I recently discovered a heuristic (sp?) infection with SuperAntiSpyware. The Microsoft Security Essentials antivirus program was unable to update with latest definitions, (I believe I may have inadvertantly downloaded an unsigned file purporting to be ATI in my attempt to update my drivers). I uninstalled then reinstalled MSSE however every attempt to update the definitions has failed for over a week. I discovered that all windows updates have failed for some time. I discovered Microsoft Security Client which I never authorized on system, and have been unble to determine if it is the same as Microsoft Security Essentials. It appears that they are both antivirus programs offered by MS, but I do not know the difference or where the Security Client came from.
My installer was damaged and every attempt to repair/replace was unsuccessful until a day ago. Gateway timeout warnings, damaged registry and/or .dll files interrupting messages from remote computer (MSSE), application hangs, unable to access network locations, faulty applications such as M.O.M. and Presentation Font Cache (never was aware of Presentation Font app. before) and windows files i.e., appmgmt disappearing; and new and strange files popping up here and there. I try to physically peruse portions of my Windows files/system hoping to familiarize myself of the contents. And of course, the SLOW was worse than experienced ever, but not all the time.
I have had virus/malware previously but believed it had been rid. I know that the previous infection was in my system volume information used by System Restore. Whatever may be infecting my system now appears more aggressive.
You guys are so much appreciated. I have been beating my head against the wall trying to resolve one problem at a time however they started coming at me faster than I could open IE. I am hopeful that the logs will answer most of any questions you may have. I will supply as much more detailed information and may be needed.
DDS (Ver_10-12-12.02) - NTFSx86
Run by bouncier at 1:51:57.42 on Wed 03/02/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3455.2807 [GMT -7:00]
AV: Microsoft Security Essentials *Enabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Benubird PDF\BenubirdAssistant.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Juno\exec.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpeedingUpMyPC\SPMTray.exe
C:\Program Files\Juno\exec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Juno\qsacc\x1exec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\rpcrt432.exe
C:\WINDOWS\system32\mmdrv32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\mf3216wow.exe
C:\Program Files\Cobian Backup 10\Cobian.exe
C:\Program Files\Cobian Backup 10\cbInterface.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\bouncier\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://my.juno.com/s/search?r=minisearch
uSearch Bar = hxxp://my.juno.com/s/search?r=minisearch
mDefault_Search_URL = hxxp://my.juno.com/s/search?r=minisearch
mSearch Page = hxxp://my.juno.com/s/search?r=minisearch
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:7900
uInternet Settings,ProxyOverride = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;cf.netzero.net;qs.netzero.net;*.quicken.com;feed.untd.com;*.pogo.com;<local>
uSearchURL,(Default) = hxxp://my.juno.com/s/search?r=minisearch
mSearchAssistant = hxxp://my.juno.com/s/search?r=minisearch
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\juno\SearchEnh1.dll
BHO: AutorunsDisabled - No File
BHO: {04aa65f9-bdae-40c2-9e24-68de55ad57ba} - c:\windows\system32\atiok3x232.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\juno\qsacc\X1IEBHO.dll
BHO: Juno Toolbar Helper: {fe3098b1-04a3-41fd-8ca9-bea39cb14c87} - c:\program files\juno\ucreg.dll
TB: JunoBar: {5854fac4-5bf0-47dd-b5a9-a5ea8cff3cf4} - c:\program files\juno\Toolbar.dll
uRun: [Juno_uoltray] c:\program files\juno\exec.exe regrun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SPMTray] c:\program files\speedingupmypc\SPMTray.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Benubird PDF] c:\program files\benubird pdf\BenubirdAssistant.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [LiveMonitor] c:\program files\msi\live update 3\LMonitor.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [mf3216wow.exe] c:\windows\mf3216wow.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
mExplorerRun: [RTHDBPL] c:\documents and settings\bouncier\application data\syswin\lsass.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\corelr~1.lnk - c:\program files\corel\wordperfect office 2000\register\Remind32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\corelc~2.lnk - c:\program files\corel\wordperfect office 2000\programs\ccwin9.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\corelc~1.lnk - c:\program files\corel\wordperfect office 2000\programs\alarm.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\deskto~1.lnk - c:\program files\corel\wordperfect office 2000\programs\dad9.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\launch~1.lnk - c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_294823.exe
IE: Display All Images with Full Quality - c:\program files\juno\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\program files\juno\qsacc\appres.dll/227
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/Dcode/ActiveX/MSDcode.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
TCP: {56A69CA0-9C72-4A08-98A9-3AF99BFE3953} = 64.136.52.73 64.136.44.73
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\mimefilt32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 Schedule32;Task Scheduler ;c:\windows\system32\rpcrt432.exe [2011-3-1 1327616]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\cobian backup 10\cbVSCService.exe [2011-3-2 67584]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-2-19 1684736]
S4 MpKsl8a8ff3c9;MpKsl8a8ff3c9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{24e4c23c-c5f7-4703-9c7e-e99a678ae6af}\mpksl8a8ff3c9.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{24e4c23c-c5f7-4703-9c7e-e99a678ae6af}\MpKsl8a8ff3c9.sys [?]
=============== Created Last 30 ================
2011-03-02 07:47:03 -------- d-----w- c:\docume~1\bouncier\locals~1\applic~1\Safe mirror
2011-03-02 07:46:13 -------- d-----w- c:\program files\Cobian Backup 10
2011-03-02 07:33:51 -------- d-----w- c:\program files\Cobian Backup 8
2011-03-02 06:40:30 519168 --sh--w- c:\windows\mf3216wow.exe
2011-03-02 06:40:30 -------- d-sh--w- c:\windows\system32\BA057A8FC4612FEB0D8141401B9E4E3F
2011-03-02 06:36:47 -------- d-----w- c:\windows\system32\1601329496
2011-03-02 06:36:41 -------- d-sh--w- c:\windows\system32\SysWoW32
2011-03-02 06:36:14 203776 --sh--w- c:\windows\system32\unrar.exe
2011-03-02 06:36:14 -------- d-----w- c:\windows\system32\1927785376
2011-03-02 06:29:28 1076224 --sha-w- c:\windows\system32\FE.tmp
2011-03-02 06:24:51 -------- d-----w- c:\windows\system32\NtmsData
2011-03-02 06:24:49 0 --sha-w- c:\windows\system32\FB.tmp
2011-03-02 06:24:40 1327616 ----a-w- c:\windows\system32\rpcrt432.exe
2011-03-01 23:27:41 -------- d-----w- c:\docume~1\bouncier\applic~1\SpeedingUpMyPC
2011-03-01 23:27:41 -------- d-----w- c:\docume~1\bouncier\applic~1\RegistryKeys
2011-03-01 23:27:38 -------- d-----w- c:\program files\SpeedingUpMyPC
2011-03-01 07:52:24 -------- d-----w- c:\program files\Manhattan Slots
2011-02-28 16:55:58 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-28 06:52:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2011-02-28 06:52:09 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2011-02-28 06:52:08 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2011-02-28 06:52:05 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2011-02-28 06:52:02 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2011-02-28 06:50:58 19016 -c--a-w- c:\windows\system32\dllcache\w926nd.sys
2011-02-28 06:49:57 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll
2011-02-28 06:48:59 42496 -c--a-w- c:\windows\system32\dllcache\tp4res.dll
2011-02-28 06:47:59 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys
2011-02-28 06:46:58 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll
2011-02-28 06:46:55 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys
2011-02-28 06:46:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys
2011-02-28 06:46:52 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys
2011-02-28 06:46:48 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys
2011-02-28 06:43:58 101760 -c--a-w- c:\windows\system32\dllcache\sis300ip.sys
2011-02-28 06:42:58 77824 -c--a-w- c:\windows\system32\dllcache\s3sav4m.sys
2011-02-28 06:41:58 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2011-02-28 06:40:58 19840 -c--a-w- c:\windows\system32\dllcache\philtune.sys
2011-02-28 06:39:58 351616 -c--a-w- c:\windows\system32\dllcache\ovcodek2.sys
2011-02-28 06:39:56 116736 -c--a-w- c:\windows\system32\dllcache\ovcodec2.dll
2011-02-28 06:39:53 31872 -c--a-w- c:\windows\system32\dllcache\ovce.sys
2011-02-28 06:39:50 28032 -c--a-w- c:\windows\system32\dllcache\ovcd.sys
2011-02-28 06:39:48 48000 -c--a-w- c:\windows\system32\dllcache\ovcam2.sys
2011-02-28 06:39:45 25088 -c--a-w- c:\windows\system32\dllcache\ovca.sys
2011-02-28 06:39:43 54186 -c--a-w- c:\windows\system32\dllcache\otcsercb.sys
2011-02-28 06:39:40 43689 -c--a-w- c:\windows\system32\dllcache\otceth5.sys
2011-02-28 06:39:38 27209 -c--a-w- c:\windows\system32\dllcache\otc06x5.sys
2011-02-28 06:39:35 54528 -c--a-w- c:\windows\system32\dllcache\opl3sax.sys
2011-02-28 06:39:31 198144 -c--a-w- c:\windows\system32\dllcache\nv3.sys
2011-02-28 06:39:29 123776 -c--a-w- c:\windows\system32\dllcache\nv3.dll
2011-02-28 06:39:25 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2011-02-28 06:12:23 9344 -c--a-w- c:\windows\system32\dllcache\ntapm.sys
2011-02-28 06:12:20 7552 -c--a-w- c:\windows\system32\dllcache\nsmmc.sys
2011-02-28 06:12:20 28672 -c--a-w- c:\windows\system32\dllcache\nscirda.sys
2011-02-28 06:12:17 87040 -c--a-w- c:\windows\system32\dllcache\nm6wdm.sys
2011-02-28 06:12:15 126080 -c--a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
2011-02-28 06:12:11 32840 -c--a-w- c:\windows\system32\dllcache\ngrpci.sys
2011-02-28 06:12:11 132695 -c--a-w- c:\windows\system32\dllcache\netwlan5.sys
2011-02-28 06:12:07 65278 -c--a-w- c:\windows\system32\dllcache\netflx3.sys
2011-02-28 06:12:04 39264 -c--a-w- c:\windows\system32\dllcache\neo20xx.sys
2011-02-28 06:12:02 60480 -c--a-w- c:\windows\system32\dllcache\neo20xx.dll
2011-02-28 06:10:58 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys
2011-02-28 06:09:58 26442 -c--a-w- c:\windows\system32\dllcache\lanepic5.sys
2011-02-28 06:08:56 372824 -c--a-w- c:\windows\system32\dllcache\iconf32.dll
2011-02-28 06:07:59 391199 -c--a-w- c:\windows\system32\dllcache\hsf_k56k.sys
2011-02-28 06:06:59 1733120 -c--a-w- c:\windows\system32\dllcache\g400d.dll
2011-02-27 21:15:23 -------- d-----w- c:\docume~1\bouncier\applic~1\SUPERAntiSpyware.com
2011-02-27 21:15:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-26 22:00:26 756776 ----a-w- c:\program files\OneCareCleanup.exe
2011-02-25 19:06:55 885024 ----a-w- c:\program files\JavaSetup6u24.exe
2011-02-23 22:25:39 6912 ------w- c:\windows\system32\drivers\FlashSys.sys
2011-02-23 22:25:39 18359 ------w- c:\windows\system32\Ntaccess.sys
2011-02-23 22:25:39 13368 ------w- c:\windows\system32\FlashVxd.vxd
2011-02-23 22:25:39 -------- d-----w- c:\program files\MSI
2011-02-21 01:13:39 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-02-21 01:13:39 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-20 18:49:59 69194 -c--a-w- c:\windows\system32\dllcache\el656cd5.sys
2011-02-20 18:48:59 7424 -c--a-w- c:\windows\system32\dllcache\ddsmc.sys
2011-02-20 18:47:59 39680 -c--a-w- c:\windows\system32\dllcache\cb325.sys
2011-02-20 18:46:59 104832 -c--a-w- c:\windows\system32\dllcache\atiraged.dll
2011-02-20 18:31:36 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys
2011-02-20 17:41:04 -------- d-----w- c:\windows\pss
2011-02-20 09:42:52 0 --sha-w- c:\windows\system32\124.tmp
2011-02-20 09:29:20 0 ---ha-w- c:\documents and settings\bouncier\lmogjqbdfo.tmp
2011-02-20 09:27:09 176640 ----a-w- c:\windows\system32\miglibnt32.exe
2011-02-20 09:26:47 0 --sha-w- c:\windows\system32\11B.tmp
2011-02-20 09:26:45 244224 ----a-w- c:\windows\system32\mimefilt32.dll
2011-02-20 09:26:45 1327616 ----a-w- c:\windows\system32\mmdrv32.exe
2011-02-20 09:26:45 -------- d-sh--w- c:\docume~1\bouncier\applic~1\SysWin
2011-02-20 09:26:44 1327616 ----a-w- c:\windows\system32\ntlsapi32.exe
2011-02-20 09:26:43 402944 ----a-w- c:\windows\system32\atiok3x232.dll
2011-02-20 09:26:43 176640 ----a-w- c:\windows\system32\mimefilt32.exe
2011-02-20 07:24:58 -------- d-----w- c:\documents and settings\bouncier\Shared
2011-02-20 07:24:47 -------- d-----w- c:\documents and settings\bouncier\Incomplete
2011-02-20 07:24:37 -------- d-----w- c:\docume~1\bouncier\applic~1\FrostWire
2011-02-20 01:48:06 0 ----a-w- c:\windows\ativpsrm.bin
2011-02-20 01:13:23 593920 ------w- c:\windows\system32\ati2sgag.exe
2011-02-20 01:04:49 45056 ----a-w- c:\windows\system32\aticalrt.dll
2011-02-20 01:04:49 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2011-02-20 01:04:48 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2011-02-20 01:04:48 45056 ----a-w- c:\windows\system32\aticalcl.dll
2011-02-20 01:04:48 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2011-02-20 01:04:48 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2011-02-20 01:04:48 118784 ----a-w- c:\windows\system32\atibrtmon.exe
2011-02-19 19:50:40 -------- d-----w- c:\docume~1\bouncier\applic~1\Configuration
2011-02-19 19:43:03 -------- d-----w- c:\program files\DriverGuide Toolkit
2011-02-19 13:46:34 405504 ----a-w- c:\windows\vncutil.exe
2011-02-19 13:46:33 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2011-02-19 13:46:33 122880 ----a-w- c:\windows\RtkAudioService.exe
2011-02-19 13:46:31 1684736 ----a-w- c:\windows\system32\drivers\Ambfilt.sys
2011-02-19 13:46:31 1389056 ----a-w- c:\windows\system32\drivers\Monfilt.sys
2011-02-19 04:53:34 39936 ----a-w- c:\windows\system32\RHCoInstXP.dll
2011-02-19 04:53:34 3733760 ----a-w- c:\windows\system32\drivers\RtKHDMI.sys
2011-02-19 03:21:42 -------- d-----w- c:\docume~1\alluse~1\applic~1\UAB
2011-02-19 03:21:41 -------- d-----w- c:\docume~1\bouncier\locals~1\applic~1\PC_Drivers_Headquarters
2011-02-19 03:04:30 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2011-02-18 23:55:22 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers Headquarters
2011-02-16 06:31:05 -------- d-----w- c:\docume~1\bouncier\applic~1\RadarSync
==================== Find3M ====================
2011-02-25 05:06:00 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-19 08:41:34 1200128 ----a-w- c:\windows\RtkUpd.exe
2011-02-19 06:57:51 880640 ----a-w- c:\windows\system32\RTSndMgr.CPL
2011-02-19 06:57:51 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2011-02-19 06:57:51 1826816 ----a-w- c:\windows\SkyTel.exe
2011-02-19 06:57:51 1482752 ----a-w- c:\windows\RtlUpd.exe
2011-02-19 06:57:50 9715200 ----a-w- c:\windows\RTLCPL.EXE
2011-02-19 06:57:50 18702336 ----a-w- c:\windows\RTHDCPL.EXE
2011-02-19 06:57:48 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2011-02-19 06:57:48 278528 ----a-w- c:\windows\system32\ALSNDMGR.CPL
2011-02-19 06:57:48 2170880 ----a-w- c:\windows\MicCal.exe
2011-02-19 06:57:47 831488 ----a-w- c:\windows\RtlExUpd.dll
2011-02-19 06:57:47 57344 ----a-w- c:\windows\ALCMTR.EXE
2011-02-03 00:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec
2010-12-09 15:15:09 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30:22 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42:26 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07:07 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
============= FINISH: 1:52:10.75 ===============
Attached File(s)
-
Attach.txt (159.67K)
Number of downloads: 0 -
ark.txt (16.16K)
Number of downloads: 1
This post has been edited by Budapest: 02 March 2011 - 09:07 PM

Help
This topic is locked


Back to top










