Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

think i may have a virus or trojan. HJT logs attached

  • 05-03-2009 8:59am
    #1
    Closed Accounts Posts: 1,178 ✭✭✭


    guys got a bit of a problem on the wife's laptop.

    when Ilog into windows the desktop image is displayed fine but no icons appear. if i give the laptop a three finger salute and enter task manager and start the explorer task the icons and task bar appear. but if i reboot same again. if i go into safe mode i also get the same problem.

    there's nothing in the windows event view to indicate an issue, so i ran Hijack this last night, Malwarebytes and AVG.

    you can see malwarebytes found something in C:\Documents and Settings\alan\Local Settings\Temp\ but the strange thing is I had renamed the users folder in C:\Documents and Settings\ prior to running malwarebytes in case there was something in corrupted with the profile and used Ultimate Boot CD to go in and clear out all files in the old C:\Documents and Settings\alan\Local Settings\Temp\ but as you can see malwarebytes found something in the new profile folder. I asked Malwarebytes to clean up what it found and rebooted but the bloody thing is still the same so I'm doing another scan this morning. so it's obviously being called from some place else.

    I ran AVG yesterday and it said it found something called Trojan.Heur (think that was it) I asked AVG to clean it up and on a rescan later last night it found nothing.

    All these scan where run in safe mode.

    logs are below



    HiJackThis Log
    __________________

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:16:13, on 04/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
    C:\Program Files\Kodak\printer\center\KodakSvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    c:\program files\common files\installshield\updateservice\isuspm.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
    C:\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=5070908
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.ie/hws/sb/dell-row/en/side.html?channel=ie
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ie/hws/sb/dell-row/en/side.html?channel=ie
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=5070908
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=5070908
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www1.euro.dell.com/content/default....;l=en&s=gen
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
    O4 - HKLM\..\Run: [%PROVIDERID%] "bin\sprtcmd.exe" /P %PROVIDERID%
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\HiJackThis\HijackThis.exe /startupscan
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.ie/SnapfishActivia.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 8169 bytes

    AVG Log
    ________________________
    AVG 8.5 Anti-Virus command line scanner
    Copyright © 1992 - 2009 AVG Technologies
    Program version 8.0.268, engine 8.0.273
    Virus Database: Version 270.11.7/1978 2009-03-03

    C:\Documents and Settings\alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
    C:\Documents and Settings\alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\alan\NTUSER.DAT Locked file. Not tested.
    C:\Documents and Settings\alan\ntuser.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\NetworkService\NTUSER.DAT Locked file. Not tested.
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Locked file. Not tested.
    C:\pagefile.sys Locked file. Not tested.
    C:\System Volume Information\ Locked file. Not tested.
    C:\WINDOWS\system32\config\DEFAULT Locked file. Not tested.
    C:\WINDOWS\system32\config\default.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SAM Locked file. Not tested.
    C:\WINDOWS\system32\config\SAM.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SECURITY Locked file. Not tested.
    C:\WINDOWS\system32\config\SECURITY.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SOFTWARE Locked file. Not tested.
    C:\WINDOWS\system32\config\software.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SYSTEM Locked file. Not tested.
    C:\WINDOWS\system32\config\system.LOG Locked file. Not tested.

    Objects scanned : 253964
    Found infections : 0
    Found PUPs : 0
    Healed infections : 0
    Healed PUPs : 0
    Warnings : 0

    Malwayrbytes log
    ______________________________

    Malwarebytes' Anti-Malware 1.34
    Database version: 1749
    Windows 5.1.2600 Service Pack 3

    05/03/2009 06:48:21
    mbam-log-2009-03-05 (06-47-47).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 150228
    Time elapsed: 3 hour(s), 4 minute(s), 54 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> No action taken.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\alan\Local Settings\Temp\ie3.tmp (Trojan.Agent) -> No action taken.


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hello

    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    RcAuto1.gif


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    whatnext.png


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


  • Closed Accounts Posts: 1,178 ✭✭✭dade


    ComboFix 09-03-04.01 - alan 2009-03-05 13:42:52.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.491 [GMT 0:00]
    Running from: C:\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\windows\IE4 Error Log.txt

    BITS: Possible infected sites

    hxxp://banksguard.com
    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\$NtServicePackUninstall$\userinit.exe


    .
    ((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
    .

    2009-03-05 12:38 . 2009-03-05 12:38 <DIR> d
    C:\AVG Free
    2009-03-05 12:38 . 2009-03-05 12:38 <DIR> d
    C:\AVG 8.5 free
    2009-03-05 12:38 . 2009-03-05 13:37 2,932,444 -ra
    C:\ComboFix.exe
    2009-03-05 11:29 . 2009-02-11 10:19 38,496 --a
    c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-05 11:29 . 2009-02-11 10:19 15,504 --a
    c:\windows\system32\drivers\mbam.sys
    2009-03-05 11:22 . 2009-03-05 11:22 <DIR> d
    c:\documents and settings\alan\Application Data\ATI
    2009-03-05 11:12 . 2009-03-05 11:12 <DIR> d
    c:\program files\Network Associates
    2009-03-05 11:12 . 2009-03-05 11:12 <DIR> d
    c:\program files\Common Files\Network Associates
    2009-03-05 11:12 . 2009-03-05 11:12 <DIR> d
    c:\documents and settings\All Users\Application Data\Network Associates
    2009-03-05 11:10 . 2009-03-05 12:39 <DIR> d
    c:\documents and settings\alan\Application Data\U3
    2009-03-05 11:03 . 2009-03-05 10:40 <DIR> d
    c:\windows\tmp
    2009-03-05 10:46 . 2009-03-05 10:46 536 --a
    c:\windows\regcopy.bat
    2009-03-05 10:26 . 2009-03-05 10:26 <DIR> d--hs---- c:\documents and settings\NetworkService.NT AUTHORITY.000
    2009-03-05 10:26 . 2007-09-08 09:35 <DIR> d
    c:\documents and settings\Administrator.D23H443J.000\Application Data\InstallShield
    2009-03-05 10:26 . 2007-09-08 09:45 <DIR> d
    c:\documents and settings\Administrator.D23H443J.000\Application Data\GTek
    2009-03-05 10:26 . 2007-09-08 09:49 <DIR> d
    c:\documents and settings\Administrator.D23H443J.000\Application Data\ATI
    2009-03-05 10:26 . 2009-03-05 10:26 <DIR> d
    c:\documents and settings\Administrator.D23H443J.000
    2009-03-05 10:24 . 2009-03-05 10:24 <DIR> d--hs---- c:\documents and settings\LocalService.NT AUTHORITY
    2009-03-05 10:24 . 2009-03-05 10:24 <DIR> d
    c:\documents and settings\Administrator.D23H443J
    2009-03-05 10:23 . 2009-03-05 10:24 <DIR> d--hs---- c:\documents and settings\NetworkService.NT AUTHORITY
    2009-03-04 23:40 . 2009-03-04 23:40 <DIR> d
    c:\documents and settings\alan\Application Data\Malwarebytes
    2009-03-04 23:12 . 2009-03-05 11:10 <DIR> d
    C:\HiJackThis
    2009-03-04 22:41 . 2007-09-08 09:45 <DIR> d
    c:\documents and settings\alan\Application Data\GTek
    2009-03-04 22:41 . 2009-03-05 11:22 <DIR> d---s---- c:\documents and settings\alan
    2009-03-04 15:19 . 2009-03-04 22:49 <DIR> d
    C:\$AVG8.VAULT$
    2009-03-04 15:12 . 2009-03-04 15:16 <DIR> d
    c:\windows\system32\drivers\Avg(2)
    2009-03-04 15:12 . 2009-03-05 11:10 <DIR> d
    c:\program files\AVG(2)
    2009-03-04 15:12 . 2009-03-05 11:11 <DIR> d
    c:\documents and settings\All Users\Application Data\avg8(2)
    2009-03-04 11:03 . 2009-03-05 11:29 <DIR> d
    c:\program files\Malwarebytes' Anti-Malware
    2009-03-04 11:03 . 2009-03-04 11:03 <DIR> d
    c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-04 10:14 . 2009-03-04 10:14 262,144 --a
    c:\windows\SAM
    2009-03-04 10:13 . 2009-03-04 10:13 95,744 --a
    c:\windows\system32\rnpasswd.exe
    2009-02-23 21:16 . 2008-04-14 00:12 26,112 --a
    c:\windows\system32\stu2.exe
    2009-02-19 19:33 . 2009-02-19 20:33 <DIR> d
    c:\windows\SxsCaPendDel
    2009-02-19 19:33 . 2009-02-19 19:34 <DIR> d
    C:\50acbb4617b933f6d3
    2009-02-19 19:21 . 2009-02-25 19:41 512 --a
    c:\windows\randseed.rnd
    2009-02-19 19:20 . 2009-02-19 19:20 <DIR> d
    c:\program files\Common Files\Cisco Systems
    2009-02-19 19:19 . 2007-11-26 20:00 117,024 --a
    c:\windows\system32\drivers\naiavf5x.sys
    2009-02-19 19:19 . 2007-11-26 20:00 59,904 --a
    c:\windows\system32\drivers\mvstdi5x.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-03 23:13
    d
    w c:\documents and settings\All Users\Application Data\McAfee
    .

    ((((((((((((((((((((((((((((( snapshot@2008-06-08_21.42.14.98 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-05-27 17:31:16 765,952 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\SP2QFE\vgx.dll
    + 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\update.exe
    + 2007-03-06 01:23:47 371,424 ----a-w c:\windows\$hf_mig$\KB938127-v2-IE7\update\updspapi.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB938464\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB938464\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB938464\update\spcustom.dll
    + 2007-11-30 11:20:44 755,576 ----a-w c:\windows\$hf_mig$\KB938464\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB938464\update\updspapi.dll
    + 2008-05-02 13:30:08 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP2QFE\msgsc.dll
    + 2008-05-02 14:01:49 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP3GDR\msgsc.dll
    + 2008-05-02 13:42:10 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
    + 2007-11-30 11:20:44 755,576 ----a-w c:\windows\$hf_mig$\KB946648\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
    + 2008-04-21 06:44:29 3,066,880 ----a-w c:\windows\$hf_mig$\KB950759\SP3GDR\mshtml.dll
    + 2008-04-21 06:44:29 666,112 ----a-w c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll
    + 2008-04-21 06:24:01 3,067,392 ----a-w c:\windows\$hf_mig$\KB950759\SP3QFE\mshtml.dll
    + 2008-04-21 06:24:02 666,624 ----a-w c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950759\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950759\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950759\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB950759\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB950759\update\updspapi.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950760\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950760\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950760\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB950760\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB950760\update\updspapi.dll
    + 2008-05-08 12:14:51 203,008 ----a-w c:\windows\$hf_mig$\KB950762\SP2QFE\rmcast.sys
    + 2008-05-08 14:02:52 203,136 ----a-w c:\windows\$hf_mig$\KB950762\SP3GDR\rmcast.sys
    + 2008-05-08 13:58:17 203,136 ----a-w c:\windows\$hf_mig$\KB950762\SP3QFE\rmcast.sys
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950762\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950762\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950762\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB950762\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB950762\update\updspapi.dll
    + 2008-07-07 20:06:43 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
    + 2008-07-07 20:26:58 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
    + 2008-07-07 20:23:18 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
    + 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB950974\update\update.exe
    + 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
    + 2008-04-11 18:39:39 683,520 ----a-w c:\windows\$hf_mig$\KB951066\SP2QFE\inetcomm.dll
    + 2008-04-11 19:04:26 691,712 ----a-w c:\windows\$hf_mig$\KB951066\SP3GDR\inetcomm.dll
    + 2008-04-12 00:22:26 691,712 ----a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
    + 2007-12-03 15:25:31 755,576 ----a-w c:\windows\$hf_mig$\KB951066\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
    + 2008-07-14 11:03:00 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
    + 2008-07-11 12:42:28 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
    + 2008-07-11 12:51:51 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
    + 2008-06-13 09:52:16 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys
    + 2008-06-13 11:05:51 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys
    + 2008-06-13 11:27:43 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951376-v2\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951376-v2\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\updspapi.dll
    + 2008-04-14 11:00:16 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP2QFE\bthport.sys
    + 2008-04-14 12:30:49 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP3GDR\bthport.sys
    + 2008-04-14 12:36:35 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP3QFE\bthport.sys
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951376\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951376\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951376\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB951376\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB951376\update\updspapi.dll
    + 2008-05-07 04:55:40 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP2QFE\quartz.dll
    + 2008-05-07 05:12:40 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP3GDR\quartz.dll
    + 2008-05-07 05:04:15 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP3QFE\quartz.dll
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951698\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951698\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951698\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB951698\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951698\update\updspapi.dll
    + 2008-06-20 11:48:03 138,496 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys
    + 2008-06-20 17:43:05 147,968 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
    + 2008-06-20 17:43:05 245,248 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
    + 2008-06-20 11:59:02 361,600 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    + 2008-06-20 11:16:44 225,856 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951748\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951748\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951748\update\spcustom.dll
    + 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB951748\update\update.exe
    + 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB951748\update\updspapi.dll
    + 2008-05-07 09:07:23 135,168 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\cscript.exe
    + 2008-05-09 10:45:15 512,000 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\jscript.dll
    + 2008-05-09 10:45:16 180,224 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrobj.dll
    + 2008-05-09 10:45:16 172,032 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrrun.dll
    + 2008-05-09 10:45:16 430,080 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\vbscript.dll
    + 2008-05-08 11:24:44 155,648 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wscript.exe
    + 2008-05-09 10:45:17 90,112 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wshext.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951978\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951978\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951978\update\spcustom.dll
    + 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB951978\update\update.exe
    + 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB951978\update\updspapi.dll
    + 2008-05-01 15:04:00 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP2QFE\msadce.dll
    + 2008-05-01 14:33:02 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP3GDR\msadce.dll
    + 2008-05-01 14:38:05 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB952287\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
    + 2008-06-24 16:28:00 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP2QFE\mscms.dll
    + 2008-06-24 16:43:16 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP3GDR\mscms.dll
    + 2008-06-24 16:53:10 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB952954\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
    + 2008-09-15 12:17:07 1,846,912 ----a-w c:\windows\$hf_mig$\KB954211\SP2QFE\win32k.sys
    + 2008-09-15 12:12:56 1,846,400 ----a-w c:\windows\$hf_mig$\KB954211\SP3GDR\win32k.sys
    + 2008-09-15 12:25:27 1,846,912 ----a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
    + 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB954211\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
    + 2008-09-10 01:10:56 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
    + 2008-10-03 09:49:31 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP3QFE\strmdll.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954600\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954600\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954600\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB954600\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB954600\update\updspapi.dll
    + 2008-09-04 16:32:52 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP2QFE\msxml3.dll
    + 2008-09-04 17:15:04 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3GDR\msxml3.dll
    + 2008-09-04 17:12:27 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
    + 2008-07-09 13:08:38 382,840 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
    + 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
    + 2008-08-26 09:08:35 124,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\advpack.dll
    + 2008-08-26 09:08:36 347,136 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
    + 2008-08-26 09:08:36 214,528 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
    + 2008-08-26 09:08:36 132,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\extmgr.dll
    + 2008-08-26 09:08:36 63,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
    + 2008-08-25 08:43:21 70,656 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
    + 2008-08-26 09:08:36 153,088 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
    + 2008-08-26 09:08:36 230,400 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieaksie.dll
    + 2008-08-23 05:54:50 161,792 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
    + 2008-08-26 09:08:36 380,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dll
    + 2008-08-26 09:08:37 388,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iedkcs32.dll
    + 2008-10-03 17:26:50 6,068,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
    + 2008-08-26 09:08:39 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
    + 2008-08-26 09:08:39 267,776 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
    + 2008-08-25 08:43:21 13,824 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
    + 2008-08-23 05:56:16 635,848 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
    + 2008-08-26 09:08:40 27,648 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
    + 2008-08-26 09:08:40 459,264 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
    + 2008-08-26 09:08:40 52,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
    + 2008-08-26 09:08:43 3,594,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
    + 2008-08-26 09:08:43 477,696 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
    + 2008-08-26 09:08:44 193,024 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
    + 2008-08-26 09:08:44 671,232 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
    + 2008-08-26 09:08:44 102,912 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
    + 2008-08-26 09:08:44 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
    + 2008-08-26 09:08:44 105,984 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
    + 2008-08-26 09:08:45 1,162,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
    + 2008-08-26 09:08:45 233,472 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\webcheck.dll
    + 2008-08-26 09:08:45 827,904 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
    + 2008-08-20 05:30:53 3,067,904 ----a-w c:\windows\$hf_mig$\KB956390\SP3GDR\mshtml.dll
    + 2008-08-20 05:30:51 1,499,136 ----a-w c:\windows\$hf_mig$\KB956390\SP3GDR\shdocvw.dll
    + 2008-08-20 05:30:52 619,520 ----a-w c:\windows\$hf_mig$\KB956390\SP3GDR\urlmon.dll
    + 2008-08-20 05:30:51 666,112 ----a-w c:\windows\$hf_mig$\KB956390\SP3GDR\wininet.dll
    + 2008-08-20 04:58:54 3,067,904 ----a-w c:\windows\$hf_mig$\KB956390\SP3QFE\mshtml.dll
    + 2008-08-20 04:58:47 1,499,136 ----a-w c:\windows\$hf_mig$\KB956390\SP3QFE\shdocvw.dll
    + 2008-08-20 04:58:50 620,032 ----a-w c:\windows\$hf_mig$\KB956390\SP3QFE\urlmon.dll
    + 2008-08-20 04:58:48 666,624 ----a-w c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956390\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956390\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956390\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB956390\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB956390\update\updspapi.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB956391\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
    + 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
    + 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
    + 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
    + 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
    + 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
    + 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
    + 2008-08-14 10:34:26 138,496 ----a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956803\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
    + 2008-08-14 10:09:26 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlmp.exe
    + 2008-08-14 09:33:16 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
    + 2008-08-14 09:33:16 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrpamp.exe
    + 2008-08-14 10:11:02 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
    + 2008-08-14 10:39:28 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
    + 2008-08-14 15:39:46 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
    + 2008-08-14 10:09:44 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
    + 2008-08-14 16:11:10 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956841\update\update.exe
    + 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
    + 2008-08-28 10:35:33 333,056 ----a-w c:\windows\$hf_mig$\KB957095\SP2QFE\srv.sys
    + 2008-09-08 10:41:42 333,824 ----a-w c:\windows\$hf_mig$\KB957095\SP3GDR\srv.sys
    + 2008-09-08 11:37:19 333,824 ----a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB957095\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
    + 2008-10-24 11:25:29 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP2QFE\mrxsmb.sys
    + 2008-10-24 11:21:09 455,296 ----a-w c:\windows\$hf_mig$\KB957097\SP3GDR\mrxsmb.sys
    + 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
    + 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
    + 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
    + 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
    + 2008-07-08 13:02:04 755,576 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
    + 2008-07-08 13:02:12 382,840 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
    + 2008-10-16 20:24:09 124,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\advpack.dll
    + 2008-10-16 20:24:09 347,136 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtmsft.dll
    + 2008-10-16 20:24:09 214,528 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtrans.dll
    + 2008-10-16 20:24:09 132,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\extmgr.dll
    + 2008-10-16 20:24:09 63,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\icardie.dll
    + 2008-10-16 12:46:08 70,656 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ie4uinit.exe
    + 2008-10-16 20:24:09 153,088 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakeng.dll
    + 2008-10-16 20:24:09 230,400 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieaksie.dll
    + 2008-10-15 06:33:26 161,792 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dat
    + 2008-10-16 20:24:09 380,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dll
    + 2008-10-16 20:24:09 388,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iedkcs32.dll
    + 2008-10-16 20:24:09 6,068,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieframe.dll
    + 2008-10-16 20:24:09 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iernonce.dll
    + 2008-10-16 20:24:09 267,776 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iertutil.dll
    + 2008-10-16 12:46:08 13,824 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieudinit.exe
    + 2008-10-15 06:34:58 633,632 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
    + 2008-10-16 20:24:10 27,648 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\jsproxy.dll
    + 2008-10-16 20:24:10 459,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeeds.dll
    + 2008-10-16 20:24:10 52,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeedsbs.dll
    + 2008-10-16 20:24:10 3,595,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
    + 2008-10-16 20:24:10 477,696 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtmled.dll
    + 2008-10-16 20:24:10 193,024 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msrating.dll
    + 2008-10-16 20:24:10 671,232 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mstime.dll
    + 2008-10-16 20:24:10 102,912 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\occache.dll
    + 2008-10-16 20:24:10 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\pngfilt.dll
    + 2008-10-16 20:24:10 105,984 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\url.dll
    + 2008-10-16 20:24:11 1,163,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\urlmon.dll
    + 2008-10-16 20:24:11 233,472 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\webcheck.dll
    + 2008-10-16 20:24:11 827,904 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\updspapi.dll
    + 2008-10-16 06:34:08 3,067,904 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\mshtml.dll
    + 2008-10-16 01:04:06 1,499,136 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\shdocvw.dll
    + 2008-10-16 01:04:06 620,032 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\urlmon.dll
    + 2008-10-16 01:04:06 667,136 ----a-w c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB958215\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB958215\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB958215\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB958215\update\update.exe
    + 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB958215\update\updspapi.dll
    + 2008-10-15 16:53:28 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP2QFE\netapi32.dll
    + 2008-10-15 16:34:24 337,408 ----a-w c:\windows\$hf_mig$\KB958644\SP3GDR\netapi32.dll
    + 2008-10-15 16:25:53 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
    + 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958644\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
    + 2008-12-11 12:33:59 333,952 ----a-w c:\windows\$hf_mig$\KB958687\SP3QFE\srv.sys
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB958687\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB958687\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB958687\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958687\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958687\update\updspapi.dll
    + 2008-12-13 06:26:56 3,594,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
    + 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\update.exe
    + 2007-03-06 01:23:47 371,424 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\updspapi.dll
    + 2008-12-12 17:14:50 3,067,904 ----a-w c:\windows\$hf_mig$\KB960714\SP3QFE\mshtml.dll
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB960714\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB960714\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB960714\update\spcustom.dll
    + 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB960714\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB960714\update\updspapi.dll
    + 2006-08-16 11:58:05 100,352 -c----w c:\windows\$NtServicePackUninstall$\6to4svc.dll
    + 2006-11-13 06:02:58 116,736 -c----w c:\windows\$NtServicePackUninstall$\aaclient.dll
    + 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll
    + 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll.000
    + 2004-08-04 04:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\accwiz.exe
    + 2004-08-04 04:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll
    + 2004-08-04 04:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll.000
    + 2004-08-04 04:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll
    + 2004-08-04 04:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll.000
    + 2004-08-04 04:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll
    + 2004-08-04 04:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll.000
    + 2004-08-04 04:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\aclui.dll
    + 2004-08-04 04:00:00 187,776 -c----w c:\windows\$NtServicePackUninstall$\acpi.sys
    + 2004-08-04 04:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll
    + 2004-08-04 04:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll.000
    + 2004-08-04 04:00:00 194,048 -c----w c:\windows\$NtServicePackUninstall$\activeds.dll
    + 2004-08-04 04:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\actmovie.exe
    + 2004-08-04 04:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\actxprxy.dll
    + 2004-08-04 04:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll
    + 2004-08-04 04:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll.000
    + 2004-08-04 04:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\admparse.dll
    + 2004-08-04 04:00:00 175,616 -c----w c:\windows\$NtServicePackUninstall$\adsldp.dll
    + 2004-08-04 04:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\adsldpc.dll
    + 2004-08-04 04:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\adsmsext.dll
    + 2004-08-04 04:00:00 263,680 -c----w c:\windows\$NtServicePackUninstall$\adsnt.dll
    + 2004-08-04 04:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\adsnw.dll
    + 2004-08-04 04:00:00 616,960 -c----w c:\windows\$NtServicePackUninstall$\advapi32.dll
    + 2004-08-04 04:00:00 99,840 -c----w c:\windows\$NtServicePackUninstall$\advpack.dll
    + 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys
    + 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys.000
    + 2004-08-04 04:00:00 138,496 -c----w c:\windows\$NtServicePackUninstall$\afd.sys
    + 2004-08-04 04:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentanm.dll
    + 2004-08-04 04:00:00 214,016 -c----w c:\windows\$NtServicePackUninstall$\agentctl.dll
    + 2006-10-12 14:02:52 42,496 -c----w c:\windows\$NtServicePackUninstall$\agentdp2.dll
    + 2007-03-09 13:46:24 57,344 -c----w c:\windows\$NtServicePackUninstall$\agentdpv.dll
    + 2004-08-04 04:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\agentmpx.dll
    + 2004-08-04 04:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentpsh.dll
    + 2004-08-04 04:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\agentsr.dll
    + 2006-10-12 11:09:53 256,512 -c----w c:\windows\$NtServicePackUninstall$\agentsvr.exe
    + 2004-08-03 22:07:42 42,368 -c----w c:\windows\$NtServicePackUninstall$\agp440.sys
    + 2004-08-03 22:07:44 44,928 -c----w c:\windows\$NtServicePackUninstall$\agpcpq.sys
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0405.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0406.dll
    + 2004-08-04 04:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt0407.dll
    + 2004-08-04 04:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\agt0408.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0409.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt040b.dll
    + 2004-08-04 04:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt040c.dll
    + 2004-08-04 04:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\agt040e.dll
    + 2004-08-04 04:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0410.dll
    + 2004-08-04 04:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0413.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0414.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0415.dll
    + 2004-08-04 04:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0416.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0419.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041d.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041f.dll
    + 2004-08-04 04:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0816.dll
    + 2004-08-04 04:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0c0a.dll
    + 2004-08-04 04:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agtintl.dll
    + 2004-08-04 04:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\ahui.exe
    + 2004-08-04 04:00:00 44,544 -c----w c:\windows\$NtServicePackUninstall$\alg.exe
    + 2004-08-03 22:07:42 42,752 -c----w c:\windows\$NtServicePackUninstall$\alim1541.sys
    + 2004-08-04 04:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\alrsvc.dll
    + 2004-08-03 22:07:44 43,008 -c----w c:\windows\$NtServicePackUninstall$\amdagp.sys
    + 2004-08-04 04:00:00 36,992 -c----w c:\windows\$NtServicePackUninstall$\amdk6.sys
    + 2004-08-04 04:00:00 37,376 -c----w c:\windows\$NtServicePackUninstall$\amdk7.sys
    + 2004-08-04 04:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\amstream.dll
    + 2004-08-04 04:00:00 126,976 -c----w c:\windows\$NtServicePackUninstall$\apphelp.dll
    + 2004-08-04 04:00:00 167,936 -c----w c:\windows\$NtServicePackUninstall$\appmgmts.dll
    + 2004-08-04 04:00:00 295,936 -c----w c:\windows\$NtServicePackUninstall$\appmgr.dll
    + 2004-08-04 04:00:00 60,800 -c----w c:\windows\$NtServicePackUninstall$\arp1394.sys
    + 2001-03-02 19:52:40 15,360 -c----w c:\windows\$NtServicePackUninstall$\asfsipc.dll
    + 2004-08-04 04:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\asr_fmt.exe
    + 2004-08-04 04:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\asr_pfu.exe
    + 2004-08-04 04:00:00 65,024 -c----w c:\windows\$NtServicePackUninstall$\asycfilt.dll
    + 2004-08-04 04:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\asyncmac.sys
    + 2004-08-04 04:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\at.exe
    + 2004-08-03 21:59:44 95,360 -c----w c:\windows\$NtServicePackUninstall$\atapi.sys
    + 2004-08-04 04:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\atl.dll
    + 2004-08-04 04:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\atmadm.exe
    + 2004-08-04 04:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\atmarpc.sys
    + 2004-08-04 04:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\atmfd.dll
    + 2004-08-04 04:00:00 55,936 -c----w c:\windows\$NtServicePackUninstall$\atmlane.sys
    + 2004-08-04 04:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\atmlib.dll
    + 2004-08-04 04:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\attrib.exe
    + 2004-08-04 04:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\audiosrv.dll
    + 2004-08-04 04:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\auditusr.exe
    + 2005-03-02 18:09:29 56,832 -c----w c:\windows\$NtServicePackUninstall$\authz.dll
    + 2004-08-04 04:00:00 588,800 -c----w c:\windows\$NtServicePackUninstall$\autochk.exe
    + 2004-08-04 04:00:00 602,624 -c----w c:\windows\$NtServicePackUninstall$\autoconv.exe
    + 2004-08-04 04:00:00 580,608 -c----w c:\windows\$NtServicePackUninstall$\autofmt.exe
    + 2004-08-04 04:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\autolfn.exe
    + 2004-08-04 04:00:00 84,992 -c----w c:\windows\$NtServicePackUninstall$\avifil32.dll
    + 2004-08-04 04:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\basesrv.dll
    + 2004-08-04 04:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\batmeter.dll
    + 2004-08-04 04:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\batt.dll
    + 2001-08-17 12:57:54 14,080 -c----w c:\windows\$NtServicePackUninstall$\battc.sys
    + 2004-08-04 04:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\bidispl.dll
    + 2004-08-04 04:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\bitsprx2.dll
    + 2004-08-04 04:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\bitsprx3.dll
    + 2004-08-04 04:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\blastcln.exe
    + 2004-08-04 04:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\bootcfg.exe
    + 2004-08-04 04:00:00 71,552 -c----w c:\windows\$NtServicePackUninstall$\bridge.sys
    + 2004-08-04 04:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\browselc.dll
    + 2004-08-04 04:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\browser.dll
    + 2008-08-20 05:33:19 1,024,000 -c----w c:\windows\$NtServicePackUninstall$\browseui.dll
    + 2004-08-04 04:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\browsewm.dll
    + 2004-08-04 04:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\bthci.dll
    + 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys
    + 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys.000
    + 2004-08-04 04:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\bthserv.dll
    + 2004-08-04 04:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\btpanui.dll
    + 2004-08-04 04:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\cabinet.dll
    + 2004-08-04 04:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\cabview.dll
    + 2004-08-04 04:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\cacls.exe
    + 2004-08-04 04:00:00 385,024 -c----w c:\windows\$NtServicePackUninstall$\callcont.dll
    + 2004-08-04 04:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\camocx.dll
    + 2004-08-04 04:00:00 142,848 -c----w c:\windows\$NtServicePackUninstall$\capesnpn.dll
    + 2005-07-26 04:39:42 225,792 -c----w c:\windows\$NtServicePackUninstall$\catsrv.dll
    + 2004-08-04 04:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\catsrvps.dll
    + 2005-07-26 04:39:43 625,152 -c----w c:\windows\$NtServicePackUninstall$\catsrvut.dll
    + 2004-08-04 04:00:00 63,744 -c----w c:\windows\$NtServicePackUninstall$\cdfs.sys
    + 2008-08-20 05:33:17 151,040 -c----w c:\windows\$NtServicePackUninstall$\cdfview.dll
    + 2005-09-10 01:53:41 2,067,968 -c----w c:\windows\$NtServicePackUninstall$\cdosys.dll
    + 2004-08-04 04:00:00 49,536 -c----w c:\windows\$NtServicePackUninstall$\cdrom.sys
    + 2004-08-04 04:00:00 194,560 -c----w c:\windows\$NtServicePackUninstall$\certcli.dll
    + 2004-08-04 04:00:00 457,728 -c----w c:\windows\$NtServicePackUninstall$\certmgr.dll
    + 2004-08-04 04:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\cfgbkend.dll
    + 2004-08-04 04:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\cfgmgr32.dll
    + 2004-08-04 04:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\cic.dll
    + 2004-08-04 04:00:00 1,352,192 -c----w c:\windows\$NtServicePackUninstall$\cimwin32.dll
    + 2006-06-22 05:06:29 69,120 -c----w c:\windows\$NtServicePackUninstall$\ciodm.dll
    + 2004-08-04 04:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\cipher.exe
    + 2004-08-04 04:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\cisvc.exe
    + 2004-08-04 04:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\classpnp.sys
    + 2005-07-26 04:39:43 110,080 -c----w c:\windows\$NtServicePackUninstall$\clbcatex.dll
    + 2005-07-26 04:39:43 498,688 -c----w c:\windows\$NtServicePackUninstall$\clbcatq.dll
    + 2004-08-04 04:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\cleanmgr.exe
    + 2004-08-04 04:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.dll
    + 2004-08-04 04:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.exe
    + 2004-08-04 04:00:00 102,912 -c----w c:\windows\$NtServicePackUninstall$\clipbrd.exe
    + 2004-08-04 04:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\clipsrv.exe
    + 2004-08-04 04:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\clusapi.dll
    + 2004-08-03 22:07:40 14,080 -c----w c:\windows\$NtServicePackUninstall$\cmbatt.sys
    + 2004-08-04 04:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\cmcfg32.dll
    + 2004-08-04 04:00:00 388,608 -c----w c:\windows\$NtServicePackUninstall$\cmd.exe
    + 2004-08-04 04:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\cmdevtgprov.dll
    + 2004-08-04 04:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\cmdial32.dll
    + 2004-08-04 04:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cmdl32.exe
    + 2004-08-04 04:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmmon32.exe
    + 2004-08-04 04:00:00 185,344 -c----w c:\windows\$NtServicePackUninstall$\cmprops.dll
    + 2004-08-04 04:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\cmsetacl.dll
    + 2004-08-04 04:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cmstp.exe
    + 2004-08-04 04:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmutil.dll
    + 2004-08-04 04:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cnbjmon.dll
    + 2005-04-27 23:15:36 17,920 -c----w c:\windows\$NtServicePackUninstall$\cobramsg.dll
    + 2005-07-26 04:39:43 60,416 -c----w c:\windows\$NtServicePackUninstall$\colbact.dll
    + 2004-08-04 04:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\comaddin.dll
    + 2005-07-26 04:39:44 195,072 -c----w c:\windows\$NtServicePackUninstall$\comadmin.dll
    + 2006-08-25 15:45:58 617,472 -c----w c:\windows\$NtServicePackUninstall$\comctl32.dll
    + 2004-08-04 04:00:00 276,992 -c----w c:\windows\$NtServicePackUninstall$\comdlg32.dll
    + 2004-08-04 04:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\compatui.dll
    + 2001-08-17 12:58:00 9,344 -c----w c:\windows\$NtServicePackUninstall$\compbatt.sys
    + 2004-08-04 04:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\compstui.dll
    + 2005-07-26 04:39:44 97,792 -c----w c:\windows\$NtServicePackUninstall$\comrepl.dll
    + 2004-08-04 04:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\comrepl.exe
    + 2004-08-04 04:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\comrereg.exe
    + 2004-08-04 04:00:00 792,064 -c----w c:\windows\$NtServicePackUninstall$\comres.dll
    + 2004-08-04 04:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\comsetup.dll
    + 2004-08-04 04:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\comsnap.dll
    + 2005-07-26 04:39:44 1,267,200 -c----w c:\windows\$NtServicePackUninstall$\comsvcs.dll
    + 2005-07-26 04:39:45 540,160 -c----w c:\windows\$NtServicePackUninstall$\comuid.dll
    + 2004-08-04 04:00:00 1,032,192 -c----w c:\windows\$NtServicePackUninstall$\conf.exe
    + 2004-08-04 04:00:00 45,056 -c----w c:\windows\$NtServicePackUninstall$\confmrsl.dll
    + 2004-08-04 04:00:00 345,600 -c----w c:\windows\$NtServicePackUninstall$\confmsp.dll
    + 2004-08-04 04:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\conime.exe
    + 2004-08-04 04:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\corpol.dll
    + 2004-08-04 04:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\credui.dll
    + 2004-08-04 04:00:00 36,480 -c----w c:\windows\$NtServicePackUninstall$\crusoe.sys
    + 2004-08-04 04:00:00 597,504 -c----w c:\windows\$NtServicePackUninstall$\crypt32.dll
    + 2004-08-04 04:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\cryptdlg.dll
    + 2004-08-04 04:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\cryptdll.dll
    + 2004-08-04 04:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\cryptext.dll
    + 2004-08-04 04:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cryptnet.dll
    + 2004-08-04 04:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\cryptsvc.dll
    + 2004-08-04 04:00:00 512,512 -c----w c:\windows\$NtServicePackUninstall$\cryptui.dll
    + 2004-08-04 04:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\cscdll.dll
    + 2004-08-04 04:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\cscript.exe
    + 2004-08-04 04:00:00 326,656 -c----w c:\windows\$NtServicePackUninstall$\cscui.dll
    + 2004-08-04 04:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\csrsrv.dll
    + 2004-08-04 04:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\csrss.exe
    + 2004-08-04 04:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\ctfmon.exe
    + 2004-08-04 04:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\custsat.dll
    + 2004-08-04 04:00:00 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\d3d8.dll
    + 2004-08-04 04:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\d3d8thk.dll
    + 2004-08-04 04:00:00 1,689,088 -c----w c:\windows\$NtServicePackUninstall$\d3d9.dll
    + 2004-08-04 04:00:00 825,344 -c----w c:\windows\$NtServicePackUninstall$\d3dim700.dll
    + 2008-08-20 05:33:18 1,054,208 -c----w c:\windows\$NtServicePackUninstall$\danim.dll
    + 2004-08-04 04:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\dataclen.dll
    + 2004-08-04 04:00:00 152,064 -c----w c:\windows\$NtServicePackUninstall$\datime.dll
    + 2004-08-04 04:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\davclnt.dll
    + 2004-08-04 04:00:00 640,000 -c----w c:\windows\$NtServicePackUninstall$\dbghelp.dll
    + 2004-08-04 04:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\dbmsrpcn.dll
    + 2004-08-04 04:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\dbnetlib.dll
    + 2004-08-04 04:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dbnmpntw.dll
    + 2004-08-04 04:00:00 1,788 -c----w c:\windows\$NtServicePackUninstall$\dcache.bin
    + 2004-08-04 04:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\dcap32.dll
    + 2004-08-04 04:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\dciman32.dll
    + 2004-08-04 04:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dcomcnfg.exe
    + 2004-08-04 04:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\ddeshare.exe
    + 2004-08-04 04:00:00 266,240 -c----w c:\windows\$NtServicePackUninstall$\ddraw.dll
    + 2004-08-04 04:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\ddrawex.dll
    + 2004-08-04 04:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\defrag.exe
    + 2004-08-04 04:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\devenum.dll
    + 2004-08-04 04:00:00 282,624 -c----w c:\windows\$NtServicePackUninstall$\devmgr.dll
    + 2004-08-04 04:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dfrgfat.exe
    + 2004-08-04 04:00:00 104,960 -c----w c:\windows\$NtServicePackUninstall$\dfrgntfs.exe
    + 2004-08-04 04:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\dfrgsnap.dll
    + 2004-08-04 04:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\dfrgui.dll
    + 2004-08-04 04:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dfsshlex.dll
    + 2004-08-04 04:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\dgnet.dll
    + 2006-05-19 12:59:41 111,616 -c----w c:\windows\$NtServicePackUninstall$\dhcpcsvc.dll
    + 2004-08-04 04:00:00 370,176 -c----w c:\windows\$NtServicePackUninstall$\dhcpmon.dll
    + 2004-08-04 04:00:00 539,136 -c----w c:\windows\$NtServicePackUninstall$\dialer.exe
    + 2004-08-04 04:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\diantz.exe
    + 2004-08-04 04:00:00 68,608 -c----w c:\windows\$NtServicePackUninstall$\digest.dll
    + 2004-08-04 04:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\dinput.dll
    + 2004-08-04 04:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dinput8.dll
    + 2007-05-16 15:12:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\directdb.dll
    + 2004-08-04 04:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\disk.sys
    + 2004-08-04 04:00:00 1,501,696 -c----w c:\windows\$NtServicePackUninstall$\diskcopy.dll
    + 2004-08-04 04:00:00 14,208 -c----w c:\windows\$NtServicePackUninstall$\diskdump.sys
    + 2004-08-04 04:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\diskpart.exe
    + 2004-08-04 04:00:00 45,083 -c----w c:\windows\$NtServicePackUninstall$\dispex.dll
    + 2004-08-04 04:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dllhost.exe
    + 2004-08-04 04:00:00 224,768 -c----w c:\windows\$NtServicePackUninstall$\dmadmin.exe
    + 2004-08-04 04:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dmband.dll
    + 2004-08-04 04:00:00 799,744 -c----w c:\windows\$NtServicePackUninstall$\dmboot.sys
    + 2004-08-04 04:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\dmcompos.dll
    + 2004-08-04 04:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\dmdlgs.dll
    + 2004-08-04 04:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\dmdskmgr.dll
    + 2004-08-04 04:00:00 181,248 -c----w c:\windows\$NtServicePackUninstall$\dmime.dll
    + 2004-08-04 04:00:00 153,344 -c----w c:\windows\$NtServicePackUninstall$\dmio.sys
    + 2004-08-04 04:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\dmloader.dll
    + 2004-08-04 04:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\dmremote.exe
    + 2004-08-04 04:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dmscript.dll
    + 2004-08-04 04:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dmserver.dll
    + 2004-08-04 04:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\dmstyle.dll
    + 2004-08-04 04:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\dmsynth.dll
    + 2004-08-04 04:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\dmusic.dll
    + 2004-08-03 22:07:40 52,864 -c----w c:\windows\$NtServicePackUninstall$\dmusic.sys
    + 2004-08-04 04:00:00 52,224 -c----w c:\windows\$NtServicePackUninstall$\dmutil.dll
    + 2008-02-20 05:32:43 148,992 -c----w c:\windows\$NtServicePackUninstall$\dnsapi.dll
    + 2008-02-20 05:32:43 45,568 -c----w c:\windows\$NtServicePackUninstall$\dnsrslvr.dll
    + 2004-08-04 04:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\docprop2.dll
    + 2004-08-04 04:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\dpcdll.dll
    + 2004-08-04 04:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\dplaysvr.exe
    + 2004-08-04 04:00:00 229,888 -c----w c:\windows\$NtServicePackUninstall$\dplayx.dll
    + 2004-08-04 04:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dpmodemx.dll
    + 2004-08-04 04:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnaddr.dll
    + 2004-08-04 04:00:00 375,296 -c----w c:\windows\$NtServicePackUninstall$\dpnet.dll
    + 2004-08-04 04:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\dpnhpast.dll
    + 2004-08-04 04:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\dpnhupnp.dll
    + 2004-08-04 04:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnlobby.dll
    + 2004-08-04 04:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\dpnsvr.exe
    + 2004-08-04 04:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\dpvacm.dll
    + 2004-08-04 04:00:00 212,480 -c----w c:\windows\$NtServicePackUninstall$\dpvoice.dll
    + 2004-08-04 04:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\dpvsetup.exe
    + 2004-08-04 04:00:00 116,736 -c----w c:\windows\$NtServicePackUninstall$\dpvvox.dll
    + 2004-08-04 04:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\dpwsockx.dll
    + 2004-08-04 04:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\driverquery.exe
    + 2004-08-03 22:08:00 60,288 -c----w c:\windows\$NtServicePackUninstall$\drmk.sys
    + 2004-08-03 22:07:58 2,944 -c----w c:\windows\$NtServicePackUninstall$\drmkaud.sys
    + 2004-08-04 04:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\drprov.dll
    + 2004-08-04 04:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\ds32gt.dll
    + 2004-08-04 04:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dsdmo.dll
    + 2004-08-04 04:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\dsdmoprp.dll
    + 2004-08-04 04:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\dskquota.dll
    + 2004-08-04 04:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\dskquoui.dll
    + 2004-08-04 04:00:00 367,616 -c----w c:\windows\$NtServicePackUninstall$\dsound.dll
    + 2004-08-04 04:00:00 1,294,336 -c----w c:\windows\$NtServicePackUninstall$\dsound3d.dll
    + 2004-08-04 04:00:00 142,336 -c----w c:\windows\$NtServicePackUninstall$\dsprop.dll
    + 2004-08-04 04:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\dsprpres.dll
    + 2004-08-04 04:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\dsquery.dll
    + 2004-08-04 04:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\dssec.dll
    + 2004-08-04 04:00:00 137,216 -c----w c:\windows\$NtServicePackUninstall$\dssenh.dll
    + 2004-08-04 04:00:00 113,152 -c----w c:\windows\$NtServicePackUninstall$\dsuiext.dll
    + 2004-08-04 04:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\dswave.dll
    + 2004-08-04 04:00:00 10,752 -c----w c:\windows\$NtServicePackUninstall$\dumprep.exe
    + 2004-08-04 04:00:00 304,128 -c----w c:\windows\$NtServicePackUninstall$\duser.dll
    + 2004-08-04 04:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\dvdupgrd.exe
    + 2004-08-04 04:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\dwwin.exe
    + 2004-08-04 04:00:00 619,008 -c----w c:\windows\$NtServicePackUninstall$\dx7vb.dll
    + 2004-08-04 04:00:00 1,227,264 -c----w c:\windows\$NtServicePackUninstall$\dx8vb.dll
    + 2004-08-04 04:00:00 1,298,432 -c----w c:\windows\$NtServicePackUninstall$\dxdiag.exe
    + 2004-08-04 04:00:00 2,113,536 -c----w c:\windows\$NtServicePackUninstall$\dxdiagn.dll
    + 2004-08-04 04:00:00 71,040 -c----w c:\windows\$NtServicePackUninstall$\dxg.sys
    + 2006-08-22 03:05:26 498,742 -c----w c:\windows\$NtServicePackUninstall$\dxmasf.dll
    + 2008-08-20 05:33:18 357,888 -c----w c:\windows\$NtServicePackUninstall$\dxtmsft.dll
    + 2008-08-20 05:33:18 205,312 -c----w c:\windows\$NtServicePackUninstall$\dxtrans.dll
    + 2004-08-04 04:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\efsadu.dll
    + 2004-08-04 04:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\els.dll
    + 2004-08-04 04:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\encapi.dll
    + 2004-08-04 04:00:00 186,368 -c----w c:\windows\$NtServicePackUninstall$\encdec.dll
    + 2004-08-04 04:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\ersvc.dll
    + 2008-07-07 20:32:22 253,952 -c----w c:\windows\$NtServicePackUninstall$\es.dll
    + 2005-10-20 22:20:03 1,082,368 -c----w c:\windows\$NtServicePackUninstall$\esent.dll
    + 2004-08-04 04:00:00 247,808 -c----w c:\windows\$NtServicePackUninstall$\esscli.dll
    + 2004-08-04 04:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\eudcedit.exe
    + 2004-08-04 04:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\eventcreate.exe
    + 2004-08-04 04:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\eventlog.dll
    + 2004-08-04 04:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\eventtriggers.exe
    + 2004-08-04 04:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\evntrprv.dll
    + 2007-06-13 10:23:07 1,033,216 -c----w c:\windows\$NtServicePackUninstall$\explorer.exe
    + 2004-08-04 04:00:00 380,957 -c----w c:\windows\$NtServicePackUninstall$\expsrv.dll
    + 2008-08-20 05:33:18 55,808 -c----w c:\windows\$NtServicePackUninstall$\extmgr.dll
    + 2004-08-04 04:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\extrac32.exe
    + 2004-08-04 04:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\exts.dll
    + 2004-08-04 04:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fastfat.sys
    + 2004-08-04 04:00:00 472,064 -c----w c:\windows\$NtServicePackUninstall$\fastprox.dll
    + 2004-08-04 04:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\faultrep.dll
    + 2004-08-04 04:00:00 27,392 -c----w c:\windows\$NtServicePackUninstall$\fdc.sys
    + 2004-08-04 04:00:00 117,760 -c----w c:\windows\$NtServicePackUninstall$\fde.dll
    + 2004-08-04 04:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\fdeploy.dll
    + 2004-08-04 04:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\feclient.dll
    + 2004-08-04 04:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\filemgmt.dll
    + 2004-08-04 04:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\findstr.exe
    + 2004-08-04 04:00:00 34,944 -c----w c:\windows\$NtServicePackUninstall$\fips.sys
    + 2004-08-04 04:00:00 87,552 -c----w c:\windows\$NtServicePackUninstall$\fldrclnr.dll
    + 2004-08-04 04:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\flpydisk.sys
    + 2006-08-21 12:21:06 16,896 -c----w c:\windows\$NtServicePackUninstall$\fltlib.dll
    + 2006-08-21 09:14:58 23,040 -c----w c:\windows\$NtServicePackUninstall$\fltmc.exe
    + 2006-08-21 09:14:58 128,896 -c----w c:\windows\$NtServicePackUninstall$\fltmgr.sys
    + 2004-08-04 04:00:00 382,976 -c----w c:\windows\$NtServicePackUninstall$\fontext.dll
    + 2005-10-17 21:14:45 80,896 -c----w c:\windows\$NtServicePackUninstall$\fontsub.dll
    + 2004-08-04 04:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\fontview.exe
    + 2004-08-04 04:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\forcedos.exe
    + 2004-08-04 04:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\format.com
    + 2004-08-04 04:00:00 32,828 -c----w c:\windows\$NtServicePackUninstall$\fp40ext.dll
    + 2003-03-24 15:52:04 618,605 -c----w c:\windows\$NtServicePackUninstall$\fp4autl.dll
    + 2004-08-04 04:00:00 9,344 -c----w c:\windows\$NtServicePackUninstall$\framebuf.dll
    + 2004-08-04 04:00:00 185,856 -c----w c:\windows\$NtServicePackUninstall$\framedyn.dll
    + 2004-08-04 04:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\fsquirt.exe
    + 2004-08-04 04:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\ftp.exe
    + 2004-08-04 04:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\fwcfg.dll
    + 2004-08-04 04:00:00 452,096 -c----w c:\windows\$NtServicePackUninstall$\fxsapi.dll
    + 2004-08-04 04:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fxsclnt.exe
    + 2004-08-04 04:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\fxscom.dll
    + 2004-08-04 04:00:00 285,184 -c----w c:\windows\$NtServicePackUninstall$\fxscomex.dll
    + 2004-08-04 04:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\fxscover.exe
    + 2004-08-04 04:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\fxsdrv.dll
    + 2004-08-04 04:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\fxsevent.dll
    + 2004-08-04 04:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\fxsext32.dll
    + 2004-08-04 04:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\fxsmon.dll
    + 2004-08-04 04:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\fxsocm.dll
    + 2004-08-04 04:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\fxsperf.dll
    + 2004-08-04 04:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\fxsres.dll
    + 2004-08-04 04:00:00 562,176 -c----w c:\windows\$NtServicePackUninstall$\fxsst.dll
    + 2004-08-04 04:00:00 267,776 -c----w c:\windows\$NtServicePackUninstall$\fxssvc.exe
    + 2004-08-04 04:00:00 246,272 -c----w c:\windows\$NtServicePackUninstall$\fxst30.dll
    + 2004-08-04 04:00:00 397,312 -c----w c:\windows\$NtServicePackUninstall$\fxstiff.dll
    + 2004-08-04 04:00:00 154,112 -c----w c:\windows\$NtServicePackUninstall$\fxsui.dll
    + 2004-08-04 04:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\fxswzrd.dll
    + 2004-08-04 04:00:00 400,384 -c----w c:\windows\$NtServicePackUninstall$\fxsxp32.dll
    + 2008-02-20 06:51:05 282,624 -c----w c:\windows\$NtServicePackUninstall$\gdi32.dll
    + 2004-08-04 04:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\getmac.exe
    + 2004-08-04 04:00:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\glu32.dll
    + 2004-08-04 04:00:00 566,784 -c----w c:\windows\$NtServicePackUninstall$\gpedit.dll
    + 2004-08-04 04:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\gpkrsrc.dll
    + 2004-08-04 04:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\gpresult.exe
    + 2004-08-04 04:00:00 198,656 -c----w c:\windows\$NtServicePackUninstall$\gptext.dll
    + 2004-08-04 04:00:00 39,424 -c----w c:\windows\$NtServicePackUninstall$\grpconv.exe
    + 2005-04-28 19:16:29 133,120 -c----w c:\windows\$NtServicePackUninstall$\guitrn.dll
    + 2005-04-28 19:16:29 115,200 -c----w c:\windows\$NtServicePackUninstall$\guitrna.dll
    + 2004-08-04 04:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\h323cc.dll
    + 2004-08-04 04:00:00 614,912 -c----w c:\windows\$NtServicePackUninstall$\h323msp.dll
    + 2005-06-23 00:0


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hello

    Please download OTMoveIt3 by OldTimer
    • Save it to your desktop.
    • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      :Processes
      explorer.exe
      
      :Services
      
      :Reg
      [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d9b4680-73e7-11dc-8feb-0019b98950e7}]
      
      :Files
      c:\windows\system32\stu2.exe
      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
      
    • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt3
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


    • Make sure to use Internet Explorer for this
    • Please go to VirSCAN.org FREE on-line scan service
    • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
      • c:\windows\system32\userinit.exe
    • Click on the Upload button
    • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
    • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
    • Paste the contents of the Clipboard in your next reply.


  • Closed Accounts Posts: 1,178 ✭✭✭dade


    OTmove log,

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d9b4680-73e7-11dc-8feb-0019b98950e7}\\ deleted successfully.
    ========== FILES ==========
    c:\windows\system32\stu2.exe moved successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\alan\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03052009_155751

    Files moved on Reboot...
    C:\DOCUME~1\alan\LOCALS~1\Temp\hpodvd09.log moved successfully.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

    VirSCAN LogVirSCAN.org Scanned Report :
    Scanned time : 2009/03/05 16:08:41 (GMT)
    Scanner results: 3% Scanner(1/37) found malware!
    File Name : userinit.exe
    File Size : 24576 byte
    File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5 : 39b1ffb03c2296323832acbae50d2aff
    SHA1 : e5aedcbe25a97c89101f1f3860ff846e94d70445
    Online report : http://virscan.org/report/62673f4534c08297ca39ada792786a86.html

    Scanner Engine Ver Sig Ver Sig Date Time Scan result
    a-squared 4.0.0.32 20090305045332 2009-03-05 2.29 -
    AhnLab V3 2009.03.05.03 2009.03.05 2009-03-05 1.09 -
    AntiVir 7.9.0.100 7.1.2.127 2009-03-05 1.88 -
    Antiy 2.0.18 20090305.2210017 2009-03-05 0.12 -
    Authentium 5.1.1 200903041747 2009-03-04 1.09 -
    AVAST! 3.0.1 090305-0 2009-03-05 0.01 -
    AVG 7.5.52.442 270.11.8/1985 2009-03-05 1.94 -
    BitDefender 7.81008.2743764 7.23981 2009-03-05 2.56 -
    CA (VET) 9.0.0.143 31.6.6382 2009-03-05 5.41 -
    ClamAV 0.94.2 9073 2009-03-05 0.01 -
    Comodo 3.8 986 2009-03-05 0.46 -
    CP Secure 1.1.0.715 2009.03.05 2009-03-05 7.22 -
    Dr.Web 4.44.0.9170 2009.03.05 2009-03-05 4.15 -
    F-Prot 4.4.4.56 20090304 2009-03-04 1.09 -
    F-Secure 5.51.6100 2009.03.05.06 2009-03-05 0.08 -
    Fortinet 2.81-3.117 10.120 2009-03-05 0.18 -
    GData 19.3652/19.249 20090305 2009-03-05 3.37 -
    ViRobot 20090305 2009.03.05 2009-03-05 0.41 -
    Ikarus T3.1.01.45 2009.03.05.72386 2009-03-05 3.85 -
    JiangMin 11.0.706 2009.03.05 2009-03-05 1.62 -
    Kaspersky 5.5.10 2009.03.05 2009-03-05 0.07 -
    KingSoft 2009.2.5.15 2009.3.5.21 2009-03-05 0.62 -
    McAfee 5.3.00 5543 2009-03-04 2.84 -
    Microsoft 1.4405 2009.03.05 2009-03-05 8.65 -
    mks_vir 2.01 2009.03.05 2009-03-05 2.67 Trojan.Exploit.Iis.Printeroverflow.C
    Norman 6.00.06 6.00.00 2009-03-05 8.01 -
    Panda 9.05.01 2009.03.04 2009-03-04 1.89 -
    Trend Micro 8.700-1004 5.882.03 2009-03-05 0.03 -
    Quick Heal 10.00 2009.03.05 2009-03-05 1.30 -
    Rising 20.0 21.19.32.00 2009-03-05 1.10 -
    Sophos 2.84.1 4.39 2009-03-05 2.05 -
    Sunbelt 5022 5022 2009-03-04 0.56 -
    Symantec 1.3.0.24 20090304.017 2009-03-04 0.05 -
    nProtect 20090305.02 3243337 2009-03-05 4.56 -
    The Hacker 6.3.2.7 v00272 2009-03-04 0.86 -
    VBA32 3.12.10.1 20090304.1443 2009-03-04 1.82 -
    VirusBuster 4.5.11.10 10.101.35/966288 2009-03-05 1.19 -


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hello

    Please download ATF Cleaner by Atribune.
      Double-click
    ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
    If you use Firefox browser
      Click
    Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
      Click
    Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.




    Please download Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






    Go to Kaspersky website and perform an online antivirus scan.
    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
        Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
        Mail databases
      [*]Click on My Computer under Scan.
      [*]Once the scan is complete, it will display the results. Click on View Scan Report.
      [*]You will see a list of infected items there. Click on Save Report As....
      [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


    5. Advertisement
    6. Closed Accounts Posts: 1,178 ✭✭✭dade


      Malwarebytes' Anti-Malware 1.34
      Database version: 1822
      Windows 5.1.2600 Service Pack 3

      05/03/2009 21:19:38
      mbam-log-2009-03-05 (21-19-38).txt

      Scan type: Quick Scan
      Objects scanned: 92104
      Time elapsed: 4 minute(s), 0 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


      Running online scannow will report back as soon as i have a log


    7. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      post a new HJT log with it as well


    8. Closed Accounts Posts: 1,178 ✭✭✭dade


      will do. having some trouble getting the scanner to work. it keeps telling me i need java 1.5 or higher. i click on the link and it takes me to sun and i download and verify the java install restart the browser and it happens again :mad:

      even a reboot didn't get teh jave working. very strange.


    9. Closed Accounts Posts: 1,178 ✭✭✭dade


      got it. bloody plug-in wasn't enabled in IE7. damn microsoft

      right downloading everything needed for scan, vI'll update with the log of the and HJT when they're done.

      really appreciate your help on this.


    10. Closed Accounts Posts: 1,178 ✭✭✭dade


      sorry for the delay

      AV Log

      KASPERSKY ONLINE SCANNER 7 REPORT
      Friday, March 6, 2009
      Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
      Kaspersky Online Scanner 7 version: 7.0.25.0
      Program database last update: Friday, March 06, 2009 07:20:41
      Records in database: 1873391

      Scan settings:
      Scan using the following database: extended
      Scan archives: yes
      Scan mail databases: yes

      Scan area - My Computer:
      C:\
      D:\
      E:\
      F:\

      Scan statistics:
      Files scanned: 89590
      Threat name: 2
      Infected objects: 2
      Suspicious objects: 0
      Duration of the scan: 03:20:46


      File name / Threat name / Threats count
      C:\QooBox\Quarantine\C\WINDOWS\system32\userinit.exe.vir Infected: Trojan.Win32.Small.buq 1
      F:\tightvnc-1.3.9-setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1370 1

      The selected area was scanned.


      ___________________________
      HJT Log


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:13:54, on 06/03/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\WLTRYSVC.EXE
      C:\WINDOWS\System32\bcmwltry.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Kodak\printer\center\KodakSvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\stsystra.exe
      C:\WINDOWS\system32\WLTRAY.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
      C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\NOTEPAD.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=5070908
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
      O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
      O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [%PROVIDERID%] "bin\sprtcmd.exe" /P %PROVIDERID%
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.ie/SnapfishActivia.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
      O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

      --
      End of file - 8179 bytes


    11. Advertisement
    12. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      your logs are clean

      Follow these steps to uninstall Combofix and tools used in the removal of malware
      • Click START then RUN
      • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
        CF_Cleanup.png




      Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
      • Click the Pt. Restauration button and press OK to the prompts.
      • Click the Corbeille button and press OK to the prompt.
      • Click the Fichiers temp button and press OK to the prompt.
      • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
      • Once it is done click the Suppression button and let it remove anything it finds.
      • Close the program



      Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
      http://www.adobe.com/products/acrobat/readstep2.html



      Below I have included a number of recommendations for how to protect your computer against malware infections.
      • Keep Windows updated by regularly checking their website at :
        http://windowsupdate.microsoft.com/
        This will ensure your computer has always the latest security updates available installed on your computer.

      • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

      • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

      • Make Internet Explorer more secure
        • Click Start > Run
        • Type Inetcpl.cpl & click OK
        • Click on the Security tab
        • Click Reset all zones to default level
        • Make sure the Internet Zone is selected & Click Custom level
        • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
        • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
      • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

      • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

      • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
        secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
        blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
        Here


        If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
        • NoScript - for blocking ads and other potential website attacks
        • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

      • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

      • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

      • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

      • Please read my guide on how to prevent malware and about safe computing here
      Thank you for your patience, and performing all of the procedures requested.


    13. Closed Accounts Posts: 1,178 ✭✭✭dade


      cheers mate i owe you one.

      I'll follow these last steps and also make sure the AV is kept current. I'll gonna get rid of all old restore points too and create a new one in case there's something in those


    Advertisement