I was getting several popups claiming to be virus scanners. Panda ActiveScan indicated several active instances of W32/Koobface.FL.worm. I tried MS Malicious Software Removal Tool. It would consistently encounter an error and attempt to close, requiring me to kill it in Task Manager. Running it in Safe Mode did partially work; it found and removed two instances.
However, Panda still says I have one active W32/Koobface.FL.worm. I am still getting one particular popup, though it's always a 404. MS Malicious Software Removal Tool finds nothing. Spybot S&D also finds nothing.
DDS log is below.
DDS (Ver_09-10-26.01) - NTFSx86
Run by Vicki Moeckly at 9:47:24.51 on Sun 11/08/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.546 [GMT -6:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\pp12.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Vicki Moeckly\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://desmoines.mediacomtoday.com/community/index.php
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: {61bacec0-3751-4595-af65-2e03746fd627} - c:\windows\system32\pmkjh.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SoftSoldier] c:\program files\softsoldier software\softsoldier\SoftSoldier.exe -min
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Toshiba Hotkey Utility] "c:\program files\toshiba\windows utilities\Hotkey.exe" /lang en
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [CFSServ.exe] CFSServ.exe -NoClient
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [pp] c:\windows\pp12.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
mExplorerRun: [win1AB.tmp.exe] c:\windows\temp\win1AB.tmp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: oprah.com\www2
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {3FC4CAA7-71B5-44FC-A516-61D2AC9EF30D} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\vickim~1\applic~1\mozilla\firefox\profiles\9xjhl0i2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-10-21 28552]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
=============== Created Last 30 ================
2009-12-26 22:31:57 16529 ----a-w- c:\windows\35baaddwarz9240.ocx
2009-12-25 14:55:49 8132 ----a-w- c:\windows\3222thzea5293339.cpl
2009-12-25 11:47:53 11799 ----a-w- c:\windows\5db0vir999z.ocx
2009-12-25 04:38:10 5799 ----a-w- c:\windows\z30569orm754.dll
2009-12-23 14:31:53 16309 ----a-w- c:\windows\system32\z5006troj497.dll
2009-12-23 14:16:48 8792 ----a-w- c:\windows\6739sp5mbot2z9.cpl
2009-12-21 17:48:19 16841 ----a-w- c:\windows\49b9vir569z.dll
2009-12-21 03:34:51 2701 ----a-w- c:\windows\7bb3szy9are23555.bin
2009-12-20 11:13:49 17397 ----a-w- c:\windows\system32\29cb9hrz5t1497.ocx
2009-12-19 16:04:49 2942 ----a-w- c:\windows\1619threz520159.exe
2009-12-19 12:47:20 11517 ----a-w- c:\windows\2z9asparse975.bin
2009-12-19 10:37:57 12128 ----a-w- c:\windows\system32\6905zirusc9.bin
2009-12-13 23:33:56 3358 ----a-w- c:\windows\63f19hreat31562z.cpl
2009-12-13 13:58:38 4225 ----a-w- c:\windows\system32\2494zwo9m185.ocx
2009-12-11 09:25:43 2875 ----a-w- c:\windows\526threaz149545.exe
2009-12-04 03:08:42 10003 ----a-w- c:\windows\system32\13164zroj3e59.ocx
2009-12-03 11:46:29 16991 ----a-w- c:\windows\28590hackt95z786.bin
2009-12-03 02:11:53 3972 ----a-w- c:\windows\20z69vi5us509.bin
2009-12-02 10:28:11 14769 ----a-w- c:\windows\31301troz5099.dll
2009-12-01 20:07:08 9423 ----a-w- c:\windows\system32\1dz8spywa5e27159.exe
2009-11-25 19:29:37 3231 ----a-w- c:\windows\system32\6aabdowzload952576.bin
2009-11-25 14:06:56 3540 ----a-w- c:\windows\4993stealz5915.dll
2009-11-23 22:44:21 16688 ----a-w- c:\windows\system32\5z34downlo9der5463.cpl
2009-11-20 08:28:27 3262 ----a-w- c:\windows\14z519pye0.bin
2009-11-19 06:38:37 11706 ----a-w- c:\windows\system32\44645hzef3909.bin
2009-11-18 20:46:35 11899 ----a-w- c:\windows\1z996troj557.cpl
2009-11-12 21:23:36 6648 ----a-w- c:\windows\system32\655ethze9t16555.dll
2009-11-12 06:22:14 3051 ----a-w- c:\windows\system32\28z59pyware2370.bin
2009-11-10 23:35:40 12387 ----a-w- c:\windows\system32\5914tr5z6b5.cpl
2009-11-10 12:36:55 5635 ----a-w- c:\windows\system32\144zt9rea525322.exe
2009-11-09 08:00:50 14028 ----a-w- c:\windows\18323tzo56249.exe
2009-11-08 04:19:50 0 d-----w- C:\b7de13d1310c3b8a276bd01e1e6be6b6
2009-11-07 18:39:47 0 d-----w- C:\7ce7a3eca54f62f94704b69629
2009-11-07 01:05:48 9328 ----a-w- c:\windows\system32\59d6sparsez757.cpl
2009-11-06 22:28:49 16759 ----a-w- c:\windows\system32\12359spam5otz90.cpl
2009-11-06 22:17:21 6235 ----a-w- c:\windows\system32\745own9oazer3164.cpl
2009-11-05 15:20:07 15807 ----a-w- c:\windows\system32\1457sparze9566.cpl
2009-11-02 14:34:00 10204 ----a-w- c:\windows\system32\39653sz5507.bin
2009-11-01 01:28:34 18196 ----a-w- c:\windows\7d995ir1z19.ocx
2009-10-25 00:36:55 17054 ----a-w- c:\windows\system32\102z4not-a-vir9s51f.ocx
2009-10-22 04:47:52 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-22 01:27:52 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-21 16:00:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-10-21 16:00:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-10-21 08:24:34 13815 ----a-w- c:\windows\system32\1621down9oa5ez1569.exe
2009-10-21 00:40:17 4065 ----a-w- c:\windows\system32\129z5sp97df5.ocx
2009-10-20 05:32:10 10923 ----a-w- c:\windows\system32\69zdspyware59.bin
2009-10-17 23:03:11 7392 ----a-w- c:\windows\53c9v9rz8585.bin
2009-10-17 00:47:24 13888 ----a-w- c:\windows\44f5s5arse1389z.bin
2009-10-16 01:11:56 12956 ----a-w- c:\windows\6283tzr5at29901.dll
2009-10-15 19:43:52 115712 ----a-w- c:\windows\rdr_1255635830.exe
2009-10-15 19:15:03 115712 ----a-w- c:\windows\rdr_1255634101.exe
2009-10-15 19:08:00 13507 ----a-w- c:\windows\15540vi9us5za.cpl
2009-10-15 14:02:17 115712 ----a-w- c:\windows\rdr_1255615334.exe
2009-10-15 13:49:51 64512 ---h--w- c:\windows\pp12.exe
2009-10-15 13:49:51 1 ----a-w- c:\windows\fdgg34353edfgdfdf
2009-10-15 13:49:26 2 ----a-w- c:\windows\0101120101464855.xxe
2009-10-15 13:49:26 1 ---h--w- c:\windows\bk23567.dat
2009-10-15 13:49:24 2 ----a-w- c:\windows\010112010146116101.xxe
2009-10-15 13:48:21 2 ----a-w- c:\windows\010112010146101105.rx
2009-10-15 06:10:34 7993 ----a-w- c:\windows\d9z5ir538.cpl
2009-10-14 12:12:50 4683 ----a-w- c:\windows\z469parse13635.ocx
2009-10-13 18:57:00 13565 ----a-w- c:\windows\system32\691zba5kdoor809.exe
2009-10-12 14:17:21 11842 ----a-w- c:\windows\95495zoj993.dll
2009-10-12 05:14:04 16811 ----a-w- c:\windows\system32\1667ztro95c9.bin
2009-10-12 00:13:11 9563 ----a-w- c:\windows\system32\91395troj1z5.dll
2009-10-11 00:51:56 3333 ----a-w- c:\windows\4558bzckdoor9197.exe
2009-10-10 10:44:02 17460 ----a-w- c:\windows\c9bv5z3193.ocx
==================== Find3M ====================
2009-10-07 20:45:59 4017 ----a-w- c:\windows\5583zownl9ader2557.dll
2009-10-07 11:02:53 4209 ----a-w- c:\windows\system32\65fcz9ief2442.exe
2009-10-06 02:49:02 8405 ----a-w- c:\windows\system32\50c9zhrea55614.bin
2009-10-05 03:33:14 5023 ----a-w- c:\windows\19324n5t-a-vizus1c6.exe
2009-10-04 18:37:44 7655 ----a-w- c:\windows\system32\31695not-a-5irus7ze.dll
2009-10-04 16:19:33 14140 ----a-w- c:\windows\system32\z555wor956b.bin
2009-10-04 02:15:08 5360 ----a-w- c:\windows\system32\13z12t9oj7af5.dll
2009-09-28 22:27:46 29696 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-27 23:43:27 11727 ----a-w- c:\windows\f56z9ief141.dll
2009-09-26 19:22:45 17668 ----a-w- c:\windows\system32\555cbazk9oor1686.dll
2009-09-24 19:25:39 16270 ----a-w- c:\windows\system32\6cf1s5z9se365.dll
2009-09-23 06:44:24 4158 ----a-w- c:\windows\system32\2348addwa9e241z5.exe
2009-09-19 07:57:05 7044 ----a-w- c:\windows\system32\15195spamz9t7c1.bin
2009-09-19 00:04:17 18263 ----a-w- c:\windows\z6a35ddware3209.dll
2009-09-16 10:01:05 3022 ----a-w- c:\windows\720bzownlo5d9r1921.exe
2009-09-15 00:31:47 15222 ----a-w- c:\windows\1905znot-a-vi5us669.exe
2009-09-13 12:14:57 17583 ----a-w- c:\windows\59czsparse917.dll
2009-09-12 23:29:31 2930 ----a-w- c:\windows\2559spyzare181.bin
2009-09-12 20:02:00 16440 ----a-w- c:\windows\50d6downzoa5er1975.bin
2009-09-12 15:27:55 5517 ----a-w- c:\windows\93353spz57b.exe
2009-09-11 17:14:39 8827 ----a-w- c:\windows\system32\3c319teal514z.bin
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 00:19:51 4576 ----a-w- c:\windows\system32\13805virus9zc5.dll
2009-09-06 22:22:35 9221 ----a-w- c:\windows\system32\307t5reatz2579.bin
2009-09-06 05:35:31 6608 ----a-w- c:\windows\system32\12b8stza920245.exe
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-03 08:40:40 4756 ----a-w- c:\windows\system32\7eacb5ckdo9r2z89.bin
2009-09-03 06:26:25 15923 ----a-w- c:\windows\90z3worm695.exe
2009-09-03 01:53:44 6668 ----a-w- c:\windows\6b45st9al20z1.exe
2009-09-02 22:34:17 5246 ----a-w- c:\windows\system32\2e6fdownzoad9r950.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 00:42:52 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 09:15:54 5699 ----a-w- c:\windows\3521zspy89.dll
2009-08-26 14:07:03 3377 ----a-w- c:\windows\system32\7f98vir94z5.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-26 07:49:31 11103 ----a-w- c:\windows\system32\5585sp9ware3098z.dll
2009-08-24 16:08:52 12851 ----a-w- c:\windows\5772st9al1z54.dll
2009-08-21 00:53:10 12113 ----a-w- c:\windows\4490threaz153295.exe
2009-08-20 15:59:54 12901 ----a-w- c:\windows\110bdo9nzoader2125.dll
2009-08-19 17:48:58 6697 ----a-w- c:\windows\system32\7ad9th5zf179.dll
2009-08-15 13:11:41 4189 ----a-w- c:\windows\14997wo5z240.bin
2009-08-12 22:43:46 17672 ----a-w- c:\windows\system32\6959threzt4605.bin
2009-08-10 19:54:08 17835 ----a-w- c:\windows\18935szy19a5.exe
2007-01-07 07:01:23 847040 --sh--w- c:\windows\system32\knnmp.bak1
2007-01-07 10:02:05 847180 --sh--w- c:\windows\system32\knnmp.bak2
2009-01-16 14:34:08 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011620090117\index.dat
============= FINISH: 9:48:02.09 ===============
Attached File(s)
-
ark.txt (2.47K)
Number of downloads: 2 -
Attach.txt (14.07K)
Number of downloads: 4

Help

Back to top










