ib_ikram
12-09-2008, 09:15 PM
Hi guys!
Since the last time I ran HJT, Combofix and Malware Bytes, I've had no problems on my computer. But recently, I've started getting annoying things happen again to my computer (random pop-ups telling me to install an antivirus program, yeah right)... so I thought I would run the same process again that I was told to do last time: that is, to run Malware Bytes, then run Combofix, and then run HJT.
Could someone please tell me if my computer's cleared up now? Thanks so much!
Here's the logs:
Malware Bytes
Malwarebytes' Anti-Malware 1.30
Database version: 1403
Windows 5.1.2600 Service Pack 3
12/10/2008 1:43:57 PM
mbam-log-2008-12-10 (13-43-57).txt
Scan type: Quick Scan
Objects scanned: 78193
Time elapsed: 16 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 3
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\pepimude.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\delehele.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\5c0bc4ba (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\cpm5f38f726 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\lalebivipi (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\delehele.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\delehele.dll -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\pepimude.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\edumipep.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\delehele.dll (Trojan.BHO) -> Delete on reboot.
C:\WINDOWS\system32\katowola.dll (Trojan.Agent) -> Delete on reboot.
Combofix
ComboFix 08-12-07.04 - Natan Marsden 2008-12-10 13:51:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.548 [GMT 13:00]
Running from: c:\documents and settings\Natan Marsden\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
.
2008-12-03 19:27 . 2008-12-03 19:27 <DIR> d-------- c:\program files\BitPim
2008-11-29 11:34 . 2008-11-29 11:34 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\documents and settings\Natan Marsden\Application Data\Malwarebytes
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-17 19:40 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-17 19:40 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-16 18:30 . 2008-11-16 18:30 <DIR> d-------- C:\HijackThis
2008-11-16 18:15 . 2008-11-16 18:15 <DIR> d-------- c:\program files\Trend Micro
2008-11-16 18:12 . 2008-11-16 18:16 <DIR> d-------- C:\HJT
2008-11-12 17:46 . 2008-10-25 00:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 17:45 . 2008-09-05 06:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 08:54 . 2008-11-12 08:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-11 18:44 . 2004-07-09 04:26 52,096 --a------ c:\windows\system32\drivers\msdv.sys
2008-11-11 18:44 . 2004-07-09 04:26 52,096 --a--c--- c:\windows\system32\dllcache\msdv.sys
2008-11-11 18:44 . 2004-07-09 04:26 47,104 --a--c--- c:\windows\system32\dllcache\wstdecod.dll
2008-11-11 18:44 . 2004-07-09 04:26 15,104 --a------ c:\windows\system32\drivers\mpe.sys
2008-11-11 18:44 . 2004-07-09 04:26 15,104 --a--c--- c:\windows\system32\dllcache\mpe.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-12-04 22:10 --------- d-----w c:\documents and settings\Everyone else\Application Data\Skype
2008-12-03 06:09 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-11-28 22:34 --------- d-----w c:\program files\Java
2008-11-22 10:33 --------- d-----w c:\program files\SecondLife
2008-11-22 08:01 --------- d-----w c:\program files\LimeWire
2008-11-17 12:53 --------- d-----w c:\program files\DivX
2008-11-12 03:44 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-11 19:53 --------- d-----w c:\program files\Nokia
2008-11-11 19:53 --------- d-----w c:\program files\Common Files\Nokia
2008-11-11 19:51 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-11 05:46 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-11 05:46 --------- d-----w c:\program files\Common Files\Adobe
2008-10-26 12:27 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-10-26 12:26 --------- d-----w c:\program files\AVG
2008-10-26 12:26 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 00:41 --------- d-----w c:\program files\iTunes
2008-10-24 00:41 --------- d-----w c:\program files\iPod
2008-10-24 00:41 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
.
((((((((((((((((((((((((((((( snapshot@2008-11-17_20.21.10.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 07:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-07-18 10:10:48 94,920 ----a-w c:\windows\system32\cdm.dll
+ 2008-10-16 01:09:44 92,696 ----a-w c:\windows\system32\cdm.dll
- 2008-07-18 10:10:48 94,920 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 01:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
- 2008-07-18 10:09:44 563,912 -c--a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 01:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-18 10:10:42 53,448 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 01:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-18 10:09:42 1,811,656 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 01:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-18 10:09:46 325,832 -c--a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 01:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-18 10:10:20 36,552 -c--a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 01:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
- 2008-07-18 10:09:44 205,000 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 01:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
- 2008-06-09 13:21:01 135,168 ----a-w c:\windows\system32\java.exe
+ 2008-11-28 22:34:08 144,792 ----a-w c:\windows\system32\java.exe
- 2008-06-09 13:21:04 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-28 22:34:08 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-06-09 14:32:34 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-28 22:34:08 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-07-23 16:48:40 1,044,480 ----a-w c:\windows\system32\libdivx.dll
+ 2008-09-19 21:55:58 1,044,480 ----a-w c:\windows\system32\libdivx.dll
- 2008-03-25 03:21:18 2,889,088 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 03:21:20 218,496 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUt il.exe
+ 2008-10-05 03:24:04 235,936 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUt il.exe
- 2008-06-21 05:25:00 70,264 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugi n.exe
+ 2008-11-23 01:03:08 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugi n.exe
- 2008-07-18 10:07:34 270,880 ----a-w c:\windows\system32\mucltui.dll
+ 2008-10-16 01:06:48 268,648 ----a-w c:\windows\system32\mucltui.dll
- 2008-07-18 10:07:32 210,976 ----a-w c:\windows\system32\muweb.dll
+ 2008-10-16 01:06:48 208,744 ----a-w c:\windows\system32\muweb.dll
- 2008-09-27 22:52:16 72,356 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-03 05:56:40 72,356 ----a-w c:\windows\system32\perfc009.dat
- 2008-09-27 22:52:16 444,858 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-03 05:56:40 444,858 ----a-w c:\windows\system32\perfh009.dat
+ 2008-10-16 01:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\Ser viceStartup\wups.dll\7.2.6001.788\wups.dll
continued...
Since the last time I ran HJT, Combofix and Malware Bytes, I've had no problems on my computer. But recently, I've started getting annoying things happen again to my computer (random pop-ups telling me to install an antivirus program, yeah right)... so I thought I would run the same process again that I was told to do last time: that is, to run Malware Bytes, then run Combofix, and then run HJT.
Could someone please tell me if my computer's cleared up now? Thanks so much!
Here's the logs:
Malware Bytes
Malwarebytes' Anti-Malware 1.30
Database version: 1403
Windows 5.1.2600 Service Pack 3
12/10/2008 1:43:57 PM
mbam-log-2008-12-10 (13-43-57).txt
Scan type: Quick Scan
Objects scanned: 78193
Time elapsed: 16 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 3
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\pepimude.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\delehele.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\5c0bc4ba (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\cpm5f38f726 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\lalebivipi (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\delehele.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\delehele.dll -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\pepimude.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\edumipep.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\delehele.dll (Trojan.BHO) -> Delete on reboot.
C:\WINDOWS\system32\katowola.dll (Trojan.Agent) -> Delete on reboot.
Combofix
ComboFix 08-12-07.04 - Natan Marsden 2008-12-10 13:51:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.548 [GMT 13:00]
Running from: c:\documents and settings\Natan Marsden\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
.
2008-12-03 19:27 . 2008-12-03 19:27 <DIR> d-------- c:\program files\BitPim
2008-11-29 11:34 . 2008-11-29 11:34 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\documents and settings\Natan Marsden\Application Data\Malwarebytes
2008-11-17 19:40 . 2008-11-17 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-17 19:40 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-17 19:40 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-16 18:30 . 2008-11-16 18:30 <DIR> d-------- C:\HijackThis
2008-11-16 18:15 . 2008-11-16 18:15 <DIR> d-------- c:\program files\Trend Micro
2008-11-16 18:12 . 2008-11-16 18:16 <DIR> d-------- C:\HJT
2008-11-12 17:46 . 2008-10-25 00:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 17:45 . 2008-09-05 06:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 08:54 . 2008-11-12 08:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-11 18:44 . 2004-07-09 04:26 52,096 --a------ c:\windows\system32\drivers\msdv.sys
2008-11-11 18:44 . 2004-07-09 04:26 52,096 --a--c--- c:\windows\system32\dllcache\msdv.sys
2008-11-11 18:44 . 2004-07-09 04:26 47,104 --a--c--- c:\windows\system32\dllcache\wstdecod.dll
2008-11-11 18:44 . 2004-07-09 04:26 15,104 --a------ c:\windows\system32\drivers\mpe.sys
2008-11-11 18:44 . 2004-07-09 04:26 15,104 --a--c--- c:\windows\system32\dllcache\mpe.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-12-04 22:10 --------- d-----w c:\documents and settings\Everyone else\Application Data\Skype
2008-12-03 06:09 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-11-28 22:34 --------- d-----w c:\program files\Java
2008-11-22 10:33 --------- d-----w c:\program files\SecondLife
2008-11-22 08:01 --------- d-----w c:\program files\LimeWire
2008-11-17 12:53 --------- d-----w c:\program files\DivX
2008-11-12 03:44 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-11 19:53 --------- d-----w c:\program files\Nokia
2008-11-11 19:53 --------- d-----w c:\program files\Common Files\Nokia
2008-11-11 19:51 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-11 05:46 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-11 05:46 --------- d-----w c:\program files\Common Files\Adobe
2008-10-26 12:27 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-10-26 12:26 --------- d-----w c:\program files\AVG
2008-10-26 12:26 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 00:41 --------- d-----w c:\program files\iTunes
2008-10-24 00:41 --------- d-----w c:\program files\iPod
2008-10-24 00:41 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
.
((((((((((((((((((((((((((((( snapshot@2008-11-17_20.21.10.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 07:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-07-18 10:10:48 94,920 ----a-w c:\windows\system32\cdm.dll
+ 2008-10-16 01:09:44 92,696 ----a-w c:\windows\system32\cdm.dll
- 2008-07-18 10:10:48 94,920 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 01:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
- 2008-07-18 10:09:44 563,912 -c--a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 01:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-18 10:10:42 53,448 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 01:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-18 10:09:42 1,811,656 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 01:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-18 10:09:46 325,832 -c--a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 01:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-18 10:10:20 36,552 -c--a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 01:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
- 2008-07-18 10:09:44 205,000 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 01:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
- 2008-06-09 13:21:01 135,168 ----a-w c:\windows\system32\java.exe
+ 2008-11-28 22:34:08 144,792 ----a-w c:\windows\system32\java.exe
- 2008-06-09 13:21:04 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-28 22:34:08 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-06-09 14:32:34 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-28 22:34:08 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-07-23 16:48:40 1,044,480 ----a-w c:\windows\system32\libdivx.dll
+ 2008-09-19 21:55:58 1,044,480 ----a-w c:\windows\system32\libdivx.dll
- 2008-03-25 03:21:18 2,889,088 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 03:21:20 218,496 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUt il.exe
+ 2008-10-05 03:24:04 235,936 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUt il.exe
- 2008-06-21 05:25:00 70,264 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugi n.exe
+ 2008-11-23 01:03:08 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugi n.exe
- 2008-07-18 10:07:34 270,880 ----a-w c:\windows\system32\mucltui.dll
+ 2008-10-16 01:06:48 268,648 ----a-w c:\windows\system32\mucltui.dll
- 2008-07-18 10:07:32 210,976 ----a-w c:\windows\system32\muweb.dll
+ 2008-10-16 01:06:48 208,744 ----a-w c:\windows\system32\muweb.dll
- 2008-09-27 22:52:16 72,356 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-03 05:56:40 72,356 ----a-w c:\windows\system32\perfc009.dat
- 2008-09-27 22:52:16 444,858 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-03 05:56:40 444,858 ----a-w c:\windows\system32\perfh009.dat
+ 2008-10-16 01:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\Ser viceStartup\wups.dll\7.2.6001.788\wups.dll
continued...