688 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2007-08-13 15:54:12 3,578,368 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 00:57:38 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 00:58:46 369,376 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
- 2006-12-01 09:03:18 316,416 ----a-w c:\windows\inf\unregmp2.exe
+ 2007-06-27 13:34:56 317,952 ----a-w c:\windows\inf\unregmp2.exe
- 2001-01-12 13:10:24 6,550 ----a-w c:\windows\jautoexp.dat
+ 2003-02-28 13:35:26 6,550 ----a-w c:\windows\jautoexp.dat
+ 2008-10-27 00:13:25 2,678 ----a-w c:\windows\java\Packages\Data\
08AJT37X.DAT
+ 2008-10-27 00:13:26 2,678 ----a-w c:\windows\java\Packages\Data\F7ZDBBHB.DAT
+ 2008-10-27 00:13:25 2,678 ----a-w c:\windows\java\Packages\Data\LBN9ZDBP.DAT
+ 2008-10-27 00:13:33 2,678 ----a-w c:\windows\java\Packages\Data\M5BVZPZV.DAT
+ 2008-10-27 00:13:25 2,678 ----a-w c:\windows\java\Packages\Data\OVTV575N.DAT
- 2000-08-31 05:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 05:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2001-01-12 15:04:08 46,352 ----a-w c:\windows\setdebug.exe
+ 2003-02-28 15:26:30 46,352 ----a-w c:\windows\setdebug.exe
- 2004-08-03 21:55:32 61,440 ----a-w c:\windows\system32\admparse.dll
+ 2007-08-13 15:39:20 71,680 ----a-w c:\windows\system32\admparse.dll
- 2004-08-03 21:55:32 99,840 ----a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:04:07 124,928 ----a-w c:\windows\system32\advpack.dll
- 2008-08-20 05:36:15 1,023,488 ----a-w c:\windows\system32\browseui.dll
+ 2008-10-16 10:37:27 1,023,488 ----a-w c:\windows\system32\browseui.dll
- 2008-08-20 05:36:11 151,040 ----a-w c:\windows\system32\cdfview.dll
+ 2008-10-16 10:37:23 151,040 ----a-w c:\windows\system32\cdfview.dll
- 2007-07-30 16:19:20 92,504 ----a-w c:\windows\system32\cdm.dll
+ 2008-10-16 11:09:44 92,696 ----a-w c:\windows\system32\cdm.dll
- 2001-01-12 15:04:06 49,424 ----a-w c:\windows\system32\clspack.exe
+ 2003-02-28 15:26:26 49,424 ----a-w c:\windows\system32\clspack.exe
- 2008-10-22 05:08:02 16,384 ----a-w c:\windows\system32\config\systemprofile\******s\index.dat
+ 2009-02-26 07:32:05 16,384 ----a-w c:\windows\system32\config\systemprofile\******s\index.dat
- 2008-10-22 05:08:02 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-26 07:32:05 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-10-22 05:08:02 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\*******.IE5\index.dat
+ 2009-02-26 07:32:05 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\*******.IE5\index.dat
+ 2008-12-06 15:01:23 245,760 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat
- 2004-08-03 21:55:34 35,328 ----a-w c:\windows\system32\corpol.dll
+ 2007-08-13 15:42:54 17,408 ----a-w c:\windows\system32\corpol.dll
- 2004-08-03 21:56:08 98,304 ----a-w c:\windows\system32\cscript.exe
+ 2007-07-31 17:45:06 114,688 ----a-w c:\windows\system32\cscript.exe
- 2008-08-20 05:36:11 1,053,696 ----a-w c:\windows\system32\danim.dll
+ 2008-10-16 10:37:23 1,053,696 ----a-w c:\windows\system32\danim.dll
- 2001-09-19 12:00:00 45,083 ----a-w c:\windows\system32\dispex.dll
+ 2007-07-31 17:45:24 32,768 ----a-w c:\windows\system32\dispex.dll
- 2004-08-03 21:55:32 61,440 -c--a-w c:\windows\system32\dllcache\admparse.dll
+ 2007-08-13 15:39:20 71,680 -c--a-w c:\windows\system32\dllcache\admparse.dll
- 2004-08-03 21:55:32 99,840 -c--a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:04:07 124,928 -c--a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-20 05:36:15 1,023,488 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2008-10-16 10:37:27 1,023,488 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2004-08-03 20:10:40 17,024 -c--a-w c:\windows\system32\dllcache\bthenum.sys
+ 2004-08-03 19:58:40 100,992 -c--a-w c:\windows\system32\dllcache\bthpan.sys
+ 2004-08-03 20:10:36 18,944 -c--a-w c:\windows\system32\dllcache\bthusb.sys
- 2008-08-20 05:36:11 151,040 -c--a-w c:\windows\system32\dllcache\cdfview.dll
+ 2008-10-16 10:37:23 151,040 -c--a-w c:\windows\system32\dllcache\cdfview.dll
- 2007-07-30 16:19:20 92,504 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 11:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
- 2004-08-03 21:55:34 35,328 -c--a-w c:\windows\system32\dllcache\corpol.dll
+ 2007-08-13 15:42:54 17,408 -c--a-w c:\windows\system32\dllcache\corpol.dll
- 2004-08-03 21:56:08 98,304 -c--a-w c:\windows\system32\dllcache\cscript.exe
+ 2007-07-31 17:45:06 114,688 -c--a-w c:\windows\system32\dllcache\cscript.exe
- 2004-08-03 21:55:34 28,672 -c--a-w c:\windows\system32\dllcache\custsat.dll
+ 2007-08-13 15:54:10 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll
- 2008-08-20 05:36:11 1,053,696 -c--a-w c:\windows\system32\dllcache\danim.dll
+ 2008-10-16 10:37:23 1,053,696 -c--a-w c:\windows\system32\dllcache\danim.dll
- 2001-09-19 12:00:00 45,083 -c--a-w c:\windows\system32\dllcache\dispex.dll
+ 2007-07-31 17:45:24 32,768 -c--a-w c:\windows\system32\dllcache\dispex.dll
- 2008-08-20 05:36:11 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:04:07 347,136 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-20 05:36:12 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:04:07 214,528 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-20 05:36:12 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:04:08 133,120 -c--a-w c:\windows\system32\dllcache\extmgr.dll
- 2004-08-03 21:55:38 278,016 -c--a-w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 12:59:23 283,648 -c--a-w c:\windows\system32\dllcache\gdi32.dll
- 2004-08-03 21:55:38 38,912 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2007-08-13 15:18:02 60,416 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2008-10-16 20:04:08 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
- 2004-08-03 21:56:16 34,304 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:09:53 70,656 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2004-08-03 21:55:38 139,264 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:04:08 153,088 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-03 21:55:38 216,064 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:04:08 230,400 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
- 2001-09-19 12:00:00 221,184 -c--a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 -c----w c:\windows\system32\dllcache\ieapfltr.dat
+ 2008-10-16 20:04:08 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
- 2004-08-03 21:55:38 323,584 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:04:09 384,512 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-08-19 09:30:39 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
+ 2007-08-13 15:44:02 69,120 -c--a-w c:\windows\system32\dllcache\iedw.exe
- 2004-08-03 21:55:38 81,920 -c--a-w c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-13 15:45:18 78,336 -c--a-w c:\windows\system32\dllcache\ieencode.dll
+ 2008-10-16 20:04:12 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-20 05:36:12 250,880 -c--a-w c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 15:54:10 191,488 -c--a-w c:\windows\system32\dllcache\iepeers.dll
- 2004-08-03 21:55:38 48,128 -c--a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:04:12 44,544 -c--a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:04:12 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
- 2004-08-03 21:55:38 62,976 -c--a-w c:\windows\system32\dllcache\iesetup.dll
+ 2007-08-13 15:39:12 55,296 -c--a-w c:\windows\system32\dllcache\iesetup.dll
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
- 2004-08-03 21:56:16 93,184 -c--a-w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 -c--a-w c:\windows\system32\dllcache\iexplore.exe
- 2004-08-03 21:55:38 35,840 -c--a-w c:\windows\system32\dllcache\imgutil.dll
+ 2007-08-13 15:36:06 36,352 -c--a-w c:\windows\system32\dllcache\imgutil.dll
- 2008-08-20 05:36:12 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2007-08-13 15:39:02 92,672 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2004-08-03 21:56:18 152,064 -c--a-w c:\windows\system32\dllcache\irftp.exe
+ 2004-08-03 21:55:40 26,624 -c--a-w c:\windows\system32\dllcache\irmon.dll
- 2007-12-18 14:41:00 450,560 -c--a-w c:\windows\system32\dllcache\jscript.dll
+ 2007-07-31 17:45:24 491,520 -c--a-w c:\windows\system32\dllcache\jscript.dll
- 2008-08-20 05:36:14 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:04:13 27,648 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-03 21:55:40 22,016 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
+ 2007-08-13 15:44:18 40,960 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
- 2006-10-18 17:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-17 22:09:22 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-10-24 11:10:42 453,632 -c----w c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-10-16 20:04:13 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:04:13 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
- 2004-08-03 21:56:22 29,184 -c--a-w c:\windows\system32\dllcache\mshta.exe
+ 2007-08-13 15:32:30 45,568 -c--a-w c:\windows\system32\dllcache\mshta.exe
- 2008-08-20 05:36:17 3,081,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:36:43 3,593,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-20 05:36:14 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:04:16 477,696 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-03 21:53:52 56,832 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
+ 2007-08-13 15:01:12 48,128 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
- 2001-09-19 12:00:00 146,432 -c--a-w c:\windows\system32\dllcache\msls31.dll
+ 2007-08-13 15:54:10 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll
- 2008-08-20 05:36:12 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:04:17 193,024 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-20 05:36:12 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:04:17 671,232 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2004-08-03 21:55:46 1,236,480 -c--a-w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-04 16:44:08 1,106,944 -c--a-w c:\windows\system32\dllcache\msxml3.dll
- 2004-08-03 21:55:46 96,256 -c--a-w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:04:17 102,912 -c--a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-20 05:36:12 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:04:17 44,544 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-03 20:10:40 59,648 -c--a-w c:\windows\system32\dllcache\rfcomm.sys
- 2004-08-03 21:55:50 159,744 -c--a-w c:\windows\system32\dllcache\scrobj.dll
+ 2007-07-31 17:45:28 163,840 -c--a-w c:\windows\system32\dllcache\scrobj.dll
- 2004-08-03 21:55:50 151,552 -c--a-w c:\windows\system32\dllcache\scrrun.dll
+ 2007-07-31 17:45:28 155,648 -c--a-w c:\windows\system32\dllcache\scrrun.dll
- 2008-08-20 05:36:13 1,494,528 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
+ 2008-10-16 10:37:25 1,494,528 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
- 2004-08-03 21:55:52 8,369,664 -c--a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:14:56 8,440,320 -c--a-w c:\windows\system32\dllcache\shell32.dll
- 2008-08-20 05:36:14 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
+ 2008-10-16 10:37:26 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
- 2008-08-28 10:04:17 333,056 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2004-08-03 21:55:54 246,302 -c--a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:15:47 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll
- 2006-12-01 09:03:18 316,416 -c--a-w c:\windows\system32\dllcache\unregmp2.exe
+ 2007-06-27 13:34:56 317,952 -c--a-w c:\windows\system32\dllcache\unregmp2.exe
- 2004-08-03 21:55:54 48,640 -c--a-w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:04:17 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
- 2008-08-20 05:36:15 614,912 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:04:18 1,160,192 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2007-12-18 14:41:00 417,792 -c--a-w c:\windows\system32\dllcache\vbscript.dll
+ 2007-07-31 17:45:28 413,696 -c--a-w c:\windows\system32\dllcache\vbscript.dll
- 2004-08-03 21:55:54 848,384 -c--a-w c:\windows\system32\dllcache\vgx.dll
+ 2008-05-27 17:23:58 765,952 -c--a-w c:\windows\system32\dllcache\vgx.dll
- 2004-08-03 21:55:58 276,480 -c--a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:04:18 233,472 -c--a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-09-05 20:30:46 266,792 -c----w c:\windows\system32\dllcache\wgaLogon.dll
+ 2008-09-05 20:29:58 942,632 -c----w c:\windows\system32\dllcache\WgaTray.exe
- 2008-08-20 05:36:13 657,920 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:04:19 826,368 -c--a-w c:\windows\system32\dllcache\wininet.dll
- 2006-10-18 18:47:20 937,984 -c--a-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-18 02:03:08 938,496 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-18 18:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 02:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
- 2004-08-03 21:56:36 114,688 -c--a-w c:\windows\system32\dllcache\wscript.exe
+ 2007-07-31 17:45:22 135,168 -c--a-w c:\windows\system32\dllcache\wscript.exe
- 2004-08-03 21:56:00 65,536 -c--a-w c:\windows\system32\dllcache\wshext.dll
+ 2007-07-31 17:45:30 69,632 -c--a-w c:\windows\system32\dllcache\wshext.dll
+ 2004-08-03 21:56:00 8,192 -c--a-w c:\windows\system32\dllcache\wshirda.dll
- 2007-07-30 16:19:36 549,720 -c--a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 11:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-30 16:19:16 53,080 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 11:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-30 16:19:42 1,712,984 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 11:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-30 16:19:32 325,976 -c--a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 11:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-30 16:18:40 33,624 -c--a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 11:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-30 16:19:28 203,096 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 11:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2004-08-03 20:10:40 17,024 ----a-w c:\windows\system32\drivers\BthEnum.sys
+ 2004-08-03 19:58:40 100,992 ----a-w c:\windows\system32\drivers\bthpan.sys
+ 2004-08-03 20:10:36 18,944 ----a-w c:\windows\system32\drivers\BTHUSB.SYS
- 2008-10-21 21:07:32 213,008 ----a-w c:\windows\system32\drivers\klif.sys
+ 2009-02-26 08:51:30 213,520 ----a-w c:\windows\system32\drivers\klif.sys
- 2004-08-03 20:15:18 451,456 ----a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:10:42 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-03 20:10:40 59,648 ----a-w c:\windows\system32\drivers\rfcomm.sys
- 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 11:57:21 333,184 ----a-w c:\windows\system32\drivers\srv.sys
- 2001-01-12 13:09:58 313,856 ----a-w c:\windows\system32\dx3j.dll
+ 2003-02-28 13:34:42 313,856 ----a-w c:\windows\system32\dx3j.dll
- 2008-08-20 05:36:11 357,888 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:04:07 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-20 05:36:12 205,312 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:04:07 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-20 05:36:12 55,808 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:04:08 133,120 ----a-w c:\windows\system32\extmgr.dll
- 2004-08-03 21:55:38 278,016 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 12:59:23 283,648 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-16 20:04:08 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2006-06-29 05:05:44 26,112 ------w c:\windows\system32\idndl.dll
- 2004-08-03 21:56:16 34,304 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:09:53 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2004-08-03 21:55:38 139,264 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:04:08 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2004-08-03 21:55:38 216,064 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:04:08 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2001-09-19 12:00:00 221,184 ----a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\system32\ieapfltr.dat
+ 2008-10-16 20:04:08 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2004-08-03 21:55:38 323,584 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:04:09 384,512 ----a-w c:\windows\system32\iedkcs32.dll
- 2004-08-03 21:55:38 81,920 ----a-w c:\windows\system32\ieencode.dll
+ 2007-08-13 15:45:18 78,336 ----a-w c:\windows\system32\ieencode.dll
+ 2008-10-16 20:04:12 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-08-20 05:36:12 250,880 ----a-w c:\windows\system32\iepeers.dll
+ 2007-08-13 15:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll
- 2004-08-03 21:55:38 48,128 ----a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:04:12 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:04:12 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2004-08-03 21:55:38 62,976 ----a-w c:\windows\system32\iesetup.dll
+ 2007-08-13 15:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll
+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2007-08-13 15:54:10 180,736 ------w c:\windows\system32\ieui.dll
- 2004-08-03 21:55:38 35,840 ----a-w c:\windows\system32\imgutil.dll
+ 2007-08-13 15:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll
- 2008-08-20 05:36:12 96,256 ----a-w c:\windows\system32\inseng.dll
+ 2007-08-13 15:39:02 92,672 ----a-w c:\windows\system32\inseng.dll
+ 2004-08-03 21:56:18 152,064 ----a-w c:\windows\system32\irftp.exe
+ 2004-08-03 21:55:40 26,624 ----a-w c:\windows\system32\irmon.dll
- 2001-01-12 15:04:00 187,152 ----a-w c:\windows\system32\javacypt.dll
+ 2003-02-28 15:26:16 187,152 ----a-w c:\windows\system32\javacypt.dll
- 2001-01-12 15:04:00 139,536 ----a-w c:\windows\system32\javaee.dll
+ 2003-02-28 15:26:18 139,536 ----a-w c:\windows\system32\javaee.dll
- 2001-01-12 15:04:00 63,248 ----a-w c:\windows\system32\javaprxy.dll
+ 2003-02-28 15:26:18 63,248 ----a-w c:\windows\system32\javaprxy.dll
- 2001-01-12 15:04:02 404,752 ----a-w c:\windows\system32\javart.dll
+ 2003-02-28 15:26:18 404,752 ----a-w c:\windows\system32\javart.dll
- 2001-01-12 15:04:08 15,120 ----a-w c:\windows\system32\jdbgmgr.exe
+ 2003-02-28 15:26:30 15,120 ----a-w c:\windows\system32\jdbgmgr.exe
- 2001-01-12 15:04:02 171,280 ----a-w c:\windows\system32\jit.dll
+ 2003-02-28 15:26:20 171,280 ----a-w c:\windows\system32\jit.dll
- 2007-12-18 14:41:00 450,560 ----a-w c:\windows\system32\jscript.dll
+ 2007-07-31 17:45:24 491,520 ----a-w c:\windows\system32\jscript.dll
- 2008-08-20 05:36:14 16,384 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:04:13 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2001-01-12 15:04:08 172,304 ----a-w c:\windows\system32\jview.exe
+ 2003-02-28 15:26:30 172,304 ----a-w c:\windows\system32\jview.exe
+ 2008-09-05 20:30:06 1,480,232 ------w c:\windows\system32\LegitCheckControl.dll
- 2004-08-03 21:55:40 22,016 ----a-w c:\windows\system32\licmgr10.dll
+ 2007-08-13 15:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll
- 2006-10-18 17:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-17 22:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2009-02-12 04:56:17 21,244,872 ----a-w c:\windows\system32\MRT.exe
- 2001-01-12 15:04:02 154,896 ----a-w c:\windows\system32\msawt.dll
+ 2003-02-28 15:26:20 154,384 ----a-w c:\windows\system32\msawt.dll
+ 2008-10-16 20:04:13 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:04:13 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 15:36:40 12,288 ------w c:\windows\system32\msfeedssync.exe
- 2004-08-03 21:56:22 29,184 ----a-w c:\windows\system32\mshta.exe
+ 2007-08-13 15:32:30 45,568 ----a-w c:\windows\system32\mshta.exe
- 2008-08-20 05:36:17 3,081,216 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:36:43 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-20 05:36:14 449,024 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:04:16 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2004-08-03 21:53:52 56,832 ----a-w c:\windows\system32\mshtmler.dll
+ 2007-08-13 15:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll
- 2001-01-12 15:04:06 945,424 ----a-w c:\windows\system32\msjava.dll
+ 2003-02-28 15:26:26 947,472 ----a-w c:\windows\system32\msjava.dll
- 2001-01-12 15:04:06 21,264 ----a-w c:\windows\system32\msjdbc10.dll
+ 2003-02-28 15:26:26 21,264 ----a-w c:\windows\system32\msjdbc10.dll
- 2001-09-19 12:00:00 146,432 ----a-w c:\windows\system32\msls31.dll
+ 2007-08-13 15:54:10 156,160 ----a-w c:\windows\system32\msls31.dll
- 2008-08-20 05:36:12 146,432 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:04:17 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-08-20 05:36:12 532,480 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:04:17 671,232 ----a-w c:\windows\system32\mstime.dll
- 2004-08-03 21:55:46 1,236,480 ----a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 16:44:08 1,106,944 ----a-w c:\windows\system32\msxml3.dll
+ 2006-06-28 14:59:26 24,576 ------w c:\windows\system32\nlsdl.dll
+ 2006-06-29 05:05:44 23,552 ------w c:\windows\system32\normaliz.dll
- 2004-08-03 21:55:46 96,256 ----a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:04:17 102,912 ----a-w c:\windows\system32\occache.dll
- 2008-10-26 18:36:40 59,878 ----a-w c:\windows\system32\perfc001.dat
+ 2008-12-26 15:47:26 59,878 ----a-w c:\windows\system32\perfc001.dat
- 2008-10-26 18:36:40 59,774 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-26 15:47:26 59,774 ----a-w c:\windows\system32\perfc009.dat
- 2008-10-26 18:36:40 331,338 ----a-w c:\windows\system32\perfh001.dat
+ 2008-12-26 15:47:26 331,338 ----a-w c:\windows\system32\perfh001.dat
- 2008-10-26 18:36:40 395,534 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-26 15:47:26 395,534 ----a-w c:\windows\system32\perfh009.dat
- 2008-10-12 19:09:37 278,528 ----a-w c:\windows\system32\pncrt.dll
+ 2008-12-23 13:50:35 278,528 ----a-w c:\windows\system32\pncrt.dll
- 2008-10-12 19:09:38 6,656 ----a-w c:\windows\system32\pndx5016.dll
+ 2008-12-23 13:50:39 6,656 ----a-w c:\windows\system32\pndx5016.dll
- 2008-10-12 19:09:38 5,632 ----a-w c:\windows\system32\pndx5032.dll
+ 2008-12-23 13:50:39 5,632 ----a-w c:\windows\system32\pndx5032.dll
- 2008-08-20 05:36:12 39,424 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:04:17 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2009-02-25 21:50:04 989,344 ----a-w c:\windows\system32\Restore\rstrlog.dat
- 2008-10-12 19:09:43 185,944 ----a-w c:\windows\system32\rmoc3260.dll
+ 2008-12-23 13:51:11 185,920 ----a-w c:\windows\system32\rmoc3260.dll
- 2004-08-03 21:55:50 159,744 ----a-w c:\windows\system32\scrobj.dll
+ 2007-07-31 17:45:28 163,840 ----a-w c:\windows\system32\scrobj.dll
- 2004-08-03 21:55:50 151,552 ----a-w c:\windows\system32\scrrun.dll
+ 2007-07-31 17:45:28 155,648 ----a-w c:\windows\system32\scrrun.dll
- 2008-08-20 05:36:13 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 10:37:25 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
- 2004-08-03 21:55:52 8,369,664 ----a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:14:56 8,440,320 ----a-w c:\windows\system32\shell32.dll
- 2008-08-20 05:36:14 474,112 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-10-16 10:37:26 474,112 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-10-16 11:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 11:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2007-11-30 11:18:09 17,784 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:01 17,784 ------w c:\windows\system32\spmsg.dll
- 2004-08-03 21:55:54 246,302 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ----a-w c:\windows\system32\strmdll.dll
- 2008-07-14 11:09:18 62,976 ------w c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe
- 2004-08-03 21:55:54 48,640 ----a-w c:\windows\system32\url.dll
+ 2008-10-16 20:04:17 105,984 ----a-w c:\windows\system32\url.dll
- 2008-08-20 05:36:15 614,912 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:04:18 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2007-12-18 14:41:00 417,792 ----a-w c:\windows\system32\vbscript.dll
+ 2007-07-31 17:45:28 413,696 ----a-w c:\windows\system32\vbscript.dll
- 2001-01-12 15:04:06 286,992 ----a-w c:\windows\system32\vmhelper.dll
+ 2003-02-28 15:26:26 286,992 ----a-w c:\windows\system32\vmhelper.dll
- 2004-08-03 21:55:58 276,480 ----a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:04:18 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-09-05 20:30:46 266,792 ------w c:\windows\system32\WgaLogon.dll
+ 2008-09-05 20:29:58 942,632 ------w c:\windows\system32\WgaTray.exe
+ 2007-08-13 15:45:16 206,336 ------w c:\windows\system32\WinFXDocObj.exe
- 2008-08-20 05:36:13 657,920 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:04:19 826,368 ----a-w c:\windows\system32\wininet.dll
- 2001-01-12 15:04:08 171,792 ----a-w c:\windows\system32\wjview.exe
+ 2003-02-28 15:26:32 171,792 ----a-w c:\windows\system32\wjview.exe
- 2006-10-18 18:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll
+ 2008-06-18 02:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-18 18:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 02:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
- 2004-08-03 21:56:36 114,688 ----a-w c:\windows\system32\wscript.exe
+ 2007-07-31 17:45:22 135,168 ----a-w c:\windows\system32\wscript.exe
- 2004-08-03 21:56:00 28,672 ----a-w c:\windows\system32\wshcon.dll
+ 2007-07-31 17:45:30 36,864 ----a-w c:\windows\system32\wshcon.dll
- 2004-08-03 21:56:00 65,536 ----a-w c:\windows\system32\wshext.dll
+ 2007-07-31 17:45:30 69,632 ----a-w c:\windows\system32\wshext.dll
+ 2004-08-03 21:56:00 8,192 ----a-w c:\windows\system32\wshirda.dll
- 2007-07-30 16:19:36 549,720 ----a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 11:12:20 561,688 ----a-w c:\windows\system32\wuapi.dll
- 2007-07-30 16:19:16 53,080 ----a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 11:09:44 51,224 ----a-w c:\windows\system32\wuauclt.exe
- 2007-07-30 16:19:42 1,712,984 ----a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 11:13:40 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
- 2007-07-30 16:19:32 325,976 ----a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 11:12:22 323,608 ----a-w c:\windows\system32\wucltui.dll
- 2007-07-30 16:18:40 33,624 ----a-w c:\windows\system32\wups.dll
+ 2008-10-16 11:08:58 34,328 ----a-w c:\windows\system32\wups.dll
- 2007-07-30 16:19:12 43,352 ----a-w c:\windows\system32\wups2.dll
+ 2008-10-16 11:09:44 43,544 ----a-w c:\windows\system32\wups2.dll
- 2007-07-30 16:19:28 203,096 ----a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 11:13:40 202,776 ----a-w c:\windows\system32\wuweb.dll
+ 2006-07-14 15:51:51 121,856 ------w c:\windows\system32\xmllite.dll
- 2008-08-19 12:21:32 690,176 ------w c:\windows\system32\xpsp3res.dll
+ 2008-10-15 17:05:22 690,176 ----a-w c:\windows\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [10/28/2008 11:00 PM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [02/26/2009 11:51 AM 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/23/2008 04:50 PM 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^سرعة تشغيل Adobe Reader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\سرعة تشغيل Adobe Reader.lnk
backup=c:\windows\pss\سرعة تشغيل Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^قائمة ابدأ^البرامج^بدء التشغيل^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\user\قائمة ابدأ\البرامج\بدء التشغيل\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 05/10/2006 11:12 AM 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--------- 08/16/2006 06:20 AM 53248 c:\program files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
-ra------ 08/16/2006 06:24 AM 1236992 c:\windows\system32\WLTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 12:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 10/27/2006 12:47 AM 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
--a------ 09/07/2006 02:52 PM 479232 c:\progra~1\LAUNCH~1\QtZgAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 08/04/2004 01:09 AM 1667584 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 11/02/2004 08:24 PM 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoftCatcher]
--a------ 10/21/2008 12:15 AM 992256 c:\program files\Soft Catcher\SoftCatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 08/16/2006 06:34 AM 766041 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 12/23/2008 04:50 PM 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 08/16/2006 06:23 AM 16248320 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 08/16/2006 06:21 AM 2879488 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S3 AVPsys;AVPsys;c:\windows\system32\drivers\cdaudio.sys [2008-10-21 18688]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c96d4896-99b2-11dd-ab63-001636e432c4}]
\Shell\AutoRun\command - G:\yssjnngm.cmd
\Shell\explore\Command - G:\yssjnngm.cmd
\Shell\open\Command - G:\yssjnngm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c96d4897-99b2-11dd-ab63-001636e432c4}]
\Shell\AutoRun\command - H:\yssjnngm.cmd
\Shell\explore\Command - H:\yssjnngm.cmd
\Shell\open\Command - H:\yssjnngm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c96d4898-99b2-11dd-ab63-001636e432c4}]
\Shell\AutoRun\command - I:\yssjnngm.cmd
\Shell\explore\Command - I:\yssjnngm.cmd
\Shell\open\Command - I:\yssjnngm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d11a400b-9e62-11dd-ab87-001636e432c4}]
\Shell\AutoRun\command - G:\yssjnngm.cmd
\Shell\explore\Command - G:\yssjnngm.cmd
\Shell\open\Command - G:\yssjnngm.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc5de6e-9e82-11dd-ab8b-001636e432c4}]
\Shell\AutoRun\command - G:\yssjnngm.cmd
\Shell\explore\Command - G:\yssjnngm.cmd
\Shell\open\Command - G:\yssjnngm.cmd
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-GREATITCH - c:\docume~1\user\APPLIC~1\MOVENE~1\mail log.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-03 21:42:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1108)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 03/03/2009 21:44:11
ComboFix-quarantined-files.txt 2009-03-03 18:44:08
ComboFix2.txt 2008-10-26 19:39:10
ComboFix3.txt 2008-10-21 17:53:17
Pre-Run: 3,983,077,376 bytes free
Post-Run: 4,264,226,816 bytes free
870 --- E O F --- 2009-02-27 00:19:12