Bienvenido: ( Identificarse | Registrarse )      
Foros de Trucos Windows
 
Closed TopicStart new topicStart Poll

Outline · [ Estándar ] · Lineal+

> EL PROBLEMA CPU AL 100% VOLVIO :s

pacho929
post May 10 2008, 03:28 AM
Publicado: #1


Newbie
*

Grupo: Members
Mensajes: 18
Registrado: 8-May 08
Miembro nº: 230.796



hola, mis disculpas por volver a poner este post, pero es que ayer tube que salir, y lo del computador me toco hacerlo hoy y pense que ya no responderian en el post anterior por eso vuelvo a poner este.

los sintomas son, Lentitud, uso de CPU AL 100%, y no se si esto este relacionado pero muchas veces se cae el internet y cuando doy diagnosticar problemas, me sale que algo le pasa al catalogo de winsock y me toca reiniciar el compu.

ayudaaa cry1at.gif , es que tengo mucho trabajo que hacer y no ´puedo con este computador tan put...te lento ranting.gif wacko.gif

aqui les dejo mi log, mas el del avg

---------------------------------------------------------
AVG Anti-Spyware - Informe del análisis
---------------------------------------------------------

+ Creado en: 05:05:55 p.m. 09/05/2008

+ Resultado del análisis:



C:\Documents and Settings\Fabio\Cookies\fabio[arroba]msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Limpios.
C:\Documents and Settings\Fabio\Cookies\fabio[arroba]adrevolver[2].txt -> TrackingCookie.Adrevolver : Limpios.
C:\Documents and Settings\Fabio\Cookies\fabio[arroba]media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Limpios.
C:\Documents and Settings\Fabio\Cookies\fabio[arroba]atdmt[2].txt -> TrackingCookie.Atdmt : Limpios.
C:\Documents and Settings\Fabio\Cookies\fabio[arroba]doubleclick[2].txt -> TrackingCookie.Doubleclick : Limpios.


::Fin del informe


Logfile of HijackThis v1.99.1
Scan saved at 09:27:54 p.m., on 09/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe
C:\Archivos de programa\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\pctspk.exe
C:\Archivos de programa\Ahead\InCD\InCD.exe
C:\DOCUME~1\user\CONFIG~1\Temp\62.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\vkppaa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\DOCUME~1\user\CONFIG~1\Temp\Rar$EX03.109\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Yahoo! Barra de herramientas - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Complemento del Asistente para Internet de Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Asistente para Internet de Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Barra de herramientas - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar3.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Archivos de programa\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Archivos de programa\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PowerDVD] "C:\Archivos de programa\CyberLink" DVD Solution\PowerDVD\PowerDVD.exe /autostart
O4 - HKLM\..\Run: [Microsoft Kinetik Svc] msftksvc.exe
O4 - HKLM\..\Run: [NvGraphicsInterface] C:\DOCUME~1\user\CONFIG~1\Temp\62.exe
O4 - HKLM\..\Run: [vkppaa] "C:\WINDOWS\system32\vkppaa.exe" \u
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [NBJ] "C:\Archivos de programa\Ahead\Nero BackItUp\NBJ.exe"
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Archivos de programa\Archivos comunes\Autodesk Shared\acstart16.exe
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Abrir en nueva ficha de fondo - res://C:\Archivos de programa\Windows Live Toolbar\Components\es-xl\msntabres.dll.mui/229?aca0b88157d644a3875ea33b0e14dc2c
O8 - Extra context menu item: Abrir en nueva ficha en primer plano - res://C:\Archivos de programa\Windows Live Toolbar\Components\es-xl\msntabres.dll.mui/230?aca0b88157d644a3875ea33b0e14dc2c
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Archivos de programa\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-LA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Archivos de programa\AutoCAD LT 2002\AcDcToday.ocx
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab55579.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (ZPA_HRTZ Object) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab55579.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Archivos de programa\AutoCAD LT 2002\InstBanr.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Archivos de programa\AutoCAD LT 2002\InstFred.ocx
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Archivos de programa\AutoCAD LT 2002\AcPreview.ocx
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check...PA.cab55579.cab
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.237 85.255.112.78
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Archivos de programa\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Motor de Spy Sweeper de Webroot (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe




User is offlineProfile CardPM
Go to the top of the page
+Quote Post
francisco.javier
post May 10 2008, 10:55 AM
Publicado: #2


Erradicando infecciones
**********

Grupo: Members
Mensajes: 4.023
Registrado: 21-December 06
Desde: A 23 km de A Coruña - Galicia
Miembro nº: 189.100



Combo Fix
1. Descarga Combofix.exe en el escritorio
2. Haz Doble click en combofix.exe y lo ejecutas, sigues los avisos
3. Al finalizar la ejecuccion produce un log localizado en: (C:\ComboFix.txt).

pegas ese report y un nuevo log

Un saludo


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
pacho929
post May 11 2008, 02:43 AM
Publicado: #3


Newbie
*

Grupo: Members
Mensajes: 18
Registrado: 8-May 08
Miembro nº: 230.796




listo aqui esta

ComboFix 08-05-09.1 - user 2008-05-10 20:15:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.3082.18.135 [GMT -5:00]
Se ejecuta desde: C:\Documents and Settings\user\Escritorio\ComboFix.exe
* Creado un nuevo punto de restauración
* Resident AV is active


ADVERTENCIA - ESTE EQUIPO NO TIENE INSTALADA LA CONSOLA DE RECUPERACION!
.

(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\939994.exe

.
(((((((((((((((((( Archivos creados desde 2008-04-11 - 2008-05-11 )))))))))))))))))))))))))))))))))
.

2008-05-09 07:02 . 2008-05-09 07:02 <DIR> d-------- C:\Documents and Settings\Fabio\Datos de programa\Grisoft
2008-05-08 09:44 . 2008-05-08 09:44 <DIR> d-------- C:\Documents and Settings\user\Datos de programa\Grisoft
2008-05-08 09:44 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-07 21:23 . 2008-05-07 21:23 16,732 --a------ C:\WINDOWS\system32\wbers.dat.dmp
2008-05-07 21:23 . 2008-05-07 21:23 2,313 --a------ C:\WINDOWS\system32\wbers.dat
2008-05-07 20:26 . 2008-05-07 20:26 244 --ah----- C:\sqmnoopt16.sqm
2008-05-07 20:26 . 2008-05-07 20:26 232 --ah----- C:\sqmdata16.sqm
2008-05-07 19:53 . 2008-05-07 19:53 172 --ah----- C:\sqmnoopt15.sqm
2008-05-07 19:53 . 2008-05-07 19:53 172 --ah----- C:\sqmdata15.sqm
2008-05-07 19:46 . 2008-05-07 19:46 268 --ah----- C:\sqmdata14.sqm
2008-05-07 19:46 . 2008-05-07 19:46 244 --ah----- C:\sqmnoopt14.sqm
2008-05-07 13:14 . 2008-05-07 13:14 268 --ah----- C:\sqmdata13.sqm
2008-05-07 13:14 . 2008-05-07 13:14 244 --ah----- C:\sqmnoopt13.sqm
2008-05-07 12:02 . 2008-05-07 12:02 268 --ah----- C:\sqmdata12.sqm
2008-05-07 12:02 . 2008-05-07 12:02 244 --ah----- C:\sqmnoopt12.sqm
2008-05-06 13:53 . 2008-05-06 13:53 <DIR> d-------- C:\Archivos de programa\Microsoft Games
2008-05-05 01:21 . 2008-05-05 01:21 59,392 --a------ C:\Documents and Settings\user\rajm.exe
2008-05-05 00:13 . 2008-05-05 00:13 <DIR> d-------- C:\Archivos de programa\Graficador de Ecuaciones
2008-05-05 00:10 . 2008-05-05 00:13 290,816 --------- C:\WINDOWS\Setup1.exe
2008-05-05 00:10 . 2008-05-05 00:13 74,240 --a------ C:\WINDOWS\ST6UNST.EXE
2008-05-04 12:32 . 2008-05-04 12:32 59,392 --a------ C:\Documents and Settings\user\wgwlp.exe
2008-05-04 12:22 . 2008-05-04 12:22 59,392 --a------ C:\Documents and Settings\user\lwwxr.exe
2008-05-04 12:11 . 2008-05-04 12:11 59,392 --a------ C:\Documents and Settings\user\oqe.exe
2008-05-04 12:00 . 2008-05-04 12:00 59,392 --a------ C:\Documents and Settings\user\lwwkdgs.exe
2008-05-04 11:50 . 2008-05-04 11:50 59,392 --a------ C:\Documents and Settings\user\dhtsulx.exe
2008-05-04 11:37 . 2008-05-04 11:37 59,392 --a------ C:\Documents and Settings\user\gjc.exe
2008-05-04 11:27 . 2008-05-04 11:27 59,392 --a------ C:\Documents and Settings\user\onnaqhh.exe
2008-05-04 11:16 . 2008-05-05 01:31 169,120 --a------ C:\WINDOWS\system32\drivers\ndisio.sys
2008-05-04 11:16 . 2008-05-04 11:16 59,392 --a------ C:\Documents and Settings\user\holmfhe.exe
2008-05-01 18:26 . 2008-05-01 18:25 59,392 --a------ C:\WINDOWS\system32\vkppaa.exe
2008-05-01 18:26 . 2008-05-01 18:25 59,392 ---h----- C:\Documents and Settings\user\lqjctv.exe
2008-04-23 07:43 . 2008-04-23 07:43 <DIR> d-------- C:\Documents and Settings\Fabio\Datos de programa\U3
2008-04-22 17:29 . 2008-04-22 17:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-04-19 18:14 . 2008-04-19 18:14 244 --ah----- C:\sqmnoopt11.sqm
2008-04-19 18:14 . 2008-04-19 18:14 244 --ah----- C:\sqmnoopt10.sqm
2008-04-19 18:14 . 2008-04-19 18:14 232 --ah----- C:\sqmdata11.sqm
2008-04-19 18:14 . 2008-04-19 18:14 232 --ah----- C:\sqmdata10.sqm
2008-04-19 18:13 . 2008-04-19 18:13 244 --ah----- C:\sqmnoopt09.sqm
2008-04-19 18:13 . 2008-04-19 18:13 232 --ah----- C:\sqmdata09.sqm
2008-04-16 19:30 . 2008-04-16 19:30 <DIR> d-------- C:\Documents and Settings\NetworkService\Datos de programa\Xfire
2008-04-14 22:14 . 2008-05-01 19:38 <DIR> d-------- C:\Documents and Settings\user\Datos de programa\Xfire
2008-04-14 22:14 . 2008-04-29 06:37 <DIR> d---s---- C:\Archivos de programa\Xfire

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-09 18:40 --------- d-----w C:\Archivos de programa\EsetOnlineScanner
2008-05-05 05:12 3,215 ----a-w C:\Archivos de programa\ST6UNST.LOG
2008-05-04 23:08 --------- d-----w C:\Archivos de programa\SUPERAntiSpyware
2008-05-03 23:16 --------- d-----w C:\Archivos de programa\Minilyrics
2008-05-03 23:03 --------- d-----w C:\Archivos de programa\Archivos comunes\AVSMedia
2008-05-03 22:43 --------- d--h--w C:\Archivos de programa\InstallShield Installation Information
2008-04-19 21:30 --------- d-----w C:\Archivos de programa\GameSpy Arcade
2008-04-14 00:13 --------- d-----w C:\Archivos de programa\eMule
2008-04-09 14:45 --------- d-----w C:\Documents and Settings\JONATHAN\Datos de programa\Media Player Classic
2008-04-03 04:54 --------- d-----w C:\Documents and Settings\user\Datos de programa\Media Player Classic
2008-03-21 21:37 --------- d-----w C:\Archivos de programa\ScannerU
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 01:27 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-03-14 01:27 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-03-14 01:27 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2006-11-23 17:24 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2006-01-23 03:12 61,880 ----a-w C:\Documents and Settings\JONATHAN\Datos de programa\GDIPFONTCACHEV1.DAT
2005-04-01 03:17 40,960 ----a-w C:\Archivos de programa\Uninstall_CDS.exe
2002-01-12 18:22 98,304 ----a-w C:\Archivos de programa\graficador.exe
2001-12-17 14:54 10,824 ----a-w C:\Archivos de programa\graficador.gid
2001-12-02 23:31 93,184 ----a-w C:\Archivos de programa\graficador.fts
2001-12-02 23:30 13,997 ----a-w C:\Archivos de programa\graficador.hlp
2001-12-02 22:46 262 ----a-w C:\Archivos de programa\graficador.cnt
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2006-11-26 22:58 56 --sh--r C:\WINDOWS\system32\F910A38595.sys
2006-11-26 22:58 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot[arroba]2008-01-05_19.08.50.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2008-03-20 07:57:25 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
+ 2007-12-04 18:30:15 551,936 ----a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll
+ 2007-11-07 09:50:07 731,648 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
+ 2007-12-07 01:42:43 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll
+ 2007-12-19 22:20:29 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll
+ 2007-12-07 01:42:44 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll
+ 2007-12-07 01:42:44 133,120 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll
+ 2007-12-07 01:42:44 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll
+ 2007-12-06 08:34:28 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe
+ 2007-12-07 01:42:44 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll
+ 2007-12-07 01:42:44 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll
+ 2007-12-06 05:00:02 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat
+ 2007-12-07 01:42:44 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll
+ 2007-12-07 01:42:45 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll
+ 2007-12-07 01:42:47 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll
+ 2007-12-07 01:42:47 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll
+ 2007-12-07 01:42:47 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll
+ 2007-12-06 08:34:29 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe
+ 2007-12-06 08:34:45 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
+ 2007-12-07 01:42:48 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll
+ 2007-12-07 01:42:48 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll
+ 2007-12-07 01:42:48 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll
+ 2007-12-07 01:42:50 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
+ 2007-12-07 01:42:51 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll
+ 2007-12-07 01:42:51 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll
+ 2007-12-07 01:42:52 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll
+ 2007-12-07 01:42:52 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll
+ 2008-01-11 05:54:04 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll
+ 2007-12-07 01:42:52 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\url.dll
+ 2007-12-07 01:42:53 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll
+ 2007-12-07 01:42:53 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll
+ 2007-12-07 01:42:54 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\updspapi.dll
+ 2008-02-20 05:20:23 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:50:24 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
+ 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
+ 2008-03-01 12:34:17 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
+ 2008-03-01 12:34:17 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
+ 2008-03-01 12:34:17 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
+ 2008-03-01 12:34:17 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
+ 2008-03-01 12:34:17 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
+ 2008-02-22 09:39:56 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
+ 2008-03-01 12:34:17 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
+ 2008-03-01 12:34:17 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
+ 2008-03-01 12:34:17 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
+ 2008-03-01 12:34:18 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
+ 2008-03-01 12:34:19 6,067,712 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
+ 2008-03-01 12:34:19 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
+ 2008-03-01 12:34:19 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
+ 2008-02-22 09:39:56 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
+ 2008-02-22 09:40:22 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
+ 2008-03-01 12:34:19 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
+ 2008-03-01 12:34:20 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
+ 2008-03-01 12:34:20 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
+ 2008-03-01 12:34:21 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
+ 2008-03-01 12:34:21 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
+ 2008-03-01 12:34:21 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
+ 2008-03-01 12:34:21 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
+ 2008-03-01 12:34:21 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
+ 2008-03-01 12:34:21 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
+ 2008-03-01 12:34:22 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
+ 2008-03-01 12:34:22 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
+ 2008-03-01 12:34:22 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
+ 2008-03-01 12:34:22 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:27:44 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe
+ 2007-03-06 01:27:43 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll
+ 2008-02-20 06:52:41 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:27:45 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:27:44 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
+ 2007-03-06 01:27:44 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll
+ 2007-03-06 01:27:50 215,776 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe
+ 2007-03-06 01:27:43 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll
+ 2007-03-06 01:28:08 724,704 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe
+ 2007-03-06 01:29:00 389,856 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
+ 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll
+ 2007-03-08 15:32:46 1,843,712 -c----w C:\WINDOWS\$NtUninstallKB941693$\win32k.sys
+ 2007-05-17 11:30:03 549,376 -c----w C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll
+ 2006-08-17 12:29:42 726,528 -c----w C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll
+ 2006-06-26 17:41:27 148,480 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll
+ 2004-08-19 13:42:02 45,568 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll
+ 2004-08-03 21:00:58 181,248 -c----w C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll
+ 2007-06-19 13:30:47 282,112 -c----w C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll
+ 2006-10-16 21:10:58 221,488 -c----w C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe
+ 2006-10-16 21:10:58 379,184 -c----w C:\WINDOWS\$NtUninstallWIC$\spuninst\updspapi.dll
+ 2008-05-11 00:36:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-01-14 20:37:14 45,056 ----a-w C:\WINDOWS\Downloaded Program Files\ijjiNotify2.exe
+ 2008-01-14 20:37:20 73,728 ----a-w C:\WINDOWS\Downloaded Program Files\ijjiPreNotify2.exe
+ 2008-01-14 20:40:14 81,920 ----a-w C:\WINDOWS\Downloaded Program Files\ijjiPreStarter2.exe
+ 2007-09-10 16:55:54 114,688 ----a-w C:\WINDOWS\Downloaded Program Files\ijjiSetup1010.dll
+ 2008-04-16 02:03:16 925,696 ----a-w C:\WINDOWS\Downloaded Program Files\ijjistarter2.exe
+ 2005-10-21 01:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 13:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 13:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2007-10-10 23:50:10 124,928 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\advpack.dll
+ 2006-10-17 16:58:06 346,624 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtmsft.dll
+ 2007-10-10 23:50:10 214,528 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtrans.dll
+ 2007-10-10 23:50:10 132,608 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\extmgr.dll
+ 2007-10-10 23:50:10 63,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\icardie.dll
+ 2007-10-10 11:00:07 70,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ie4uinit.exe
+ 2007-10-10 23:50:10 153,088 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakeng.dll
+ 2007-10-10 23:50:10 230,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieaksie.dll
+ 2007-10-10 05:46:55 161,792 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakui.dll
+ 2007-10-10 23:50:10 383,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieapfltr.dll
+ 2007-10-10 23:50:10 384,512 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iedkcs32.dll
+ 2007-10-10 23:50:11 6,065,664 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieframe.dll
+ 2007-10-10 23:50:11 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iernonce.dll
+ 2007-10-10 23:50:11 267,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iertutil.dll
+ 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieudinit.exe
+ 2007-10-10 11:00:20 625,152 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
+ 2007-10-10 23:50:11 27,648 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\jsproxy.dll
+ 2007-10-10 23:50:11 459,264 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeeds.dll
+ 2007-10-10 23:50:11 52,224 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeedsbs.dll
+ 2007-10-30 23:23:09 3,590,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll
+ 2007-10-10 23:50:12 478,208 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtmled.dll
+ 2007-10-10 23:50:12 193,024 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msrating.dll
+ 2007-10-10 23:50:12 671,232 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mstime.dll
+ 2007-10-10 23:50:12 102,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\occache.dll
+ 2006-10-17 16:58:08 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\pngfilt.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\updspapi.dll
+ 2007-10-10 23:50:12 105,984 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\url.dll
+ 2007-10-10 23:50:12 1,159,680 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\urlmon.dll
+ 2007-10-10 23:50:12 232,960 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\webcheck.dll
+ 2007-10-10 23:50:13 824,832 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
+ 2007-12-07 02:08:48 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
+ 2007-12-19 22:53:07 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
+ 2007-12-07 02:08:49 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
+ 2007-12-07 02:08:49 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
+ 2007-12-07 02:08:49 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
+ 2007-12-06 11:01:34 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
+ 2007-12-07 02:08:49 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
+ 2007-12-07 02:08:49 230,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
+ 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
+ 2007-12-07 02:08:49 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
+ 2007-12-07 02:08:49 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
+ 2007-12-07 02:08:51 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
+ 2007-12-07 02:08:51 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
+ 2007-12-07 02:08:51 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
+ 2007-12-06 11:02:07 625,664 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
+ 2007-12-07 02:08:52 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
+ 2007-12-07 02:08:52 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
+ 2007-12-07 02:08:52 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
+ 2007-12-08 05:08:54 3,592,192 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
+ 2007-12-07 02:08:54 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
+ 2007-12-07 02:08:54 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
+ 2007-12-07 02:08:54 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
+ 2007-12-07 02:08:54 102,912 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
+ 2008-01-11 05:37:31 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
+ 2007-03-06 01:27:50 215,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:29:00 389,856 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:08:54 105,984 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
+ 2007-12-07 02:08:55 1,159,680 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
+ 2007-12-07 02:08:55 233,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
+ 2007-12-07 02:08:55 824,832 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
+ 2003-07-08 02:36:00 2,058,343 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\A0C0110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-09 00:48:00 115,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\A0C0110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2008-01-13 23:47:01 26,694 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\ARPPRODUCTICON.exe
+ 2008-01-13 23:47:01 26,694 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-01-13 23:47:02 26,694 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-01-13 23:47:02 65,536 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-01-13 23:47:02 65,536 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut2_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-01-13 23:47:01 26,694 ----a-r C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
+ 2008-03-04 21:35:23 86,746 ----a-r C:\WINDOWS\Installer\{27186902-32C5-4649-8952-8B9A7765ABAD}\wlmail.exe
- 2006-03-29 12:55:10 593,920 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-04-09 05:03:20 593,920 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2006-03-29 12:55:10 12,288 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-04-09 05:03:20 12,288 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-03-29 12:55:10 86,016 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-04-09 05:03:20 86,016 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-03-29 12:55:09 135,168 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-04-09 05:03:20 135,168 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-03-29 12:55:10 11,264 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-04-09 05:03:20 11,264 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-03-29 12:55:10 27,136 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-04-09 05:03:20 27,136 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-03-29 12:55:10 4,096 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-04-09 05:03:20 4,096 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-03-29 12:55:10 794,624 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-04-09 05:03:20 794,624 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-03-29 12:55:09 249,856 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-04-09 05:03:20 249,856 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-03-29 12:55:09 61,440 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-04-09 05:03:20 61,440 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-03-29 12:55:10 23,040 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-04-09 05:03:20 23,040 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-03-29 12:55:09 286,720 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-04-09 05:03:20 286,720 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-03-29 12:55:09 409,600 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-04-09 05:03:20 409,600 ----a-r C:\WINDOWS\Installer\{90110C0A-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-01-23 03:10:22 2,560 ----a-r C:\WINDOWS\Installer\{90280C0A-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2008-03-05 16:41:03 123,008 ----a-r C:\WINDOWS\Installer\{937DC62D-E794-431B-84E5-ADC2D23B12ED}\WLXPhotoGalleryIcon.exe
+ 2008-03-04 21:23:27 29,926 ----a-r C:\WINDOWS\Installer\{FC411B47-30BF-428C-9C1E-F6C54A94EA7E}\MsblIco.Exe
- 2000-08-31 13:00:00 51,200 ----a-w C:\WINDOWS\NirCmd.exe
+ 2000-08-31 13:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2005-12-21 12:19:47 2,426 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2000-08-31 13:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2000-08-31 13:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 13:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 13:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
+ 2001-08-24 16:00:00 2,000 ----a-w C:\WINDOWS\system\KEYBOARD.DRV
+ 2001-08-24 16:00:00 73,696 ----a-w C:\WINDOWS\system\MCIAVI.DRV
+ 2001-08-24 16:00:00 25,344 ----a-w C:\WINDOWS\system\MCISEQ.DRV
+ 2001-08-24 16:00:00 28,160 ----a-w C:\WINDOWS\system\MCIWAVE.DRV
+ 2001-08-24 16:00:00 2,032 ----a-w C:\WINDOWS\system\MOUSE.DRV
+ 2001-08-24 16:00:00 1,744 ----a-w C:\WINDOWS\system\SOUND.DRV
+ 2001-08-24 16:00:00 3,360 ----a-w C:\WINDOWS\system\SYSTEM.DRV
+ 2001-08-24 16:00:00 4,128 ----a-w C:\WINDOWS\system\TIMER.DRV
+ 2001-08-24 16:00:00 2,176 ----a-w C:\WINDOWS\system\VGA.DRV
+ 2001-08-24 16:00:00 13,600 ----a-w C:\WINDOWS\system\WFWNET.DRV
+ 2004-08-19 13:43:26 146,944 ----a-w C:\WINDOWS\system\WINSPOOL.DRV
- 2007-10-10 23:50:10 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-03-01 12:58:33 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2001-08-24 16:00:00 10,544 ----a-w C:\WINDOWS\system32\comm.drv
+ 2006-11-29 18:06:18 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
+ 2004-08-19 13:58:52 1,788 ----a-w C:\WINDOWS\system32\Dcache.bin
- 2004-09-03 18:03:47 716,800 ----a-w C:\WINDOWS\system32\DivX.dll
+ 2007-12-04 07:33:16 682,496 ----a-w C:\WINDOWS\system32\divx.dll
- 2007-10-10 23:50:10 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-03-01 12:58:33 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2006-06-26 17:41:27 148,480 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-02-20 05:35:05 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2004-08-19 13:42:02 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
+ 2008-02-20 05:35:06 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
+ 2004-08-04 04:07:58 2,944 -c--a-w C:\WINDOWS\system32\dllcache\drmkaud.sys
- 2006-10-17 16:58:06 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-03-01 12:58:33 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-10-10 23:50:10 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-03-01 12:58:33 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-10-10 23:50:10 132,608 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-03-01 12:58:33 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-06-19 13:30:47 282,112 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
+ 2008-02-20 06:51:29 282,624 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
- 2007-10-10 23:50:10 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-03-01 12:58:33 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
- 2007-10-10 11:00:07 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-02-29 08:55:23 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-10-10 23:50:10 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-03-01 12:58:33 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-10-10 23:50:10 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-03-01 12:58:34 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-10-10 05:46:55 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-02-15 05:44:25 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-10-10 23:50:10 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-03-01 12:58:34 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2007-10-10 23:50:10 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-03-01 12:58:34 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-10-10 23:50:11 6,065,664 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-03-01 12:58:36 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2007-10-10 23:50:11 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-03-01 12:58:36 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2007-10-10 23:50:11 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-03-01 12:58:37 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-02-22 10:00:51 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2007-10-10 11:00:20 625,152 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-02-29 08:55:45 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-10-10 23:50:11 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-03-01 12:58:38 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2001-08-24 16:00:00 2,000 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.drv
- 2006-08-17 12:29:42 726,528 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-11-07 09:28:35 726,528 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2001-08-24 16:00:00 2,560 -c--a-w C:\WINDOWS\system32\dllcache\lz32.dll
+ 2001-08-24 16:00:00 73,696 -c--a-w C:\WINDOWS\system32\dllcache\mciavi.drv
+ 2001-08-24 16:00:00 25,344 -c--a-w C:\WINDOWS\system32\dllcache\mciseq.drv
+ 2001-08-24 16:00:00 28,160 -c--a-w C:\WINDOWS\system32\dllcache\mciwave.drv
+ 2001-08-24 16:00:00 2,032 -c--a-w C:\WINDOWS\system32\dllcache\mouse.drv
- 2004-08-03 21:00:58 181,248 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
+ 2007-12-18 09:51:35 179,584 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
- 2007-10-10 23:50:11 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-03-01 12:58:38 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2007-10-10 23:50:11 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-03-01 12:58:38 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2007-10-30 23:23:09 3,590,656 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-03-01 23:28:42 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-10-10 23:50:12 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-03-01 12:58:40 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-10-10 23:50:12 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-03-01 12:58:40 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-10-10 23:50:12 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-03-01 12:58:41 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2001-08-24 16:00:00 2,944 -c--a-w C:\WINDOWS\system32\dllcache\null.sys
- 2007-10-10 23:50:12 102,400 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-03-01 12:58:41 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2007-05-17 11:30:03 549,376 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
+ 2007-12-04 18:41:03 550,912 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
- 2006-10-17 16:58:08 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-03-01 12:58:41 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2001-08-24 16:00:00 1,744 -c--a-w C:\WINDOWS\system32\dllcache\sound.drv
+ 2001-08-24 16:00:00 3,360 -c--a-w C:\WINDOWS\system32\dllcache\system.drv
- 2006-04-20 11:51:50 359,808 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-10-30 17:20:55 360,064 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2001-08-24 16:00:00 4,128 -c--a-w C:\WINDOWS\system32\dllcache\timer.drv
- 2007-10-10 23:50:12 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-03-01 12:58:41 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
- 2007-10-10 23:50:12 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-03-01 12:58:42 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2001-08-24 16:00:00 2,176 -c--a-w C:\WINDOWS\system32\dllcache\vga.drv
+ 2004-08-19 20:43:26 23,552 -c--a-w C:\WINDOWS\system32\dllcache\wdmaud.drv
- 2007-10-10 23:50:12 232,960 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-03-01 12:58:42 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2001-08-24 16:00:00 13,600 -c--a-w C:\WINDOWS\system32\dllcache\wfwnet.drv
- 2007-03-08 15:32:46 1,843,712 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2008-03-20 08:09:25 1,845,376 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
- 2007-10-10 23:50:13 824,832 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-03-01 12:58:42 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2001-08-24 16:00:00 2,864 -c--a-w C:\WINDOWS\system32\dllcache\winsock.dll
+ 2004-08-19 13:43:26 146,944 -c--a-w C:\WINDOWS\system32\dllcache\winspool.drv
+ 2001-08-24 16:00:00 2,112 -c--a-w C:\WINDOWS\system32\dllcache\winspool.exe
+ 2001-08-24 16:00:00 2,736 -c--a-w C:\WINDOWS\system32\dllcache\wowdeb.exe
- 2006-06-26 17:41:27 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-02-20 05:35:05 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2007-11-30 04:28:24 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
+ 2006-08-25 03:47:00 2,432 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
+ 2006-08-25 03:47:00 2,560 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
+ 2004-08-04 04:07:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
- 2004-08-03 21:00:58 181,248 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
+ 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
+ 2001-08-24 16:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\null.sys
+ 2008-01-18 04:02:31 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
- 2006-04-20 11:51:50 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2006-10-17 16:58:06 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-03-01 12:58:33 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-10-10 23:50:10 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-03-01 12:58:33 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-10-10 23:50:10 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-03-01 12:58:33 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-12-24 18:49:52 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
- 2007-12-15 11:51:26 399,936 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-05-07 01:21:10 393,568 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-10-10 23:50:10 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-03-01 12:58:33 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2007-10-10 11:00:07 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-02-29 08:55:23 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2007-10-10 23:50:10 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-03-01 12:58:33 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2007-10-10 23:50:10 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-03-01 12:58:34 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2007-10-10 05:46:55 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2007-10-10 23:50:10 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-03-01 12:58:34 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2007-10-10 23:50:10 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-03-01 12:58:34 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2007-10-10 23:50:11 6,065,664 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-03-01 12:58:36 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2007-10-10 23:50:11 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-03-01 12:58:36 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2007-10-10 23:50:11 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-03-01 12:58:37 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2007-10-10 10:59:40 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-02-22 10:00:51 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-06-21 23:59:50 58,776 ----a-w C:\WINDOWS\system32\ijjiPlugin2.dll
+ 2007-09-27 17:08:06 692,224 ----a-w C:\WINDOWS\system32\ijjiSetup.exe
- 2007-10-10 23:50:11 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-03-01 12:58:38 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2001-08-24 16:00:00 2,000 ----a-w C:\WINDOWS\system32\keyboard.drv
+ 2001-08-24 16:00:00 224,736 ----a-w C:\WINDOWS\system32\lanman.drv
- 2006-08-17 12:29:42 726,528 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2007-11-07 09:28:35 726,528 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2001-08-24 16:00:00 2,560 ----a-w C:\WINDOWS\system32\lz32.dll
+ 2007-11-21 00:04:14 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
+ 2008-01-17 16:11:59 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2001-08-24 16:00:00 73,696 ----a-w C:\WINDOWS\system32\mciavi.drv
+ 1998-03-22 18:50:02 11,776 ----a-w C:\WINDOWS\system32\mciqtz.drv
+ 2001-08-24 16:00:00 25,344 ----a-w C:\WINDOWS\system32\mciseq.drv
+ 2001-08-24 16:00:00 28,160 ----a-w C:\WINDOWS\system32\mciwave.drv
+ 2001-08-24 16:00:00 2,032 ----a-w C:\WINDOWS\system32\mouse.drv
- 2007-12-02 23:00:05 18,684,536 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2001-08-24 16:00:00 20,992 ----a-w C:\WINDOWS\system32\msacm32.drv
- 2007-10-10 23:50:11 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-03-01 12:58:38 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-10-10 23:50:11 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-03-01 12:58:38 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2004-08-19 13:43:26 188,416 ----a-w C:\WINDOWS\system32\msh261.drv
+ 2004-08-19 13:56:12 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
- 2007-10-30 23:23:09 3,590,656 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-03-01 23:28:42 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-10-10 23:50:12 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-03-01 12:58:40 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-10-10 23:50:12 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-03-01 12:58:40 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
- 2007-10-10 23:50:12 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-03-01 12:58:41 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2007-07-31 00:19:10 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
+ 2007-07-31 00:19:04 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
+ 2001-08-24 16:00:00 2,656 ----a-w C:\WINDOWS\system32\netware.drv
+ 2005-01-02 21:43:08 4,682 ----a-w C:\WINDOWS\system32\npptNT2.sys
- 2007-10-10 23:50:12 102,400 ----a-w C:\WINDOWS\system32\occache.dll
+ 2008-03-01 12:58:41 102,912 ----a-w C:\WINDOWS\system32\occache.dll
- 2007-05-17 11:30:03 549,376 ----a-w C:\WINDOWS\system32\oleaut32.dll
+ 2007-12-04 18:41:03 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
- 2007-08-08 21:30:12 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
+ 2007-08-06 18:17:40 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
- 2007-10-28 16:36:40 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
+ 2008-02-01 15:15:00 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
+ 2006-10-24 17:30:20 412,160 ------w C:\WINDOWS\system32\photometadatahandler.dll
- 2006-10-17 16:58:08 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-03-01 12:58:41 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-01-18 03:36:57 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
+ 2008-01-18 04:02:14 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
+ 2007-11-30 04:30:28 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
- 2007-01-19 17:53:04 51,056 ----a-w C:\WINDOWS\system32\sirenacm.dll
+ 2007-10-18 16:31:46 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
+ 2001-08-24 16:00:00 1,744 ----a-w C:\WINDOWS\system32\sound.drv
- 2006-12-10 19:10:04 16,176 ------w C:\WINDOWS\system32\spmsg.dll
+ 2006-10-16 21:10:58 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2001-08-23 03:13:16 2,560 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNBPGR02.DLL
- 2006-09-25 22:58:48 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-10-16 21:10:58 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2001-08-24 16:00:00 3,360 ----a-w C:\WINDOWS\system32\system.drv
+ 2001-08-24 16:00:00 4,128 ----a-w C:\WINDOWS\system32\timer.drv
+ 2007-12-12 15:13:52 1,536 ----a-w C:\WINDOWS\system32\TrueSoft.dat
+ 2007-09-04 22:56:10 164,352 ----a-w C:\WINDOWS\system32\unrar.dll
- 2007-10-10 23:50:12 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-03-01 12:58:41 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-10-10 23:50:12 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-03-01 12:58:42 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 1999-05-24 01:07:52 119,568 ----a-w C:\WINDOWS\system32\vb6es.dll
+ 1998-07-28 05:00:00 119,568 ----a-w C:\WINDOWS\system32\VB6ES.DLL
+ 1998-07-28 05:00:00 102,912 ----a-w C:\WINDOWS\system32\VB6STKIT.DLL
+ 2001-08-24 16:00:00 2,176 ----a-w C:\WINDOWS\system32\vga.drv
+ 1998-03-22 19:21:48 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
+ 2004-08-19 20:43:26 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
- 2007-10-10 23:50:12 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-03-01 12:58:42 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2001-08-24 16:00:00 13,600 ----a-w C:\WINDOWS\system32\wfwnet.drv
+ 2006-10-24 17:30:06 716,288 ------w C:\WINDOWS\system32\WindowsCodecs.dll
+ 2006-10-24 17:29:50 352,256 ------w C:\WINDOWS\system32\WindowsCodecsExt.dll
+ 2001-08-24 16:00:00 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
+ 2004-08-19 13:43:26 146,944 ----a-w C:\WINDOWS\system32\winspool.drv
+ 2001-08-24 16:00:00 2,112 ----a-w C:\WINDOWS\system32\winspool.exe
+ 2006-10-24 17:30:00 276,992 ------w C:\WINDOWS\system32\WMPhoto.dll
+ 2001-08-24 16:00:00 2,736 ----a-w C:\WINDOWS\system32\wowdeb.exe
- 2004-07-04 02:59:06 524,288 ----a-w C:\WINDOWS\system32\xvidcore.dll
+ 2007-07-25 19:24:30 1,559,040 ----a-w C:\WINDOWS\system32\xvidcore.dll
- 2004-07-04 03:08:04 139,264 ----a-w C:\WINDOWS\system32\xvidvfw.dll
+ 2007-03-10 17:51:50 282,624 ----a-w C:\WINDOWS\system32\xvidvfw.dll
+ 2004-01-25 22:18:44 217,088 ----a-w C:\WINDOWS\system32\yv12vfw.dll
+ 2000-08-31 13:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
+ 2005-09-23 04:49:12 95,744 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2005-09-23 06:16:02 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-23 06:16:06 1,079,808 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 06:16:08 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-23 06:16:10 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 05:58:06 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2005-09-23 05:58:06 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2005-09-23 05:58:06 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2005-09-23 05:58:06 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2005-09-23 05:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2005-09-23 05:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2005-09-23 05:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2005-09-23 05:58:06 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2005-09-23 05:58:06 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2005-09-23 06:35:10 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
+ 2008-02-01 16:17:36 587,264 ----a-w C:\WINDOWS\WL


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Lestat
post May 11 2008, 06:51 AM
Publicado: #4


Experto Logs HijackThis
Group Icon

Grupo: Global
Mensajes: 9.989
Registrado: 15-April 06
Desde: Vigo-Galicia
Miembro nº: 165.999



El report no esta entero, el proximo lo pegas en dos partes y listo

1.-Abre el Notepad (Bloc de Notas)

* Ir a INICIO > EJECUTAR >
* Y ahí pones notepad.exe y ACEPTAR

2.-Ahora copia y pega estos archivos dentro del Notepad
CODE

KillAll::

File::
C:\sqmdata14.sqm
C:\sqmnoopt14.sqm
C:\sqmdata13.sqm
C:\sqmnoopt13.sqm
C:\sqmdata12.sqm
C:\sqmnoopt12.sqm
C:\Documents and Settings\user\rajm.exe
C:\Documents and Settings\user\wgwlp.exe
C:\Documents and Settings\user\lwwxr.exe
C:\Documents and Settings\user\oqe.exe
C:\Documents and Settings\user\lwwkdgs.exe
C:\Documents and Settings\user\dhtsulx.exe
C:\Documents and Settings\user\gjc.exe
C:\Documents and Settings\user\onnaqhh.exe
C:\Documents and Settings\user\holmfhe.exe
C:\WINDOWS\system32\vkppaa.exe
C:\Documents and Settings\user\lqjctv.exe
C:\sqmnoopt11.sqm
C:\sqmnoopt10.sqm
C:\sqmdata11.sqm
C:\sqmdata10.sqm
C:\sqmnoopt09.sqm
C:\sqmdata09.sqm
C:\Documents and Settings\JONATHAN\Datos de programa\GDIPFONTCACHEV1.DAT
C:\Archivos de programa\graficador.exe
C:\Archivos de programa\graficador.gid
C:\Archivos de programa\graficador.fts
C:\Archivos de programa\graficador.hlp
C:\Archivos de programa\graficador.cnt
C:\WINDOWS\fdsv.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\NirCmd.exe
C:\WINDOWS\Nircmd.exe


3.- Graba este archivo con el nombre CFScript.txt ,déjalo en tu escritorio y reinicia en Modo Seguro.


4.-A continuación arrastrar y soltar el archivo CFScript.txt dentro del archivo ComboFix.exe como lo muestra la animación de abajo. Esto activara ComboFix nuevamente.

imagen externa



Pegas el report y un nuevo log de Hijackthis

Un Saludo
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
pacho929
post May 11 2008, 04:48 PM
Publicado: #5


Newbie
*

Grupo: Members
Mensajes: 18
Registrado: 8-May 08
Miembro nº: 230.796



listo, aqui esta, no se si ya se solucionó pero todo parece normal.

ComboFix 08-05-09.1 - user 2008-05-11 10:16:07.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.3082.18.262 [GMT -5:00]
Se ejecuta desde: C:\Documents and Settings\user\Escritorio\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Escritorio\CFScript.txt

ADVERTENCIA - ESTE EQUIPO NO TIENE INSTALADA LA CONSOLA DE RECUPERACION!

FILE ::
C:\Archivos de programa\graficador.cnt
C:\Archivos de programa\graficador.exe
C:\Archivos de programa\graficador.fts
C:\Archivos de programa\graficador.gid
C:\Archivos de programa\graficador.hlp
C:\Documents and Settings\JONATHAN\Datos de programa\GDIPFONTCACHEV1.DAT
C:\Documents and Settings\user\dhtsulx.exe
C:\Documents and Settings\user\gjc.exe
C:\Documents and Settings\user\holmfhe.exe
C:\Documents and Settings\user\lqjctv.exe
C:\Documents and Settings\user\lwwkdgs.exe
C:\Documents and Settings\user\lwwxr.exe
C:\Documents and Settings\user\onnaqhh.exe
C:\Documents and Settings\user\oqe.exe
C:\Documents and Settings\user\rajm.exe
C:\Documents and Settings\user\wgwlp.exe
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\WINDOWS\fdsv.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\Nircmd.exe
C:\WINDOWS\NirCmd.exe
C:\WINDOWS\system32\vkppaa.exe
.

(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Archivos de programa\graficador.cnt
C:\Archivos de programa\graficador.exe
C:\Archivos de programa\graficador.fts
C:\Archivos de programa\graficador.gid
C:\Archivos de programa\graficador.hlp
C:\Documents and Settings\JONATHAN\Datos de programa\GDIPFONTCACHEV1.DAT
C:\Documents and Settings\user\dhtsulx.exe
C:\Documents and Settings\user\gjc.exe
C:\Documents and Settings\user\holmfhe.exe
C:\Documents and Settings\user\lqjctv.exe
C:\Documents and Settings\user\lwwkdgs.exe
C:\Documents and Settings\user\lwwxr.exe
C:\Documents and Settings\user\onnaqhh.exe
C:\Documents and Settings\user\oqe.exe
C:\Documents and Settings\user\rajm.exe
C:\Documents and Settings\user\wgwlp.exe
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\WINDOWS\fdsv.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\Nircmd.exe
C:\WINDOWS\system32\vkppaa.exe

.
(((((((((((((((((( Archivos creados desde 2008-04-11 - 2008-05-11 )))))))))))))))))))))))))))))))))
.

2008-05-09 07:02 . 2008-05-09 07:02 <DIR> d-------- C:\Documents and Settings\Fabio\Datos de programa\Grisoft
2008-05-08 09:44 . 2008-05-08 09:44 <DIR> d-------- C:\Documents and Settings\user\Datos de programa\Grisoft
2008-05-08 09:44 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-07 21:23 . 2008-05-07 21:23 16,732 --a------ C:\WINDOWS\system32\wbers.dat.dmp
2008-05-07 21:23 . 2008-05-07 21:23 2,313 --a------ C:\WINDOWS\system32\wbers.dat
2008-05-07 20:26 . 2008-05-07 20:26 244 --ah----- C:\sqmnoopt16.sqm
2008-05-07 20:26 . 2008-05-07 20:26 232 --ah----- C:\sqmdata16.sqm
2008-05-07 19:53 . 2008-05-07 19:53 172 --ah----- C:\sqmnoopt15.sqm
2008-05-07 19:53 . 2008-05-07 19:53 172 --ah----- C:\sqmdata15.sqm
2008-05-06 13:53 . 2008-05-06 13:53 <DIR> d-------- C:\Archivos de programa\Microsoft Games
2008-05-05 00:13 . 2008-05-05 00:13 <DIR> d-------- C:\Archivos de programa\Graficador de Ecuaciones
2008-05-05 00:10 . 2008-05-05 00:13 290,816 --------- C:\WINDOWS\Setup1.exe
2008-05-05 00:10 . 2008-05-05 00:13 74,240 --a------ C:\WINDOWS\ST6UNST.EXE
2008-05-04 11:16 . 2008-05-05 01:31 169,120 --a------ C:\WINDOWS\system32\drivers\ndisio.sys
2008-04-23 07:43 . 2008-04-23 07:43 <DIR> d-------- C:\Documents and Settings\Fabio\Datos de programa\U3
2008-04-22 17:29 . 2008-04-22 17:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-04-16 19:30 . 2008-04-16 19:30 <DIR> d-------- C:\Documents and Settings\NetworkService\Datos de programa\Xfire
2008-04-14 22:14 . 2008-05-01 19:38 <DIR> d-------- C:\Documents and Settings\user\Datos de programa\Xfire
2008-04-14 22:14 . 2008-04-29 06:37 <DIR> d---s---- C:\Archivos de programa\Xfire

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-09 18:40 --------- d-----w C:\Archivos de programa\EsetOnlineScanner
2008-05-05 05:12 3,215 ----a-w C:\Archivos de programa\ST6UNST.LOG
2008-05-04 23:08 --------- d-----w C:\Archivos de programa\SUPERAntiSpyware
2008-05-03 23:16 --------- d-----w C:\Archivos de programa\Minilyrics
2008-05-03 23:03 --------- d-----w C:\Archivos de programa\Archivos comunes\AVSMedia
2008-05-03 22:43 --------- d--h--w C:\Archivos de programa\InstallShield Installation Information
2008-04-19 21:30 --------- d-----w C:\Archivos de programa\GameSpy Arcade
2008-04-14 00:13 --------- d-----w C:\Archivos de programa\eMule
2008-04-09 14:45 --------- d-----w C:\Documents and Settings\JONATHAN\Datos de programa\Media Player Classic
2008-04-03 04:54 --------- d-----w C:\Documents and Settings\user\Datos de programa\Media Player Classic
2008-03-21 21:37 --------- d-----w C:\Archivos de programa\ScannerU
2006-11-23 17:24 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-04-01 03:17 40,960 ----a-w C:\Archivos de programa\Uninstall_CDS.exe
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2006-11-26 22:58 56 --sh--r C:\WINDOWS\system32\F910A38595.sys
2006-11-26 22:58 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot_2008-05-10_20.28.18,04 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-11 00:36:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-11 15:19:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vac¡as & entradas leg¡timas predeterminadas no son mostradas

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 08:42 15360]
"swg"="C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 11:06 68856]
"updateMgr"="C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"NBJ"="C:\Archivos de programa\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 19:38 1957888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 16:36 53248 C:\WINDOWS\system32\VTTimer.exe]
"SunJavaUpdateSched"="C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"RemoteControl"="C:\Archivos de programa\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"PCTVOICE"="pctspk.exe" [2003-07-17 14:01 180224 C:\WINDOWS\system32\pctspk.exe]
"nod32kui"="C:\Archivos de programa\Eset\nod32kui.exe" [2007-09-08 10:54 950664]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"InCD"="C:\Archivos de programa\Ahead\InCD\InCD.exe" [2005-06-10 09:20 1397760]
"Cmaudio"="cmicnfg.cpl" []
"PowerDVD"="C:\Archivos de programa\CyberLink DVD Solution\PowerDVD\PowerDVD.exe" [2004-01-07 18:10 413696]
"Microsoft Kinetik Svc"="msftksvc.exe" []
"vkppaa"="C:\WINDOWS\system32\vkppaa.exe" [ ]
"!AVG Anti-Spyware"="C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Archivos de programa\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.YV12"= yv12vfw.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\Explorer.EXE"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccbf89c4-bbc0-11db-8314-00138f142a9b}]
\Shell\AutoRun\command - F:\bltkcde.exe
\Shell\explore\Command - F:\bltkcde.exe
\Shell\open\Command - F:\bltkcde.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{18B0E5C2-99CB-11CF-AXX5-00401C648513}]
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\keygen.exe
.
Contenido de carpeta 'Tareas Programadas'
"2008-05-11 15:22:05 C:\WINDOWS\Tasks\Comprobar actualizaciones de Windows Live Toolbar.job"
- C:\Archivos de programa\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-11 15:22:34 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Archivos de programa\Windows Defender\MpCmdRun.exe
"2008-05-09 20:00:10 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Archivos de programa\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-11 10:22:39
Windows 5.1.2600 Service Pack 2 NTFS

escaneando procesos ocultos ...

escaneando entradas ocultas de autostart ...

escaneando archivos ocultos ...

el escaneo se completo con exito
archivos ocultos: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\ESET\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Tiempo completado: 2008-05-11 10:35:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-11 15:35:10
ComboFix2.txt 2008-05-11 01:29:55

15 dirs 14,612,615,168 bytes libres
18 dirs 14,609,113,088 bytes libres

213 --- E O F --- 2008-05-09 18:29:23

Logfile of HijackThis v1.99.1
Scan saved at 10:48:33 a.m., on 11/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe
C:\Archivos de programa\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\pctspk.exe
C:\Archivos de programa\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\DOCUME~1\user\CONFIG~1\Temp\Rar$EX00.938\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Yahoo! Barra de herramientas - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87