Malware Doc?

View previous topic View next topic Go down

Malware Doc?

Post by brainrepaircenter on 18th July 2009, 3:44 pm

Hi
Sorry if this is already discussed to death but I think I have Malware doctor infection. I can't install Norton and their tech support want to charge an additional $100 to deal with it. I just spent $100 on Norton 360 so I'm pissed. I looked at other posts on Malware Doc but I haven't done anything yet. BTW I tried to download the latest Microsoft service pack and after following dialogue boxes it gave me a service denied message. I assume thats part of the malware. It acts like the other posts described. Can't install antivirus software, can't access google or any anitvirus sites, can't access taskmgr or open registry. Here's the log file. THX
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:18 PM, on 18/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxdjcoms.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Desktop\winlogon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {71BD4E4D-240D-44BB-95C8-85475B2DEEFD} - c:\windows\system32\ukqdqil.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [CPM2b2541e2] Rundll32.exe "c:\windows\system32\vumeburi.dll",a
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\User\LOCALS~1\Temp\360784770.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
O4 - Startup: ChkDisk.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - [You must be registered and logged in to see this link.]
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\hisekeke.dll c:\windows\system32\vumeburi.dll,
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O20 - Winlogon Notify: hbzhkpdn - C:\WINDOWS\SYSTEM32\ukqdqil.dll
O20 - Winlogon Notify: __c006bdc1 - C:\WINDOWS\system32\__c006BDC1.dat (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vumeburi.dll (file missing)
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vumeburi.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AshEvtSvc - Unknown owner - C:\WINDOWS\System32\AshEvtSvc.exe (file missing)
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdj_device - - C:\WINDOWS\system32\lxdjcoms.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 8348 bytes
Let me think

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by Origin on 18th July 2009, 8:58 pm

Hello brainrepaircenter,

Welcome to Geek Police, my name is Origin and I will be helping you today. Please keep the following in mind:

  • If you do not get a reply from me or another helper within 2 days, please reply to your topic with the phrase BUMP
  • If you have any cracked/pirated software in your computer delete them or we will not help you.
  • Only follow advise from Geek Police Staff and not a regular member.
  • Do NOT run any tool without Geek Police supervision as it could hinder your system useless.


  • Open HijackThis.
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {71BD4E4D-240D-44BB-95C8-85475B2DEEFD} - c:\windows\system32\ukqdqil.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [CPM2b2541e2] Rundll32.exe "c:\windows\system32\vumeburi.dll",a
    O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
    O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\User\LOCALS~1\Temp\360784770.exe
    O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
    O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
    O4 - Startup: ChkDisk.lnk = ?
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: C:\WINDOWS\system32\hisekeke.dll c:\windows\system32\vumeburi.dll,
    O20 - Winlogon Notify: crypt - crypts.dll (file missing)
    O20 - Winlogon Notify: __c006bdc1 - C:\WINDOWS\system32\__c006BDC1.dat (file missing)
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vumeburi.dll (file missing)



  • Press "Fix Checked"
  • Close Hijack This.

1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.


Last edited by Origin on 20th July 2009, 4:01 pm; edited 1 time in total


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31493
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 20th July 2009, 2:16 am

Thanks Here is the Combofix file.

ComboFix 09-07-19.04 - User 19/07/2009 23:01.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.714 [GMT -3:00]
Running from: c:\documents and settings\User\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\User\Local Settings\Temporary Internet Files\fbk.sts
c:\recycler\S-1-5-21-4597782882-0958235421-979859742-1900
c:\windows\kb913800.exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\axhoshcg.dll
c:\windows\system32\bwfkigr.dll
c:\windows\system32\drivers\dyykwpil.sys
c:\windows\system32\drivers\ovfsthsqreaxfpoqmnceexcdtfuwmxbdietjqw.sys
c:\windows\system32\drivers\tweqadqc.sys
c:\windows\system32\onowurul.ini
c:\windows\system32\ovfsthawxxfritsytsipolywarasselcttyxur.dll
c:\windows\system32\ovfsthbabdrdktpgnbbrxnmwpnlxcpvpeornlp.dll
c:\windows\system32\ovfsthdeqtganquqxvnylqpuhbdvwhybcnvfen.dat
c:\windows\system32\ovfsthdmesuscnpfpxvqkgbqhxnehtfgdaaoxk.dll
c:\windows\system32\ovfsthdoabynyblhqoilygswopvxehnafitnda.dll
c:\windows\system32\ovfsthepqljfbmycrqpioypwvjjtrbfkrwcthw.dat
c:\windows\system32\ovfsthiqwbrpyxnsdjolgekxymxbqdjmkgufpp.dat
c:\windows\system32\ovfsthlcjeocpxegriivyfwywtxbvrlyuipvye.dll
c:\windows\system32\ovfsthmqtnvneuobwgkurvbvtuenwbjlluaqmq.dll
c:\windows\system32\ovfsthnnjtxcldriotfpmtvaousspfvdicnqwb.dat
c:\windows\system32\ovfsthpqjkrabwsartcuptdtvivlsogdudnxne.dll
c:\windows\system32\ovfsthqjgedtspqtfmkfqskuaipmpdrfsaikbf.dll
c:\windows\system32\ovfsthrjqvcxtpuyfqqhxbdmetokoixgibitnt.dll
c:\windows\system32\ovfsthsticxvptavmbwuxtnyqwtnlnkbcyigdv.dll
c:\windows\system32\ovfsthurwbpfwkfcqoufaxwtfdfnmtgknuxmrb.dat
c:\windows\system32\ovfsthuxnkijwipylpcycrnbwxvwyhetwxccmj.dll
c:\windows\system32\ovfsthvomptxopgqgulkumqarxfawsymsbaubc.dat
c:\windows\system32\ovfsthwlxssjucjwmymvniootfllbmapxcwevj.dll
c:\windows\system32\ovfsthwosvrcjismcecciwulbyxmxgextitqfv.dll
c:\windows\system32\ovfsthxtfdivcvmbadsthodrbqowoqripjqvnm.dll
c:\windows\system32\ovfsthxuetpjlncvqpovbejlvbbwdictowfhww.dat
c:\windows\system32\ovfsthydehqpvmtvhhclckxpsvksbiggxwomej.dll
c:\windows\system32\ozuwalif.ini
c:\windows\system32\ukqdqil.dll
c:\windows\system32\uniq.tll
c:\windows\system32\uruzegid.ini
c:\windows\Tasks\At1.job
c:\windows\Temp\1169377288.exe
c:\windows\Temp\2160525552.exe
c:\windows\Temp\3871666524.exe
C:\xcrashdump.dat

Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - The cat ate it Smile
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthuwptbijixtheviymsbcoxfvripdjtkos
-------\Legacy_ASHEVTSVC
-------\Legacy_DYYKWPIL
-------\Legacy_wbsvnjkl
-------\Service_dyykwpil
-------\Service_wbsvnjkl


((((((((((((((((((((((((( Files Created from 2009-06-20 to 2009-07-20 )))))))))))))))))))))))))))))))
.

2009-07-19 19:17 . 2009-07-19 19:17 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\yotnurjo
2009-07-19 19:17 . 2009-07-19 19:17 -------- d-----w- c:\documents and settings\NetworkService\Application Data\yotnurjo
2009-07-18 19:02 . 2009-07-18 19:02 46640 ----a-w- c:\windows\system32\msln.exe
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2009-07-18 18:16 . 2009-07-13 16:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 18:16 . 2009-07-13 16:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-18 18:07 . 2009-07-18 18:07 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\yotnurjo
2009-07-18 18:07 . 2009-07-18 18:07 -------- d-----w- c:\documents and settings\User\Application Data\yotnurjo
2009-07-18 15:27 . 2009-07-18 15:27 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-18 15:26 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\[You must be registered and logged in to see this link.]
2009-07-18 15:26 . 2009-07-18 15:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-18 15:26 . 2009-07-18 15:26 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-07-18 15:25 . 2009-07-18 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-18 15:25 . 2009-07-18 18:56 -------- d-----w- c:\program files\NOS
2009-07-18 15:17 . 2009-07-18 15:17 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 15:17 . 2009-07-18 15:17 -------- d-----w- c:\program files\Java
2009-07-16 06:02 . 2009-07-16 06:02 77594624 --sha-w- C:\NRTPage.sys
2009-07-16 00:24 . 2009-07-18 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-07-16 00:22 . 2009-07-18 19:18 -------- d-----w- c:\program files\NortonInstaller
2009-07-16 00:22 . 2009-07-18 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-07-15 18:01 . 2009-07-15 18:01 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\yotnurjo
2009-07-05 15:28 . 2006-10-26 22:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-07-05 15:27 . 2009-07-05 15:27 -------- d-----w- c:\program files\Microsoft Works
2009-07-05 15:26 . 2009-07-05 15:26 -------- d-----w- c:\program files\Microsoft.NET
2009-07-05 15:23 . 2009-07-05 15:23 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-05 15:22 . 2009-07-05 15:26 -------- d-----w- c:\windows\SHELLNEW
2009-07-05 15:22 . 2009-07-05 15:22 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Microsoft Help
2009-07-05 15:22 . 2009-07-05 15:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-05 15:21 . 2009-07-05 15:21 -------- d--h--r- C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-20 02:01 . 2006-02-28 12:00 182656 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-07-18 19:14 . 2009-05-27 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-18 19:01 . 2009-05-27 00:16 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 00:38 . 2009-02-23 20:59 69232 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 00:20 . 2009-02-20 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-19 01:49 . 2009-06-19 14:53 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-11 18:28 . 2009-06-11 18:28 826344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-11 18:28 . 2009-06-19 01:49 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-11 18:28 . 2009-06-19 01:49 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-11 18:28 . 2009-06-19 01:49 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-11 18:28 . 2009-06-11 18:28 1452312 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-08 20:27 . 2009-06-06 18:58 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-06-06 18:59 . 2009-06-06 18:59 -------- d-----w- c:\documents and settings\User\Application Data\Sierra
2009-06-06 18:51 . 2009-06-06 18:51 -------- d-----w- c:\program files\Sierra
2009-06-06 18:51 . 2009-02-20 18:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-27 12:52 . 2009-05-27 10:37 12912 ----a-w- c:\windows\system32\ser.exe
2009-05-27 00:53 . 2009-06-11 18:28 487704 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-05-27 00:49 . 2009-05-27 00:49 -------- d-----w- c:\documents and settings\User\Application Data\AVG8
2009-05-08 18:11 . 2009-05-07 19:47 0 ----a-w- c:\windows\system32\drivers\307e2377.sys
2009-05-07 19:46 . 2009-05-07 19:46 119296 ----a-w- c:\documents and settings\User\Application Data\servicehost.dll
2009-05-07 19:46 . 2009-05-07 19:46 119296 ----a-w- c:\documents and settings\User\Application Data\servicehost.dll
2009-04-21 15:59 . 2009-04-21 15:59 265448 ----a-w- c:\documents and settings\All Users\SPL3.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-18 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-01-24 2289664]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\lxdjcoms.exe"=
"c:\\Program Files\\Lexmark 1400 Series\\lxdjamon.exe"=
"c:\\Program Files\\Lexmark 1400 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\lxdjcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjjswx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjpswx.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjtime.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58157:TCP"= 58157:TCP:Pando Media Booster
"58157:UDP"= 58157:UDP:Pando Media Booster

S1 307e2377;307e2377;c:\windows\system32\drivers\307e2377.sys [07/05/2009 4:47 PM 0]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - DYYKWPIL
*Deregistered* - dyykwpil

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-07-19 23:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1136)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxdjcoms.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-07-20 23:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-20 02:13

Pre-Run: 63,426,772,992 bytes free
Post-Run: 63,755,350,016 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

226 --- E O F --- 2009-04-15 02:44

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by Origin on 20th July 2009, 4:07 pm

Now open a new notepad file.
Input this into the notepad file:

Folder::
c:\documents and settings\NetworkService\Local Settings\Application Data\yotnurjo
c:\documents and settings\NetworkService\Application Data\yotnurjo
c:\documents and settings\User\Local Settings\Application Data\yotnurjo
c:\documents and settings\User\Application Data\yotnurjo
c:\windows\system32\config\systemprofile\Application Data\yotnurjo

File::
c:\documents and settings\All Users\SPL3.tmp

Registry::
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"=-
"NoActiveDesktopChanges"=-


Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31493
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 22nd July 2009, 3:35 am

Origin

The log file is too large to post. Do I break it up into parts or is ther a particular section you want to see?

Andrew

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by Origin on 23rd July 2009, 7:17 pm

Yes please break it up.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31493
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:31 am

OK. Part 1

omboFix 09-07-21.02 - User 22/07/2009 0:04.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.649 [GMT -3:00]
Running from: c:\documents and settings\User\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\documents and settings\All Users\SPL3.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\SPL3.tmp
c:\documents and settings\NetworkService\Application Data\yotnurjo
c:\documents and settings\NetworkService\Application Data\yotnurjo\profiles.ini
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\cert8.db
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\compatibility.ini
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\compreg.dat
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\cookies.sqlite
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\formhistory.sqlite
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\key3.db
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\localstore.rdf
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\permissions.sqlite
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\places.sqlite-journal
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\places.sqlite
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\pluginreg.dat
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\prefs.js
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\secmod.db
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\webappsstore.sqlite
c:\documents and settings\NetworkService\Application Data\yotnurjo\Profiles\fjenvcfc.default\xpti.dat
c:\documents and settings\NetworkService\Local Settings\Application Data\yotnurjo
c:\documents and settings\NetworkService\Local Settings\Application Data\yotnurjo\Profiles\fjenvcfc.default\urlclassifier3.sqlite
c:\documents and settings\NetworkService\Local Settings\Application Data\yotnurjo\Profiles\fjenvcfc.default\XPC.mfl
c:\documents and settings\User\Application Data\yotnurjo
c:\documents and settings\User\Application Data\yotnurjo\profiles.ini
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\cert8.db
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\compatibility.ini
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\compreg.dat
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\cookies.sqlite
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\formhistory.sqlite
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\key3.db
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\localstore.rdf
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\permissions.sqlite
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\places.sqlite-journal
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\places.sqlite
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\pluginreg.dat
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\prefs.js
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\secmod.db
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\webappsstore.sqlite
c:\documents and settings\User\Application Data\yotnurjo\Profiles\370018jh.default\xpti.dat
c:\documents and settings\User\Local Settings\Application Data\yotnurjo
c:\documents and settings\User\Local Settings\Application Data\yotnurjo\Profiles\370018jh.default\urlclassifier3.sqlite
c:\documents and settings\User\Local Settings\Application Data\yotnurjo\Profiles\370018jh.default\XPC.mfl
c:\windows\system32\config\systemprofile\Application Data\yotnurjo
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\profiles.ini
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\cert8.db
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\compatibility.ini
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\compreg.dat
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\cookies.sqlite
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\formhistory.sqlite
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\key3.db
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\localstore.rdf
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\permissions.sqlite
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\places.sqlite-journal
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\places.sqlite
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\pluginreg.dat
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\prefs.js
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\secmod.db
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\webappsstore.sqlite
c:\windows\system32\config\systemprofile\Application Data\yotnurjo\Profiles\djzqjq40.default\xpti.dat

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:31 am

Part 2

.
((((((((((((((((((((((((( Files Created from 2009-06-22 to 2009-07-22 )))))))))))))))))))))))))))))))
.

2009-07-22 02:34 . 2009-07-22 02:34 -------- d-----w- C:\Westwood
2009-07-21 20:20 . 2009-07-20 02:57 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\EECTRL.SYS
2009-07-21 20:20 . 2009-07-20 02:57 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\ERASER.SYS
2009-07-21 20:20 . 2009-07-20 02:57 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\NAVENG32.DLL
2009-07-21 20:20 . 2009-07-20 02:57 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\NAVEX32A.DLL
2009-07-21 20:20 . 2009-07-20 02:56 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\ECMSVR32.DLL
2009-07-21 20:20 . 2009-07-20 02:56 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\CCERASER.DLL
2009-07-21 20:20 . 2009-07-19 08:00 87888 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\NAVENG.SYS
2009-07-21 20:20 . 2009-07-19 08:00 875728 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090721.006\NAVEX15.SYS
2009-07-21 01:20 . 2009-07-21 01:20 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Temp
2009-07-20 03:20 . 2009-07-20 03:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-20 03:07 . 2009-07-20 03:07 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-20 03:06 . 2009-07-20 03:14 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Google
2009-07-20 03:06 . 2009-07-20 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-20 03:06 . 2009-07-20 03:08 -------- d-----w- c:\program files\Google
2009-07-20 03:02 . 2009-07-20 03:02 -------- d-sh--w- c:\documents and settings\User\PrivacIE
2009-07-20 02:59 . 2009-07-11 19:34 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSXpx86.sys
2009-07-20 02:59 . 2009-07-11 19:34 293424 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSvix86.sys
2009-07-20 02:59 . 2009-07-11 19:34 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\Scxpx86.dll
2009-07-20 02:59 . 2009-07-11 19:34 451960 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSxpx86.dll
2009-07-20 02:59 . 2009-07-11 19:34 397360 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSviA64.sys
2009-07-20 02:57 . 2009-07-20 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-07-20 02:57 . 2009-07-20 02:57 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Downloaded Installations
2009-07-20 02:57 . 2009-07-20 02:57 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-07-20 02:57 . 2009-07-20 02:57 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-07-20 02:57 . 2009-07-20 02:57 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-07-20 02:57 . 2009-07-20 02:57 -------- d-----w- c:\program files\Symantec
2009-07-20 02:57 . 2009-07-20 02:57 1290592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-07-20 02:57 . 2009-07-20 02:57 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-07-20 02:56 . 2009-07-20 02:56 796016 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-07-20 02:56 . 2009-07-20 02:56 -------- d-----w- c:\windows\system32\drivers\N360
2009-07-20 02:56 . 2009-07-20 02:56 -------- d-----w- c:\program files\Norton 360
2009-07-20 02:56 . 2009-07-20 02:56 -------- d-----w- c:\program files\Windows Sidebar
2009-07-20 02:54 . 2009-07-20 02:54 -------- d-sh--w- c:\documents and settings\User\IETldCache
2009-07-20 02:49 . 2008-04-13 23:11 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2009-07-20 02:41 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-20 02:41 . 2009-07-20 02:41 -------- d-----w- c:\windows\ie8updates
2009-07-20 02:41 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-20 02:41 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-20 02:39 . 2009-07-20 02:41 -------- dc-h--w- c:\windows\ie8
2009-07-20 02:27 . 2009-07-20 02:27 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-07-20 02:16 . 2009-05-07 15:32 345600 -c----w- c:\windows\system32\dllcache\localspl.dll
2009-07-20 02:16 . 2009-04-15 14:51 585216 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2009-07-20 02:16 . 2009-04-29 04:55 78336 -c----w- c:\windows\system32\dllcache\ieencode.dll
2009-07-20 02:16 . 2009-04-29 04:55 78336 ------w- c:\windows\system32\ieencode.dll
2009-07-20 02:15 . 2009-06-16 14:36 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2009-07-20 02:15 . 2009-06-16 14:36 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2009-07-18 19:02 . 2009-07-18 19:02 46640 ----a-w- c:\windows\system32\msln.exe
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2009-07-18 18:16 . 2009-07-13 16:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-18 18:16 . 2009-07-18 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 18:16 . 2009-07-13 16:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-18 15:27 . 2009-07-18 15:27 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-18 15:26 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\[You must be registered and logged in to see this link.]
2009-07-18 15:26 . 2009-07-18 15:26 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-18 15:26 . 2009-07-18 15:26 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-07-18 15:25 . 2009-07-18 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-18 15:25 . 2009-07-18 18:56 -------- d-----w- c:\program files\NOS
2009-07-18 15:17 . 2009-07-18 15:17 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 15:17 . 2009-07-18 15:17 -------- d-----w- c:\program files\Java
2009-07-16 06:02 . 2009-07-16 06:02 77594624 --sha-w- C:\NRTPage.sys
2009-07-16 00:24 . 2009-07-20 02:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-07-16 00:22 . 2009-07-20 02:55 -------- d-----w- c:\program files\NortonInstaller
2009-07-16 00:22 . 2009-07-18 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-07-11 19:34 . 2009-07-11 19:34 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34 293424 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 451960 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 397360 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-07-05 15:28 . 2008-11-10 14:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2009-07-05 15:27 . 2009-07-20 02:45 -------- d-----w- c:\program files\Microsoft Works
2009-07-05 15:26 . 2009-07-05 15:26 -------- d-----w- c:\program files\Microsoft.NET
2009-07-05 15:23 . 2009-07-05 15:23 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-05 15:22 . 2009-07-05 15:26 -------- d-----w- c:\windows\SHELLNEW
2009-07-05 15:22 . 2009-07-05 15:22 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Microsoft Help
2009-07-05 15:22 . 2009-07-20 21:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-05 15:21 . 2009-07-05 15:21 -------- d--h--r- C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-22 02:29 . 2009-02-20 20:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-20 15:37 . 2009-05-27 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-20 03:37 . 2009-05-27 00:16 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-20 02:57 . 2009-07-20 02:57 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-20 02:57 . 2009-07-20 02:57 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-07-20 02:50 . 2009-07-20 02:50 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-20 02:50 . 2009-07-20 02:50 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-20 02:01 . 2006-02-28 12:00 182656 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-07-16 00:38 . 2009-02-23 20:59 69232 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 00:20 . 2009-02-20 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-19 01:49 . 2009-06-19 14:53 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-16 14:36 . 2006-11-14 19:20 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-11-14 19:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-11 18:28 . 2009-06-11 18:28 826344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-11 18:28 . 2009-06-19 01:49 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-11 18:28 . 2009-06-19 01:49 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-11 18:28 . 2009-06-19 01:49 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-11 18:28 . 2009-06-11 18:28 1452312 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-08 20:27 . 2009-06-06 18:58 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-06-06 18:59 . 2009-06-06 18:59 -------- d-----w- c:\documents and settings\User\Application Data\Sierra
2009-06-06 18:51 . 2009-06-06 18:51 -------- d-----w- c:\program files\Sierra
2009-06-06 18:51 . 2009-02-20 18:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-03 19:09 . 2006-11-14 19:20 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-27 00:53 . 2009-06-11 18:28 487704 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-05-27 00:49 . 2009-05-27 00:49 -------- d-----w- c:\documents and settings\User\Application Data\AVG8
2009-05-13 05:15 . 2006-11-14 19:21 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 04:14 . 2009-05-09 04:14 1418120 ----a-w- c:\windows\system32\wdfcoinstaller01005.dll
2009-05-09 04:14 . 2009-05-09 04:14 14736 ----a-w- c:\windows\system32\drivers\nuidfltr.sys
2009-05-08 18:11 . 2009-05-07 19:47 0 ----a-w- c:\windows\system32\drivers\307e2377.sys
2009-05-07 19:46 . 2009-05-07 19:46 119296 ----a-w- c:\documents and settings\User\Application Data\servicehost.dll
2009-05-07 19:46 . 2009-05-07 19:46 119296 ----a-w- c:\documents and settings\User\Application Data\servicehost.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
.

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:33 am

part 3

((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 02:31 . 2009-07-22 02:31 16384 c:\windows\Temp\Perflib_Perfdata_360.dat
+ 2009-07-22 02:29 . 2009-07-22 02:29 16384 c:\windows\Temp\Perflib_Perfdata_1d8.dat
+ 2009-02-20 19:39 . 2009-01-07 21:21 26144 c:\windows\system32\spupdsvc.exe
+ 2009-07-05 15:28 . 2008-11-10 14:41 67472 c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2009-07-05 15:28 . 2008-11-10 14:41 67472 c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2009-02-20 19:40 . 2009-01-07 21:20 16928 c:\windows\system32\spmsg.dll
+ 2009-07-20 02:49 . 2008-04-13 23:11 21504 c:\windows\system32\ReinstallBackups\0015\DriverFiles\i386\hidserv.dll
+ 2006-11-14 19:20 . 2009-03-08 07:31 46592 c:\windows\system32\pngfilt.dll
- 2006-02-28 12:00 . 2009-07-20 02:05 72108 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2009-07-22 02:34 72108 c:\windows\system32\perfc009.dat
- 2006-06-29 12:05 . 2006-06-29 12:05 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 12:05 . 2009-01-07 21:20 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 21:59 . 2009-01-07 21:20 24576 c:\windows\system32\nlsdl.dll
- 2006-06-28 21:59 . 2006-06-28 21:59 24576 c:\windows\system32\nlsdl.dll
- 2006-02-28 12:00 . 2007-08-13 22:01 48128 c:\windows\system32\mshtmler.dll
+ 2006-02-28 12:00 . 2009-03-08 07:31 48128 c:\windows\system32\mshtmler.dll
+ 2006-11-14 19:19 . 2009-03-08 07:31 66560 c:\windows\system32\mshtmled.dll
- 2006-02-28 12:00 . 2007-08-13 22:32 45568 c:\windows\system32\mshta.exe
+ 2006-02-28 12:00 . 2009-03-08 07:31 45568 c:\windows\system32\mshta.exe
+ 2007-08-13 22:36 . 2009-03-08 07:31 13312 c:\windows\system32\msfeedssync.exe
+ 2007-08-13 22:54 . 2009-03-08 07:31 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 43008 c:\windows\system32\licmgr10.dll
+ 2006-11-14 19:18 . 2009-04-30 21:22 25600 c:\windows\system32\jsproxy.dll
+ 2006-11-14 19:18 . 2009-03-08 07:32 94720 c:\windows\system32\inseng.dll
+ 2006-02-28 12:00 . 2009-03-08 07:31 34816 c:\windows\system32\imgutil.dll
+ 2007-08-13 22:39 . 2009-03-08 07:32 36864 c:\windows\system32\ieudinit.exe
+ 2006-02-28 12:00 . 2009-03-08 07:32 71680 c:\windows\system32\iesetup.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 55808 c:\windows\system32\iernonce.dll
+ 2006-06-29 12:05 . 2009-01-07 21:20 26112 c:\windows\system32\idndl.dll
- 2006-06-29 12:05 . 2006-06-29 12:05 26112 c:\windows\system32\idndl.dll
+ 2007-08-13 22:36 . 2009-03-08 07:31 59904 c:\windows\system32\icardie.dll
+ 2009-07-20 02:57 . 2009-01-15 15:19 23848 c:\windows\system32\DRVSTORE\GEARAspiWD_4F4AA3475F1B13A1E8212B6D40B351211BC358CE\x86\GEARAspiWDM.sys
+ 2006-11-02 10:22 . 2006-11-02 10:22 32224 c:\windows\system32\drivers\wdfldr.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 39984 c:\windows\system32\drivers\N360\0300000.086\symndisv.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 37296 c:\windows\system32\drivers\N360\0300000.086\symndis.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 34736 c:\windows\system32\drivers\N360\0300000.086\symids.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 89776 c:\windows\system32\drivers\N360\0300000.086\symfw.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 43696 c:\windows\system32\drivers\N360\0300000.086\srtspx.sys
+ 2009-04-13 15:29 . 2009-01-15 15:19 23848 c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2006-11-14 19:20 . 2009-03-08 07:31 46592 c:\windows\system32\dllcache\pngfilt.dll
- 2006-02-28 12:00 . 2007-08-13 22:01 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2006-02-28 12:00 . 2009-03-08 07:31 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2006-11-14 19:19 . 2009-03-08 07:31 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2006-02-28 12:00 . 2007-08-13 22:32 45568 c:\windows\system32\dllcache\mshta.exe
+ 2006-02-28 12:00 . 2009-03-08 07:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2009-02-20 20:08 . 2009-03-08 07:31 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 43008 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-11-14 19:18 . 2009-04-30 21:22 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-11-14 19:18 . 2009-03-08 07:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2006-02-28 12:00 . 2009-03-08 07:31 34816 c:\windows\system32\dllcache\imgutil.dll
- 2009-02-20 20:08 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2009-02-20 20:08 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2006-02-28 12:00 . 2009-03-08 07:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 20:08 . 2009-03-08 07:31 59904 c:\windows\system32\dllcache\icardie.dll
+ 2009-02-20 17:42 . 2009-03-08 07:24 68608 c:\windows\system32\dllcache\hmmapi.dll
+ 2009-03-08 07:33 . 2009-03-08 07:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2006-02-28 12:00 . 2009-03-08 07:33 18944 c:\windows\system32\corpol.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 72704 c:\windows\system32\admparse.dll
+ 2009-07-20 03:15 . 2009-07-20 03:15 22528 c:\windows\Installer\676b7.msi
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2009-07-20 03:07 . 2009-07-20 03:07 25214 c:\windows\Installer\{CC016F21-3970-11DE-B878-005056806466}\ARPPRODUCTICON.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-04-02 17:23 . 2009-04-02 17:23 10104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\XLCALL32.DLL
+ 2009-04-03 21:01 . 2009-04-03 21:01 71504 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\XL12CNVP.DLL
+ 2009-04-03 20:57 . 2009-04-03 20:57 21320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WRD12EXE.EXE
+ 2006-07-24 13:50 . 2006-07-24 13:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\VBAME.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 54088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\SCANOST.EXE
+ 2009-03-04 20:24 . 2009-03-04 20:24 75608 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\RM.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 38240 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\RECALL.DLL
+ 2009-01-07 00:31 . 2009-01-07 00:31 48512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PUBTRAP.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 52072 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLVBA.DLL
+ 2008-11-25 01:32 . 2008-11-25 01:32 46928 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLRPC.DLL
+ 2006-07-24 13:50 . 2006-07-24 13:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSADDNDR.DLL
+ 2008-10-31 00:24 . 2008-10-31 00:24 21368 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MLSHEXT.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 34192 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\DUMPSTER.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 87392 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\DLGSETP.DLL
+ 2006-10-27 00:17 . 2006-10-27 00:17 11072 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 72472 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XL12CNVP.DLL
+ 2006-10-27 18:11 . 2006-10-27 18:11 21264 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2009-07-05 15:27 . 2009-07-05 15:27 12096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPOL.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 12080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBIDEPOL.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 64288 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBIDEPIA.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 76624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 19784 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 51008 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 27456 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 58168 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL
+ 2006-10-26 17:05 . 2006-10-26 17:05 86840 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 29976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:34 am

part 4

+ 2006-10-26 22:59 . 2006-10-26 22:59 15672 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SMARTTAGINSTALL.EXE
+ 2006-10-26 22:49 . 2006-10-26 22:49 34104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETLANG.EXE
+ 2006-10-26 23:55 . 2006-10-26 23:55 55056 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCANOST.EXE
+ 2006-10-26 23:55 . 2006-10-26 23:55 76576 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\RM.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 19784 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 40424 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFIEBAR.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 38168 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 39208 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\RECALL.DLL
+ 2006-10-26 23:09 . 2006-10-26 23:09 48448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PUBTRAP.DLL
+ 2006-10-26 17:05 . 2006-10-26 17:05 77144 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL
+ 2009-07-05 15:27 . 2009-07-05 15:27 12112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPOL.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 53048 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLVBA.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 46864 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
+ 2006-10-26 22:59 . 2006-10-26 22:59 46936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUPPS.DLL
+ 2006-10-26 22:59 . 2006-10-26 22:59 18760 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OPHPROXY.DLL
+ 2006-10-26 23:24 . 2006-10-26 23:24 72504 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONFILTER.DLL
+ 2006-10-26 23:24 . 2006-10-26 23:24 98632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTEM.EXE
+ 2006-10-26 22:59 . 2006-10-26 22:59 16728 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMUOPTINPS.DLL
+ 2006-10-26 23:00 . 2006-10-26 23:00 23392 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISCTRL.DLL
+ 2006-10-27 18:11 . 2006-10-27 18:11 54680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFRHD.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 11544 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFICEPL.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 65824 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 12104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTAGPOL.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 20280 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTAGPIA.DLL
+ 2006-10-26 22:59 . 2006-10-26 22:59 43832 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSH.DLL
+ 2006-10-27 18:26 . 2006-10-27 18:26 35152 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOSTYLE.DLL
+ 2006-10-26 22:56 . 2006-10-26 22:56 67408 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSONPUI.DLL
+ 2006-10-26 22:56 . 2006-10-26 22:56 32592 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSONPMON.DLL
+ 2006-10-26 22:52 . 2006-10-26 22:52 66368 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOMSE.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 67896 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOHTMED.EXE
+ 2006-10-27 18:01 . 2006-10-27 18:01 76088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOHEV.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 26936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL
+ 2006-10-26 22:48 . 2006-10-26 22:48 14664 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL
+ 2006-10-26 22:59 . 2006-10-26 22:59 19768 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSMH.DLL
+ 2006-10-26 22:52 . 2006-10-26 22:52 48424 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSE7.EXE
+ 2006-10-27 00:18 . 2006-10-27 00:18 66880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 21312 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MLSHEXT.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 89400 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\METCONV.DLL
+ 2006-10-27 00:41 . 2006-10-27 00:41 66368 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INLAUNCH.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 35112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMMODE.DLL
+ 2006-10-27 03:47 . 2006-10-27 03:47 16688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTDURLLAUNCHER.EXE
+ 2006-10-27 03:47 . 2006-10-27 03:47 22808 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVENEW.DLL
+ 2006-10-27 03:47 . 2006-10-27 03:47 31016 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMONITOR.EXE
+ 2006-10-27 03:47 . 2006-10-27 03:47 33568 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECLEAN.EXE
+ 2006-10-27 18:37 . 2006-10-27 18:37 34088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUTOPROXY.DLL
+ 2006-10-27 03:47 . 2006-10-27 03:47 65824 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDITSERVICE.EXE
+ 2009-07-05 15:26 . 2009-07-05 15:26 12096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPHPOL.DLL
+ 2006-10-26 17:04 . 2006-10-26 17:04 75576 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 12096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCELPOL.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 35160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DUMPSTER.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 87344 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DLGSETP.DLL
+ 2006-10-27 00:30 . 2006-10-27 00:30 65312 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\COLLIMP.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 53576 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\AUTHZAX.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 56120 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 47976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL
+ 2006-10-27 00:18 . 2006-10-27 00:18 94016 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCOLK.DLL
+ 2009-07-20 02:41 . 2009-03-08 07:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll
+ 2009-07-20 02:41 . 2009-03-08 07:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll
+ 2009-07-20 02:40 . 2009-03-08 17:23 58464 c:\windows\ie8\spuninst\iecustom.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 44544 c:\windows\ie8\pngfilt.dll
+ 2009-07-20 02:39 . 2007-08-13 22:01 48128 c:\windows\ie8\mshtmler.dll
+ 2009-07-20 02:39 . 2007-08-13 22:32 45568 c:\windows\ie8\mshta.exe
+ 2009-07-20 02:39 . 2007-08-13 22:36 12288 c:\windows\ie8\msfeedssync.exe
+ 2009-07-20 02:39 . 2009-02-20 18:09 52224 c:\windows\ie8\msfeedsbs.dll
+ 2009-07-20 02:39 . 2007-08-13 22:44 40960 c:\windows\ie8\licmgr10.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 27648 c:\windows\ie8\jsproxy.dll
+ 2009-07-20 02:39 . 2007-08-13 22:39 92672 c:\windows\ie8\inseng.dll
+ 2009-07-20 02:39 . 2007-08-13 22:36 36352 c:\windows\ie8\imgutil.dll
+ 2009-07-20 02:39 . 2007-08-13 22:39 55296 c:\windows\ie8\iesetup.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 44544 c:\windows\ie8\iernonce.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 78336 c:\windows\ie8\ieencode.dll
+ 2009-07-20 02:39 . 2009-02-20 10:20 70656 c:\windows\ie8\ie4uinit.exe
+ 2009-07-20 02:39 . 2009-02-20 18:09 63488 c:\windows\ie8\icardie.dll
+ 2009-07-20 02:39 . 2007-08-13 22:18 60416 c:\windows\ie8\hmmapi.dll
+ 2009-07-20 02:39 . 2008-04-14 00:11 35328 c:\windows\ie8\corpol.dll
+ 2009-07-20 02:39 . 2007-08-13 22:39 71680 c:\windows\ie8\admparse.dll
+ 2009-07-20 02:42 . 2009-02-20 10:20 13824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-07-20 02:45 . 2009-07-20 02:45 10576 c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 11112 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-07-20 02:46 . 2009-07-20 02:46 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 11136 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-07-20 02:47 . 2009-07-20 02:47 11152 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-07-20 02:46 . 2009-07-20 02:46 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 19320 c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-07-20 02:41 . 2009-03-08 07:35 2048 c:\windows\ie8updates\KB971930-IE8\iecompat.dll
- 2009-02-20 20:06 . 2008-04-14 00:12 121856 c:\windows\system32\xmllite.dll
+ 2009-02-20 20:06 . 2009-01-07 21:21 121856 c:\windows\system32\xmllite.dll
+ 2007-08-13 22:45 . 2009-03-08 07:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2006-02-28 12:00 . 2009-03-08 07:34 236544 c:\windows\system32\webcheck.dll
+ 2006-11-14 19:20 . 2009-03-08 07:33 420352 c:\windows\system32\vbscript.dll
- 2006-02-28 12:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 105984 c:\windows\system32\url.dll
+ 2009-07-05 15:28 . 2008-11-10 14:41 864144 c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2009-07-05 15:28 . 2008-11-10 14:41 864144 c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-11-14 19:20 . 2009-04-15 14:51 585216 c:\windows\system32\rpcrt4.dll
+ 2006-02-28 12:00 . 2009-07-22 02:34 444358 c:\windows\system32\perfh009.dat
- 2006-02-28 12:00 . 2009-07-20 02:05 444358 c:\windows\system32\perfh009.dat
+ 2006-02-28 12:00 . 2009-03-08 07:34 109568 c:\windows\system32\occache.dll
+ 2006-11-14 19:19 . 2009-03-08 07:32 611840 c:\windows\system32\mstime.dll
+ 2006-11-14 19:19 . 2009-03-08 07:34 193536 c:\windows\system32\msrating.dll
+ 2006-02-28 12:00 . 2009-03-08 07:22 156160 c:\windows\system32\msls31.dll
- 2006-02-28 12:00 . 2007-08-13 22:54 156160 c:\windows\system32\msls31.dll
+ 2007-08-13 22:54 . 2009-03-08 07:32 594432 c:\windows\system32\msfeeds.dll
+ 2009-01-07 21:20 . 2009-01-07 21:20 265720 c:\windows\system32\msdbg2.dll
+ 2006-11-14 19:18 . 2009-03-08 07:33 726528 c:\windows\system32\jscript.dll

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:37 am

part 5

+ 2007-08-13 22:54 . 2009-03-08 07:22 164352 c:\windows\system32\ieui.dll
+ 2006-11-14 19:18 . 2009-03-08 07:31 183808 c:\windows\system32\iepeers.dll
+ 2006-02-28 12:00 . 2009-04-30 21:22 385536 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 16:27 . 2009-03-08 07:11 445952 c:\windows\system32\ieapfltr.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 163840 c:\windows\system32\ieakui.dll
+ 2006-02-28 12:00 . 2009-03-08 07:33 229376 c:\windows\system32\ieaksie.dll
+ 2006-02-28 12:00 . 2009-03-08 07:33 125952 c:\windows\system32\ieakeng.dll
+ 2006-02-28 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe
+ 2009-02-20 13:04 . 2009-07-20 02:53 267800 c:\windows\system32\FNTCACHE.DAT
- 2009-02-20 13:04 . 2009-07-12 02:53 267800 c:\windows\system32\FNTCACHE.DAT
+ 2006-11-14 19:18 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll
- 2006-11-14 19:18 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
+ 2006-11-14 19:18 . 2009-03-08 07:31 216064 c:\windows\system32\dxtrans.dll
+ 2006-11-14 19:18 . 2009-03-08 07:31 348160 c:\windows\system32\dxtmsft.dll
+ 2009-07-20 02:57 . 2008-04-17 15:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_4F4AA3475F1B13A1E8212B6D40B351211BC358CE\x86\GEARAspi.dll
+ 2006-11-02 10:22 . 2006-11-02 10:22 492000 c:\windows\system32\drivers\wdf01000.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 217392 c:\windows\system32\drivers\N360\0300000.086\symtdi.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 310320 c:\windows\system32\drivers\N360\0300000.086\SymEFA.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 307760 c:\windows\system32\drivers\N360\0300000.086\srtsp.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 482352 c:\windows\system32\drivers\N360\0300000.086\cchpx86.sys
+ 2009-07-20 02:57 . 2009-07-20 02:57 258608 c:\windows\system32\drivers\N360\0300000.086\BHDrvx86.sys
+ 2006-11-14 19:21 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\wininet.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2009-02-20 17:43 . 2009-03-08 07:33 759296 c:\windows\system32\dllcache\VGX.dll
+ 2009-02-23 19:24 . 2009-03-08 07:33 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 105984 c:\windows\system32\dllcache\url.dll
- 2006-02-28 12:00 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-07 21:20 . 2009-01-07 21:20 134144 c:\windows\system32\dllcache\sqmapi.dll
+ 2009-01-07 21:20 . 2009-01-07 21:20 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2006-02-28 12:00 . 2009-03-08 07:34 109568 c:\windows\system32\dllcache\occache.dll
+ 2006-11-14 19:19 . 2009-03-08 07:32 611840 c:\windows\system32\dllcache\mstime.dll
+ 2006-11-14 19:19 . 2009-03-08 07:34 193536 c:\windows\system32\dllcache\msrating.dll
+ 2006-02-28 12:00 . 2009-03-08 07:22 156160 c:\windows\system32\dllcache\msls31.dll
- 2006-02-28 12:00 . 2007-08-13 22:54 156160 c:\windows\system32\dllcache\msls31.dll
+ 2009-02-20 20:08 . 2009-03-08 07:32 594432 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-02-23 19:24 . 2009-03-08 07:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-02-20 17:42 . 2009-03-08 17:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2006-11-14 19:18 . 2009-03-08 07:31 183808 c:\windows\system32\dllcache\iepeers.dll
+ 2006-02-28 12:00 . 2009-04-30 21:22 385536 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-02-20 20:08 . 2009-03-08 07:11 445952 c:\windows\system32\dllcache\ieapfltr.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2006-02-28 12:00 . 2009-03-08 07:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-02-28 12:00 . 2009-03-08 07:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-02-28 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-11-14 19:18 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-11-14 19:18 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-11-14 19:18 . 2009-03-08 07:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-11-14 19:18 . 2009-03-08 07:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2006-02-28 12:00 . 2009-03-08 07:32 128512 c:\windows\system32\advpack.dll
+ 2009-05-26 21:53 . 2009-05-26 21:53 579072 c:\windows\Installer\afaf5.msp
+ 2009-07-20 02:57 . 2009-07-20 02:57 621056 c:\windows\Installer\402df.msi
+ 2009-03-20 14:48 . 2009-03-20 14:48 183808 c:\windows\Installer\1e8538.msp
+ 2009-07-20 02:27 . 2009-07-20 02:27 470528 c:\windows\Installer\118ba7.msi
- 2009-07-05 15:22 . 2009-07-05 15:22 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-07-20 02:43 . 2009-07-20 02:43 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-04-03 21:11 . 2009-04-03 21:11 408424 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WINWORD.EXE
+ 2009-03-04 20:24 . 2009-03-04 20:24 282032 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\SCNPST64.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 273320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\SCNPST32.DLL
+ 2009-03-06 05:06 . 2009-03-06 05:06 407904 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\RTFHTML.DLL
+ 2009-03-06 06:41 . 2009-03-06 06:41 589704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PUBCONV.DLL
+ 2009-01-08 13:59 . 2009-01-08 13:59 624520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PTXT9.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 420696 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PSTPRX32.DLL
+ 2008-10-25 09:21 . 2008-10-25 09:21 136072 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PRTF9.DLL
+ 2009-07-20 02:47 . 2009-07-20 02:47 350064 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PPTPIA.DLL
+ 2009-04-03 21:04 . 2009-04-03 21:04 521064 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\POWERPNT.EXE
+ 2008-11-21 03:49 . 2008-11-21 03:49 169360 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLPH.DLL
+ 2009-03-06 05:05 . 2009-03-06 05:05 593288 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLMIME.DLL
+ 2008-10-31 00:24 . 2008-10-31 00:24 137552 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLCTL.DLL
+ 2009-03-06 07:55 . 2009-03-06 07:55 194448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OMSXP32.DLL
+ 2009-03-06 07:55 . 2009-03-06 07:55 661888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OMSMAIN.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 253808 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OLKFSTUB.DLL
+ 2006-07-24 13:50 . 2006-07-24 13:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSSTDFMT.DLL
+ 2008-11-04 03:04 . 2008-11-04 03:04 498072 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MORPH9.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 340304 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MIMEDIR.DLL
+ 2009-03-04 20:24 . 2009-03-04 20:24 138072 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\IMPMAIL.DLL
+ 2008-11-21 03:48 . 2008-11-21 03:48 155016 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ENVELOPE.DLL
+ 2008-11-21 03:48 . 2008-11-21 03:48 116600 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\EMABLT32.DLL
+ 2009-03-06 05:05 . 2009-03-06 05:05 127336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\CONTAB32.DLL
+ 2006-10-26 17:05 . 2006-10-26 17:05 530760 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL
+ 2006-10-26 23:49 . 2006-10-26 23:49 509200 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WRD12CVR.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 781104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPIA.DLL
+ 2006-10-27 18:23 . 2006-10-27 18:23 347432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2006-10-26 17:05 . 2006-10-26 17:05 126784 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:38 am

part 6

+ 2006-07-28 18:21 . 2006-07-28 18:21 277320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SSGEN.DLL
+ 2006-10-27 00:18 . 2006-10-27 00:18 502608 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL
+ 2006-10-26 23:06 . 2006-10-26 23:06 439600 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE
+ 2006-10-26 23:13 . 2006-10-26 23:13 503624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE
+ 2006-10-26 23:55 . 2006-10-26 23:55 272744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST64.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 263520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SCNPST32.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 408880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\RTFHTML.DLL
+ 2006-10-27 00:42 . 2006-10-27 00:42 744808 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REGFORM.EXE
+ 2006-10-26 23:09 . 2006-10-26 23:09 590144 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 18:04 . 2006-10-27 18:04 624456 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 413472 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSTPRX32.DLL
+ 2006-10-26 23:09 . 2006-10-26 23:09 136008 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 248632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPIA.DLL
+ 2006-10-27 00:07 . 2006-10-27 00:07 368968 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPSLAX.DLL
+ 2006-10-27 18:04 . 2006-10-27 18:04 465200 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 00:30 . 2006-10-27 00:30 482088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 176976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLPH.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 594256 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLMIME.DLL
+ 2006-07-26 21:53 . 2006-07-26 21:53 459080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 138512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLCTL.DLL
+ 2006-10-26 23:23 . 2006-10-26 23:23 782720 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL
+ 2006-10-27 18:39 . 2006-10-27 18:39 687432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL
+ 2006-10-26 23:32 . 2006-10-26 23:32 604000 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL
+ 2006-10-26 23:34 . 2006-10-26 23:34 192848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSXP32.DLL
+ 2006-10-26 23:34 . 2006-10-26 23:34 660792 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSMAIN.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 254776 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLKFSTUB.DLL
+ 2006-10-26 23:00 . 2006-10-26 23:00 285008 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL
+ 2006-10-26 23:00 . 2006-10-26 23:00 998208 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL
+ 2006-10-26 23:00 . 2006-10-26 23:00 274744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE
+ 2006-10-20 11:37 . 2006-10-20 11:37 637744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGALEGIT.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 416544 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFICE.DLL
+ 2006-10-26 23:06 . 2006-10-26 23:06 232816 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
+ 2006-10-26 22:55 . 2006-10-26 22:55 538904 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL
+ 2006-10-26 22:55 . 2006-10-26 22:55 145688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORE.EXE
+ 2006-10-26 22:55 . 2006-10-26 22:55 832800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE
+ 2006-10-26 16:56 . 2006-10-26 16:56 505136 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL
+ 2006-10-26 22:50 . 2006-10-26 22:50 672024 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE
+ 2006-10-26 17:47 . 2006-10-26 17:47 727840 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPROOF6.DLL
+ 2006-10-26 16:56 . 2006-10-26 16:56 436520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL
+ 2006-10-26 22:56 . 2006-10-26 22:56 864080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSONPDRV.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 428816 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL
+ 2006-10-27 17:59 . 2006-10-27 17:59 161080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL
+ 2006-10-26 16:58 . 2006-10-26 16:58 117552 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL
+ 2006-10-26 16:58 . 2006-10-26 16:58 290576 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCDM.DLL
+ 2006-10-27 18:04 . 2006-10-27 18:04 497504 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-26 22:52 . 2006-10-26 22:52 460616 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MODHELP.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 340248 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MIMEDIR.DLL
+ 2006-10-26 22:55 . 2006-10-26 22:55 828704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL
+ 2009-07-05 15:27 . 2009-07-05 15:27 118112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMINT.DLL
+ 2009-07-05 15:27 . 2009-07-05 15:27 609104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMHOST.DLL
+ 2006-10-27 00:42 . 2006-10-27 00:42 176976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOLK.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 138024 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-10-26 23:00 . 2006-10-26 23:00 178488 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IETAG.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 173328 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 631080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBSERVICES.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 572216 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBPLATFORMSERVICES.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 268080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBBROWSERTOOL2.DLL

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:39 am

part 7

+ 2006-10-27 03:48 . 2006-10-27 03:48 955680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUTIL.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 222512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMSERVICES.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 363304 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESKETCHTOOL.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 224048 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEPROJECTTOOLSET.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 317736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMIGRATOR.EXE
+ 2006-10-27 03:48 . 2006-10-27 03:48 197920 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEGAMES.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 284976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEFETCHSERVICES.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 377136 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDATAVIEWERTOOL.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 768304 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMPONENTMGR.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 117584 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 300336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECALENDARTOOL.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 284448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDIO.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 338216 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVE.EXE
+ 2009-07-05 15:26 . 2009-07-05 15:26 150320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPHPIA.DLL
+ 2006-10-27 18:09 . 2006-10-27 18:09 983376 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 154960 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ENVELOPE.DLL
+ 2006-10-26 23:55 . 2006-10-26 23:55 116544 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EMABLT32.DLL
+ 2006-10-26 22:48 . 2006-10-26 22:48 434528 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
+ 2006-10-26 22:48 . 2006-10-26 22:48 439568 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL
+ 2006-10-26 23:12 . 2006-10-26 23:12 106824 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DSSM.EXE
+ 2006-10-27 03:48 . 2006-10-27 03:48 234784 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DRAT.EXE
+ 2006-10-26 23:12 . 2006-10-26 23:12 189760 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 133936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTAB32.DLL
+ 2006-10-26 22:59 . 2006-10-26 22:59 205616 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE
+ 2006-10-27 18:41 . 2006-10-27 18:41 399640 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 371568 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL
+ 2006-10-27 18:40 . 2006-10-27 18:40 208760 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 224104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 551800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 289648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 260976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 392048 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 387960 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 279352 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 207736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 629616 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL
+ 2006-10-26 23:13 . 2006-10-26 23:13 338800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 191360 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 576376 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL
+ 2006-10-27 00:18 . 2006-10-27 00:18 162616 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 576376 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL
+ 2006-10-26 22:49 . 2006-10-26 22:49 970528 c:\windows\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL
+ 2009-07-20 02:41 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971930-IE8\spuninst\updspapi.dll
+ 2009-07-20 02:41 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971930-IE8\spuninst\spuninst.exe
+ 2009-07-20 02:41 . 2009-03-08 07:34 914944 c:\windows\ie8updates\KB969897-IE8\wininet.dll
+ 2009-07-20 02:41 . 2008-07-09 07:38 382840 c:\windows\ie8updates\KB969897-IE8\spuninst\updspapi.dll
+ 2009-07-20 02:41 . 2007-11-30 12:39 231288 c:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe
+ 2009-07-20 02:41 . 2009-03-08 07:33 246784 c:\windows\ie8updates\KB969897-IE8\ieproxy.dll
+ 2009-07-20 02:41 . 2009-03-08 17:09 391536 c:\windows\ie8updates\KB969897-IE8\iedkcs32.dll
+ 2009-07-20 02:41 . 2009-03-08 07:32 173056 c:\windows\ie8updates\KB969897-IE8\ie4uinit.exe
+ 2009-07-20 02:39 . 2009-03-03 00:18 826368 c:\windows\ie8\wininet.dll
+ 2009-07-20 02:39 . 2007-08-13 22:45 206336 c:\windows\ie8\winfxdocobj.exe
+ 2009-07-20 02:39 . 2009-02-20 18:09 233472 c:\windows\ie8\webcheck.dll
+ 2009-07-20 02:39 . 2008-05-27 17:23 765952 c:\windows\ie8\vgx.dll
+ 2009-07-20 02:39 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 105984 c:\windows\ie8\url.dll
+ 2009-07-20 02:40 . 2009-01-07 21:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2009-07-20 02:40 . 2009-01-07 21:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2009-07-20 02:39 . 2006-09-06 21:43 213216 c:\windows\ie8\spuninst.exe
+ 2009-07-20 02:39 . 2009-02-20 18:09 102912 c:\windows\ie8\occache.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 671232 c:\windows\ie8\mstime.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 193024 c:\windows\ie8\msrating.dll
+ 2009-07-20 02:39 . 2007-08-13 22:54 156160 c:\windows\ie8\msls31.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 477696 c:\windows\ie8\mshtmled.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 459264 c:\windows\ie8\msfeeds.dll
+ 2009-07-20 02:39 . 2008-05-09 10:53 512000 c:\windows\ie8\jscript.dll
+ 2009-07-20 02:39 . 2009-02-28 04:54 636072 c:\windows\ie8\iexplore.exe
+ 2009-07-20 02:39 . 2007-08-13 22:54 180736 c:\windows\ie8\ieui.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 268288 c:\windows\ie8\iertutil.dll
+ 2009-07-20 02:39 . 2007-08-13 22:54 287744 c:\windows\ie8\ieproxy.dll
+ 2009-07-20 02:39 . 2007-08-13 22:54 191488 c:\windows\ie8\iepeers.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 385024 c:\windows\ie8\iedkcs32.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 383488 c:\windows\ie8\ieapfltr.dll
+ 2009-07-20 02:39 . 2009-02-20 05:14 161792 c:\windows\ie8\ieakui.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 230400 c:\windows\ie8\ieaksie.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 153088 c:\windows\ie8\ieakeng.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 214528 c:\windows\ie8\dxtrans.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 347136 c:\windows\ie8\dxtmsft.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 124928 c:\windows\ie8\advpack.dll
+ 2009-07-20 02:42 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-07-20 02:42 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-07-20 02:42 . 2009-02-20 18:09 133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-07-20 02:47 . 2009-07-20 02:47 609160 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2009-07-20 02:47 . 2009-07-20 02:47 118176 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 423784 c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-07-20 02:46 . 2009-07-20 02:46 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-07-20 21:12 . 2009-07-20 21:12 350064 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-07-20 02:45 . 2009-07-20 02:45 149352 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2006-11-14 19:21 . 2009-04-17 12:26 1847168 c:\windows\system32\win32k.sys

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:39 am

part 8

+ 2006-11-14 19:20 . 2009-04-30 21:22 1207808 c:\windows\system32\urlmon.dll
+ 2006-11-14 19:19 . 2009-05-13 05:15 5936128 c:\windows\system32\mshtml.dll
+ 2007-08-13 22:34 . 2009-04-30 21:22 1985024 c:\windows\system32\iertutil.dll
+ 2007-02-12 20:10 . 2009-02-07 00:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2008-11-21 02:06 . 2008-11-21 02:06 1194848 c:\windows\system32\FM20.DLL
+ 2009-02-20 19:12 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2006-11-14 19:20 . 2009-04-30 21:22 1207808 c:\windows\system32\dllcache\urlmon.dll
+ 2009-01-07 21:20 . 2009-01-07 21:20 1497088 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-02-20 19:13 . 2009-06-03 19:09 1291264 c:\windows\system32\dllcache\quartz.dll
+ 2006-11-14 19:19 . 2009-05-13 05:15 5936128 c:\windows\system32\dllcache\mshtml.dll
+ 2009-02-20 20:08 . 2009-04-30 21:22 1985024 c:\windows\system32\dllcache\iertutil.dll
+ 2009-02-20 20:08 . 2009-02-07 00:07 3698584 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-01-07 21:20 . 2009-01-07 21:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2009-05-04 10:46 . 2009-05-04 10:46 8299008 c:\windows\Installer\afb6e.msp
+ 2009-05-26 21:54 . 2009-05-26 21:54 4192768 c:\windows\Installer\afb57.msp
+ 2009-05-04 10:47 . 2009-05-04 10:47 9124864 c:\windows\Installer\afb3c.msp
+ 2009-04-24 15:30 . 2009-04-24 15:30 2583552 c:\windows\Installer\afb25.msp
+ 2009-04-24 15:28 . 2009-04-24 15:28 4450816 c:\windows\Installer\afb0d.msp
+ 2009-04-24 15:29 . 2009-04-24 15:29 9013760 c:\windows\Installer\afae0.msp
+ 2009-07-20 03:07 . 2009-07-20 03:07 1401344 c:\windows\Installer\676b2.msi
+ 2009-07-02 19:23 . 2009-07-02 19:23 5027328 c:\windows\Installer\1e854e.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 1282560 c:\windows\Installer\1e852e.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 7888384 c:\windows\Installer\1e8527.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 9926144 c:\windows\Installer\1e851e.msp
+ 2009-04-04 13:14 . 2009-04-04 13:14 1094656 c:\windows\Installer\1e8365.msp
+ 2009-02-25 22:08 . 2009-02-25 22:08 8311808 c:\windows\Installer\1e835a.msp
+ 2009-07-05 15:28 . 2009-07-20 21:15 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-03 20:57 . 2009-04-03 20:57 4671320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WRD12CNV.DLL
+ 2009-04-03 21:04 . 2009-04-03 21:04 8468840 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PPCORE.DLL
+ 2009-03-06 05:05 . 2009-03-06 05:05 2964336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OLMAPI32.DLL
+ 2009-03-06 06:41 . 2009-03-06 06:41 9589096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSPUB.EXE
+ 2006-10-26 17:05 . 2006-10-26 17:05 1181520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL
+ 2006-10-27 18:11 . 2006-10-27 18:11 4235560 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 01:58 . 2006-10-27 01:58 3732792 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2006-10-27 02:00 . 2006-10-27 02:00 1841984 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-09-30 03:42 . 2006-09-30 03:42 2583344 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL
+ 2006-10-27 17:57 . 2006-10-27 17:57 2330968 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-26 22:52 . 2006-10-26 22:52 2012480 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-27 18:04 . 2006-10-27 18:04 7980848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2006-09-15 19:25 . 2006-09-15 19:25 3611416 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-26 23:07 . 2006-10-26 23:07 6536992 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-10-27 18:03 . 2006-10-27 18:03 6579512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-26 23:24 . 2006-10-26 23:24 1165112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 18:03 . 2006-10-27 18:03 1018664 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2006-10-27 18:16 . 2006-10-27 18:16 2939704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLMAPI32.DLL
+ 2006-10-27 18:18 . 2006-10-27 18:18 1658152 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-26 23:14 . 2006-10-26 23:14 7033152 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-26 23:42 . 2006-10-26 23:42 8423224 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OARTCONV.DLL
+ 2006-10-26 17:47 . 2006-10-26 17:47 1512304 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NLSD0000.DLL
+ 2006-10-27 18:04 . 2006-10-27 18:04 9581360 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-26 23:00 . 2006-10-26 23:00 6635320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 5281592 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 5456704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 1439032 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE
+ 2006-10-27 18:37 . 2006-10-27 18:37 1396008 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 4746536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 1163048 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 2738472 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 2210608 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 7053096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 1555232 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 3071288 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 1359648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 3508544 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 2689336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 6191400 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL
+ 2006-10-26 23:02 . 2006-10-26 23:02 2526520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-26 22:21 . 2006-10-26 22:21 1682232 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2006-10-26 17:10 . 2006-10-26 17:10 1190688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 1276720 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCELPIA.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 1751904 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-26 22:49 . 2006-10-26 22:49 1011488 c:\windows\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2009-07-20 02:41 . 2009-03-08 07:34 1206784 c:\windows\ie8updates\KB969897-IE8\urlmon.dll
+ 2009-07-20 02:41 . 2009-03-08 07:41 5937152 c:\windows\ie8updates\KB969897-IE8\mshtml.dll
+ 2009-07-20 02:41 . 2009-03-08 07:32 1985024 c:\windows\ie8updates\KB969897-IE8\iertutil.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 1160192 c:\windows\ie8\urlmon.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 3595264 c:\windows\ie8\mshtml.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 6066176 c:\windows\ie8\ieframe.dll
+ 2009-07-20 02:39 . 2008-07-09 14:25 2455488 c:\windows\ie8\ieapfltr.dat
+ 2009-07-20 02:46 . 2009-07-20 02:46 1279848 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-07-20 02:38 . 2009-07-07 11:10 24539592 c:\windows\system32\MRT.exe
+ 2007-08-13 22:54 . 2009-04-30 21:22 11064832 c:\windows\system32\ieframe.dll
+ 2009-02-20 20:08 . 2009-04-30 21:22 11064832 c:\windows\system32\dllcache\ieframe.dll
+ 2009-05-04 10:49 . 2009-05-04 10:49 10955776 c:\windows\Installer\afba9.msp
+ 2009-04-04 20:09 . 2009-04-04 20:09 15190016 c:\windows\Installer\1e8385.msp
+ 2009-04-04 14:36 . 2009-04-04 14:36 21390848 c:\windows\Installer\1e8366.msp
+ 2009-07-22 02:26 . 2009-07-22 02:26 15706112 c:\windows\Installer\159dd95.msp
+ 2009-04-03 21:01 . 2009-04-03 21:01 15108448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\XL12CNV.EXE
+ 2009-04-03 21:11 . 2009-04-03 21:11 17740136 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WWLIB.DLL
+ 2009-03-06 05:06 . 2009-03-06 05:06 12707696 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLOOK.EXE
+ 2009-04-03 21:11 . 2009-04-03 21:11 18330984 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\EXCEL.EXE
+ 2006-10-27 00:13 . 2006-10-27 00:13 14674216 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2006-10-27 18:23 . 2006-10-27 18:23 17483560 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 12813096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLOOK.EXE
+ 2006-10-27 18:14 . 2006-10-27 18:14 14151456 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 18:26 . 2006-10-27 18:26 16870712 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 18:01 . 2006-10-27 18:01 10371880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE
+ 2006-10-27 18:07 . 2006-10-27 18:07 17891112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2009-07-20 02:41 . 2009-03-08 07:39 11063808 c:\windows\ie8updates\KB969897-IE8\ieframe.dll
+ 2009-04-04 20:08 . 2009-04-04 20:08 343058432 c:\windows\Installer\1e8514.msp
.
-- Snapshot reset to current date --

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:40 am

part 9

+ 2006-11-14 19:20 . 2009-04-30 21:22 1207808 c:\windows\system32\urlmon.dll
+ 2006-11-14 19:19 . 2009-05-13 05:15 5936128 c:\windows\system32\mshtml.dll
+ 2007-08-13 22:34 . 2009-04-30 21:22 1985024 c:\windows\system32\iertutil.dll
+ 2007-02-12 20:10 . 2009-02-07 00:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2008-11-21 02:06 . 2008-11-21 02:06 1194848 c:\windows\system32\FM20.DLL
+ 2009-02-20 19:12 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2006-11-14 19:20 . 2009-04-30 21:22 1207808 c:\windows\system32\dllcache\urlmon.dll
+ 2009-01-07 21:20 . 2009-01-07 21:20 1497088 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-02-20 19:13 . 2009-06-03 19:09 1291264 c:\windows\system32\dllcache\quartz.dll
+ 2006-11-14 19:19 . 2009-05-13 05:15 5936128 c:\windows\system32\dllcache\mshtml.dll
+ 2009-02-20 20:08 . 2009-04-30 21:22 1985024 c:\windows\system32\dllcache\iertutil.dll
+ 2009-02-20 20:08 . 2009-02-07 00:07 3698584 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-01-07 21:20 . 2009-01-07 21:20 1022976 c:\windows\system32\dllcache\browseui.dll
+ 2009-05-04 10:46 . 2009-05-04 10:46 8299008 c:\windows\Installer\afb6e.msp
+ 2009-05-26 21:54 . 2009-05-26 21:54 4192768 c:\windows\Installer\afb57.msp
+ 2009-05-04 10:47 . 2009-05-04 10:47 9124864 c:\windows\Installer\afb3c.msp
+ 2009-04-24 15:30 . 2009-04-24 15:30 2583552 c:\windows\Installer\afb25.msp
+ 2009-04-24 15:28 . 2009-04-24 15:28 4450816 c:\windows\Installer\afb0d.msp
+ 2009-04-24 15:29 . 2009-04-24 15:29 9013760 c:\windows\Installer\afae0.msp
+ 2009-07-20 03:07 . 2009-07-20 03:07 1401344 c:\windows\Installer\676b2.msi
+ 2009-07-02 19:23 . 2009-07-02 19:23 5027328 c:\windows\Installer\1e854e.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 1282560 c:\windows\Installer\1e852e.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 7888384 c:\windows\Installer\1e8527.msp
+ 2009-04-04 20:10 . 2009-04-04 20:10 9926144 c:\windows\Installer\1e851e.msp
+ 2009-04-04 13:14 . 2009-04-04 13:14 1094656 c:\windows\Installer\1e8365.msp
+ 2009-02-25 22:08 . 2009-02-25 22:08 8311808 c:\windows\Installer\1e835a.msp
+ 2009-07-05 15:28 . 2009-07-20 21:15 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-07-05 15:28 . 2009-07-20 21:15 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-07-05 15:28 . 2009-07-05 15:28 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-03 20:57 . 2009-04-03 20:57 4671320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WRD12CNV.DLL
+ 2009-04-03 21:04 . 2009-04-03 21:04 8468840 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\PPCORE.DLL
+ 2009-03-06 05:05 . 2009-03-06 05:05 2964336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OLMAPI32.DLL
+ 2009-03-06 06:41 . 2009-03-06 06:41 9589096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSPUB.EXE
+ 2006-10-26 17:05 . 2006-10-26 17:05 1181520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL
+ 2006-10-27 18:11 . 2006-10-27 18:11 4235560 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 01:58 . 2006-10-27 01:58 3732792 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2006-10-27 02:00 . 2006-10-27 02:00 1841984 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-09-30 03:42 . 2006-09-30 03:42 2583344 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL
+ 2006-10-27 17:57 . 2006-10-27 17:57 2330968 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-26 22:52 . 2006-10-26 22:52 2012480 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-27 18:04 . 2006-10-27 18:04 7980848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2006-09-15 19:25 . 2006-09-15 19:25 3611416 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-26 23:07 . 2006-10-26 23:07 6536992 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-10-27 18:03 . 2006-10-27 18:03 6579512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-26 23:24 . 2006-10-26 23:24 1165112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 18:03 . 2006-10-27 18:03 1018664 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2006-10-27 18:16 . 2006-10-27 18:16 2939704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLMAPI32.DLL
+ 2006-10-27 18:18 . 2006-10-27 18:18 1658152 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-26 23:14 . 2006-10-26 23:14 7033152 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-26 23:42 . 2006-10-26 23:42 8423224 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OARTCONV.DLL
+ 2006-10-26 17:47 . 2006-10-26 17:47 1512304 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NLSD0000.DLL
+ 2006-10-27 18:04 . 2006-10-27 18:04 9581360 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-26 23:00 . 2006-10-26 23:00 6635320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 5281592 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 5456704 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL
+ 2006-10-27 18:10 . 2006-10-27 18:10 1439032 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE
+ 2006-10-27 18:37 . 2006-10-27 18:37 1396008 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 4746536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 1163048 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 2738472 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 2210608 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 7053096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL
+ 2006-10-27 03:48 . 2006-10-27 03:48 1555232 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 3071288 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 1359648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 3508544 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL
+ 2006-10-27 18:37 . 2006-10-27 18:37 2689336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL
+ 2006-10-27 18:38 . 2006-10-27 18:38 6191400 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL
+ 2006-10-26 23:02 . 2006-10-26 23:02 2526520 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-26 22:21 . 2006-10-26 22:21 1682232 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2006-10-26 17:10 . 2006-10-26 17:10 1190688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL
+ 2009-07-05 15:26 . 2009-07-05 15:26 1276720 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCELPIA.DLL
+ 2006-10-27 18:00 . 2006-10-27 18:00 1751904 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-26 22:49 . 2006-10-26 22:49 1011488 c:\windows\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2009-07-20 02:41 . 2009-03-08 07:34 1206784 c:\windows\ie8updates\KB969897-IE8\urlmon.dll
+ 2009-07-20 02:41 . 2009-03-08 07:41 5937152 c:\windows\ie8updates\KB969897-IE8\mshtml.dll
+ 2009-07-20 02:41 . 2009-03-08 07:32 1985024 c:\windows\ie8updates\KB969897-IE8\iertutil.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 1160192 c:\windows\ie8\urlmon.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 3595264 c:\windows\ie8\mshtml.dll
+ 2009-07-20 02:39 . 2009-02-20 18:09 6066176 c:\windows\ie8\ieframe.dll
+ 2009-07-20 02:39 . 2008-07-09 14:25 2455488 c:\windows\ie8\ieapfltr.dat
+ 2009-07-20 02:46 . 2009-07-20 02:46 1279848 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-07-20 02:38 . 2009-07-07 11:10 24539592 c:\windows\system32\MRT.exe
+ 2007-08-13 22:54 . 2009-04-30 21:22 11064832 c:\windows\system32\ieframe.dll
+ 2009-02-20 20:08 . 2009-04-30 21:22 11064832 c:\windows\system32\dllcache\ieframe.dll
+ 2009-05-04 10:49 . 2009-05-04 10:49 10955776 c:\windows\Installer\afba9.msp
+ 2009-04-04 20:09 . 2009-04-04 20:09 15190016 c:\windows\Installer\1e8385.msp
+ 2009-04-04 14:36 . 2009-04-04 14:36 21390848 c:\windows\Installer\1e8366.msp
+ 2009-07-22 02:26 . 2009-07-22 02:26 15706112 c:\windows\Installer\159dd95.msp
+ 2009-04-03 21:01 . 2009-04-03 21:01 15108448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\XL12CNV.EXE
+ 2009-04-03 21:11 . 2009-04-03 21:11 17740136 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\WWLIB.DLL
+ 2009-03-06 05:06 . 2009-03-06 05:06 12707696 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OUTLOOK.EXE
+ 2009-04-03 21:11 . 2009-04-03 21:11 18330984 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\EXCEL.EXE
+ 2006-10-27 00:13 . 2006-10-27 00:13 14674216 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2006-10-27 18:23 . 2006-10-27 18:23 17483560 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-27 18:16 . 2006-10-27 18:16 12813096 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLOOK.EXE
+ 2006-10-27 18:14 . 2006-10-27 18:14 14151456 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 18:26 . 2006-10-27 18:26 16870712 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 18:01 . 2006-10-27 18:01 10371880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE
+ 2006-10-27 18:07 . 2006-10-27 18:07 17891112 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2009-07-20 02:41 . 2009-03-08 07:39 11063808 c:\windows\ie8updates\KB969897-IE8\ieframe.dll
+ 2009-04-04 20:08 . 2009-04-04 20:08 343058432 c:\windows\Installer\1e8514.msp
.
-- Snapshot reset to current date --

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:41 am

part 10

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-01-24 2289664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\lxdjcoms.exe"=
"c:\\Program Files\\Lexmark 1400 Series\\lxdjamon.exe"=
"c:\\Program Files\\Lexmark 1400 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\lxdjcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjjswx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjpswx.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdjtime.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58157:TCP"= 58157:TCP:Pando Media Booster
"58157:UDP"= 58157:UDP:Pando Media Booster

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.086\SymEFA.sys [19/07/2009 11:57 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.086\BHDrvx86.sys [19/07/2009 11:57 PM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.086\cchpx86.sys [19/07/2009 11:57 PM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSXpx86.sys [19/07/2009 11:59 PM 276344]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe [19/07/2009 11:57 PM 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [19/07/2009 11:59 PM 101936]
S1 307e2377;307e2377;c:\windows\system32\drivers\307e2377.sys [07/05/2009 4:47 PM 0]
S2 gupdate1ca08e72884f470;Google Update Service (gupdate1ca08e72884f470);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2009 12:07 AM 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-07-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-07-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-20 03:06]

2009-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-20 03:06]

2009-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-20 03:06]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-07-22 00:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.134\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-07-22 0:12
ComboFix-quarantined-files.txt 2009-07-22 03:12
ComboFix2.txt 2009-07-20 02:13

Pre-Run: 60,507,013,120 bytes free
Post-Run: 60,472,008,704 bytes free

835 --- E O F --- 2009-07-22 02:26

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 24th July 2009, 12:41 am

And Origin...Thanks dude you are the best!!!!

A

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by brainrepaircenter on 27th July 2009, 2:16 pm

Origin

Is there anything else I need to do. Things are running fine. I installed Norton 360.

Thanks a million!

Andrew

brainrepaircenter
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27007
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malware Doc?

Post by Belahzur on 27th July 2009, 3:58 pm

Hello.
Sorry for the delay, your post was pushed back.

The log looks fine now and if the machine is running fine, I'd say were done.

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u



This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245079
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum