تفضل
ComboFix 09-09-27.05 - user 09/28/2009 1:50.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.894.481 [GMT -7:00]
Running from: c:\documents and settings\user\My Documents\ComboFix.exe3.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Adobe Gamma Loader.lnk
c:\documents and settings\user\Application Data\Desktopicon
c:\documents and settings\user\Application Data\Desktopicon\config.ini
c:\documents and settings\user\Application Data\Desktopicon\eBayShortcuts.exe
.
---- Previous Run -------
.
c:\documents and settings\user\Application Data\wiaserva.log
c:\documents and settings\user\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe
C:\t4224u.exe
C:\t46654u.exe
c:\windows\ALCMTR.EXE
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_acpi32
-------\Service_ksi32sk
-------\Service_nicsk32
-------\Service_systemntmi
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-28 )))))))))))))))))))))))))))))))
.
2009-09-19 01:12 . 2009-09-19 01:12 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-09-18 11:42 . 2009-02-06 17:22 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-18 11:42 . 2009-02-06 17:24 2180480 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-18 11:42 . 2009-02-06 16:49 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-18 11:42 . 2009-02-06 16:49 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-09-18 03:35 . 2009-09-18 03:35 -------- d-----w- c:\program files\PLUS FACE
2009-09-17 11:54 . 2009-09-17 11:54 -------- d-----w- c:\program files\Ask Search Assistant
2009-09-17 04:01 . 2009-09-17 04:01 -------- d-----w- c:\program files\Trend Micro
2009-09-10 09:36 . 2009-09-10 09:36 -------- d-----w- c:\windows\Sun
2009-09-10 04:38 . 2009-09-10 04:38 -------- d-----w- c:\documents and settings\user\Application Data\CyberScrub
2009-09-10 04:38 . 2009-09-10 04:38 -------- d-----w- c:\documents and settings\user\Application Data\cleaner
2009-09-09 03:15 . 2009-09-09 03:15 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-09 03:15 . 2009-09-09 03:15 -------- d-----w- c:\program files\Java
2009-08-31 02:01 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-08-31 02:01 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-08-30 08:43 . 2009-08-30 08:43 -------- d-----w- c:\documents and settings\user\Application Data\GRETECH
2009-08-30 01:34 . 2009-08-30 01:34 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 21:39 . 2009-06-27 15:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-27 12:21 . 2009-07-28 10:34 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-26 00:39 . 2009-07-17 08:52 -------- d-----w- c:\program files\Crcle Developement
2009-09-26 00:24 . 2009-07-17 08:53 -------- d-----w- c:\documents and settings\user\Application Data\PLUS FACE
2009-09-21 22:42 . 2009-06-27 15:34 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-21 22:42 . 2009-06-27 15:34 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-21 00:17 . 2009-06-28 00:51 299568 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-20 11:30 . 2009-06-27 15:47 -------- d-----w- c:\program files\Microsoft Works
2009-09-18 03:36 . 2009-07-17 08:56 -------- d-----w- c:\documents and settings\All Users\Application Data\seek film amok web
2009-09-18 03:34 . 2009-07-17 08:52 -------- d-----w- c:\program files\Messenger Plus! Live
2009-08-30 00:21 . 2009-06-27 15:38 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-29 02:57 . 2009-06-27 16:20 10 ----a-w- c:\windows\popcinfo.dat
2009-08-18 22:00 . 2009-06-27 16:24 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-08-05 09:11 . 2004-08-04 00:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 01:14 . 2009-07-31 01:14 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-07-31 01:12 . 2009-06-27 15:33 311328 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-31 01:12 . 2009-06-27 15:33 2204192 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-31 01:12 . 2009-06-27 15:33 2144 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-31 01:12 . 2009-06-27 15:33 18300 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-31 01:08 . 2009-06-27 15:33 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-31 01:07 . 2009-06-28 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-29 04:53 . 2004-08-04 00:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:53 . 2001-08-23 14:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-03 22:48 . 2009-07-03 22:48 219664 ----a-w- c:\windows\system32\klogon.dll
2009-07-03 22:45 . 2009-07-03 22:45 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
.
(((((((((((((((((((((((((((((
SnapShot@2009-09-19_10.52.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-18 11:11 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2009-06-28 01:03 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
+ 2009-06-27 15:50 . 2007-04-09 20:23 28552 c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2009-06-27 15:50 . 2007-04-09 20:23 46472 c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2009-06-27 15:50 . 2007-04-09 20:23 46472 c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2009-08-25 01:14 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2001-08-23 14:00 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe
- 2001-08-23 14:00 . 2009-09-20 01:54 40836 c:\windows\system32\perfc009.dat
+ 2001-08-23 14:00 . 2009-09-21 00:17 40836 c:\windows\system32\perfc009.dat
+ 2009-06-28 00:42 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 66560 c:\windows\system32\mtxclu.dll
+ 2004-08-04 00:56 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
- 2009-06-28 00:42 . 2004-08-04 00:56 58880 c:\windows\system32\msdtclog.dll
+ 2009-06-27 15:50 . 2007-04-09 20:23 28040 c:\windows\system32\mdimon.dll
+ 2007-03-23 02:17 . 2007-03-23 02:17 35440 c:\windows\system32\FM20ENU.DLL
+ 2001-08-23 14:00 . 2009-02-06 16:54 35328 c:\windows\system32\dllcache\sc.exe
+ 2009-06-28 00:42 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2004-08-04 00:56 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2009-06-28 00:42 . 2004-08-04 00:56 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2001-08-23 14:00 . 2009-07-29 04:53 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2009-06-28 00:42 . 2005-07-26 04:39 60416 c:\windows\system32\dllcache\colbact.dll
+ 2009-06-28 00:50 . 2009-09-22 08:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-06-28 00:50 . 2009-09-20 01:33 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-28 00:50 . 2009-09-22 08:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-06-28 00:50 . 2009-09-20 01:33 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-06-28 00:50 . 2009-09-22 08:44 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-06-28 00:50 . 2009-09-20 01:33 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-28 00:42 . 2005-07-26 04:39 60416 c:\windows\system32\colbact.dll
- 2009-06-27 15:50 . 2009-06-27 15:50 23040 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 23040 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 61440 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 61440 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 27136 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 27136 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 11264 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 11264 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 86016 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 86016 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 12288 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 12288 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2003-01-17 21:03 . 2003-01-17 21:03 59466 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
+ 2003-07-15 05:57 . 2003-07-15 05:57 59960 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\UNBIND.EXE
+ 2002-10-07 16:49 . 2002-10-07 16:49 81983 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
+ 2003-07-15 06:00 . 2003-07-15 06:00 99904 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 11848 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 58944 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 66616 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 74288 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\RM.DLL
+ 2002-10-07 16:49 . 2002-10-07 16:49 81984 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 40512 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-05-09 04:54 . 2003-05-09 04:54 77824 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 05:42 . 2003-07-15 05:42 37432 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-07-15 05:40 . 2003-07-15 05:40 51256 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 93752 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 49208 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 64056 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 88128 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2003-07-15 05:41 . 2003-07-15 05:41 24640 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 95792 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OSA.EXE
+ 2003-07-15 10:14 . 2003-07-15 10:14 27192 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 13888 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 56888 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 41528 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 16384 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 39488 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 55360 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 05:46 . 2003-07-15 05:46 42040 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 39488 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 55872 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOSVABW.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 35896 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 28224 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 54328 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOMSE.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 55360 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2003-07-15 05:44 . 2003-07-15 05:44 25144 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 27704 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 17464 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-07-15 05:51 . 2003-07-15 05:51 87104 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 40504 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSE7.EXE
+ 2003-07-15 06:12 . 2003-07-15 06:12 47872 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSB1XTOR.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 35328 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 18944 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 17920 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 58944 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\INLAUNCH.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 87096 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
+ 2003-07-15 05:41 . 2003-07-15 05:41 13368 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 98360 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-07-15 05:56 . 2003-07-15 05:56 14904 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-26 01:57 . 2003-07-26 01:57 75832 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 47160 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 44608 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\CONVTEXT.EXE
+ 2003-07-15 05:53 . 2003-07-15 05:53 46144 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\BLNMGRPS.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 60984 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 94768 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 38968 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 87616 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
- 2009-06-27 15:50 . 2009-06-27 15:50 4096 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 4096 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2003-06-19 00:31 . 2003-06-19 00:31 6144 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OCRPS.DLL
+ 2009-09-18 11:23 . 2009-04-15 09:24 351744 c:\windows\system32\xpsp3res.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 132096 c:\windows\system32\wkssvc.dll
+ 2004-08-04 00:56 . 2009-06-10 06:32 132096 c:\windows\system32\wkssvc.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 351232 c:\windows\system32\winhttp.dll
+ 2004-08-04 00:56 . 2008-12-16 12:47 351232 c:\windows\system32\winhttp.dll
+ 2009-06-28 00:42 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2009-06-28 00:42 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2009-06-28 00:42 . 2009-02-09 10:20 473088 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-04 00:56 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll
+ 2009-06-27 15:50 . 2007-04-09 20:24 758664 c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2009-06-27 15:50 . 2007-04-09 20:24 758664 c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2004-08-04 00:56 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe
+ 2004-08-04 00:56 . 2008-12-05 07:12 144896 c:\windows\system32\schannel.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 144896 c:\windows\system32\schannel.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 399360 c:\windows\system32\rpcss.dll
+ 2004-08-04 00:56 . 2009-04-15 15:11 584192 c:\windows\system32\rpcrt4.dll
- 2001-08-23 14:00 . 2009-09-20 01:54 314508 c:\windows\system32\perfh009.dat
+ 2001-08-23 14:00 . 2009-09-21 00:17 314508 c:\windows\system32\perfh009.dat
- 2004-08-04 00:56 . 2004-08-04 00:56 283648 c:\windows\system32\pdh.dll
+ 2004-08-04 00:56 . 2009-03-06 14:44 283648 c:\windows\system32\pdh.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 714752 c:\windows\system32\ntdll.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 245248 c:\windows\system32\mswsock.dll
+ 2004-08-04 00:56 . 2008-06-20 17:41 245248 c:\windows\system32\mswsock.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 723456 c:\windows\system32\lsasrv.dll
+ 2004-08-04 00:56 . 2009-05-07 15:44 344064 c:\windows\system32\localspl.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 450560 c:\windows\system32\jscript.dll
+ 2004-08-04 00:56 . 2009-08-21 09:46 450560 c:\windows\system32\jscript.dll
+ 2009-06-28 00:44 . 2008-04-11 18:50 683520 c:\windows\system32\inetcomm.dll
+ 2009-06-27 17:36 . 2009-09-21 00:12 757032 c:\windows\system32\FNTCACHE.DAT
- 2009-06-27 17:36 . 2009-08-05 20:52 757032 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-04 00:56 . 2008-07-07 20:32 253952 c:\windows\system32\es.dll
+ 2004-08-03 23:07 . 2008-06-20 22:22 225920 c:\windows\system32\drivers\tcpip6.sys
+ 2004-08-03 23:14 . 2008-06-20 10:45 360320 c:\windows\system32\drivers\tcpip.sys
+ 2004-08-03 23:14 . 2008-12-11 11:57 333184 c:\windows\system32\drivers\srv.sys
+ 2001-08-23 14:00 . 2008-05-08 12:28 202752 c:\windows\system32\drivers\rmcast.sys
+ 2004-08-03 23:15 . 2008-10-24 11:10 453632 c:\windows\system32\drivers\mrxsmb.sys
+ 2009-06-30 23:43 . 2008-06-13 13:10 272128 c:\windows\system32\drivers\bthport.sys
+ 2004-08-03 23:14 . 2008-08-14 09:51 138368 c:\windows\system32\drivers\afd.sys
+ 2004-08-04 00:56 . 2008-06-21 06:11 148992 c:\windows\system32\dnsapi.dll
+ 2009-06-28 00:42 . 2008-04-21 10:02 215552 c:\windows\system32\dllcache\wordpad.exe
+ 2009-06-28 00:42 . 2009-02-06 16:39 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2009-06-28 00:42 . 2009-02-09 10:20 453120 c:\windows\system32\dllcache\wmiprvsd.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 132096 c:\windows\system32\dllcache\wkssvc.dll
+ 2004-08-04 00:56 . 2009-06-10 06:32 132096 c:\windows\system32\dllcache\wkssvc.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2004-08-04 00:56 . 2008-12-16 12:47 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2009-06-28 00:44 . 2009-06-21 22:04 153088 c:\windows\system32\dllcache\triedit.dll
- 2009-06-28 00:44 . 2004-08-04 00:56 153088 c:\windows\system32\dllcache\triedit.dll
+ 2004-08-03 23:07 . 2008-06-20 22:22 225920 c:\windows\system32\dllcache\tcpip6.sys
+ 2004-08-03 23:14 . 2008-06-20 10:45 360320 c:\windows\system32\dllcache\tcpip.sys
+ 2004-08-04 00:56 . 2009-07-29 04:53 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2004-08-04 00:56 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2004-08-03 23:14 . 2008-12-11 11:57 333184 c:\windows\system32\dllcache\srv.sys
+ 2004-08-04 00:56 . 2009-02-06 17:14 110592 c:\windows\system32\dllcache\services.exe
- 2004-08-04 00:56 . 2004-08-04 00:56 144896 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-04 00:56 . 2008-12-05 07:12 144896 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 399360 c:\windows\system32\dllcache\rpcss.dll
+ 2004-08-04 00:56 . 2009-04-15 15:11 584192 c:\windows\system32\dllcache\rpcrt4.dll
+ 2001-08-23 14:00 . 2008-05-08 12:28 202752 c:\windows\system32\dllcache\rmcast.sys
- 2004-08-04 00:56 . 2004-08-04 00:56 283648 c:\windows\system32\dllcache\pdh.dll
+ 2004-08-04 00:56 . 2009-03-06 14:44 283648 c:\windows\system32\dllcache\pdh.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 714752 c:\windows\system32\dllcache\ntdll.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2004-08-04 00:56 . 2008-06-20 17:41 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2004-08-04 00:56 . 2009-08-05 09:11 204800 c:\windows\system32\dllcache\mswebdvd.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2009-06-28 00:42 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
- 2009-06-28 00:44 . 2004-08-04 00:56 331776 c:\windows\system32\dllcache\msadce.dll
+ 2009-06-28 00:44 . 2008-05-01 14:30 331776 c:\windows\system32\dllcache\msadce.dll
+ 2009-08-23 18:25 . 2008-10-24 11:10 453632 c:\windows\system32\dllcache\mrxsmb.sys
+ 2004-08-04 00:56 . 2009-02-09 10:20 723456 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-04 00:56 . 2009-05-07 15:44 344064 c:\windows\system32\dllcache\localspl.dll
+ 2004-08-04 00:56 . 2009-08-21 09:46 450560 c:\windows\system32\dllcache\jscript.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 450560 c:\windows\system32\dllcache\jscript.dll
+ 2009-06-28 00:44 . 2008-04-11 18:50 683520 c:\windows\system32\dllcache\inetcomm.dll
+ 2009-06-28 00:42 . 2009-02-09 10:20 473088 c:\windows\system32\dllcache\fastprox.dll
+ 2004-08-04 00:56 . 2008-07-07 20:32 253952 c:\windows\system32\dllcache\es.dll
+ 2004-08-04 00:56 . 2008-06-21 06:11 148992 c:\windows\system32\dllcache\dnsapi.dll
+ 2009-06-30 23:43 . 2008-06-13 13:10 272128 c:\windows\system32\dllcache\bthport.sys
+ 2004-08-03 23:14 . 2008-08-14 09:51 138368 c:\windows\system32\dllcache\afd.sys
- 2004-08-04 00:56 . 2004-08-04 00:56 616960 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 616960 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-04 00:56 . 2006-08-16 11:58 100352 c:\windows\system32\dllcache\6to4svc.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 100352 c:\windows\system32\dllcache\6to4svc.dll
+ 2004-08-04 00:56 . 2009-02-09 10:20 616960 c:\windows\system32\advapi32.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 616960 c:\windows\system32\advapi32.dll
- 2004-08-04 00:56 . 2004-08-04 00:56 100352 c:\windows\system32\6to4svc.dll
+ 2004-08-04 00:56 . 2006-08-16 11:58 100352 c:\windows\system32\6to4svc.dll
+ 2009-06-27 15:50 . 2009-09-20 11:44 409600 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 409600 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 286720 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 286720 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 249856 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 249856 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 794624 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 794624 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 135168 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 135168 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-06-27 15:50 . 2009-06-27 15:50 593920 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-06-27 15:50 . 2009-09-20 11:44 593920 c:\windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2002-10-07 16:51 . 2002-10-07 16:51 221252 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWSTRUCT.DLL
+ 2002-10-07 16:50 . 2002-10-07 16:50 118847 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWRECE.DLL
+ 2002-10-07 16:51 . 2002-10-07 16:51 102467 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWORIENT.DLL
+ 2002-10-07 16:51 . 2002-10-07 16:51 147520 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWLAY32.DLL
+ 2002-10-07 16:51 . 2002-10-07 16:51 180289 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWCUTLIN.DLL
+ 2002-10-07 16:50 . 2002-10-07 16:50 241729 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\TWCUTCHR.DLL
+ 2002-10-07 16:53 . 2002-10-07 16:53 106561 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\THOCRAPI.DLL
+ 2003-08-06 20:26 . 2003-08-06 20:26 445488 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SOA.DLL
+ 2003-08-06 20:31 . 2003-08-06 20:31 362552 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SETLANG.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 349248 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\SELFCERT.EXE
+ 2003-07-21 18:46 . 2003-07-21 18:46 390712 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
+ 2003-07-15 05:50 . 2003-07-15 05:50 551480 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PUBCONV.DLL
+ 2003-07-15 05:51 . 2003-07-15 05:51 604728 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PTXT9.DLL
+ 2002-10-07 17:11 . 2002-10-07 17:11 167997 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PSOM.DLL
+ 2003-07-15 05:40 . 2003-07-15 05:40 130104 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PRTF9.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 430136 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 139320 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 196152 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
+ 2003-07-08 18:48 . 2003-07-08 18:48 115288 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 102968 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 242240 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 828472 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 283696 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OIS.EXE
+ 2003-07-15 06:00 . 2003-07-15 06:00 145984 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-24 05:40 . 2003-07-24 05:40 482872 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 124984 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
+ 2003-07-15 06:02 . 2003-07-15 06:02 627256 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
+ 2003-07-15 06:02 . 2003-07-15 06:02 637496 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSQRY32.EXE
+ 2003-06-19 23:05 . 2003-06-19 23:05 364648 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-06-19 23:05 . 2003-06-19 23:05 128104 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPSCAN.EXE
+ 2003-06-19 00:31 . 2003-06-19 00:31 788480 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPFILT.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 376888 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
+ 2003-07-24 05:35 . 2003-07-24 05:35 127032 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 106552 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 120888 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2002-04-10 03:14 . 2002-04-10 03:14 187560 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 139328 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSJSPP40.DLL
+ 2002-12-18 02:08 . 2002-12-18 02:08 359600 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
+ 2003-07-15 05:51 . 2003-07-15 05:51 116288 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSCONV97.DLL
+ 2003-07-15 05:58 . 2003-07-15 05:58 230968 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 124480 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSB1CORE.DLL
+ 2003-07-15 10:13 . 2003-07-15 10:13 130112 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSAEXP30.DLL
+ 2003-07-15 06:01 . 2003-07-15 06:01 445496 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MODHELP.DLL
+ 2003-07-15 05:46 . 2003-07-15 05:46 176696 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
+ 2003-05-28 22:42 . 2003-05-28 22:42 342616 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\METCONV.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 443904 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 252928 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 758784 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
+ 2003-05-28 22:42 . 2003-05-28 22:42 514680 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\INTLNAME.DLL
+ 2003-07-24 05:32 . 2003-07-24 05:32 121400 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 161336 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
+ 2003-07-26 02:14 . 2003-07-26 02:14 799288 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
+ 2003-07-15 05:40 . 2003-07-15 05:40 179768 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
+ 2003-07-15 06:36 . 2003-07-15 06:36 186424 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
+ 2002-10-07 16:49 . 2002-10-07 16:49 192573 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FORM.DLL
+ 2003-07-31 22:19 . 2003-07-31 22:19 131648 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 350264 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
+ 2003-07-15 10:13 . 2003-07-15 10:13 166456 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\ACCWIZ.DLL
+ 2009-08-23 18:25 . 2008-10-24 11:10 453632 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-08-23 18:18 . 2008-06-13 13:10 272128 c:\windows\Driver Cache\i386\bthport.sys
+ 2009-09-18 11:37 . 2008-04-15 17:54 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
+ 2004-08-04 00:56 . 2009-06-03 19:27 1290752 c:\windows\system32\quartz.dll
+ 2004-08-03 23:18 . 2009-02-06 17:22 2136064 c:\windows\system32\ntoskrnl.exe
+ 2004-08-03 22:59 . 2009-02-06 16:49 2015744 c:\windows\system32\ntkrnlpa.exe
+ 2007-06-06 17:53 . 2007-06-06 17:53 1195888 c:\windows\system32\FM20.DLL
+ 2004-08-04 00:56 . 2009-06-03 19:27 1290752 c:\windows\system32\dllcache\quartz.dll
+ 2005-10-26 21:59 . 2005-10-26 21:59 2883072 c:\windows\Installer\1847c1.msp
+ 2009-08-25 21:57 . 2009-08-25 21:57 5518336 c:\windows\Installer\1847ab.msp
+ 2003-04-30 18:52 . 2003-04-30 18:52 1581120 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\XPAGE3C.DLL
+ 2002-10-07 17:03 . 2002-10-07 17:03 1794113 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\XIMAGE3B.DLL
+ 2003-07-03 22:19 . 2003-07-03 22:19 2502656 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\VBE6.DLL
+ 2003-08-03 17:52 . 2003-08-03 17:52 2808376 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
+ 2003-07-31 22:21 . 2003-07-31 22:21 1782840 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
+ 2003-07-30 19:40 . 2003-07-30 19:40 6133312 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
+ 2003-08-01 22:09 . 2003-08-01 22:09 8086072 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
+ 2003-08-04 20:19 . 2003-08-04 20:19 7330360 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OWC10.DLL
+ 2003-08-10 06:06 . 2003-08-10 06:06 7522360 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLLIB.DLL
+ 2003-07-07 20:36 . 2003-07-07 20:36 2058343 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-15 06:05 . 2003-07-15 06:05 1054264 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-07-28 19:24 . 2003-07-28 19:24 5677112 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPUB.EXE
+ 2003-06-19 00:31 . 2003-06-19 00:31 1033216 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
+ 2003-07-11 09:15 . 2003-07-11 09:15 1292872 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
+ 2002-12-18 02:09 . 2002-12-18 02:09 2071752 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSOLAP80.DLL
+ 2002-12-18 02:08 . 2002-12-18 02:08 1383592 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSDMINE.DLL
+ 2003-08-15 07:54 . 2003-08-15 07:54 6627392 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSACCESS.EXE
+ 2003-08-01 22:07 . 2003-08-01 22:07 4815424 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\INFOPATH.EXE
+ 2003-07-15 06:11 . 2003-07-15 06:11 2139192 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
+ 2003-07-26 02:00 . 2003-07-26 02:00 1157696 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
+ 2003-07-24 06:01 . 2003-07-24 06:01 1949240 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FPCUTL.DLL
+ 2003-08-03 17:56 . 2003-08-03 17:56 1146184 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\FM20.DLL
+ 2009-09-18 11:42 . 2009-02-06 17:24 2180480 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-09-18 11:42 . 2009-02-06 16:49 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-09-18 11:42 . 2009-02-06 16:49 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-09-18 11:42 . 2009-02-06 17:22 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2003-08-06 20:24 . 2003-08-06 20:24 12037688 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
+ 2003-08-08 07:23 . 2003-08-08 07:23 12172336 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\MSO.DLL
+ 2003-08-13 09:34 . 2003-08-13 09:34 10073144 c:\windows\Installer\$PatchCache$\Managed\1040110900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
+ 2007-07-27 15:10 . 2007-07-27 15:10 108331008 c:\windows\Installer\184794.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-27 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-27 185896]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-05-31 303104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Internet Connection Wizard Setup Tool"="c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-09 149280]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-08-03 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2006-07-11 176128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\user\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [27/06/2009 05:56 م 13696]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06 م 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [14/08/2006 10:51 ص 654848]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = https=a:3
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-09-28 01:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
.
Completion time: 2009-09-28 1:55
ComboFix-quarantined-files.txt 2009-09-28 08:55
Pre-Run: 32,191,836,160 bytes free
Post-Run: 32,244,264,960 bytes free
462 --- E O F --- 2009-09-20 11:46