ComboFix 08-06-20.4 - user 06/28/2008 23:23:17.3 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.292 [GMT -7:00] Running from: C:\Documents and Settings\EOL1\Desktop\virus software\ComboFix.exe Command switches used :: C:\Documents and Settings\EOL1\Desktop\virus software\CFScript.txt [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-29 ))))))))))))))))))))))))))))))) . 2008-06-28 23:23 . 06/28/08 11:23p 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_404.dat 2008-06-27 14:09 . 06/27/08 02:09p d--h----- C:\WINNT\PIF 2008-06-27 07:44 . 07/30/07 07:18p 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui 2008-06-27 07:44 . 07/30/07 07:19p 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui 2008-06-27 07:44 . 07/30/07 07:19p 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui 2008-06-27 07:44 . 07/30/07 07:18p 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui 2008-06-24 15:49 . 06/24/08 03:49p d-------- C:\Program Files\MyPublisher 2008-06-24 15:48 . 06/24/08 03:48p d-------- C:\Documents and Settings\EOL1\Application Data\MyPublisher 2008-06-24 15:46 . 06/24/08 03:48p 10,795,384 --a------ C:\Program Files\CostcoPublisher.exe 2008-06-21 14:54 . 06/21/08 02:54p d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-06-21 14:53 . 06/21/08 02:54p d-------- C:\Program Files\SUPERAntiSpyware 2008-06-21 14:53 . 06/21/08 02:53p d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-06-21 14:53 . 06/21/08 02:53p d-------- C:\Documents and Settings\EOL1\Application Data\SUPERAntiSpyware.com 2008-06-14 09:42 . 06/14/08 09:42a d-------- C:\Documents and Settings\EOL1\Application Data\Snapfish 2008-06-13 15:57 . 06/13/08 03:57p d-------- C:\Program Files\Uniblue 2008-06-13 15:57 . 06/13/08 03:57p d-------- C:\Documents and Settings\EOL1\Application Data\Uniblue 2008-06-13 11:03 . 06/13/08 11:03a d-------- C:\Program Files\Trend Micro 2008-06-13 10:30 . 06/13/08 11:27a d--h----- C:\$AVG8.VAULT$ 2008-06-13 10:27 . 06/28/08 05:36p d-------- C:\WINNT\system32\drivers\Avg 2008-06-13 10:27 . 06/13/08 10:27a d-------- C:\Program Files\AVG 2008-06-13 10:27 . 06/13/08 10:27a d-------- C:\Documents and Settings\EOL1\Application Data\AVGTOOLBAR 2008-06-13 10:27 . 06/13/08 10:27a d-a------ C:\Documents and Settings\All Users\Application Data\avg8 2008-06-13 10:27 . 06/23/08 09:48a 96,520 --a------ C:\WINNT\system32\drivers\avgldx86.sys 2008-06-13 10:27 . 06/23/08 09:49a 76,040 --a------ C:\WINNT\system32\drivers\avgtdix.sys 2008-06-13 10:27 . 06/23/08 09:48a 12,936 --a------ C:\WINNT\system32\drivers\avgrkx86.sys 2008-06-13 10:27 . 06/23/08 09:48a 10,520 --a------ C:\WINNT\system32\avgrsstx.dll 2008-06-08 22:49 . 06/27/08 11:32p 642,890 ---h----- C:\WINNT\ShellIconCache 2008-06-08 18:52 . 06/08/08 06:52p d-------- C:\Program Files\Common Files\Mozilla Shared . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-10 16:53 --------- d-----w C:\Program Files\Apple Software Update 2008-05-10 16:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-07 23:06 --------- d-----w C:\Program Files\iTunes 2008-05-01 05:16 1,222,656 ----a-w C:\WINNT\system32\quartz.dll 2008-04-18 15:55 575,488 ----a-w C:\WINNT\system32\WININET.DLL 2007-03-02 18:20 271 ---h--w C:\Program Files\desktop.ini 2007-03-02 18:20 21,952 ---h--w C:\Program Files\folder.htt 1999-12-07 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys . ((((((((((((((((((((((((((((( snapshot@Sat 06-21-2008_15.32.33.54 ))))))))))))))))))))))))))))))))))))))))) . - 2007-03-02 21:38:35 1,257,472 ----a-w C:\WINNT\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll + 2008-06-29 00:40:46 1,265,664 ----a-w C:\WINNT\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll - 2007-03-02 21:32:14 1,224,704 ----a-w C:\WINNT\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll + 2008-06-29 00:40:47 1,232,896 ----a-w C:\WINNT\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll + 2008-06-29 00:41:05 61,440 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_39794f05\CustomMarshalers.dll + 2008-06-29 00:41:38 3,391,488 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b8fa6ebe\mscorlib.dll + 2008-06-29 00:41:31 1,470,464 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_454c9c12\System.Design.dll + 2008-06-29 00:41:07 90,112 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_6358fe9f\System.Drawing.Design.dll + 2008-06-29 00:41:34 835,584 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_451ad498\System.Drawing.dll + 2008-06-29 00:41:17 3,018,752 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_96a968f0\System.Windows.Forms.dll + 2008-06-29 00:41:23 2,088,960 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_888d909f\System.Xml.dll + 2008-06-29 00:41:03 1,966,080 ----a-w C:\WINNT\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_317b3d0c\System.dll - 2006-06-21 06:52:16 712,976 ----a-w C:\WINNT\Driver Cache\i386\kernel32.dll + 2007-04-16 12:44:08 712,976 ----a-w C:\WINNT\Driver Cache\i386\kernel32.dll - 2006-09-12 11:48:11 1,714,432 ----a-w C:\WINNT\Driver Cache\i386\ntkrnlmp.exe + 2007-03-05 15:51:49 1,714,496 ----a-w C:\WINNT\Driver Cache\i386\ntkrnlmp.exe - 2006-09-12 11:48:34 1,713,536 ----a-w C:\WINNT\Driver Cache\i386\ntkrnlpa.exe + 2007-03-05 15:52:06 1,713,536 ----a-w C:\WINNT\Driver Cache\i386\ntkrnlpa.exe - 2006-09-12 11:48:39 1,735,808 ----a-w C:\WINNT\Driver Cache\i386\ntkrpamp.exe + 2007-03-05 15:52:05 1,735,808 ----a-w C:\WINNT\Driver Cache\i386\ntkrpamp.exe - 2006-09-12 11:48:11 1,690,880 ----a-w C:\WINNT\Driver Cache\i386\ntoskrnl.exe + 2007-03-05 15:51:49 1,690,880 ----a-w C:\WINNT\Driver Cache\i386\ntoskrnl.exe - 2005-10-06 09:33:46 1,638,672 ------w C:\WINNT\Driver Cache\i386\win32k.sys + 2008-03-19 09:26:34 1,644,080 ------w C:\WINNT\Driver Cache\i386\win32k.sys - 2005-09-23 11:03:26 245,008 ----a-w C:\WINNT\Driver Cache\i386\winsrv.dll + 2007-03-13 09:44:49 245,520 ----a-w C:\WINNT\Driver Cache\i386\winsrv.dll + 2005-10-21 03:02:28 163,328 ----a-w C:\WINNT\erdnt\subs\ERDNT.EXE - 2004-07-15 08:49:16 258,048 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll + 2007-04-14 04:30:52 258,048 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll - 2004-07-15 08:49:22 32,768 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe + 2007-04-14 04:30:52 32,768 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe - 2004-07-15 07:32:22 81,920 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll + 2007-04-14 03:57:52 81,920 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll - 2003-02-21 02:09:14 86,016 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorie.dll + 2007-04-14 03:57:58 86,016 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorie.dll - 2004-07-15 07:25:06 315,392 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll + 2007-04-14 03:56:30 315,392 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll - 2004-07-15 07:33:04 102,400 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorld.dll + 2007-04-14 03:58:00 102,400 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorld.dll - 2004-07-15 21:29:02 2,138,112 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll + 2007-04-14 03:50:46 2,142,208 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll - 2003-02-21 02:09:18 77,824 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll + 2007-04-14 03:58:02 77,824 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll - 2004-07-15 07:26:52 2,510,848 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll + 2007-04-14 03:57:00 2,523,136 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll - 2004-07-15 07:28:34 2,502,656 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll + 2007-04-14 03:57:28 2,514,944 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll - 2004-08-10 23:20:00 106,496 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe + 2007-01-15 23:11:26 73,728 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe + 2004-07-15 08:49:16 258,048 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_aspnet_isapi.dll + 2004-07-15 07:32:22 81,920 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_CORPerfMonExt.dll + 2004-07-15 07:24:30 282,624 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_fusion.dll + 2004-07-15 07:25:06 315,392 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_mscorjit.dll + 2004-07-15 21:29:02 2,138,112 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_mscorlib.dll + 2003-02-21 02:09:18 77,824 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_mscorsn.dll + 2004-07-15 07:26:52 2,510,848 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_mscorsvr.dll + 2004-07-15 07:28:34 2,502,656 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_mscorwks.dll + 2003-02-21 11:42:22 348,160 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_msvcr71.dll + 2004-07-15 07:34:50 94,208 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\SHADOW1624\_PerfCounter.dll - 2004-07-15 21:31:16 1,224,704 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\System.dll + 2007-04-14 04:35:38 1,232,896 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\System.dll - 2004-10-08 13:20:12 1,257,472 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\System.Web.dll + 2007-04-14 04:35:46 1,265,664 ----a-w C:\WINNT\Microsoft.NET\Framework\v1.1.4322\System.Web.dll - 2006-08-24 08:07:56 53,008 ----a-w C:\WINNT\msagent\agentdpv.dll + 2007-06-25 06:25:34 53,008 ----a-w C:\WINNT\msagent\agentdpv.dll - 2007-01-02 16:33:40 1,017,856 ----a-w C:\WINNT\system32\BROWSEUI.DLL + 2008-04-18 16:00:22 1,018,368 ----a-w C:\WINNT\system32\BROWSEUI.DLL - 2007-01-02 16:34:00 143,360 ----a-w C:\WINNT\system32\CDFVIEW.DLL + 2008-04-18 16:00:26 143,360 ----a-w C:\WINNT\system32\CDFVIEW.DLL - 2005-05-26 11:16:24 75,544 ----a-w C:\WINNT\system32\cdm.dll + 2007-07-31 02:19:20 92,504 ----a-w C:\WINNT\system32\cdm.dll - 2006-12-12 20:55:04 1,054,208 ----a-w C:\WINNT\system32\DANIM.DLL + 2008-02-16 08:59:36 1,054,208 ----a-w C:\WINNT\system32\DANIM.DLL - 2001-10-18 15:41:10 86,097 ----a-w C:\WINNT\system32\dbnetlib.dll + 2003-10-28 16:22:54 86,588 ----a-w C:\WINNT\system32\dbnetlib.dll - 2006-08-24 08:07:56 53,008 -c--a-w C:\WINNT\system32\dllcache\agentdpv.dll + 2007-06-25 06:25:34 53,008 -c--a-w C:\WINNT\system32\dllcache\agentdpv.dll - 2007-01-02 16:33:40 1,017,856 -c--a-w C:\WINNT\system32\dllcache\BROWSEUI.DLL + 2008-04-18 16:00:22 1,018,368 -c--a-w C:\WINNT\system32\dllcache\BROWSEUI.DLL - 2007-01-02 16:34:00 143,360 -c--a-w C:\WINNT\system32\dllcache\CDFVIEW.DLL + 2008-04-18 16:00:26 143,360 -c--a-w C:\WINNT\system32\dllcache\CDFVIEW.DLL - 2005-05-26 11:16:24 75,544 -c--a-w C:\WINNT\system32\dllcache\cdm.dll + 2007-07-31 02:19:20 92,504 -c--a-w C:\WINNT\system32\dllcache\cdm.dll - 2006-12-12 20:55:04 1,054,208 -c--a-w C:\WINNT\system32\dllcache\DANIM.DLL + 2008-02-16 08:59:36 1,054,208 -c--a-w C:\WINNT\system32\dllcache\DANIM.DLL - 2004-03-01 05:28:20 561,424 -c----w C:\WINNT\system32\dllcache\dao360.dll + 2008-03-27 07:00:14 554,008 -c----w C:\WINNT\system32\dllcache\dao360.dll - 2006-02-27 20:31:38 75,776 -c--a-w C:\WINNT\system32\dllcache\DIRECTDB.DLL + 2007-08-20 00:55:12 75,776 -c--a-w C:\WINNT\system32\dllcache\DIRECTDB.DLL - 2006-07-06 11:45:32 137,488 -c----w C:\WINNT\system32\dllcache\dnsapi.dll + 2008-02-15 13:24:10 137,488 -c----w C:\WINNT\system32\dllcache\dnsapi.dll - 2006-07-06 11:45:32 96,528 -c----w C:\WINNT\system32\dllcache\dnsrslvr.dll + 2008-02-15 13:24:10 96,528 -c----w C:\WINNT\system32\dllcache\dnsrslvr.dll - 2007-01-02 17:16:40 351,744 -c--a-w C:\WINNT\system32\dllcache\DXTMSFT.DLL + 2008-04-18 15:54:54 351,744 -c--a-w C:\WINNT\system32\dllcache\DXTMSFT.DLL - 2007-01-02 17:16:32 192,512 -c--a-w C:\WINNT\system32\dllcache\DXTRANS.DLL + 2008-04-18 15:54:52 192,512 -c--a-w C:\WINNT\system32\dllcache\DXTRANS.DLL - 2005-12-30 16:15:56 233,744 -c--a-w C:\WINNT\system32\dllcache\GDI32.DLL + 2008-02-19 17:08:58 236,304 -c--a-w C:\WINNT\system32\dllcache\GDI32.DLL - 2007-01-02 17:16:50 236,032 -c--a-w C:\WINNT\system32\dllcache\IEPEERS.DLL + 2008-04-18 15:55:04 236,032 -c--a-w C:\WINNT\system32\dllcache\IEPEERS.DLL - 2006-11-06 19:47:54 596,480 -c--a-w C:\WINNT\system32\dllcache\INETCOMM.DLL + 2007-08-20 00:55:32 596,992 -c--a-w C:\WINNT\system32\dllcache\INETCOMM.DLL - 2006-02-27 20:31:50 47,616 -c--a-w C:\WINNT\system32\dllcache\INETRES.DLL + 2007-08-20 00:55:26 47,616 -c--a-w C:\WINNT\system32\dllcache\INETRES.DLL - 2007-01-02 16:51:12 69,632 -c--a-w C:\WINNT\system32\dllcache\INSENG.DLL + 2008-04-18 15:55:08 69,632 -c--a-w C:\WINNT\system32\dllcache\INSENG.DLL + 2007-08-17 06:48:22 39,184 -c----w C:\WINNT\system32\dllcache\jpeg2x32.dll - 2006-05-17 18:43:58 465,864 -c--a-w C:\WINNT\system32\dllcache\jscript.dll + 2008-01-05 10:05:56 458,752 -c--a-w C:\WINNT\system32\dllcache\jscript.dll - 2007-01-02 16:52:16 12,288 -c--a-w C:\WINNT\system32\dllcache\JSPROXY.DLL + 2008-04-18 15:55:22 12,288 -c--a-w C:\WINNT\system32\dllcache\JSPROXY.DLL - 2006-06-21 06:52:16 712,976 -c----w C:\WINNT\system32\dllcache\kernel32.dll + 2007-04-16 12:44:08 712,976 -c----w C:\WINNT\system32\dllcache\kernel32.dll + 2007-05-11 07:41:54 524,560 -c----w C:\WINNT\system32\dllcache\kodakimg.exe + 2007-05-11 07:42:16 73,488 -c----w C:\WINNT\system32\dllcache\kodakprv.exe - 2005-01-12 19:39:46 37,136 -c--a-w C:\WINNT\system32\dllcache\mf3216.dll + 2007-03-06 11:17:46 38,160 -c--a-w C:\WINNT\system32\dllcache\mf3216.dll - 2005-04-08 11:54:36 57,104 -c--a-w C:\WINNT\system32\dllcache\mpr.dll + 2007-04-16 12:44:08 54,032 -c--a-w C:\WINNT\system32\dllcache\mpr.dll - 2005-01-12 19:39:52 291,088 -c----w C:\WINNT\system32\dllcache\mq1repl.dll + 2007-10-17 07:22:06 292,112 -c--a-w C:\WINNT\system32\dllcache\mq1repl.dll - 2003-12-22 07:56:24 14,096 -c----w C:\WINNT\system32\dllcache\mq1sync.exe + 2007-10-16 13:51:24 14,096 -c--a-w C:\WINNT\system32\dllcache\mq1sync.exe - 2004-10-24 13:10:20 77,680 -c----w C:\WINNT\system32\dllcache\mqac.sys + 2007-10-16 13:51:26 77,712 -c----w C:\WINNT\system32\dllcache\mqac.sys - 2005-01-12 19:39:52 217,360 -c----w C:\WINNT\system32\dllcache\mqads.dll + 2007-10-17 07:22:06 218,384 -c--a-w C:\WINNT\system32\dllcache\mqads.dll + 2007-10-16 13:51:26 25,360 -c----w C:\WINNT\system32\dllcache\mqbkup.exe + 2007-10-17 07:22:06 29,456 -c----w C:\WINNT\system32\dllcache\mqcertui.dll - 2005-01-12 19:39:54 50,448 -c----w C:\WINNT\system32\dllcache\mqclus.dll + 2007-10-17 07:22:06 50,448 -c--a-w C:\WINNT\system32\dllcache\mqclus.dll + 2007-10-17 07:22:06 29,968 -c----w C:\WINNT\system32\dllcache\mqdbodbc.dll - 2005-01-12 19:39:54 76,560 -c----w C:\WINNT\system32\dllcache\mqdscli.dll + 2007-10-17 07:22:06 77,072 -c--a-w C:\WINNT\system32\dllcache\mqdscli.dll - 2005-01-12 19:39:54 42,256 -c----w C:\WINNT\system32\dllcache\mqdssrv.dll + 2007-10-17 07:22:06 42,256 -c--a-w C:\WINNT\system32\dllcache\mqdssrv.dll - 1999-12-07 12:00:00 87,312 -c--a-w C:\WINNT\system32\dllcache\mqlogmgr.dll + 2007-10-17 07:22:06 96,016 -c--a-w C:\WINNT\system32\dllcache\mqlogmgr.dll - 2003-12-22 07:56:26 98,064 -c----w C:\WINNT\system32\dllcache\mqmig.exe + 2007-10-16 13:51:28 98,064 -c--a-w C:\WINNT\system32\dllcache\mqmig.exe - 2005-01-12 19:39:54 266,512 -c----w C:\WINNT\system32\dllcache\mqmigrat.dll + 2007-10-17 07:22:06 267,536 -c--a-w C:\WINNT\system32\dllcache\mqmigrat.dll - 2005-01-12 19:39:54 222,480 -c----w C:\WINNT\system32\dllcache\mqoa.dll + 2007-10-17 07:22:06 222,480 -c--a-w C:\WINNT\system32\dllcache\mqoa.dll - 2005-01-12 19:39:54 10,000 -c----w C:\WINNT\system32\dllcache\mqperf.dll + 2007-10-17 07:22:06 10,000 -c--a-w C:\WINNT\system32\dllcache\mqperf.dll - 2005-01-12 19:39:54 438,544 -c----w C:\WINNT\system32\dllcache\mqqm.dll + 2007-10-17 07:22:06 440,592 -c--a-w C:\WINNT\system32\dllcache\mqqm.dll + 2007-10-17 07:22:06 8,464 -c----w C:\WINNT\system32\dllcache\mqrperf.dll - 2005-04-08 10:34:42 102,672 -c----w C:\WINNT\system32\dllcache\mqrt.dll + 2007-10-17 07:22:06 102,672 -c--a-w C:\WINNT\system32\dllcache\mqrt.dll - 2005-01-12 19:39:54 70,928 -c----w C:\WINNT\system32\dllcache\mqsec.dll + 2007-10-17 07:22:06 70,928 -c--a-w C:\WINNT\system32\dllcache\mqsec.dll - 2005-01-12 19:39:54 400,656 -c----w C:\WINNT\system32\dllcache\mqsnap.dll + 2007-10-17 07:22:06 400,656 -c--a-w C:\WINNT\system32\dllcache\mqsnap.dll + 2007-10-16 13:51:34 14,096 -c----w C:\WINNT\system32\dllcache\mqsvc.exe - 2005-01-12 19:39:54 23,824 -c----w C:\WINNT\system32\dllcache\mqupgrd.dll + 2007-10-17 07:22:06 23,824 -c--a-w C:\WINNT\system32\dllcache\mqupgrd.dll - 2005-01-12 19:39:54 110,864 -c----w C:\WINNT\system32\dllcache\mqutil.dll + 2007-10-17 07:22:06 111,888 -c--a-w C:\WINNT\system32\dllcache\mqutil.dll - 2003-09-26 10:42:48 512,272 -c----w C:\WINNT\system32\dllcache\msexch40.dll + 2008-03-27 07:00:47 518,944 -c----w C:\WINNT\system32\dllcache\msexch40.dll - 2004-07-20 02:56:40 319,760 -c----w C:\WINNT\system32\dllcache\msexcl40.dll + 2008-03-27 07:00:52 326,432 -c----w C:\WINNT\system32\dllcache\msexcl40.dll - 2007-01-02 17:16:34 2,704,896 -c--a-w C:\WINNT\system32\dllcache\MSHTML.DLL + 2008-04-18 15:54:58 2,705,408 -c--a-w C:\WINNT\system32\dllcache\MSHTML.DLL + 2007-04-05 07:17:39 2,854,400 -c----w C:\WINNT\system32\dllcache\msi.dll - 2006-02-27 20:29:32 44,032 -c--a-w C:\WINNT\system32\dllcache\MSIDENT.DLL + 2007-08-20 00:52:36 44,032 -c--a-w C:\WINNT\system32\dllcache\MSIDENT.DLL - 2006-02-27 20:32:04 56,832 -c--a-w C:\WINNT\system32\dllcache\MSIMN.EXE + 2007-08-20 00:55:44 56,832 -c--a-w C:\WINNT\system32\dllcache\MSIMN.EXE - 2004-07-20 02:56:44 1,507,600 -c----w C:\WINNT\system32\dllcache\msjet40.dll + 2008-03-27 07:01:34 1,516,568 -c----w C:\WINNT\system32\dllcache\msjet40.dll - 2004-02-17 09:56:44 352,528 -c----w C:\WINNT\system32\dllcache\msjetol1.dll + 2008-03-27 07:02:34 355,112 -c----w C:\WINNT\system32\dllcache\msjetol1.dll - 2003-09-26 10:42:54 151,824 -c----w C:\WINNT\system32\dllcache\msjint40.dll + 2008-03-27 07:13:31 151,583 -c----w C:\WINNT\system32\dllcache\msjint40.dll - 2003-09-26 10:42:54 53,520 -c----w C:\WINNT\system32\dllcache\msjter40.dll + 2008-03-27 07:02:57 60,192 -c----w C:\WINNT\system32\dllcache\msjter40.dll - 2004-07-20 02:56:46 241,936 -c----w C:\WINNT\system32\dllcache\msjtes40.dll + 2008-03-27 07:03:05 248,608 -c----w C:\WINNT\system32\dllcache\msjtes40.dll - 2003-09-26 10:42:56 213,264 -c----w C:\WINNT\system32\dllcache\msltus40.dll + 2008-03-27 07:03:25 219,936 -c----w C:\WINNT\system32\dllcache\msltus40.dll + 2007-10-17 07:22:06 159,504 -c----w C:\WINNT\system32\dllcache\msmqocm.dll - 2006-02-27 20:32:00 1,176,064 -c--a-w C:\WINNT\system32\dllcache\MSOE.DLL + 2007-08-20 00:55:38 1,176,064 -c--a-w C:\WINNT\system32\dllcache\MSOE.DLL - 2006-02-27 20:31:40 229,376 -c--a-w C:\WINNT\system32\dllcache\MSOEACCT.DLL + 2007-08-20 00:55:14 229,376 -c--a-w C:\WINNT\system32\dllcache\MSOEACCT.DLL - 2006-02-27 20:32:08 2,479,616 -c--a-w C:\WINNT\system32\dllcache\MSOERES.DLL + 2007-08-20 00:55:48 2,479,616 -c--a-w C:\WINNT\system32\dllcache\MSOERES.DLL - 2006-02-27 20:31:36 91,136 -c--a-w C:\WINNT\system32\dllcache\MSOERT2.DLL + 2007-08-20 00:55:10 91,136 -c--a-w C:\WINNT\system32\dllcache\MSOERT2.DLL - 2004-07-20 02:56:46 348,432 -c----w C:\WINNT\system32\dllcache\mspbde40.dll + 2008-03-27 07:03:43 355,104 -c----w C:\WINNT\system32\dllcache\mspbde40.dll - 2007-01-02 16:34:38 132,096 -c--a-w C:\WINNT\system32\dllcache\MSRATING.DLL + 2008-04-18 16:00:44 132,096 -c--a-w C:\WINNT\system32\dllcache\MSRATING.DLL - 2003-09-26 10:42:58 422,160 -c----w C:\WINNT\system32\dllcache\msrd2x40.dll + 2008-03-27 07:04:07 432,928 -c----w C:\WINNT\system32\dllcache\msrd2x40.dll - 2003-09-26 10:42:58 315,664 -c----w C:\WINNT\system32\dllcache\msrd3x40.dll + 2008-03-27 07:04:27 322,336 -c----w C:\WINNT\system32\dllcache\msrd3x40.dll - 2004-07-20 02:56:48 553,232 -c----w C:\WINNT\system32\dllcache\msrepl40.dll + 2008-03-27 07:04:57 559,904 -c----w C:\WINNT\system32\dllcache\msrepl40.dll - 2004-10-26 14:52:16 258,320 -c----w C:\WINNT\system32\dllcache\mstext40.dll + 2008-03-27 07:05:21 264,992 -c----w C:\WINNT\system32\dllcache\mstext40.dll - 2007-01-02 17:16:26 498,176 -c--a-w C:\WINNT\system32\dllcache\MSTIME.DLL + 2008-04-18 15:54:48 498,176 -c--a-w C:\WINNT\system32\dllcache\MSTIME.DLL - 2003-09-26 10:43:02 831,760 -c----w C:\WINNT\system32\dllcache\mswdat10.dll + 2008-03-27 07:05:38 838,432 -c----w C:\WINNT\system32\dllcache\mswdat10.dll - 2003-09-26 10:43:02 614,672 -c----w C:\WINNT\system32\dllcache\mswstr10.dll + 2008-03-27 07:05:51 621,344 -c----w C:\WINNT\system32\dllcache\mswstr10.dll - 2004-07-20 02:56:28 348,432 -c----w C:\WINNT\system32\dllcache\msxbde40.dll + 2008-03-27 07:06:00 355,104 -c----w C:\WINNT\system32\dllcache\msxbde40.dll - 2006-09-06 04:58:48 1,110,528 -c----w C:\WINNT\system32\dllcache\msxml3.dll + 2007-06-07 06:50:04 1,119,232 -c----w C:\WINNT\system32\dllcache\msxml3.dll - 2005-06-03 04:58:10 938,768 -c----w C:\WINNT\system32\dllcache\ntdsa.dll + 2007-04-23 06:22:01 939,280 -c--a-w C:\WINNT\system32\dllcache\ntdsa.dll - 2006-09-12 11:48:11 1,714,432 -c--a-w C:\WINNT\system32\dllcache\NTKRNLMP.EXE + 2007-03-05 15:51:49 1,714,496 -c--a-w C:\WINNT\system32\dllcache\NTKRNLMP.EXE - 2006-09-12 11:48:34 1,713,536 -c----w C:\WINNT\system32\dllcache\ntkrnlpa.exe + 2007-03-05 15:52:06 1,713,536 -c----w C:\WINNT\system32\dllcache\ntkrnlpa.exe - 2006-09-12 11:48:39 1,735,808 -c--a-w C:\WINNT\system32\dllcache\NTKRPAMP.EXE + 2007-03-05 15:52:05 1,735,808 -c--a-w C:\WINNT\system32\dllcache\NTKRPAMP.EXE - 2006-09-12 11:48:11 1,690,880 -c----w C:\WINNT\system32\dllcache\ntoskrnl.exe + 2007-03-05 15:51:49 1,690,880 -c----w C:\WINNT\system32\dllcache\ntoskrnl.exe - 2002-04-15 20:20:52 221,456 -c--a-w C:\WINNT\system32\dllcache\odbc32.dll + 2003-10-29 01:35:00 417,792 -c--a-w C:\WINNT\system32\dllcache\odbc32.dll - 2002-04-15 20:20:54 102,672 -c--a-w C:\WINNT\system32\dllcache\odbccp32.dll + 2003-10-29 01:34:44 217,088 -c--a-w C:\WINNT\system32\dllcache\odbccp32.dll - 2006-02-27 20:31:58 93,184 -c--a-w C:\WINNT\system32\dllcache\OEIMPORT.DLL + 2007-08-20 00:55:36 93,184 -c--a-w C:\WINNT\system32\dllcache\OEIMPORT.DLL - 2006-02-27 20:32:08 55,808 -c--a-w C:\WINNT\system32\dllcache\OEMIG50.EXE + 2007-08-20 00:55:50 55,808 -c--a-w C:\WINNT\system32\dllcache\OEMIG50.EXE - 2006-02-27 20:32:10 31,744 -c--a-w C:\WINNT\system32\dllcache\OEMIGLIB.DLL + 2007-08-20 00:55:50 31,744 -c--a-w C:\WINNT\system32\dllcache\OEMIGLIB.DLL + 2007-08-17 06:48:22 448,272 -c----w C:\WINNT\system32\dllcache\oieng400.dll + 2007-12-05 10:40:00 631,056 -c----w C:\WINNT\system32\dllcache\oleaut32.dll - 2007-01-02 17:16:46 34,816 -c--a-w C:\WINNT\system32\dllcache\PNGFILT.DLL + 2008-04-18 15:55:02 34,816 -c--a-w C:\WINNT\system32\dllcache\PNGFILT.DLL - 2005-08-30 16:14:00 1,227,776 -c--a-w C:\WINNT\system32\dllcache\quartz.dll + 2008-05-01 05:16:26 1,222,656 -c--a-w C:\WINNT\system32\dllcache\quartz.dll - 2006-04-13 05:17:08 437,008 -c----w C:\WINNT\system32\dllcache\rpcrt4.dll + 2007-07-17 06:42:52 439,056 -c----w C:\WINNT\system32\dllcache\rpcrt4.dll - 2007-01-02 16:33:28 1,340,416 -c--a-w C:\WINNT\system32\dllcache\SHDOCVW.DLL + 2008-04-18 16:00:12 1,340,416 -c--a-w C:\WINNT\system32\dllcache\SHDOCVW.DLL - 2007-01-02 16:33:14 402,944 -c--a-w C:\WINNT\system32\dllcache\SHLWAPI.DLL + 2008-04-18 16:00:00 402,944 -c--a-w C:\WINNT\system32\dllcache\SHLWAPI.DLL - 2006-05-03 06:57:40 6,401,024 -c--a-w C:\WINNT\system32\dllcache\sp3res.dll + 2007-05-28 07:56:03 6,258,688 -c--a-w C:\WINNT\system32\dllcache\sp3res.dll - 2006-04-25 13:38:52 320,336 -c----w C:\WINNT\system32\dllcache\tcpip.sys + 2007-10-05 06:54:54 320,368 -c----w C:\WINNT\system32\dllcache\tcpip.sys - 1999-12-07 12:00:00 33,552 -c--a-w C:\WINNT\system32\dllcache\tifflt.dll + 2007-08-17 06:48:22 33,552 -c--a-w C:\WINNT\system32\dllcache\tifflt.dll - 2007-01-25 16:52:58 462,336 -c--a-w C:\WINNT\system32\dllcache\URLMON.DLL + 2008-04-18 15:55:22 462,848 -c--a-w C:\WINNT\system32\dllcache\URLMON.DLL - 2005-04-21 08:08:44 419,600 -c----w C:\WINNT\system32\dllcache\USER32.DLL + 2007-03-06 11:17:48 381,200 -c--a-w C:\WINNT\system32\dllcache\USER32.DLL - 2002-02-26 22:58:06 462,906 -c--a-w C:\WINNT\system32\dllcache\vbscript.dll + 2008-01-05 10:05:56 401,408 -c--a-w C:\WINNT\system32\dllcache\vbscript.dll - 2006-12-20 18:54:32 2,286,080 -c--a-w C:\WINNT\system32\dllcache\VGX.DLL + 2007-06-26 21:52:08 2,286,080 -c--a-w C:\WINNT\system32\dllcache\VGX.DLL - 2006-02-27 20:31:46 42,496 -c--a-w C:\WINNT\system32\dllcache\WAB.EXE + 2007-08-20 00:55:20 42,496 -c--a-w C:\WINNT\system32\dllcache\WAB.EXE - 2006-06-05 21:44:14 465,920 -c--a-w C:\WINNT\system32\dllcache\WAB32.DLL + 2007-08-20 00:55:20 465,920 -c--a-w C:\WINNT\system32\dllcache\WAB32.DLL - 2006-02-27 20:31:48 30,208 -c--a-w C:\WINNT\system32\dllcache\WABFIND.DLL + 2007-08-20 00:55:22 30,208 -c--a-w C:\WINNT\system32\dllcache\WABFIND.DLL - 2006-02-27 20:31:44 77,824 -c--a-w C:\WINNT\system32\dllcache\WABIMP.DLL + 2007-08-20 00:55:18 77,824 -c--a-w C:\WINNT\system32\dllcache\WABIMP.DLL - 2006-02-27 20:31:42 27,648 -c--a-w C:\WINNT\system32\dllcache\WABMIG.EXE + 2007-08-20 00:55:16 27,648 -c--a-w C:\WINNT\system32\dllcache\WABMIG.EXE - 2005-10-06 09:33:46 1,638,672 -c----w C:\WINNT\system32\dllcache\win32k.sys + 2008-03-19 09:26:34 1,644,080 -c----w C:\WINNT\system32\dllcache\win32k.sys - 2007-01-02 16:52:24 575,488 -c--a-w C:\WINNT\system32\dllcache\WININET.DLL + 2008-04-18 15:55:26 575,488 -c--a-w C:\WINNT\system32\dllcache\WININET.DLL - 2005-09-23 11:03:26 245,008 -c----w C:\WINNT\system32\dllcache\winsrv.dll + 2007-03-13 09:44:49 245,520 -c----w C:\WINNT\system32\dllcache\winsrv.dll + 2007-10-31 09:17:04 230,912 -c----w C:\WINNT\system32\dllcache\wmasf.dll - 2006-04-24 22:40:00 4,730,880 -c----w C:\WINNT\system32\dllcache\wmp.dll + 2007-04-30 09:22:16 4,734,976 -c----w C:\WINNT\system32\dllcache\wmp.dll - 2006-12-08 01:02:23 2,174,976 -c----w C:\WINNT\system32\dllcache\wmvcore.dll + 2007-10-31 09:17:04 2,109,440 -c----w C:\WINNT\system32\dllcache\wmvcore.dll - 2005-05-26 11:16:30 124,184 -c--a-w C:\WINNT\system32\dllcache\wuauclt.exe + 2007-07-31 02:19:16 53,080 -c--a-w C:\WINNT\system32\dllcache\wuauclt.exe - 2005-05-26 11:16:30 1,343,768 -c--a-w C:\WINNT\system32\dllcache\wuaueng.dll + 2007-07-31 02:19:42 1,712,984 -c--a-w C:\WINNT\system32\dllcache\wuaueng.dll - 2006-07-06 11:45:32 137,488 ----a-w C:\WINNT\system32\dnsapi.dll + 2008-02-15 13:24:10 137,488 ----a-w C:\WINNT\system32\dnsapi.dll - 2006-07-06 11:45:32 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll + 2008-02-15 13:24:10 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll - 2008-06-13 17:27:51 26,184 ----a-w C:\WINNT\system32\drivers\avgmfx86.sys + 2008-06-23 16:48:41 26,824 ----a-w C:\WINNT\system32\drivers\avgmfx86.sys - 2006-04-25 13:38:52 320,336 ----a-w C:\WINNT\system32\drivers\tcpip.sys + 2007-10-05 06:54:54 320,368 ----a-w C:\WINNT\system32\drivers\tcpip.sys - 2007-01-02 17:16:40 351,744 ----a-w C:\WINNT\system32\DXTMSFT.DLL + 2008-04-18 15:54:54 351,744 ----a-w C:\WINNT\system32\DXTMSFT.DLL - 2007-01-02 17:16:32 192,512 ----a-w C:\WINNT\system32\DXTRANS.DLL + 2008-04-18 15:54:52 192,512 ----a-w C:\WINNT\system32\DXTRANS.DLL - 2007-11-13 23:13:22 240,736 ----a-w C:\WINNT\system32\FNTCACHE.DAT + 2008-06-29 00:52:10 240,736 ----a-w C:\WINNT\system32\FNTCACHE.DAT - 2005-12-30 16:15:56 233,744 ----a-w C:\WINNT\system32\GDI32.DLL + 2008-02-19 17:08:58 236,304 ----a-w C:\WINNT\system32\GDI32.DLL - 2007-01-02 17:16:50 236,032 ----a-w C:\WINNT\system32\IEPEERS.DLL + 2008-04-18 15:55:04 236,032 ----a-w C:\WINNT\system32\IEPEERS.DLL - 2006-11-06 19:47:54 596,480 ----a-w C:\WINNT\system32\INETCOMM.DLL + 2007-08-20 00:55:32 596,992 ----a-w C:\WINNT\system32\INETCOMM.DLL - 2006-02-27 20:31:50 47,616 ----a-w C:\WINNT\system32\INETRES.DLL + 2007-08-20 00:55:26 47,616 ----a-w C:\WINNT\system32\INETRES.DLL - 2007-01-02 16:51:12 69,632 ----a-w C:\WINNT\system32\INSENG.DLL + 2008-04-18 15:55:08 69,632 ----a-w C:\WINNT\system32\INSENG.DLL - 1999-12-07 12:00:00 38,160 ----a-w C:\WINNT\system32\jpeg2x32.dll + 2007-08-17 06:48:22 39,184 ----a-w C:\WINNT\system32\jpeg2x32.dll - 2006-05-17 18:43:58 465,864 ----a-w C:\WINNT\system32\jscript.dll + 2008-01-05 10:05:56 458,752 ----a-w C:\WINNT\system32\jscript.dll - 2007-01-02 16:52:16 12,288 ----a-w C:\WINNT\system32\JSPROXY.DLL + 2008-04-18 15:55:22 12,288 ----a-w C:\WINNT\system32\JSPROXY.DLL - 2006-06-21 06:52:16 712,976 ----a-w C:\WINNT\system32\KERNEL32.DLL + 2007-04-16 12:44:08 712,976 ----a-w C:\WINNT\system32\KERNEL32.DLL - 2006-08-16 14:28:16 513,808 ----a-w C:\WINNT\system32\LSASRV.DLL + 2007-10-16 11:34:39 513,808 ----a-w C:\WINNT\system32\LSASRV.DLL - 2005-01-12 19:39:46 37,136 ----a-w C:\WINNT\system32\mf3216.dll + 2007-03-06 11:17:46 38,160 ----a-w C:\WINNT\system32\mf3216.dll - 2005-04-08 11:54:36 57,104 ----a-w C:\WINNT\system32\mpr.dll + 2007-04-16 12:44:08 54,032 ----a-w C:\WINNT\system32\mpr.dll - 2007-02-07 21:01:46 12,293,536 ----a-w C:\WINNT\system32\MRT.exe + 2008-05-29 23:35:12 17,486,968 ----a-w C:\WINNT\system32\MRT.exe - 2005-09-23 14:28:52 270,848 ----a-w C:\WINNT\system32\mscoree.dll + 2006-12-22 19:28:14 271,360 ----a-w C:\WINNT\system32\mscoree.dll - 2003-09-26 10:42:48 512,272 ----a-w C:\WINNT\system32\msexch40.dll + 2008-03-27 07:00:47 518,944 ----a-w C:\WINNT\system32\msexch40.dll - 2004-07-20 02:56:40 319,760 ----a-w C:\WINNT\system32\msexcl40.dll + 2008-03-27 07:00:52 326,432 ----a-w C:\WINNT\system32\msexcl40.dll - 2007-01-02 17:16:34 2,704,896 ----a-w C:\WINNT\system32\MSHTML.DLL + 2008-04-18 15:54:58 2,705,408 ----a-w C:\WINNT\system32\MSHTML.DLL - 2005-05-04 21:45:32 2,890,240 ----a-w C:\WINNT\system32\msi.dll + 2007-04-05 07:17:39 2,854,400 ----a-w C:\WINNT\system32\msi.dll - 2006-02-27 20:29:32 44,032 ----a-w C:\WINNT\system32\MSIDENT.DLL + 2007-08-20 00:52:36 44,032 ----a-w C:\WINNT\system32\MSIDENT.DLL - 2004-07-20 02:56:44 1,507,600 ----a-w C:\WINNT\system32\msjet40.dll + 2008-03-27 07:01:34 1,516,568 ----a-w C:\WINNT\system32\msjet40.dll - 2004-02-17 09:56:44 352,528 ----a-w C:\WINNT\system32\msjetoledb40.dll + 2008-03-27 07:02:34 355,112 ----a-w C:\WINNT\system32\msjetoledb40.dll - 2003-09-26 10:42:54 151,824 ----a-w C:\WINNT\system32\msjint40.dll + 2008-03-27 07:13:31 151,583 ----a-w C:\WINNT\system32\msjint40.dll - 2003-09-26 10:42:54 53,520 ----a-w C:\WINNT\system32\msjter40.dll + 2008-03-27 07:02:57 60,192 ----a-w C:\WINNT\system32\msjter40.dll - 2004-07-20 02:56:46 241,936 ----a-w C:\WINNT\system32\msjtes40.dll + 2008-03-27 07:03:05 248,608 ----a-w C:\WINNT\system32\msjtes40.dll - 2003-09-26 10:42:56 213,264 ----a-w C:\WINNT\system32\msltus40.dll + 2008-03-27 07:03:25 219,936 ----a-w C:\WINNT\system32\msltus40.dll - 2006-02-27 20:31:40 229,376 ----a-w C:\WINNT\system32\MSOEACCT.DLL + 2007-08-20 00:55:14 229,376 ----a-w C:\WINNT\system32\MSOEACCT.DLL - 2006-02-27 20:31:36 91,136 ----a-w C:\WINNT\system32\MSOERT2.DLL + 2007-08-20 00:55:10 91,136 ----a-w C:\WINNT\system32\MSOERT2.DLL - 2004-07-20 02:56:46 348,432 ----a-w C:\WINNT\system32\mspbde40.dll + 2008-03-27 07:03:43 355,104 ----a-w C:\WINNT\system32\mspbde40.dll - 2007-01-02 16:34:38 132,096 ----a-w C:\WINNT\system32\MSRATING.DLL + 2008-04-18 16:00:44 132,096 ----a-w C:\WINNT\system32\MSRATING.DLL - 2003-09-26 10:42:58 422,160 ----a-w C:\WINNT\system32\msrd2x40.dll + 2008-03-27 07:04:07 432,928 ----a-w C:\WINNT\system32\msrd2x40.dll - 2003-09-26 10:42:58 315,664 ----a-w C:\WINNT\system32\msrd3x40.dll + 2008-03-27 07:04:27 322,336 ----a-w C:\WINNT\system32\msrd3x40.dll - 2004-07-20 02:56:48 553,232 ----a-w C:\WINNT\system32\msrepl40.dll + 2008-03-27 07:04:57 559,904 ----a-w C:\WINNT\system32\msrepl40.dll - 2004-10-26 14:52:16 258,320 ----a-w C:\WINNT\system32\mstext40.dll + 2008-03-27 07:05:21 264,992 ----a-w C:\WINNT\system32\mstext40.dll - 2007-01-02 17:16:26 498,176 ----a-w C:\WINNT\system32\MSTIME.DLL + 2008-04-18 15:54:48 498,176 ----a-w C:\WINNT\system32\MSTIME.DLL - 2003-09-26 10:43:02 831,760 ----a-w C:\WINNT\system32\mswdat10.dll + 2008-03-27 07:05:38 838,432 ----a-w C:\WINNT\system32\mswdat10.dll - 2003-09-26 10:43:02 614,672 ----a-w C:\WINNT\system32\mswstr10.dll + 2008-03-27 07:05:51 621,344 ----a-w C:\WINNT\system32\mswstr10.dll - 2004-07-20 02:56:28 348,432 ----a-w C:\WINNT\system32\msxbde40.dll + 2008-03-27 07:06:00 355,104 ----a-w C:\WINNT\system32\msxbde40.dll - 2006-09-06 04:58:48 1,110,528 ----a-w C:\WINNT\system32\msxml3.dll + 2007-06-07 06:50:04 1,119,232 ----a-w C:\WINNT\system32\msxml3.dll - 2005-09-23 14:29:00 6,144 ----a-w C:\WINNT\system32\mui\[u]0[/u]409\mscorees.dll + 2006-12-22 20:02:36 6,144 ----a-w C:\WINNT\system32\mui\[u]0[/u]409\mscorees.dll - 2005-06-03 04:58:10 938,768 ----a-w C:\WINNT\system32\ntdsa.dll + 2007-04-23 06:22:01 939,280 ----a-w C:\WINNT\system32\ntdsa.dll - 2006-09-12 11:48:34 1,713,536 ----a-w C:\WINNT\system32\NTKRNLPA.EXE + 2007-03-05 15:52:06 1,713,536 ----a-w C:\WINNT\system32\NTKRNLPA.EXE - 2006-09-12 11:48:11 1,690,880 ----a-w C:\WINNT\system32\NTOSKRNL.EXE + 2007-03-05 15:51:49 1,690,880 ----a-w C:\WINNT\system32\NTOSKRNL.EXE - 2002-04-15 20:20:52 221,456 ----a-w C:\WINNT\system32\odbc32.dll + 2003-10-29 01:35:00 417,792 ----a-w C:\WINNT\system32\ODBC32.dll - 2001-10-18 15:40:28 29,252 ----a-w C:\WINNT\system32\odbcbcp.dll + 2003-10-28 16:22:54 29,252 ----a-w C:\WINNT\system32\odbcbcp.dll - 2002-04-15 20:20:54 102,672 ----a-w C:\WINNT\system32\odbccp32.dll + 2003-10-29 01:34:44 217,088 ----a-w C:\WINNT\system32\ODBCCP32.dll - 2003-06-19 19:05:04 444,176 ----a-w C:\WINNT\system32\oieng400.dll + 2007-08-17 06:48:22 448,272 ----a-w C:\WINNT\system32\oieng400.dll - 2003-06-19 19:05:04 626,960 ----a-w C:\WINNT\system32\OLEAUT32.DLL + 2007-12-05 10:40:00 631,056 ----a-w C:\WINNT\system32\OLEAUT32.DLL - 2007-01-02 17:16:46 34,816 ----a-w C:\WINNT\system32\PNGFILT.DLL + 2008-04-18 15:55:02 34,816 ----a-w C:\WINNT\system32\PNGFILT.DLL - 2006-04-13 05:17:08 437,008 ----a-w C:\WINNT\system32\rpcrt4.dll + 2007-07-17 06:42:52 439,056 ----a-w C:\WINNT\system32\rpcrt4.dll - 2005-04-08 11:51:24 151,312 ----a-w C:\WINNT\system32\SCHANNEL.DLL + 2007-04-25 07:52:16 147,216 ----a-w C:\WINNT\system32\SCHANNEL.DLL - 2003-06-19 19:05:04 159,504 ----a-w C:\WINNT\system32\Setup\msmqocm.dll + 2007-10-17 07:22:06 159,504 ----a-w C:\WINNT\system32\Setup\msmqocm.dll - 2007-01-02 16:33:28 1,340,416 ----a-w C:\WINNT\system32\SHDOCVW.DLL + 2008-04-18 16:00:12 1,340,416 ----a-w C:\WINNT\system32\SHDOCVW.DLL - 2007-01-02 16:33:14 402,944 ----a-w C:\WINNT\system32\SHLWAPI.DLL + 2008-04-18 16:00:00 402,944 ----a-w C:\WINNT\system32\SHLWAPI.DLL + 2007-07-31 02:18:40 33,624 ----a-w C:\WINNT\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll + 2007-07-31 02:19:12 43,352 ----a-w C:\WINNT\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll - 2006-05-03 06:57:40 6,401,024 ----a-w C:\WINNT\system32\sp3res.dll + 2007-05-28 07:56:03 6,258,688 ----a-w C:\WINNT\system32\sp3res.dll - 2005-06-28 17:20:23 13,536 ------w C:\WINNT\system32\spmsg.dll + 2007-07-27 17:41:40 16,760 ------w C:\WINNT\system32\spmsg.dll - 2001-10-18 15:40:30 471,121 ----a-w C:\WINNT\system32\sqlsrv32.dll + 2003-10-28 16:22:54 455,236 ----a-w C:\WINNT\system32\sqlsrv32.dll - 1999-12-07 12:00:00 33,552 ----a-w C:\WINNT\system32\tifflt.dll + 2007-08-17 06:48:22 33,552 ----a-w C:\WINNT\system32\tifflt.dll - 2007-01-25 16:52:58 462,336 ----a-w C:\WINNT\system32\URLMON.DLL + 2008-04-18 15:55:22 462,848 ----a-w C:\WINNT\system32\URLMON.DLL - 2005-04-21 08:08:44 419,600 ----a-w C:\WINNT\system32\USER32.DLL + 2007-03-06 11:17:48 381,200 ----a-w C:\WINNT\system32\USER32.DLL - 2002-02-26 22:58:06 462,906 ----a-w C:\WINNT\system32\vbscript.dll + 2008-01-05 10:05:56 401,408 ----a-w C:\WINNT\system32\vbscript.dll - 2005-10-06 09:33:46 1,638,672 ----a-w C:\WINNT\system32\WIN32K.SYS + 2008-03-19 09:26:34 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS - 2005-09-23 11:03:26 245,008 ----a-w C:\WINNT\system32\WINSRV.DLL + 2007-03-13 09:44:49 245,520 ----a-w C:\WINNT\system32\WINSRV.DLL - 2002-12-12 00:23:48 218,112 ----a-w C:\WINNT\system32\wmasf.dll + 2007-10-31 09:17:04 230,912 ----a-w C:\WINNT\system32\wmasf.dll - 2006-04-24 22:40:00 4,730,880 ----a-w C:\WINNT\system32\wmp.dll + 2007-04-30 09:22:16 4,734,976 ----a-w C:\WINNT\system32\wmp.dll - 2006-12-08 01:02:23 2,174,976 ----a-w C:\WINNT\system32\wmvcore.dll + 2007-10-31 09:17:04 2,109,440 ----a-w C:\WINNT\system32\wmvcore.dll - 2005-05-26 11:16:30 465,176 ----a-w C:\WINNT\system32\wuapi.dll + 2007-07-31 02:19:36 549,720 ----a-w C:\WINNT\system32\wuapi.dll - 2005-05-26 11:16:30 124,184 ----a-w C:\WINNT\system32\wuauclt.exe + 2007-07-31 02:19:16 53,080 ----a-w C:\WINNT\system32\wuauclt.exe - 2005-05-26 11:16:30 1,343,768 ----a-w C:\WINNT\system32\wuaueng.dll + 2007-07-31 02:19:42 1,712,984 ----a-w C:\WINNT\system32\wuaueng.dll - 2005-05-26 11:16:30 127,256 ----a-w C:\WINNT\system32\wucltui.dll + 2007-07-31 02:19:32 325,976 ----a-w C:\WINNT\system32\wucltui.dll - 2005-05-26 11:16:30 41,240 ----a-w C:\WINNT\system32\wups.dll + 2007-07-31 02:18:40 33,624 ----a-w C:\WINNT\system32\wups.dll - 2005-05-26 11:16:30 18,200 ----a-w C:\WINNT\system32\wups2.dll + 2007-07-31 02:19:12 43,352 ----a-w C:\WINNT\system32\wups2.dll - 2005-05-26 11:19:32 173,536 ----a-w C:\WINNT\system32\wuweb.dll + 2007-07-31 02:19:28 203,096 ----a-w C:\WINNT\system32\wuweb.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/16/08 09:49p 68856] "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [05/05/08 12:22p 1923352] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [05/28/08 10:33a 1506544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [06/19/03 12:05p 111376 C:\WINNT\system32\mobsync.exe] "Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [05/05/03 08:57a 143360] "DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [05/08/03 11:34a 69632] "NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [07/28/03 03:19p 4841472] "IgfxTray"="C:\WINNT\system32\igfxtray.exe" [10/15/02 11:18p 155648] "HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [10/15/02 11:05p 114688] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/07 07:51p 39792] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/08 04:25a 144784] "HP CD-DVD"="C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe" [08/16/01 05:01p 49152] "MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [03/01/06 11:58a 712704] "mspm"="C:\Program Files\Maxtor\OneTouch\utils\mspm.exe" [09/03/05 03:10a 225280] "mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [10/17/05 04:24p 81920] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/07 09:41a 282624] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [07/27/07 08:14p 271672] "QUICKCARE"="C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" [05/09/07 06:15p 198800] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/23/08 09:49a 1231128] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [06/19/03 12:05p 186640] C:\Documents and Settings\EOL1\Start Menu\Programs\Startup\ Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-12-17 13:27:54 229376] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/08 10:13a 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/07 01:41p 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= mmdrv.dll R0 AvgRkx86;avgrkx86.sys;C:\WINNT\system32\Drivers\avgrkx86.sys [06/23/08 09:48a] R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS [05/27/00 04:37a] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINNT\system32\Drivers\avgldx86.sys [06/23/08 09:48a] R1 hpcd2k;hpcd2k;C:\WINNT\system32\drivers\hpcd2k.sys [10/23/00 09:38a] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [06/23/08 09:48a] R2 AvgTdiX;AVG8 Network Redirector;C:\WINNT\system32\Drivers\avgtdix.sys [06/23/08 09:49a] R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [06/19/03 12:05p] S3 HPUATA;HP CD-Writer Controller Driver;C:\WINNT\system32\DRIVERS\HPUATA.sys [08/23/01 12:57a] . Contents of the 'Scheduled Tasks' folder "2008-05-15 23:15:00 C:\WINNT\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-28 23:24:44 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 06/28/2008 23:25:49 ComboFix-quarantined-files.txt 2008-06-29 06:25:45 ComboFix2.txt 2008-06-27 19:06:04 ComboFix3.txt 2008-06-21 22:32:58 Pre-Run: 71,520,395,264 bytes free Post-Run: 71,513,141,248 bytes free 569 --- E O F --- 2008-06-29 00:45:19