
Parametry komputera:
Procesor: Pentium 4 2.4GHZ
Karta graficzna: Gforce 5500FX
Pamięć RAM: 1.5GB
A oto log z combo fixa:
- Kod: Zaznacz wszystko
ComboFix 08-12-26.03 - Nemo 2008-12-28 16:49:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.1535.1093 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Nemo\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 081227-0] *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Pliki utworzone od 2008-11-28 do 2008-12-28 )))))))))))))))))))))))))))))))
.
2008-12-28 15:23 . 2008-12-28 15:36 782,336 --a------ c:\windows\binded_file.exe
2008-12-26 20:11 . 2008-12-26 20:11 <DIR> d-------- c:\program files\D-Tools
2008-12-26 20:11 . 2004-08-22 16:31 155,136 --a------ c:\windows\system32\drivers\d347bus.sys
2008-12-26 20:11 . 2004-08-22 16:31 5,248 --a------ c:\windows\system32\drivers\d347prt.sys
2008-12-26 11:32 . 2004-08-18 09:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll
2008-12-24 20:13 . 2008-12-24 20:15 <DIR> d-------- c:\program files\eMule
2008-12-24 15:05 . 2001-01-12 19:47 122,884 --a------ c:\windows\UnGins.exe
2008-12-20 10:20 . 2004-05-10 12:14 118,272 --a------ c:\windows\system32\SX5363S.DLL
2008-12-20 10:20 . 2004-05-10 12:14 102,400 --a------ c:\windows\system32\RV32RTP.dll
2008-12-20 10:20 . 2004-05-10 12:15 40 --a------ c:\windows\system32\Sx5363.ini
2008-12-19 19:30 . 2008-12-19 19:30 <DIR> d-------- c:\documents and settings\Nemo\.gstreamer-0.10
2008-12-14 20:33 . 2008-12-14 20:33 <DIR> d-------- c:\program files\calegta
2008-12-13 11:10 . 2008-12-13 11:10 <DIR> d-------- c:\program files\ivo
2008-12-13 11:10 . 2008-12-13 11:10 <DIR> d-------- c:\documents and settings\Nemo\Dane aplikacji\Expressivo
2008-12-10 16:34 . 2008-12-10 16:34 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-10 10:59 . 2008-10-03 11:04 247,326 --------- c:\windows\system32\dllcache\strmdll.dll
2008-12-09 16:04 . 2008-12-28 16:37 <DIR> d-------- c:\program files\Puzzle Quest
2008-12-09 16:04 . 2008-12-09 16:04 <DIR> d-------- c:\program files\OpenAL
2008-12-09 16:04 . 2008-12-09 16:04 409,600 --a------ c:\windows\system32\wrap_oal.dll
2008-12-09 16:04 . 2008-12-09 16:04 114,688 --a------ c:\windows\system32\OpenAL32.dll
2008-12-09 15:13 . 2008-12-09 15:13 <DIR> d--hs---- c:\windows\ftpcache
2008-12-06 09:14 . 2008-12-06 09:14 <DIR> d-------- c:\program files\GameShadow
2008-12-06 09:13 . 2008-12-26 20:11 <DIR> d-------- c:\windows\Downloaded Installations
2008-12-05 12:51 . 2008-12-05 12:51 <DIR> d-------- c:\program files\Activision
2008-12-05 12:51 . 2008-12-05 13:44 776 --a------ c:\windows\Thps3.INI
2008-12-02 20:36 . 2008-12-28 16:55 <DIR> d-------- c:\program files\Steam
2008-12-02 17:47 . 2008-12-03 17:02 <DIR> d-------- c:\documents and settings\Nemo\Dane aplikacji\Sports Interactive
2008-12-02 17:45 . 2008-12-02 17:48 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Sports Interactive
2008-12-02 17:41 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-12-02 17:41 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-12-02 17:41 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-12-02 17:41 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-12-02 17:41 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-12-02 17:41 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-12-02 17:41 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-12-02 17:37 . 2008-12-02 17:37 <DIR> d--h----- c:\program files\Zero G Registry
2008-12-02 17:37 . 2008-12-02 17:37 <DIR> d--h----- c:\documents and settings\Nemo\InstallAnywhere
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 15:57 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\skypePM
2008-12-28 15:57 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Skype
2008-12-28 15:56 --------- d-----w c:\program files\Spyware Process Detector
2008-12-28 15:55 --------- d-----w c:\program files\DNA
2008-12-28 15:55 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\DNA
2008-12-28 15:48 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Hamachi
2008-12-28 15:43 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-12-26 19:53 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\BitTorrent
2008-12-24 12:18 --------- d-----w c:\program files\VDOWNLOADER
2008-12-24 12:17 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Desktopicon
2008-12-23 20:48 --------- d-----w c:\program files\MoorHunt
2008-12-19 09:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-14 19:42 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Xfire
2008-12-14 15:33 203,944 ----a-w c:\windows\system32\PnkBstrB.exe
2008-12-14 15:33 139,040 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-14 15:32 --------- d-----w c:\program files\Xfire
2008-12-13 06:39 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-03 15:57 --------- d-----w c:\program files\Nowe Gadu-Gadu
2008-11-25 14:02 --------- d-----w c:\documents and settings\LocalService\Dane aplikacji\Xfire
2008-11-24 18:27 --------- d-----w c:\documents and settings\NetworkService\Dane aplikacji\Xfire
2008-11-23 12:58 --------- d-----w c:\program files\Skype
2008-11-23 12:58 --------- d-----w c:\program files\Common Files\Skype
2008-11-23 12:58 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2008-11-21 15:09 --------- d-----w c:\program files\directx
2008-11-20 20:44 42,320 ----a-w c:\windows\system32\xfcodec.dll
2008-11-19 17:40 --------- d-----w c:\program files\SubEdit-Player
2008-11-16 18:24 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\EPSON
2008-11-12 18:52 --------- d-----w c:\program files\Hamachi
2008-11-12 18:51 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2008-11-10 20:01 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\FLEXnet
2008-11-10 19:57 --------- d-----w c:\program files\Common Files\Adobe
2008-11-10 19:56 --------- d-----w c:\program files\Bonjour
2008-11-10 19:47 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-11-06 19:00 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\NVIDIA
2008-11-06 13:30 33,824 ----a-w c:\windows\system32\drivers\oreans32.sys
2008-11-04 19:11 --------- d-----w c:\program files\microsoft frontpage
2008-11-03 14:10 --------- d-----w c:\program files\R
2008-11-02 21:55 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Winamp
2008-11-02 21:53 --------- d-----w c:\program files\Winamp Toolbar
2008-11-02 21:53 --------- d-----w c:\program files\Winamp Remote
2008-11-02 21:53 --------- d-----w c:\program files\Winamp
2008-11-02 21:53 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar
2008-11-02 21:53 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\OrbNetworks
2008-11-02 18:43 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Publish Providers
2008-11-02 18:42 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Sony
2008-11-02 18:41 --------- d-----w c:\program files\Microsoft SQL Server
2008-11-02 18:40 --------- d-----w c:\program files\Vstplugins
2008-11-02 18:40 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Sony
2008-11-02 18:39 --------- d-----w c:\program files\Sony
2008-11-02 18:32 --------- d-----w c:\program files\Sony Setup
2008-11-02 18:32 --------- d-----w c:\documents and settings\Nemo\Dane aplikacji\Sony Setup
2008-11-02 09:49 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2008-11-02 09:39 --------- d-----w c:\program files\SystemRequirementsLab
2008-11-02 09:25 --------- d-----w c:\program files\Rockstar Games
2008-11-02 09:22 --------- d-----w c:\program files\PowerISO
2008-11-01 08:14 --------- d-----w c:\program files\KRU
2008-10-31 21:41 --------- d-----w c:\program files\BitTorrent
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:42 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 13:15 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:36 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-10-11 11:02 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-19 10:55 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-09-19 10:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
2008-09-19 10:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008091920080920\index.dat
2008-09-19 10:55 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-04_ 7.38.23,89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-10 01:12:48 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2007-11-30 12:40:46 19,320 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2007-11-30 12:40:46 234,360 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2007-11-30 12:40:46 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2007-11-30 12:40:47 763,256 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2007-11-30 12:40:47 398,200 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2008-09-04 17:13:36 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:21:28 19,320 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:21:28 234,360 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:21:28 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 12:40:47 763,256 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 12:27:24 398,200 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 13:20:04 19,320 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 13:20:05 234,360 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 13:20:04 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 13:20:08 763,256 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 13:20:16 398,200 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-04-14 20:50:40 1,306,624 -c----w c:\windows\$NtUninstallKB954459$\msxml6.dll
+ 2007-11-30 12:40:46 234,360 -c----w c:\windows\$NtUninstallKB954459$\spuninst\spuninst.exe
+ 2007-11-30 12:40:47 398,200 -c----w c:\windows\$NtUninstallKB954459$\spuninst\updspapi.dll
+ 2008-04-14 20:50:40 1,104,896 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
+ 2007-11-30 11:21:28 234,360 -c----w c:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe
+ 2008-07-09 12:27:24 398,200 -c----w c:\windows\$NtUninstallKB955069$\spuninst\updspapi.dll
+ 2008-04-13 22:47:02 456,576 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
+ 2008-07-08 13:20:05 234,360 -c----w c:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe
+ 2008-07-08 13:20:16 398,200 -c----w c:\windows\$NtUninstallKB957097$\spuninst\updspapi.dll
+ 2008-12-02 19:34:03 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-12-02 19:34:03 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-12-02 19:34:04 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-12-02 19:33:56 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:33:57 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:33:58 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:33:59 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:33:59 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:00 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:00 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:01 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:01 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:05 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-12-02 19:34:05 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-12-02 19:34:06 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-12-02 19:34:07 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-12-02 19:34:08 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-12-02 19:34:02 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2004-08-22 16:04:56 69,120 ----a-w c:\windows\daemon.dll
+ 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2008-08-26 08:26:55 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 08:26:55 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 08:26:55 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 08:26:55 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 08:26:55 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:42:17 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 08:26:55 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 08:26:56 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 08:26:56 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 08:26:56 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:26:30 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 08:26:58 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 08:26:58 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 08:26:58 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 08:26:59 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 08:26:59 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-27 09:27:02 3,593,216 -c----w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-26 08:27:00 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 08:27:00 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 08:27:00 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 08:27:00 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 08:27:00 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 03:28:39 216,288 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 03:29:50 386,784 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 08:27:01 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 08:27:01 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 08:27:01 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 08:27:02 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-10-17 01:03:34 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 03:28:39 216,288 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 03:29:49 386,784 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2008-12-02 19:36:10 27,648 ----a-r c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
- 1998-10-29 14:45:06 306,688 ----a-w c:\windows\IsUninst.exe
+ 2000-07-31 08:48:08 306,688 ----a-w c:\windows\IsUninst.exe
+ 2005-03-18 15:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 15:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 15:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 11:38:58 2,676,224 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 15:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 15:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 15:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 15:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 15:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 14:53:06 2,846,720 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 18:32:54 563,712 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 16:23:14 567,296 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 14:15:56 576,000 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 16:21:34 577,024 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 13:11:52 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 16:20:50 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 06:40:48 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 10:27:50 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
- 1999-06-25 08:55:30 149,504 ----a-w c:\windows\system32\Adobe\Shockwave 11\UNWISE.EXE
+ 1999-06-25 09:55:30 149,504 ----a-w c:\windows\system32\Adobe\Shockwave 11\UNWISE.EXE
- 2008-08-26 08:26:55 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:33:23 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2007-03-12 15:42:30 1,123,696 ----a-w c:\windows\system32\D3DCompiler_33.dll
+ 2007-05-16 15:45:16 1,124,720 ----a-w c:\windows\system32\D3DCompiler_34.dll
+ 2007-07-19 17:14:42 1,358,192 ----a-w c:\windows\system32\D3DCompiler_35.dll
+ 2007-10-12 14:14:00 1,374,232 ----a-w c:\windows\system32\D3DCompiler_36.dll
+ 2008-03-05 14:56:58 1,420,824 ----a-w c:\windows\system32\D3DCompiler_37.dll
+ 2007-03-15 15:57:58 443,752 ----a-w c:\windows\system32\d3dx10_33.dll
+ 2007-05-16 15:45:16 443,752 ----a-w c:\windows\system32\d3dx10_34.dll
+ 2007-07-19 17:14:42 444,776 ----a-w c:\windows\system32\d3dx10_35.dll
+ 2007-10-02 08:56:34 444,776 ----a-w c:\windows\system32\d3dx10_36.dll
+ 2008-02-05 22:07:36 462,864 ----a-w c:\windows\system32\d3dx10_37.dll
+ 2005-02-05 18:45:26 2,222,800 ----a-w c:\windows\system32\d3dx9_24.dll
- 2005-03-18 15:19:58 2,337,488 ----a-w c:\windows\system32\d3dx9_25.dll
+ 2005-03-19 00:19:58 2,337,488 ----a-w c:\windows\system32\d3dx9_25.dll
+ 2005-05-26 14:34:52 2,297,552 ----a-w c:\windows\system32\d3dx9_26.dll
+ 2005-07-22 18:59:04 2,319,568 ----a-w c:\windows\system32\d3dx9_27.dll
+ 2005-12-05 17:09:18 2,323,664 ----a-w c:\windows\system32\d3dx9_28.dll
+ 2006-02-03 07:43:16 2,332,368 ----a-w c:\windows\system32\d3dx9_29.dll
+ 2006-03-31 11:40:58 2,388,176 ----a-w c:\windows\system32\d3dx9_30.dll
+ 2006-09-28 15:05:20 2,414,360 ----a-w c:\windows\system32\d3dx9_31.dll
+ 2006-11-29 12:06:18 3,426,072 ----a-w c:\windows\system32\d3dx9_32.dll
+ 2007-03-12 15:42:30 3,495,784 ----a-w c:\windows\system32\d3dx9_33.dll
+ 2007-05-16 15:45:16 3,497,832 ----a-w c:\windows\system32\d3dx9_34.dll
+ 2007-07-19 17:14:42 3,727,720 ----a-w c:\windows\system32\d3dx9_35.dll
+ 2007-10-12 14:14:00 3,734,536 ----a-w c:\windows\system32\d3dx9_36.dll
+ 2008-03-05 14:56:58 3,786,760 ----a-w c:\windows\system32\D3DX9_37.dll
- 2008-08-26 08:26:55 124,928 ------w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:33:23 124,928 ------w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 08:26:55 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:33:23 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 08:26:55 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:33:24 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 08:26:55 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:33:24 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
- 2008-08-26 08:26:55 63,488 ------w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:33:24 63,488 ------w c:\windows\system32\dllcache\icardie.dll
- 2008-08-26 08:26:55 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:33:24 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 08:26:56 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:33:24 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-26 08:26:56 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:33:24 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 08:26:56 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:33:25 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:26:30 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:33:27 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 08:26:58 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:33:27 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 08:26:58 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:33:28 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-26 08:26:58 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:33:29 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-06-18 00:09:22 100,864 ------w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 08:26:59 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:33:29 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 08:26:59 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:33:29 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-26 08:27:00 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:33:33 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 08:27:00 193,024 ------w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:33:33 193,024 ------w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 08:27:00 671,232 ------w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:33:33 671,232 ------w c:\windows\system32\dllcache\mstime.dll
+ 2008-09-04 17:17:13 1,106,944 ------w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-10 01:15:56 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
- 2008-08-26 08:27:00 102,912 ------w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:33:33 102,912 ------w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 08:27:00 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:33:33 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
- 2008-08-26 08:27:01 105,984 ------w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:33:33 105,984 ------w c:\windows\system32\dllcache\url.dll
- 2008-08-26 08:27:01 1,159,680 ------w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:33:34 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 08:27:01 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:33:34 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 08:27:02 826,368 ------w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:33:34 826,368 ------w c:\windows\system32\dllcache\wininet.dll
+ 2008-06-18 04:03:08 938,496 ------w c:\windows\system32\dllcache\WMNetmgr.dll
+ 2008-06-18 04:03:14 2,458,112 ------w c:\windows\system32\dllcache\WMVCore.dll
+ 2006-02-28 11:41:34 61,440 ----a-w c:\windows\system32\dns-sd.exe
+ 2006-02-28 11:41:22 53,248 ----a-w c:\windows\system32\dnssd.dll
- 2008-04-13 22:47:02 456,576 ----a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
- 2008-08-26 08:26:55 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:33:23 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 08:26:55 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:33:24 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 08:26:55 133,120 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:33:24 133,120 ----a-w c:\windows\system32\extmgr.dll
- 2008-10-26 15:22:49 195,368 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-16 13:26:30 1,488,352 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-08-26 08:26:55 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:33:24 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:42:17 70,656 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:15:01 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 08:26:55 153,088 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:33:24 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 08:26:56 230,400 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:33:24 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
- 2008-08-26 08:26:56 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:33:24 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 08:26:56 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:33:25 384,512 ----a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:26:30 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:33:27 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-08-26 08:26:58 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:33:27 44,544 ----a-w c:\windows\system32\iernonce.dll
- 2008-08-26 08:26:58 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:33:28 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 08:26:58 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:33:29 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2008-05-02 06:46:43 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-03-14 22:31:26 57,344 ----a-w c:\windows\system32\Macromed\Common\SwSupport.dll
+ 2008-03-14 22:29:22 581,632 ----a-w c:\windows\system32\Macromed\Shockwave 10\Control.dll
+ 2008-03-14 22:12:30 1,490,944 ----a-w c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
+ 2008-03-14 22:29:58 24,576 ----a-w c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2008-03-14 22:10:06 606,208 ----a-w c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
+ 2008-03-14 22:28:48 339,968 ----a-w c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
+ 2008-03-14 22:28:56 475,136 ----a-w c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2008-03-14 22:21:52 180,224 ----a-w c:\windows\system32\Macromed\Shockwave 10\Proj.dll
+ 2008-03-14 22:31:28 77,824 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
+ 2008-03-15 10:38:08 86,016 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
+ 2008-03-14 22:31:28 98,304 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
- 2008-10-07 19:19:40 16,721,856 ----a-w c:\windows\system32\MRT.exe
+ 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2008-08-26 08:26:59 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:33:29 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 08:26:59 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:33:29 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 09:27:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:39:17 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-26 08:27:00 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:33:33 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 08:27:00 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:33:33 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-08-26 08:27:00 671,232 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:33:33 671,232 ----a-w c:\windows\system32\mstime.dll
- 2008-04-14 20:50:40 1,104,896 ----a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 17:17:13 1,106,944 ----a-w c:\windows\system32\msxml3.dll
- 2008-04-14 20:50:40 1,306,624 ----a-w c:\windows\system32\msxml6.dll
+ 2008-09-10 01:15:56 1,307,648 ----a-w c:\windows\system32\msxml6.dll
- 2008-08-26 08:27:00 102,912 ----a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:33:33 102,912 ----a-w c:\windows\system32\occache.dll
- 2008-08-26 08:27:00 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:33:33 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 13:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 13:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2007-11-30 11:21:28 19,320 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:40:46 19,320 ------w c:\windows\system32\spmsg.dll
- 2008-07-11 12:42:28 62,976 ----a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 ----a-w c:\windows\system32\tzchange.exe
- 2008-08-26 08:27:01 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-10-16 20:33:33 105,984 ----a-w c:\windows\system32\url.dll
- 2008-08-26 08:27:01 1,159,680 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:33:34 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2008-08-26 08:27:01 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:33:34 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2008-08-26 08:27:02 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:33:34 826,368 ----a-w c:\windows\system32\wininet.dll
- 2008-05-02 06:46:49 937,984 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2008-05-02 06:47:10 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
+ 2006-02-03 07:41:26 14,032 ----a-w c:\windows\system32\x3daudio1_0.dll
+ 2007-03-05 11:42:18 15,128 ----a-w c:\windows\system32\x3daudio1_1.dll
+ 2007-10-22 02:37:16 17,928 ----a-w c:\windows\system32\X3DAudio1_2.dll
+ 2008-03-05 15:00:06 25,608 ----a-w c:\windows\system32\X3DAudio1_3.dll
+ 2006-02-03 07:42:06 230,096 ----a-w c:\windows\system32\xactengine2_0.dll
+ 2006-03-31 11:39:48 229,584 ----a-w c:\windows\system32\xactengine2_1.dll
+ 2007-10-22 02:39:54 267,272 ----a-w c:\windows\system32\xactengine2_10.dll
+ 2006-05-31 06:24:16 230,168 ----a-w c:\windows\system32\xactengine2_2.dll
+ 2006-07-28 08:30:32 236,824 ----a-w c:\windows\system32\xactengine2_3.dll
+ 2006-09-28 15:05:56 237,848 ----a-w c:\windows\system32\xactengine2_4.dll
+ 2006-12-08 11:02:00 251,672 ----a-w c:\windows\system32\xactengine2_5.dll
+ 2007-01-24 14:27:30 255,848 ----a-w c:\windows\system32\xactengine2_6.dll
+ 2007-04-04 17:55:00 261,480 ----a-w c:\windows\system32\xactengine2_7.dll
+ 2007-06-20 19:46:04 266,088 ----a-w c:\windows\system32\xactengine2_8.dll
+ 2007-07-19 23:57:12 267,112 ----a-w c:\windows\system32\xactengine2_9.dll
+ 2008-03-05 15:03:20 238,088 ----a-w c:\windows\system32\xactengine3_0.dll
+ 2008-03-05 15:03:54 479,752 ----a-w c:\windows\system32\XAudio2_0.dll
+ 2006-03-31 11:39:24 62,672 ----a-w c:\windows\system32\xinput1_1.dll
+ 2006-07-28 08:30:14 62,744 ----a-w c:\windows\system32\xinput1_2.dll
+ 2007-04-04 17:53:42 81,768 ----a-w c:\windows\system32\xinput1_3.dll
+ 2005-12-05 17:07:30 61,136 ----a-w c:\windows\system32\xinput9_1_0.dll
+ 2008-12-28 15:55:13 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_6c4.dat
+ 2006-06-05 14:47:40 1,093,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfc80.dll
+ 2006-06-05 14:47:48 1,080,320 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfc80u.dll
+ 2006-06-05 14:47:50 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfcm80.dll
+ 2006-06-05 14:47:50 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00\mfcm80u.dll
+ 2006-06-05 14:28:32 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80CHS.dll
+ 2006-06-05 14:28:32 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80CHT.dll
+ 2006-06-05 14:28:32 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80DEU.dll
+ 2006-06-05 14:28:34 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ENU.dll
+ 2006-06-05 14:28:32 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ESP.dll
+ 2006-06-05 14:28:32 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80FRA.dll
+ 2006-06-05 14:28:32 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80ITA.dll
+ 2006-06-05 14:28:32 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80JPN.dll
+ 2006-06-05 14:28:34 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_8e53b5fe\mfc80KOR.dll
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"EPSON Stylus DX4400 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
"ares"="c:\program files\Ares\Ares.exe" [2008-08-21 888832]
"spyprodetector"="c:\program files\Spyware Process Detector\spydetector.exe" [2008-04-26 370085]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21750568]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2008-11-21 6890088]
"Steam"="c:\program files\Steam\Steam.exe" [2008-12-03 1410296]
"Expressivo"="c:\program files\ivo\Expressivo\expressivo.exe" [2007-07-12 1843200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 167936]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-17 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-17 86016]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"nwiz"="nwiz.exe" [2006-08-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-10-16 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Nemo\\Pulpit\\SA studio obsługa\\Wolfek\\ET.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Documents and Settings\\Nemo\\Pulpit\\SA studio obsługa\\Wolfek\\ETDED.exe"=
"c:\\Documents and Settings\\Nemo\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Activision\\Thps3\\Skate3.exe"=
"i:\airrivals\Launcher.atm"= i:\airrivals\Launcher.atm:Enabled:GameExe2
"i:\airrivals\Res-Voip\SCVoIP.exe"= i:\airrivals\Res-Voip\SCVoIP.exe:Enabled:GameVoIP
"d:\\eMule\\emule.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-09-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-09-19 20560]
R2 spydetector;spydetector;\??\c:\program files\Spyware Process Detector\spydetector.sys [2008-10-26 9216]
.
.
------- Skan uzupełniający -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: &Winamp Search - c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Nemo\Dane aplikacji\Mozilla\Firefox\Profiles\1oe2q7y4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - http://www.onet.pl
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\Nemo\Dane aplikacji\Mozilla\Firefox\Profiles\1oe2q7y4.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 16:56:34
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\Setup\avast.setup
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Hamachi\hamachi.exe
c:\program files\calegta\GTA San Andreas\samp.exe
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Czas ukończenia: 2008-12-28 17:00:19 - komputer został uruchomiony ponownie [Nemo]
ComboFix-quarantined-files.txt 2008-12-28 16:00:07
ComboFix2.txt 2008-11-04 06:38:47
Przed: 6,383,779,840 bajtów wolnych
Po: 6,363,283,456 bajtów wolnych
573 --- E O F --- 2008-12-18 02:00:34