Gå til innhold

Anbefalte innlegg

HJT

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:11:11, on 20.06.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe

C:\WINDOWS\system32\svchost.exe

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE

C:\Programfiler\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe

C:\Programfiler\WinZip\WZQKPICK.EXE

C:\PROGRA~1\Grisoft\AVG7\avgw.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programfiler\Opera\Opera.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programfiler\MyWebSearch\bar\3.bin\MWSBAR.DLL (file missing)

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=2 /w

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: D-Link AirPlus G+ Wireless Adapter Utility.lnk = C:\Programfiler\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZS

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\npjpi150_06.dll

O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programfiler\WIDCOMM\Bluetooth-programvare\btsendto_ie.htm

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...tup1.0.0.15.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Programfiler\Fellesfiler\Symantec Shared\ccSvcHst.exe (file missing)

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: ServiceLayer - Nokia. - C:\Programfiler\Fellesfiler\PCSuite\Services\ServiceLayer.exe

 

--

End of file - 7262 bytes

 

ComboFix

 

ComboFix 08-06-19.2 - TineMelk 2008-06-20 13:23:59.3 - NTFSx86

Running from: C:\Documents and Settings\TineMelk\Skrivebord\ComboFix.exe

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))

.

 

2008-06-12 21:10 . 2008-04-14 17:54 272,256 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-12 21:10 . 2008-04-14 17:54 272,256 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-08 12:09 . 2008-06-08 18:42 <DIR> d-------- C:\Nintendo

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-20 11:07 --------- d-----w C:\Programfiler\Trend Micro

2008-06-20 10:57 --------- d-----w C:\Documents and Settings\TineMelk\Programdata\AVG7

2008-05-24 20:57 --------- d-----w C:\Documents and Settings\TineMelk\Programdata\LimeWire

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll

2008-04-29 17:04 --------- d-----w C:\Programfiler\Windows Live

2008-04-29 17:04 --------- d-----w C:\Programfiler\MSN Messenger

2008-04-29 17:03 --------- dcsh--w C:\Programfiler\Fellesfiler\WindowsLiveInstaller

2008-04-29 17:03 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Programdata\WLInstaller

2008-04-23 04:22 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll

2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll

2008-03-20 08:11 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys

2006-03-31 11:56 917,318 ----a-w C:\Programfiler\Apr2006_MDX1_x86.cab

2006-03-31 11:56 87,989 ----a-w C:\Programfiler\Apr2006_xinput_x64.cab

2006-03-31 11:56 46,898 ----a-w C:\Programfiler\Apr2006_xinput_x86.cab

2006-03-31 11:56 41,890 ----a-w C:\Programfiler\dxdllreg_x86.cab

2006-03-31 11:56 4,163,518 ----a-w C:\Programfiler\Apr2006_MDX1_x86_Archive.cab

2006-03-31 11:56 180,021 ----a-w C:\Programfiler\Apr2006_xact_x64.cab

2006-03-31 11:56 133,991 ----a-w C:\Programfiler\Apr2006_xact_x86.cab

2006-03-31 11:56 1,398,718 ----a-w C:\Programfiler\Apr2006_d3dx9_30_x64.cab

2006-03-31 11:56 1,116,109 ----a-w C:\Programfiler\Apr2006_d3dx9_30_x86.cab

2006-03-31 11:41 81,733 ----a-w C:\Programfiler\dxupdate.cab

2006-03-31 11:40 484,560 ----a-w C:\Programfiler\DXSETUP.exe

2006-03-31 11:40 2,248,912 ----a-w C:\Programfiler\dsetup32.dll

2006-03-31 11:39 74,448 ----a-w C:\Programfiler\DSETUP.dll

2006-03-19 18:32 12,714,997 ----a-w C:\Programfiler\cpm_en_v6[1].0.8.exe

2006-03-19 10:56 8,898,672 ----a-w C:\Programfiler\avinstall.exe

2006-02-03 08:00 179,247 ------w C:\Programfiler\Feb2006_xact_x64.cab

2006-02-03 08:00 133,297 ------w C:\Programfiler\Feb2006_xact_x86.cab

2006-02-03 08:00 1,363,684 ------w C:\Programfiler\Feb2006_d3dx9_29_x64.cab

2006-02-03 08:00 1,085,608 ------w C:\Programfiler\Feb2006_d3dx9_29_x86.cab

2005-12-05 17:31 86,925 ------w C:\Programfiler\Oct2005_xinput_x64.cab

2005-12-05 17:31 46,247 ------w C:\Programfiler\Oct2005_xinput_x86.cab

2005-12-05 17:31 1,358,864 ------w C:\Programfiler\Dec2005_d3dx9_28_x64.cab

2005-12-05 17:31 1,080,344 ------w C:\Programfiler\Dec2005_d3dx9_28_x86.cab

2005-07-22 18:14 1,351,430 ------w C:\Programfiler\Aug2005_d3dx9_27_x64.cab

2005-07-22 18:14 1,078,532 ------w C:\Programfiler\Aug2005_d3dx9_27_x86.cab

2005-05-26 13:49 1,336,890 ------w C:\Programfiler\Jun2005_d3dx9_26_x64.cab

2005-05-26 13:49 1,065,813 ------w C:\Programfiler\Jun2005_d3dx9_26_x86.cab

2005-03-18 16:40 1,348,242 ------w C:\Programfiler\Apr2005_d3dx9_25_x64.cab

2005-03-18 16:40 1,079,850 ------w C:\Programfiler\Apr2005_d3dx9_25_x86.cab

2005-02-05 19:03 1,248,387 ------w C:\Programfiler\Feb2005_d3dx9_24_x64.cab

2005-02-05 19:03 1,014,113 ------w C:\Programfiler\Feb2005_d3dx9_24_x86.cab

2004-09-27 10:29 976,020 ------w C:\Programfiler\BDAXP.cab

2004-09-27 10:29 703,080 ------w C:\Programfiler\BDA.cab

2004-09-27 10:29 15,493,481 ------w C:\Programfiler\DirectX.cab

2004-09-27 10:29 13,265,040 ------w C:\Programfiler\dxnt.cab

2004-09-27 10:29 1,156,363 ------w C:\Programfiler\BDANT.cab

2004-08-20 17:09 62,865 ----a-w C:\WINDOWS\inf\IM\odysseyIM3.sys

2004-08-20 17:09 45,056 ----a-w C:\WINDOWS\inf\IM\imdinst.exe

2004-08-20 17:09 12,739 ----a-w C:\WINDOWS\inf\IM\odNetInstall.dll

1998-08-24 10:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-04-14_19.33.45,31 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-01-23 04:56:21 554,008 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll

+ 2007-12-10 12:41:11 518,944 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll

+ 2007-12-10 12:41:11 326,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll

+ 2007-12-10 12:41:11 1,516,568 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll

+ 2007-12-10 12:41:11 355,112 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll

+ 2007-11-01 05:16:22 166,688 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll

+ 2007-12-10 12:41:12 60,192 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll

+ 2007-12-10 12:41:12 248,608 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll

+ 2007-12-10 12:41:12 219,936 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll

+ 2007-12-10 12:41:12 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll

+ 2007-12-10 12:41:13 432,928 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll

+ 2007-12-10 12:41:13 322,336 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll

+ 2007-12-10 12:41:13 559,904 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll

+ 2007-12-10 12:41:13 264,992 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll

+ 2007-12-10 12:41:13 838,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll

+ 2007-11-01 05:16:23 621,344 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll

+ 2007-12-10 12:41:14 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll

+ 2007-03-06 02:01:46 14,560 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll

+ 2007-03-06 02:01:51 214,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe

+ 2007-03-06 02:01:45 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll

+ 2007-03-06 02:02:09 721,120 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\update.exe

+ 2007-03-06 02:03:01 374,496 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll

+ 2004-08-04 12:00:00 561,179 -c----w C:\WINDOWS\$NtUninstallKB950749$\dao360.dll

+ 2004-08-04 12:00:00 512,029 -c----w C:\WINDOWS\$NtUninstallKB950749$\msexch40.dll

+ 2004-08-04 12:00:00 319,517 -c----w C:\WINDOWS\$NtUninstallKB950749$\msexcl40.dll

+ 2004-08-04 12:00:00 1,507,356 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjet40.dll

+ 2004-08-04 12:00:00 358,976 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjetol1.dll

+ 2004-08-04 12:00:00 358,976 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjetoledb40.dll

+ 2004-08-04 12:00:00 159,775 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjint40.dll

+ 2004-08-04 12:00:00 53,279 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjter40.dll

+ 2004-08-04 12:00:00 241,693 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjtes40.dll

+ 2004-08-04 12:00:00 213,023 -c----w C:\WINDOWS\$NtUninstallKB950749$\msltus40.dll

+ 2004-08-04 12:00:00 348,189 -c----w C:\WINDOWS\$NtUninstallKB950749$\mspbde40.dll

+ 2004-08-04 12:00:00 421,919 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrd2x40.dll

+ 2004-08-04 12:00:00 315,423 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrd3x40.dll

+ 2004-08-04 12:00:00 552,989 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrepl40.dll

+ 2004-08-04 12:00:00 258,077 -c----w C:\WINDOWS\$NtUninstallKB950749$\mstext40.dll

+ 2004-08-04 12:00:00 831,519 -c----w C:\WINDOWS\$NtUninstallKB950749$\mswdat10.dll

+ 2004-08-04 12:00:00 614,429 -c----w C:\WINDOWS\$NtUninstallKB950749$\mswstr10.dll

+ 2004-08-04 12:00:00 348,189 -c----w C:\WINDOWS\$NtUninstallKB950749$\msxbde40.dll

+ 2007-03-06 02:01:51 214,752 -c----w C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe

+ 2007-03-06 02:03:01 374,496 -c----w C:\WINDOWS\$NtUninstallKB950749$\spuninst\updspapi.dll

- 2008-04-14 11:26:04 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-06-20 10:56:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat

+ 2008-04-14 15:54:25 272,256 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys

+ 2008-03-01 13:05:18 124,928 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll

+ 2008-03-01 13:05:18 347,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll

+ 2008-03-01 13:05:18 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll

+ 2008-03-01 13:05:18 133,120 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll

+ 2008-03-01 13:05:18 63,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll

+ 2008-02-29 08:58:26 70,656 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe

+ 2008-03-01 13:05:18 153,088 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll

+ 2008-03-01 13:05:18 230,400 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll

+ 2008-02-15 05:44:25 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll

+ 2008-03-01 13:05:18 383,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll

+ 2008-03-01 13:05:19 384,512 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll

+ 2008-03-01 13:05:20 6,066,176 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll

+ 2008-03-01 13:05:20 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll

+ 2008-03-01 13:05:20 267,776 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll

+ 2008-02-22 10:00:51 13,824 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe

+ 2008-02-29 08:58:53 625,664 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe

+ 2008-03-01 13:05:21 27,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll

+ 2008-03-01 13:05:21 459,264 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll

+ 2008-03-01 13:05:21 52,224 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll

+ 2008-03-01 16:35:26 3,591,680 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll

+ 2008-03-01 13:05:24 478,208 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll

+ 2008-03-01 13:05:24 193,024 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll

+ 2008-03-01 13:05:25 671,232 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll

+ 2008-03-01 13:05:25 102,912 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll

+ 2008-03-01 13:05:25 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll

+ 2007-03-06 02:01:51 214,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe

+ 2007-03-06 02:03:01 374,496 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll

+ 2008-03-01 13:05:25 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll

+ 2008-03-01 13:05:25 1,159,680 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll

+ 2008-03-01 13:05:25 233,472 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll

+ 2008-03-01 13:05:26 826,368 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll

+ 2003-07-15 09:13:58 166,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\ACCWIZ.DLL

+ 2003-07-15 01:14:28 350,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL

+ 2003-07-15 09:18:12 47,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE

+ 2003-08-13 08:34:38 10,073,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE

+ 2003-07-24 05:01:40 1,949,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\FPCUTL.DLL

+ 2003-07-15 05:36:14 186,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL

+ 2003-07-26 01:00:16 1,157,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL

+ 2003-07-26 01:14:50 799,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL

+ 2003-07-15 05:11:42 2,139,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE

+ 2003-07-14 20:57:44 87,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL

+ 2003-08-01 21:07:36 4,815,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\INFOPATH.EXE

+ 2003-05-28 21:42:48 514,680 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\INTLNAME.DLL

+ 2003-06-18 23:31:44 758,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL

+ 2003-06-18 23:31:48 17,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL

+ 2003-06-18 23:31:48 18,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL

+ 2003-06-18 23:31:46 35,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL

+ 2003-06-18 23:31:34 443,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL

+ 2003-05-28 21:42:50 342,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\METCONV.DLL

+ 2003-08-15 06:54:08 6,627,392 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSACCESS.EXE

+ 2003-07-15 09:13:58 130,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSAEXP30.DLL

+ 2003-07-15 09:14:00 139,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSJSPP40.DLL

+ 2003-08-08 06:23:16 12,172,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSO.DLL

+ 2003-07-15 01:14:18 106,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL

+ 2003-07-23 20:35:26 127,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL

+ 2003-06-18 23:31:24 1,033,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL

+ 2003-07-28 18:24:40 5,677,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSPUB.EXE

+ 2003-07-15 05:02:14 627,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE

+ 2003-07-15 04:56:24 124,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE

+ 2003-07-24 04:40:00 482,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL

+ 2003-07-15 09:14:26 283,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\OIS.EXE

+ 2003-07-15 09:14:26 828,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL

+ 2003-07-15 09:14:26 27,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL

+ 2003-08-04 19:19:34 7,330,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\OWC10.DLL

+ 2003-08-01 21:09:04 8,086,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\OWC11.DLL

+ 2003-07-30 18:40:40 6,133,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE

+ 2003-07-15 09:18:54 430,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL

+ 2003-07-31 21:21:08 1,782,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE

+ 2003-07-15 04:40:26 130,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\PRTF9.DLL

+ 2003-07-15 04:51:12 604,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\PTXT9.DLL

+ 2003-07-15 04:50:26 551,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\PUBCONV.DLL

+ 2003-08-06 19:26:18 445,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\SOA.DLL

+ 2003-08-03 16:52:32 2,808,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL

+ 2003-08-06 19:24:20 12,037,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE

+ 2005-05-26 23:06:54 10,095,808 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\EXCEL.EXE

+ 2005-05-03 22:06:28 465,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSDMENG.DLL

+ 2005-05-03 22:06:30 1,411,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSDMINE.DLL

+ 2005-05-03 22:06:24 199,408 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSMDUN80.DLL

+ 2005-07-22 15:47:14 12,242,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSO.DLL

+ 2005-05-03 22:06:30 2,120,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSOLAP80.DLL

+ 2005-07-05 10:08:18 5,685,440 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\MSPUB.EXE

+ 2005-03-17 12:01:56 130,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\PRTF9.DLL

+ 2005-03-17 12:02:04 605,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\PTXT9.DLL

+ 2005-03-17 12:02:02 555,720 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\PUBCONV.DLL

+ 2005-07-22 15:21:40 12,061,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\4140110900063D11C8EF10054038389C\11.0.7969\WINWORD.EXE

- 2008-04-09 20:34:23 593,920 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\accicons.exe

+ 2008-06-12 20:41:39 593,920 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\accicons.exe

- 2008-04-09 20:34:23 12,288 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\cagicon.exe

+ 2008-06-12 20:41:39 12,288 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\cagicon.exe

- 2008-04-09 20:34:23 86,016 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\inficon.exe

+ 2008-06-12 20:41:39 86,016 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\inficon.exe

- 2008-04-09 20:34:23 135,168 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\misc.exe

+ 2008-06-12 20:41:39 135,168 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\misc.exe

- 2008-04-09 20:34:24 11,264 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\mspicons.exe

+ 2008-06-12 20:41:39 11,264 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\mspicons.exe

- 2008-04-09 20:34:24 27,136 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\oisicon.exe

+ 2008-06-12 20:41:39 27,136 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\oisicon.exe

- 2008-04-09 20:34:24 4,096 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\opwicon.exe

+ 2008-06-12 20:41:39 4,096 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\opwicon.exe

- 2008-04-09 20:34:24 794,624 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\outicon.exe

+ 2008-06-12 20:41:39 794,624 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\outicon.exe

- 2008-04-09 20:34:23 249,856 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pptico.exe

+ 2008-06-12 20:41:39 249,856 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pptico.exe

- 2008-04-09 20:34:23 61,440 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pubs.exe

+ 2008-06-12 20:41:39 61,440 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\pubs.exe

- 2008-04-09 20:34:24 23,040 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\unbndico.exe

+ 2008-06-12 20:41:39 23,040 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\unbndico.exe

- 2008-04-09 20:34:23 286,720 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\wordicon.exe

+ 2008-06-12 20:41:39 286,720 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\wordicon.exe

- 2008-04-09 20:34:23 409,600 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-06-12 20:41:39 409,600 ----a-r C:\WINDOWS\Installer\{90110414-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-04-29 17:03:52 29,926 ----a-r C:\WINDOWS\Installer\{D70A63D1-2F54-4713-8AE6-BBD28D1A62E6}\MsblIco.Exe

- 2008-03-01 13:05:18 124,928 ----a-w C:\WINDOWS\system32\advpack.dll

+ 2008-04-23 04:22:22 124,928 ----a-w C:\WINDOWS\system32\advpack.dll

- 2008-03-01 13:05:18 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll

+ 2008-04-23 04:22:22 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll

- 2004-08-04 12:00:00 561,179 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll

+ 2008-03-25 04:50:25 554,008 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll

- 2008-03-01 13:05:18 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll

+ 2008-04-23 04:22:22 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll

- 2008-03-01 13:05:18 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll

+ 2008-04-23 04:22:22 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll

- 2008-03-01 13:05:18 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll

+ 2008-04-23 04:22:22 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll

- 2008-03-01 13:05:18 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll

+ 2008-04-23 04:22:22 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll

- 2008-02-29 08:58:26 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe

+ 2008-04-22 07:43:26 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe

- 2008-03-01 13:05:18 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll

+ 2008-04-23 04:22:22 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll

- 2008-03-01 13:05:18 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll

+ 2008-04-23 04:22:22 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll

- 2008-02-15 05:44:25 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll

+ 2008-04-20 05:07:51 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll

- 2008-03-01 13:05:18 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll

+ 2008-04-23 04:22:22 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll

- 2008-03-01 13:05:19 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll

+ 2008-04-23 04:22:22 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll

- 2008-03-01 13:05:20 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll

+ 2008-04-23 04:22:23 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll

- 2008-03-01 13:05:20 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll

+ 2008-04-23 04:22:23 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll

- 2008-03-01 13:05:20 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll

+ 2008-04-23 04:22:23 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll

- 2008-02-22 10:00:51 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe

+ 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe

- 2008-02-29 08:58:53 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe

+ 2008-04-22 07:43:46 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe

- 2008-03-01 13:05:21 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll

+ 2008-04-23 04:22:23 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll

- 2004-08-04 12:00:00 294,400 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll

+ 2008-02-26 12:01:53 294,912 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll

- 2004-08-04 12:00:00 512,029 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll

+ 2008-03-25 04:50:28 518,944 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll

- 2004-08-04 12:00:00 319,517 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll

+ 2008-03-25 04:50:30 326,432 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll

- 2008-03-01 13:05:21 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll

+ 2008-04-23 04:22:23 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll

- 2008-03-01 13:05:21 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll

+ 2008-04-23 04:22:23 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll

- 2008-03-01 16:35:26 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll

+ 2008-04-23 20:22:24 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll

- 2008-03-01 13:05:24 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll

+ 2008-04-23 04:22:23 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll

- 2004-08-04 12:00:00 1,507,356 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll

+ 2008-03-25 04:50:34 1,516,568 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll

- 2004-08-04 12:00:00 358,976 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll

+ 2008-03-25 04:50:40 355,112 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll

- 2004-08-04 12:00:00 159,775 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll

+ 2008-03-25 04:51:59 166,688 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll

- 2004-08-04 12:00:00 53,279 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll

+ 2008-03-25 04:50:42 60,192 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll

- 2004-08-04 12:00:00 241,693 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll

+ 2008-03-25 04:50:42 248,608 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll

- 2004-08-04 12:00:00 213,023 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll

+ 2008-03-25 04:50:44 219,936 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll

- 2004-08-04 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll

+ 2008-03-25 04:50:45 355,104 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll

- 2008-03-01 13:05:24 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll

+ 2008-04-23 04:22:23 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll

- 2004-08-04 12:00:00 421,919 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll

+ 2008-03-25 04:50:47 432,928 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll

- 2004-08-04 12:00:00 315,423 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll

+ 2008-03-25 04:50:49 322,336 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll

- 2004-08-04 12:00:00 552,989 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll

+ 2008-03-25 04:50:52 559,904 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll

- 2004-08-04 12:00:00 258,077 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll

+ 2008-03-25 04:50:55 264,992 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll

- 2008-03-01 13:05:25 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll

+ 2008-04-23 04:22:23 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll

- 2004-08-04 12:00:00 831,519 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll

+ 2008-03-25 04:50:57 838,432 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll

- 2004-08-04 12:00:00 614,429 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll

+ 2008-03-25 04:51:59 621,344 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll

- 2004-08-04 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll

+ 2008-03-25 04:50:58 355,104 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll

- 2008-03-01 13:05:25 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll

+ 2008-04-23 04:22:23 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll

- 2008-03-01 13:05:25 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll

+ 2008-04-23 04:22:23 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll

- 2007-10-29 22:45:19 1,290,752 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll

+ 2008-05-07 05:16:33 1,290,752 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll

- 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys

+ 2008-05-08 12:28:49 202,752 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys

- 2008-03-01 13:05:25 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll

+ 2008-04-23 04:22:23 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll

- 2008-03-01 13:05:25 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll

+ 2008-04-23 04:22:23 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll

- 2008-03-01 13:05:25 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll

+ 2008-04-23 04:22:23 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll

- 2008-03-01 13:05:26 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll

+ 2008-04-23 04:22:23 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll

- 2008-03-01 13:05:18 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll

+ 2008-04-23 04:22:22 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll

- 2008-03-01 13:05:18 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll

+ 2008-04-23 04:22:22 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll

- 2008-03-01 13:05:18 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll

+ 2008-04-23 04:22:22 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll

- 2008-03-01 13:05:18 63,488 ----a-w C:\WINDOWS\system32\icardie.dll

+ 2008-04-23 04:22:22 63,488 ----a-w C:\WINDOWS\system32\icardie.dll

- 2008-02-29 08:58:26 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe

+ 2008-04-22 07:43:26 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe

- 2008-03-01 13:05:18 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll

+ 2008-04-23 04:22:22 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll

- 2008-03-01 13:05:18 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll

+ 2008-04-23 04:22:22 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll

- 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll

+ 2008-04-20 05:07:51 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll

- 2008-03-01 13:05:18 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll

+ 2008-04-23 04:22:22 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll

- 2008-03-01 13:05:19 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll

+ 2008-04-23 04:22:22 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll

- 2008-03-01 13:05:20 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll

+ 2008-04-23 04:22:23 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll

- 2008-03-01 13:05:20 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll

+ 2008-04-23 04:22:23 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll

- 2008-03-01 13:05:20 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll

+ 2008-04-23 04:22:23 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll

- 2008-02-22 10:00:51 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe

+ 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe

- 2008-03-01 13:05:21 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll

+ 2008-04-23 04:22:23 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll

- 2006-04-27 23:51:38 29,968 ----a-w C:\WINDOWS\system32\mdimon.dll

+ 2004-03-22 13:17:06 24,816 ----a-w C:\WINDOWS\system32\mdimon.dll

- 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe

+ 2008-05-29 23:35:11 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe

- 2004-08-04 12:00:00 294,400 ----a-w C:\WINDOWS\system32\MSCTF.dll

+ 2008-02-26 12:01:53 294,912 ----a-w C:\WINDOWS\system32\msctf.dll

- 2004-08-04 12:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll

+ 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll

- 2004-08-04 12:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll

+ 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll

- 2008-03-01 13:05:21 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll

+ 2008-04-23 04:22:23 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll

- 2008-03-01 13:05:21 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll

+ 2008-04-23 04:22:23 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll

- 2008-03-01 16:35:26 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll

+ 2008-04-23 20:22:24 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll

- 2008-03-01 13:05:24 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll

+ 2008-04-23 04:22:23 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll

- 2004-08-04 12:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll

+ 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll

- 2004-08-04 12:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll

+ 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll

- 2004-08-04 12:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll

+ 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll

- 2004-08-04 12:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll

+ 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll

- 2004-08-04 12:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll

+ 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll

- 2004-08-04 12:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll

+ 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll

- 2008-03-01 13:05:24 193,024 ----a-w C:\WINDOWS\system32\msrating.dll

+ 2008-04-23 04:22:23 193,024 ----a-w C:\WINDOWS\system32\msrating.dll

- 2004-08-04 12:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll

+ 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll

- 2004-08-04 12:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll

+ 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll

- 2004-08-04 12:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll

+ 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll

- 2004-08-04 12:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll

+ 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll

- 2008-03-01 13:05:25 671,232 ----a-w C:\WINDOWS\system32\mstime.dll

+ 2008-04-23 04:22:23 671,232 ----a-w C:\WINDOWS\system32\mstime.dll

- 2004-08-04 12:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll

+ 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll

- 2004-08-04 12:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll

+ 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll

- 2008-03-01 13:05:25 102,912 ----a-w C:\WINDOWS\system32\occache.dll

+ 2008-04-23 04:22:23 102,912 ----a-w C:\WINDOWS\system32\occache.dll

- 2008-03-01 13:05:25 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll

+ 2008-04-23 04:22:23 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll

- 2007-01-19 11:53:04 51,056 ----a-w C:\WINDOWS\system32\sirenacm.dll

+ 2007-10-18 09:31:46 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll

- 2007-03-06 02:01:46 14,560 ------w C:\WINDOWS\system32\spmsg.dll

+ 2007-11-30 11:19:51 17,784 ------w C:\WINDOWS\system32\spmsg.dll

+ 2004-03-22 13:17:04 765,680 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll

+ 2004-03-22 13:17:10 42,224 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll

+ 2004-03-22 13:17:04 765,680 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll

+ 2004-03-22 13:17:10 42,224 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll

- 2006-04-27 23:51:40 29,968 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

+ 2004-03-22 13:17:08 25,840 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

- 2008-03-01 13:05:25 105,984 ----a-w C:\WINDOWS\system32\url.dll

+ 2008-04-23 04:22:23 105,984 ----a-w C:\WINDOWS\system32\url.dll

- 2008-03-01 13:05:25 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll

+ 2008-04-23 04:22:23 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll

- 2008-03-01 13:05:25 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll

+ 2008-04-23 04:22:23 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-18 20:34 579584]

"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

"msnmsgr"="C:\Programfiler\MSN Messenger\msnmsgr.exe" [ ]

"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 12:40 219136]

 

C:\Documents and settings\All Users.WINDOWS\Start-meny\Programmer\Oppstart\

D-Link AirPlus G+ Wireless Adapter Utility.lnk - C:\Programfiler\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE [2007-07-26 19:20:09 671744]

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

WG111v2 Smart Wizard Wireless Setting.lnk - C:\Programfiler\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-09-09 13:43:37 745472]

WinZip Quick Pick.lnk - C:\Programfiler\WinZip\WZQKPICK.EXE [2006-09-07 21:38:07 122880]

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\LimeWire\\LimeWire.exe"=

"C:\\WINDOWS\\system32\\LEXPPS.EXE"=

"C:\\Programfiler\\Java\\jre1.5.0_06\\bin\\javaw.exe"=

"C:\\Programfiler\\SmartFTP Client 2.0\\SmartFTP.exe"=

"C:\\Programfiler\\Rapid PHP 2006\\rapidphp.exe"=

"C:\\Programfiler\\PC Tools AntiVirus 2\\PCATV.exe"=

"C:\\Programfiler\\Morpheus\\Morpheus.exe"=

"C:\\Programfiler\\BitLord\\BitLord.exe"=

"C:\\Programfiler\\Opera\\Opera.exe"=

"C:\\WINDOWS\\system32\\rtcshare.exe"=

"C:\\Programfiler\\NetMeeting\\conf.exe"=

"C:\\Programfiler\\GlobalSCAPE\\CuteFTP 8 Professional\\ftpte.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programfiler\\TVAnts\\Tvants.exe"=

"C:\\Programfiler\\Internet Explorer\\iexplore.exe"=

"C:\\Programfiler\\Grisoft\\AVG7\\avginet.exe"=

"C:\\Programfiler\\Grisoft\\AVG7\\avgamsvr.exe"=

"C:\\Programfiler\\Grisoft\\AVG7\\avgcc.exe"=

"C:\\Programfiler\\Grisoft\\AVG7\\avgemc.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

 

R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 11:43]

R3 TNET1130;D-Link AirPlus G+ Wireless Adapter;C:\WINDOWS\system32\DRIVERS\GPlus.sys [2004-05-21 16:59]

S3 BTCAMDRV;Mobiola Web Camera driver;C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2005-06-02 19:19]

S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]

S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]

S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]

S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]

S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]

S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-16 11:39]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ec18813-af5f-11db-ae8b-000272cc4377}]

\Shell\AutoRun\command - G:\setupSNK.exe

 

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-06-20 13:29:13

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-06-20 13:35:51

ComboFix-quarantined-files.txt 2008-06-20 11:35:43

ComboFix2.txt 2008-04-14 17:51:20

ComboFix3.txt 2008-04-14 17:34:20

 

Pre-Run: 18,631,598,080 byte ledig

Post-Run: 18,660,249,600 byte ledig

 

503 --- E O F --- 2008-06-12 20:44:38

 

 

Endret av TomHan
Lenke til kommentar
Videoannonse
Annonse

Steng nettleser.

---

Start HijackThis "scan" finn disse linjene merk dem,så trykk fix checked.

O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programfiler\MyWebSearch\bar\3.bin\MWSBAR.DLL (file missing)

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=2 /w

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZS

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...tup1.0.0.15.cab

---

Last ned kjør CCleaner

'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t.

Kjør register-renser"svar ja til og reparere"(kjør en par ganger til alle feil er borte)

---

Last ned oppdatere og kjør full scan SAS free

Post loggen fra SAS (preferences->statistics/logs)

---

Ettersom pcen er treg tar vi med defragmering.

Auslogics Disk Defrag + Free Registry Defrag + Pagedefrag

---

Restart og lag en ny hijackthis logg.

Si litt om hvordan pcen kjører etter dette.

Endret av SNIPPSAT
Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
×
×
  • Opprett ny...