ComboFix 08-12-20.03 - Viktor 2009-01-05 3:14:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1677 [GMT 11:00]
Running from: c:\documents and settings\Viktor\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Viktor\Desktop\cfscript.txt.txt
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3515161-today junki.wma
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3545425-diamonds are forever kayne.mp3
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3545425-starfall dragonland.mp3
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3877629-zooster breakout .mp3
c:\windows\System32\mevent.dll
c:\windows\system32\SkypeComm.dll
c:\windows\System32\taskmagr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3515161-today junki.wma
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3545425-diamonds are forever kayne.mp3
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3545425-starfall dragonland.mp3
c:\documents and settings\Viktor\My Documents\LimeWire\Incomplete\T-3877629-zooster breakout .mp3
c:\windows\System32\mevent.dll
c:\windows\system32\SkypeComm.dll
c:\windows\system32\taskmagr.exe
.
((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.
2009-01-05 03:06 . 2009-01-05 03:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-01-04 00:33 . 2009-01-04 00:33 180,258 --a------ c:\windows\system32\c_20000.nls
2009-01-04 00:30 . 2007-04-12 16:33 66,082 --a------ c:\windows\system32\c_21027.nls
2009-01-04 00:29 . 2007-04-12 16:19 66,082 --a------ c:\windows\system32\c_20290.nls
2009-01-04 00:28 . 2009-01-04 00:27 162,850 --a------ c:\windows\system32\c_10001.nls
2009-01-04 00:25 . 2009-01-04 00:25 28,288 --a------ c:\windows\system32\xjis.nls
2008-12-23 01:05 . 2005-01-23 06:12 679,936 --a------ c:\windows\system32\D3DX81ab.dll
2008-12-23 01:00 . 2008-12-23 01:00 <DIR> d-------- c:\program files\WinPcap
2008-12-23 01:00 . 2008-12-23 01:54 <DIR> d-------- c:\program files\WC3Banlist
2008-12-23 00:38 . 2008-12-23 00:39 <DIR> d-------- c:\program files\PFConfig
2008-12-23 00:11 . 2008-12-23 00:11 <DIR> d-------- c:\program files\Telstra
2008-12-23 00:11 . 2008-12-23 00:11 <DIR> d-------- c:\program files\Alcatel
2008-12-23 00:11 . 2002-06-06 11:14 743,136 --a------ c:\windows\system32\drivers\alcaudsl.sys
2008-12-23 00:11 . 2002-06-14 03:16 81,920 -ra------ c:\windows\tbpu.exe
2008-12-23 00:11 . 2002-06-06 11:14 36,048 --a------ c:\windows\system32\drivers\alcan5ln.sys
2008-12-23 00:11 . 2002-06-06 11:14 5,607 --a------ c:\windows\system32\stci.dll
2008-12-23 00:11 . 2002-06-06 11:14 5,312 --a------ c:\windows\system32\drivers\alcawh.sys
2008-12-23 00:11 . 2002-06-06 11:14 4,000 --a------ c:\windows\system32\drivers\alcacr.sys
2008-12-23 00:11 . 2002-11-05 03:07 894 --------- c:\windows\z.iss
2008-12-23 00:08 . 2008-12-23 00:15 109 --a------ c:\windows\TTM.INI
2008-12-21 19:13 . 2008-12-21 19:13 <DIR> d-------- c:\program files\Ares
2008-12-16 12:15 . 2008-12-16 12:15 410,976 --a------ c:\windows\system32\deploytk.dll
2008-12-11 17:13 . 2008-12-11 17:13 15,271 --a------ c:\windows\system32\drivers\FIDE.SYS
2008-12-11 17:06 . 2008-12-11 17:06 <DIR> d-------- c:\program files\XP Codec Pack
2008-12-11 17:06 . 2008-07-09 20:05 421,888 --a------ c:\windows\system32\ac3filter.acm
2008-12-07 15:07 . 2008-12-07 15:07 <DIR> d-------- c:\program files\EA GAMES
2008-12-07 15:07 . 2004-08-18 13:14 442,368 -ra------ c:\windows\system32\vp6vfw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 14:50 --------- d-----w c:\program files\Warcraft III
2009-01-04 11:52 --------- d-----w c:\program files\Free Music Zilla
2009-01-03 14:28 --------- d-----w c:\program files\FlashGet
2008-12-29 03:25 --------- d-----w c:\documents and settings\Viktor\Application Data\uTorrent
2008-12-22 13:11 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-21 07:21 --------- d-----w c:\documents and settings\Viktor\Application Data\LimeWire
2008-12-19 07:35 --------- d-----w c:\program files\Steam
2008-12-19 07:30 137,688 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-18 13:53 --------- d-----w c:\program files\LimeWire
2008-12-18 12:00 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-17 08:49 --------- d-----w c:\program files\World of Warcraft
2008-12-16 01:14 --------- d-----w c:\program files\Java
2008-12-15 07:05 --------- d-----w c:\program files\Diablo II
2008-12-11 06:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-11 06:07 --------- d-----w c:\documents and settings\Viktor\Application Data\dvdcss
2008-12-03 10:28 --------- d-----w c:\program files\Audacity
2008-12-03 08:33 --------- d-----w c:\program files\Trend Micro
2008-12-03 08:12 --------- d-----w c:\program files\Common Files\BitDefender
2008-12-03 08:12 --------- d-----w c:\program files\BitDefender
2008-12-03 07:18 --------- d-----w c:\program files\UnHackMe
2008-12-03 07:18 --------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2008-12-03 07:17 --------- d-----w c:\program files\Spyware Doctor
2008-12-02 09:31 --------- d-----w c:\program files\Enigma Software Group
2008-11-30 04:26 --------- d-----w c:\program files\Ventrilo
2008-11-30 04:26 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-30 04:26 --------- d-----w c:\documents and settings\Viktor\Application Data\Ventrilo
2008-11-27 08:30 --------- d-----w c:\program files\Intel
2008-11-27 08:28 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2008-11-27 08:27 --------- dc-h--w c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-11-27 08:27 --------- d-----w c:\program files\Uniblue
2008-11-27 08:15 --------- d-----w c:\documents and settings\Viktor\Application Data\Uniblue
2008-11-25 10:16 --------- d-----w c:\program files\Lavasoft
2008-11-25 10:16 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-12 07:57 --------- d-----w c:\program files\Microsoft Games
2008-11-08 23:34 --------- d-----w c:\documents and settings\All Users\Application Data\ATI
2008-11-08 23:22 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-11-08 23:20 --------- d-----w c:\program files\ATI Technologies
2008-02-14 11:19 22,328 ----a-w c:\documents and settings\Viktor\Application Data\PnkBstrK.sys
2008-05-21 14:24 2 --shatr c:\windows\winstart.bat
.
((((((((((((((((((((((((((((( snapshot@2008-12-21_19.20.49.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-17 10:10:17 68,608 ----a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-12-22 14:02:04 68,608 ----a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2008-01-17 10:10:19 72,192 ----a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-12-22 14:02:12 72,192 ----a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2008-01-17 10:10:19 4,308,992 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-12-22 14:02:13 4,308,992 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2008-01-17 10:10:19 482,304 ----a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-12-22 14:02:13 482,304 ----a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2008-01-17 10:10:18 2,878,976 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2008-12-22 14:02:08 2,878,976 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2008-01-17 10:10:16 258,048 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-12-22 14:02:01 258,048 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2008-01-17 10:10:16 114,176 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2008-12-22 14:02:01 114,176 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2008-01-17 10:10:20 260,096 ----a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2008-12-22 14:02:16 260,096 ----a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2008-01-17 10:10:17 5,025,792 ----a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-12-22 14:02:06 5,025,792 ----a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-01-17 10:10:16 10,752 ----a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-12-22 14:02:03 10,752 ----a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2008-01-17 10:10:16 503,808 ----a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2008-12-22 14:02:01 503,808 ----a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2008-01-17 10:10:16 13,312 ----a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-12-22 14:02:02 13,312 ----a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2008-01-17 10:10:18 8,192 ----a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-12-22 14:02:10 8,192 ----a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2008-01-17 10:10:18 36,864 ----a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-12-22 14:02:11 36,864 ----a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2008-01-17 10:10:18 5,632 ----a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-12-22 14:02:12 5,632 ----a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2008-01-17 10:10:16 413,696 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2008-12-22 14:02:02 413,696 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2008-01-17 10:10:16 36,864 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2008-12-22 14:02:03 36,864 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2008-01-17 10:10:16 647,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2008-12-22 14:02:03 647,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2008-01-17 10:10:16 73,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2008-12-22 14:02:03 73,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2008-01-17 10:10:16 745,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-12-22 14:02:02 745,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2008-01-17 10:10:20 110,592 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-12-22 14:02:18 110,592 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2008-01-17 10:10:20 372,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2008-12-22 14:02:17 372,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2008-01-17 10:10:15 28,672 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-12-22 14:01:59 28,672 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2008-01-17 10:10:20 667,648 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-12-22 14:02:17 667,648 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2008-01-17 10:10:20 5,632 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2008-12-22 14:02:18 5,632 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2008-01-17 10:10:15 12,800 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-12-22 14:02:00 12,800 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2008-01-17 10:10:15 32,768 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-12-22 14:02:00 32,768 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2008-01-17 10:10:15 7,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-12-22 14:02:00 7,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2008-01-17 10:10:19 110,592 ----a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2008-12-22 14:02:15 110,592 ----a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2008-01-17 10:10:17 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-12-22 14:02:04 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2008-01-17 10:10:19 389,120 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2008-12-22 14:02:15 389,120 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2008-01-17 10:10:19 716,800 ----a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2008-12-22 14:02:14 716,800 ----a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2008-01-17 10:10:16 884,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2008-12-22 14:02:01 884,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2008-01-17 10:10:18 5,050,368 ----a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-12-22 14:02:08 5,050,368 ----a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2008-01-17 10:10:17 188,416 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2008-12-22 14:02:05 188,416 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2008-01-17 10:10:17 397,312 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-12-22 14:02:05 397,312 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2008-01-17 10:10:17 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-12-22 14:02:05 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2008-01-17 10:10:20 700,416 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-12-22 14:02:16 700,416 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2008-01-17 10:10:19 368,640 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-12-22 14:02:14 368,640 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2008-01-17 10:10:20 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-12-22 14:02:16 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2008-01-17 10:10:19 299,008 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-12-22 14:02:14 299,008 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2008-01-17 10:10:19 131,072 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-12-22 14:02:15 131,072 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2008-01-17 10:10:16 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-12-22 14:02:04 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2008-01-17 10:10:17 114,688 ----a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-12-22 14:02:05 114,688 ----a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2008-01-17 10:10:20 835,584 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-12-22 14:02:17 835,584 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2008-01-17 10:10:17 86,016 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExp
ressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExp
ressions.dll
+ 2008-12-22 14:02:06 86,016 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExp
ressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExp
ressions.dll
- 2008-01-17 10:10:17 823,296 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-12-22 14:02:06 823,296 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2008-01-17 10:10:17 5,316,608 ----a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-12-22 14:02:07 5,316,608 ----a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2008-01-17 10:10:18 2,035,712 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2008-12-22 14:02:07 2,035,712 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2008-01-17 10:10:20 3,018,752 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2008-12-22 14:02:15 3,018,752 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-01-04 16:06:57 58,880 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\3cd6c9dd90ab3c4c8439c68b6c01d5ce\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2009-01-04 16:06:53 253,952 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\6d713f6a5cb7af418f5b09f07b9fa100\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2009-01-04 16:06:57 229,376 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\807ec0b491bb5c478b06777d5cf24782\DriversHQ.DriverDetective.Common.ni.dll
+ 2009-01-04 16:06:46 2,560,000 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\fdaa14fc0db4784a9ae2f9a3bccd5f21\DriversHQ.DriverDetective.Client.ni.exe
+ 2009-01-04 16:06:57 258,048 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\6f53143940e60c4493b7e0b31a519b57\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2009-01-04 16:07:01 2,441,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\1b68e21dde3412489734294898b6dbee\Microsoft.JScript.ni.dll
+ 2009-01-04 16:06:58 368,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\81ecd09f6d3c6b4fb4eacf02b75706c2\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2009-01-04 16:07:02 356,352 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\d23d68073d003d4abc2cc12faa9b5cc1\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2009-01-04 16:07:02 167,936 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\eb7759425dbd1c42b5c34974b1d216c1\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2009-01-04 16:06:53 17,920 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\4b72912f63efda4bbc3855ea3f43ef52\Microsoft.VisualC.ni.dll
+ 2009-01-04 16:07:01 77,824 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\a40dbae52808604e9035cd1d5e12513a\Microsoft.Vsa.ni.dll
+ 2009-01-04 16:06:52 167,936 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\273febafd5c1514d8a5ea1967b910d9a\System.Configuration.Install.ni.dll
+ 2009-01-04 16:06:56 1,183,744 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\a6a53cbb5a9ed447aa348c2bc01da8b5\System.Data.OracleClient.ni.dll
+ 2009-01-04 16:06:51 2,703,360 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\a050c7d57b5186448663fc7674c0ec52\System.Data.SqlXml.ni.dll
+ 2009-01-04 16:06:59 1,060,864 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\ffe691be1be50f4792045327b384d177\System.Management.ni.dll
+ 2009-01-04 16:06:54 815,104 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\be6b5ffba98f3b4bb92c3d882ec9d16a\System.Runtime.Remoting.ni.dll
+ 2009-01-04 16:06:51 339,968 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\d6746b6bc139684b9108fd7b87623933\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-01-04 16:06:56 233,472 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\52f66f41244d33498a6cec6b4af8ff01\System.ServiceProcess.ni.dll
+ 2009-01-04 16:07:02 139,264 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\f61f5a99ff10664a85ac45b315a56bad\XPBurnComponent.ni.dll
+ 2008-01-17 10:10:19 299,008 ------w c:\windows\assembly\temp\ABODE3G5IV\System.Runtime.Remoting.dll
+ 2004-08-03 11:31:50 175,104 ----a-w c:\windows\ime\chsime\applets\PINTLCSA.DLL
+ 2004-08-03 11:31:50 53,760 ----a-w c:\windows\ime\chsime\applets\PINTLCSD.DLL
+ 2004-08-03 11:31:52 97,792 ----a-w c:\windows\ime\CHTIME\Applets\CHTMBX.DLL
+ 2004-08-03 11:31:54 56,320 ----a-w c:\windows\ime\CHTIME\Applets\CHTSKDIC.DLL
+ 2004-08-03 11:31:54 173,568 ----a-w c:\windows\ime\CHTIME\Applets\CHTSKF.DLL
+ 2009-01-03 14:11:16 10,096,640 ----a-w c:\windows\ime\CHTIME\Applets\HWXCHT.DLL
+ 2009-01-03 14:17:25 13,463,552 ----a-w c:\windows\ime\imjp8_1\applets\hwxjpn.dll
+ 2009-01-03 14:05:39 471,102 ----a-w c:\windows\ime\imjp8_1\applets\imskdic.dll
+ 2009-01-03 14:05:39 315,452 ----a-w c:\windows\ime\imjp8_1\applets\imskf.dll
+ 2009-01-03 14:17:25 229,439 ----a-w c:\windows\ime\imjp8_1\applets\multibox.dll
+ 2009-01-03 14:25:19 143,422 ----a-w c:\windows\ime\imjp8_1\applets\softkey.dll
+ 2002-08-28 13:39:06 426,042 ----a-w c:\windows\ime\imjp8_1\applets\voicepad.dll
+ 2002-08-28 13:39:08 86,074 ----a-w c:\windows\ime\imjp8_1\applets\voicesub.dll
+ 2002-08-28 13:38:26 57,400 ----a-w c:\windows\ime\imjp8_1\cplexe.exe
+ 2002-08-07 11:35:54 360,494 ----a-w c:\windows\ime\imjp8_1\imjpcic.dll
+ 2002-08-28 13:38:40 716,857 ----a-w c:\windows\ime\imjp8_1\imjpcus.dll
+ 2009-01-03 14:13:35 57,398 ----a-w c:\windows\ime\imjp8_1\imjpdadm.exe
+ 2002-08-28 13:38:40 81,977 ----a-w c:\windows\ime\imjp8_1\imjpdct.dll
+ 2002-08-28 13:38:40 307,258 ----a-w c:\windows\ime\imjp8_1\imjpdct.exe
+ 2002-08-28 13:38:40 155,706 ----a-w c:\windows\ime\imjp8_1\imjpdsvr.exe
+ 2002-08-28 13:38:42 196,666 ----a-w c:\windows\ime\imjp8_1\imjpinst.exe
+ 2002-08-28 13:38:42 208,953 ----a-w c:\windows\ime\imjp8_1\imjpmig.exe
+ 2002-08-28 13:38:46 233,528 ----a-w c:\windows\ime\imjp8_1\imjprw.exe
+ 2009-01-03 14:05:39 45,109 ----a-w c:\windows\ime\imjp8_1\imjpuex.exe
+ 2002-08-28 13:38:52 262,201 ----a-w c:\windows\ime\imjp8_1\imjputy.exe
+ 2002-08-28 13:38:54 274,490 ----a-w c:\windows\ime\imjp8_1\imjputyc.dll
+ 2009-01-03 14:25:19 10,129,408 ----a-w c:\windows\ime\imkr6_1\applets\hwxkor.dll
+ 2001-08-23 12:00:00 80,384 ----a-w c:\windows\ime\imkr6_1\applets\imekrmbx.dll
+ 2009-01-03 13:57:38 36,864 ----a-w c:\windows\ime\imkr6_1\dicts\hanjadic.dll
+ 2002-08-28 17:12:30 99,328 ----a-w c:\windows\ime\imkr6_1\imekrcic.dll
+ 2009-01-03 13:57:38 44,032 ----a-w c:\windows\ime\imkr6_1\imekrmig.exe
+ 2009-01-03 14:05:39 59,904 ----a-w c:\windows\ime\imkr6_1\imkrinst.exe
+ 2009-01-03 13:57:38 102,463 ----a-w c:\windows\ime\shared\imepadsm.dll
+ 2009-01-03 13:57:38 311,359 ----a-w c:\windows\ime\shared\imepadsv.exe
+ 2004-08-03 11:32:28 102,456 ----a-w c:\windows\ime\shared\imlang.dll
+ 2004-08-03 11:32:12 15,872 ----a-w c:\windows\ime\shared\res\PADRS404.DLL
+ 2009-01-03 14:11:17 36,927 ----a-w c:\windows\ime\shared\res\padrs411.dll
+ 2009-01-03 14:11:17 14,336 ----a-w c:\windows\ime\shared\res\padrs412.dll
+ 2004-08-03 11:31:50 15,360 ----a-w c:\windows\ime\shared\res\padrs804.dll
+ 2009-01-03 14:25:20 19,456 ----a-w c:\windows\msagent\intl\agt0404.dll
+ 2009-01-03 14:25:20 19,456 ----a-w c:\windows\msagent\intl\agt0411.dll
+ 2009-01-03 14:25:20 19,456 ----a-w c:\windows\msagent\intl\agt0412.dll
+ 2009-01-03 14:25:21 19,456 ----a-w c:\windows\msagent\intl\agt0804.dll
+ 2009-01-03 14:25:21 218,112 ----a-w c:\windows\system32\c_g18030.dll
+ 2009-01-03 14:25:21 6,656 ----a-w c:\windows\system32\c_is2022.dll
+ 2009-01-03 14:05:39 1,677,824 ----a-w c:\windows\system32\chsbrkr.dll
+ 2009-01-03 14:05:39 838,144 ----a-w c:\windows\system32\chtbrkr.dll
- 2008-12-21 08:05:04 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-04 16:16:24 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-21 08:05:04 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-04 16:16:24 49,152 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-31 01:34:25 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008123120090101\index.dat
+ 2008-12-31 19:57:37 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009010120090102\index.dat
- 2008-12-21 08:05:04 393,216 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-04 16:16:24 409,600 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-21 08:15:38 233,472 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat
+ 2009-01-04 16:14:14 233,472 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat
- 2001-08-23 12:00:00 19,456 -c--a-w c:\windows\system32\dllcache\agt0404.dll
+ 2009-01-03 14:25:20 19,456 -c--a-w c:\windows\system32\dllcache\agt0404.dll
- 2001-08-23 12:00:00 19,456 -c--a-w c:\windows\system32\dllcache\agt0411.dll
+ 2009-01-03 14:25:20 19,456 -c--a-w c:\windows\system32\dllcache\agt0411.dll
- 2001-08-23 12:00:00 19,456 -c--a-w c:\windows\system32\dllcache\agt0412.dll
+ 2009-01-03 14:25:20 19,456 -c--a-w c:\windows\system32\dllcache\agt0412.dll
- 2001-08-23 12:00:00 19,456 -c--a-w c:\windows\system32\dllcache\agt0804.dll
+ 2009-01-03 14:25:21 19,456 -c--a-w c:\windows\system32\dllcache\agt0804.dll
- 2001-08-23 12:00:00 218,112 -c--a-w c:\windows\system32\dllcache\c_g18030.dll
+ 2009-01-03 14:25:21 218,112 -c--a-w c:\windows\system32\dllcache\c_g18030.dll
- 2001-08-23 12:00:00 6,656 -c--a-w c:\windows\system32\dllcache\c_is2022.dll
+ 2009-01-03 14:25:21 6,656 -c--a-w c:\windows\system32\dllcache\c_is2022.dll
- 2001-08-23 12:00:00 1,677,824 -c--a-w c:\windows\system32\dllcache\chsbrkr.dll
+ 2009-01-03 14:05:39 1,677,824 -c--a-w c:\windows\system32\dllcache\chsbrkr.dll
- 2001-08-23 12:00:00 838,144 -c--a-w c:\windows\system32\dllcache\chtbrkr.dll
+ 2009-01-03 14:05:39 838,144 -c--a-w c:\windows\system32\dllcache\chtbrkr.dll
- 2002-08-28 13:39:42 97,792 -c--a-w c:\windows\system32\dllcache\chtmbx.dll
+ 2004-08-03 11:31:52 97,792 -c--a-w c:\windows\system32\dllcache\chtmbx.dll
- 2002-08-28 13:39:42 56,320 -c--a-w c:\windows\system32\dllcache\chtskdic.dll
+ 2004-08-03 11:31:54 56,320 -c--a-w c:\windows\system32\dllcache\chtskdic.dll
- 2002-08-28 13:39:42 173,568 -c--a-w c:\windows\system32\dllcache\chtskf.dll
+ 2004-08-03 11:31:54 173,568 -c--a-w c:\windows\system32\dllcache\chtskf.dll
- 2001-08-23 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\f3ahvoas.dll
+ 2009-01-03 14:25:21 7,168 -c--a-w c:\windows\system32\dllcache\f3ahvoas.dll
- 2001-08-23 12:00:00 36,864 -c--a-w c:\windows\system32\dllcache\hanjadic.dll
+ 2009-01-03 13:57:38 36,864 -c--a-w c:\windows\system32\dllcache\hanjadic.dll
- 2001-08-23 12:00:00 10,096,640 -c--a-w c:\windows\system32\dllcache\hwxcht.dll
+ 2009-01-03 14:11:16 10,096,640 -c--a-w c:\windows\system32\dllcache\hwxcht.dll
- 2001-08-23 12:00:00 13,463,552 -c--a-w c:\windows\system32\dllcache\hwxjpn.dll
+ 2009-01-03 14:17:25 13,463,552 -c--a-w c:\windows\system32\dllcache\hwxjpn.dll
- 2001-08-23 12:00:00 10,129,408 -c--a-w c:\windows\system32\dllcache\hwxkor.dll
+ 2009-01-03 14:25:19 10,129,408 -c--a-w c:\windows\system32\dllcache\hwxkor.dll
- 2001-08-23 12:00:00 44,032 -c--a-w c:\windows\system32\dllcache\imekrmig.exe
+ 2009-01-03 13:57:38 44,032 -c--a-w c:\windows\system32\dllcache\imekrmig.exe
- 2001-08-23 12:00:00 102,463 -c--a-w c:\windows\system32\dllcache\imepadsm.dll
+ 2009-01-03 13:57:38 102,463 -c--a-w c:\windows\system32\dllcache\imepadsm.dll
- 2001-08-23 12:00:00 311,359 -c--a-w c:\windows\system32\dllcache\imepadsv.exe
+ 2009-01-03 13:57:38 311,359 -c--a-w c:\windows\system32\dllcache\imepadsv.exe
- 2001-08-23 12:00:00 57,398 -c--a-w c:\windows\system32\dllcache\imjpdadm.exe
+ 2009-01-03 14:13:35 57,398 -c--a-w c:\windows\system32\dllcache\imjpdadm.exe
- 2001-08-23 12:00:00 45,109 -c--a-w c:\windows\system32\dllcache\imjpuex.exe
+ 2009-01-03 14:05:39 45,109 -c--a-w c:\windows\system32\dllcache\imjpuex.exe
- 2001-08-23 12:00:00 59,904 -c--a-w c:\windows\system32\dllcache\imkrinst.exe
+ 2009-01-03 14:05:39 59,904 -c--a-w c:\windows\system32\dllcache\imkrinst.exe
- 2002-08-28 13:39:02 102,456 -c--a-w c:\windows\system32\dllcache\imlang.dll
+ 2004-08-03 11:32:28 102,456 -c--a-w c:\windows\system32\dllcache\imlang.dll
- 2002-08-28 13:39:06 59,392 -c--a-w c:\windows\system32\dllcache\imscinst.exe
+ 2004-08-03 11:31:50 59,392 -c--a-w c:\windows\system32\dllcache\imscinst.exe
- 2001-08-23 12:00:00 471,102 -c--a-w c:\windows\system32\dllcache\imskdic.dll
+ 2009-01-03 14:05:39 471,102 -c--a-w c:\windows\system32\dllcache\imskdic.dll
- 2001-08-23 12:00:00 315,452 -c--a-w c:\windows\system32\dllcache\imskf.dll
+ 2009-01-03 14:05:39 315,452 -c--a-w c:\windows\system32\dllcache\imskf.dll
- 2001-08-23 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbd101.dll
+ 2009-01-03 14:25:21 6,144 -c--a-w c:\windows\system32\dllcache\kbd101.dll
- 2001-08-23 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbd101a.dll
+ 2009-01-03 14:25:21 6,144 -c--a-w c:\windows\system32\dllcache\kbd101a.dll
- 2001-08-23 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbd106n.dll
+ 2009-01-03 14:25:21 6,144 -c--a-w c:\windows\system32\dllcache\kbd106n.dll
- 2001-08-23 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdax2.dll
+ 2009-01-03 14:25:21 6,144 -c--a-w c:\windows\system32\dllcache\kbdax2.dll
- 2001-08-23 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\kbdibm02.dll
+ 2009-01-03 14:25:21 7,168 -c--a-w c:\windows\system32\dllcache\kbdibm02.dll
- 2001-08-23 12:00:00 6,656 -c--a-w c:\windows\system32\dllcache\kbdlk41a.dll
+ 2009-01-03 14:25:21 6,656 -c--a-w c:\windows\system32\dllcache\kbdlk41a.dll
- 2001-08-23 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdlk41j.dll
+ 2009-01-03 14:25:21 6,144 -c--a-w c:\windows\system32\dllcache\kbdlk41j.dll
- 2001-08-23 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\kbdnec95.dll
+ 2009-01-03 14:25:21 7,168 -c--a-w c:\windows\system32\dllcache\kbdnec95.dll
- 2001-08-23 12:00:00 9,216 -c--a-w c:\windows\system32\dllcache\kbdnecat.dll
+ 2009-01-03 14:25:21 9,216 -c--a-w c:\windows\system32\dllcache\kbdnecat.dll
- 2001-08-23 12:00:00 7,680 -c--a-w c:\windows\system32\dllcache\kbdnecnt.dll
+ 2009-01-03 14:25:21 7,680 -c--a-w c:\windows\system32\dllcache\kbdnecnt.dll
- 2001-08-23 12:00:00 70,656 -c--a-w c:\windows\system32\dllcache\korwbrkr.dll
+ 2009-01-03 14:05:39 70,656 -c--a-w c:\windows\system32\dllcache\korwbrkr.dll
- 2001-08-23 12:00:00 98,304 -c--a-w c:\windows\system32\dllcache\msir3jp.dll
+ 2009-01-03 14:11:17 98,304 -c--a-w c:\windows\system32\dllcache\msir3jp.dll
- 2001-08-23 12:00:00 229,439 -c--a-w c:\windows\system32\dllcache\multibox.dll
+ 2009-01-03 14:17:25 229,439 -c--a-w c:\windows\system32\dllcache\multibox.dll
- 2002-08-28 13:39:46 15,872 -c--a-w c:\windows\system32\dllcache\padrs404.dll
+ 2004-08-03 11:32:12 15,872 -c--a-w c:\windows\system32\dllcache\padrs404.dll
- 2001-08-23 12:00:00 36,927 -c--a-w c:\windows\system32\dllcache\padrs411.dll
+ 2009-01-03 14:11:17 36,927 -c--a-w c:\windows\system32\dllcache\padrs411.dll
- 2001-08-23 12:00:00 14,336 -c--a-w c:\windows\system32\dllcache\padrs412.dll
+ 2009-01-03 14:11:17 14,336 -c--a-w c:\windows\system32\dllcache\padrs412.dll
- 2002-08-28 13:39:08 15,360 -c--a-w c:\windows\system32\dllcache\padrs804.dll
+ 2004-08-03 11:31:50 15,360 -c--a-w c:\windows\system32\dllcache\padrs804.dll
- 2002-08-28 13:39:08 175,104 -c--a-w c:\windows\system32\dllcache\pintlcsa.dll
+ 2004-08-03 11:31:50 175,104 -c--a-w c:\windows\system32\dllcache\pintlcsa.dll
- 2002-08-28 13:39:08 53,760 -c--a-w c:\windows\system32\dllcache\pintlcsd.dll
+ 2004-08-03 11:31:50 53,760 -c--a-w c:\windows\system32\dllcache\pintlcsd.dll
- 2002-08-28 13:39:06 70,144 -c--a-w c:\windows\system32\dllcache\pintlphr.exe
+ 2004-08-03 11:31:50 70,144 -c--a-w c:\windows\system32\dllcache\pintlphr.exe
- 2002-08-28 13:39:08 67,584 -c--a-w c:\windows\system32\dllcache\pmigrate.dll
+ 2004-08-03 11:31:50 67,584 -c--a-w c:\windows\system32\dllcache\pmigrate.dll
- 2001-08-23 12:00:00 143,422 -c--a-w c:\windows\system32\dllcache\softkey.dll
+ 2009-01-03 14:25:19 143,422 -c--a-w c:\windows\system32\dllcache\softkey.dll
- 2002-08-28 13:39:50 44,032 -c--a-w c:\windows\system32\dllcache\tintlphr.exe
+ 2004-08-03 11:32:16 44,032 -c--a-w c:\windows\system32\dllcache\tintlphr.exe
- 2002-08-28 13:39:50 455,168 -c--a-w c:\windows\system32\dllcache\tintsetp.exe
+ 2004-08-03 11:32:16 455,168 -c--a-w c:\windows\system32\dllcache\tintsetp.exe
- 2002-08-28 13:39:48 10,240 -c--a-w c:\windows\system32\dllcache\tmigrate.dll
+ 2004-08-03 11:32:14 10,240 -c--a-w c:\windows\system32\dllcache\tmigrate.dll
+ 2005-08-02 21:10:13 32,512 ----a-w c:\windows\system32\drivers\npf.sys
+ 2006-01-17 19:50:28 61,952 ----a-w c:\windows\system32\execryptorvb.dll
+ 2009-01-03 14:25:21 7,168 ----a-w c:\windows\system32\f3ahvoas.dll
- 2008-07-28 13:06:50 117,360 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-03 14:28:02 122,928 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2002-08-28 13:39:42 201,216 ----a-w c:\windows\system32\IME\CINTLGNT\cintime.dll
+ 2002-08-28 13:39:44 480,256 ----a-w c:\windows\system32\IME\CINTLGNT\cintsetp.exe
+ 2004-08-03 11:31:50 59,392 ----a-w c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
+ 2004-08-03 11:31:50 70,144 ----a-w c:\windows\system32\IME\PINTLGNT\PINTLPHR.EXE
+ 2004-08-03 11:31:50 67,584 ----a-w c:\windows\system32\IME\PINTLGNT\PMIGRATE.DLL
+ 2004-08-03 11:32:16 44,032 ----a-w c:\windows\system32\IME\TINTLGNT\TINTLPHR.EXE
+ 2004-08-03 11:32:16 455,168 ----a-w c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
+ 2004-08-03 11:32:14 10,240 ----a-w c:\windows\system32\IME\TINTLGNT\TMIGRATE.DLL
+ 2002-06-12 11:14:46 827,438 ----a-w c:\windows\system32\imjp81k.dll
+ 2009-01-03 14:25:21 6,144 ----a-w c:\windows\system32\kbd101.dll
+ 2009-01-03 14:25:21 6,144 ----a-w c:\windows\system32\kbd101a.dll
+ 2009-01-03 14:25:21 6,144 ----a-w c:\windows\system32\kbd106n.dll
+ 2009-01-03 14:25:21 6,144 ----a-w c:\windows\system32\kbdax2.dll
+ 2009-01-03 14:25:21 7,168 ----a-w c:\windows\system32\kbdibm02.dll
+ 2009-01-03 14:25:21 6,656 ----a-w c:\windows\system32\kbdlk41a.dll
+ 2009-01-03 14:25:21 6,144 ----a-w c:\windows\system32\kbdlk41j.dll
+ 2009-01-03 14:25:21 7,168 ----a-w c:\windows\system32\kbdnec95.dll
+ 2009-01-03 14:25:21 9,216 ----a-w c:\windows\system32\kbdnecAT.dll
+ 2009-01-03 14:25:21 7,680 ----a-w c:\windows\system32\kbdnecNT.dll
+ 2009-01-03 14:05:39 70,656 ----a-w c:\windows\system32\korwbrkr.dll
+ 2009-01-03 14:11:17 98,304 ----a-w c:\windows\system32\msir3jp.dll
+ 2002-08-28 19:41:00 28,672 ----a-w c:\windows\system32\mswmdmsrv.dll
+ 2005-08-02 21:08:09 81,920 ----a-w c:\windows\system32\Packet.dll
- 2008-10-26 00:10:52 63,974 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-22 14:02:23 63,974 ----a-w c:\windows\system32\perfc009.dat
- 2008-10-26 00:10:52 406,432 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-22 14:02:23 406,432 ----a-w c:\windows\system32\perfh009.dat
- 2008-12-19 07:30:08 202,040 ----a-w c:\windows\system32\PnkBstrB.exe
+ 2009-01-02 05:44:57 202,040 ----a-w c:\windows\system32\PnkBstrB.exe
+ 2005-08-02 21:24:01 53,299 ----a-w c:\windows\system32\pthreadVC.dll
+ 2002-08-28 17:12:18 72,192 ----a-w c:\windows\system32\uniime.dll
+ 2005-08-02 21:08:06 61,440 ----a-w c:\windows\system32\WanPacket.dll
+ 2005-08-02 21:18:45 233,472 ----a-w c:\windows\system32\wpcap.dll
- 2008-01-17 10:10:16 258,048 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-12-22 14:02:01 258,048 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2008-01-17 10:10:16 114,176 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2008-12-22 14:02:01 114,176 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\ctfmon.exe" [2002-08-29 13312]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-10 385024]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-16 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"SpeedTouch USB Diagnostics"="c:\program files\Alcatel\SpeedTouch USB\Dragdiag.exe" [2002-06-06 861184]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2002-08-29 208953]
"MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-11 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-05 c:\windows\SkyTel.exe]
"AtiPTA"="atiptaxx.exe" [2006-02-22 c:\windows\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-08-29 13312]
c:\documents and settings\Viktor\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\Windows\\System32\\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-12-19 18:30 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
--a------ 2006-05-25 05:31 1372160 c:\program files\TGTSoft\StyleXP\StyleXP.exe
R3 alcan5ln;Alcatel SpeedTouch USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\System32\DRIVERS\alcan5ln.sys [2008-12-23 36048]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\DRIVERS\l151x86.sys [2008-11-27 37376]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [2007-07-20 84992]
S3 MTK;Media Technology Kernel Driver;c:\windows\System32\Drivers\fide.sys [2008-12-11 15271]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [2005-08-03 32512]
.
Contents of the 'Scheduled Tasks' folder
2008-12-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bigpond.com/
mSearchMigratedDefaultURL = hxxp://internetsearchservice.com/search?q={searchTerms}
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm -
TCP: {DFCCD8AA-B30D-4235-8DE9-4533380A2DD1} = 10.0.0.138
FF - ProfilePath - c:\documents and settings\Viktor\Application Data\Mozilla\Firefox\Profiles\2ceii8xw.default\
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWebLaunch.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-05 03:16:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(872)
c:\windows\System32\ODBC32.dll
c:\windows\System32\msctfime.ime
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(928)
c:\windows\System32\dssenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2009-01-05 3:17:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-04 16:17:30
ComboFix2.txt 2008-12-21 08:21:05
Pre-Run: 16,524,779,520 bytes free
Post-Run: 16,649,830,400 bytes free
533
Hi again,
Oh i see. I haven't really used Limewire for a while, and those songs are really old :S
I use Ares *another p2p my friend recommended - Is that safe? D:
My computer seems to running as normal. Although there is a slight lag or delay everytime I show desktop icons.
I really appreciate your work and time :)
Cheers :D
edit: I've read the thread again ; just pointing this out there, I haven't been alt-tabbed out of anything recently. :)
This post has been edited by Sanguel: 04 January 2009 - 04:29 PM