Ik geef het op...

  • Juut

    Na een hele dag en nacht geprobeerd te hebben virussen uit mijn pc te krijgen met oa avg, spybot s&d, adaware, combofix, lukt het niet om hem weer normaal te krijgen.

    De computer loopt continu vast, ik krijg valse meldingen, comcofix gaf aan geen scan te kunnen doen omdat er vermoedelijk een virus in de pc zit ( hij gaf de naam aan, maar ben ik vergeten op te schrijven) maar iig kon combofix daarom geen scan doen, wel in de veilige modus, maar als ik dan weer in de normale modus opstartte was er geen verandering, en downloade mijn computer weer van alles en nog wat op de achtergrond.

    Het is gelukt om een hijacklog te maken, en hopelijk is er iemand die het probleem en de oplossing voor mij weet.

    Alvast heel erg bedankt.

    Groetjes,

    Judith, die nu gaat slapen.

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 4:44:15, on 18-4-2010

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\AVG\AVG9\avgchsvx.exe

    C:\Program Files\AVG\AVG9\avgrsx.exe

    C:\Program Files\AVG\AVG9\avgcsrvx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\AVG\AVG9\avgwdsvc.exe

    C:\Program Files\AVG\AVG9\avgnsx.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

    O4 - HKLM\..\Run: C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\System32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\S-1-5-18\..\Run: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User ‘SYSTEM’)

    O4 - HKUS\S-1-5-18\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\System32\CTFMON.EXE (User ‘Default user’)

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab

    O16 - DPF: {068BFA33-99F4-4BA9-887D-182386FA2931} (CPlayFirstDinerDashControl Object) - http://download.playfirst.com/play/game/spongebobdash/SpongeBobDinerDashWeb.1.0.0.17.cab

    O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://juutjesspace.spaces.live.com//PhotoUpload/MsnPUpld.cab

    O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://download.playfirst.com/play/game/dinerdash2/DinerDash2.1.0.0.67.cab

    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://juutjesspace.spaces.live.com/PhotoUpload/MsnPUpld.cab

    O16 - DPF: {B102CE69-5C2F-4363-9E6D-C61B61FD92DD} (OGGPlay.UserControl1) - http://familiafm.streamonfiber.com/player/activex/oggplay.CAB

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game12.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.chat-united.com/controls/msnchat45.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    End of file - 6850 bytes

  • Luca

    Plaats ook even het gevraagde logje van Mbam aub. In je Hijackthis log kan ik niks bijzonders ontdekken, maar ik ben dan ook geen expert met dit soort dingen. Wacht daarom even de reactie van één van de andere helpers af.

  • fazantje

    Hoi Juut,

    Eerst even de stappen uitvoeren van de volgende link:

    http://antivirus.startpagina.nl/prikbord/4625317/voer-dit-eerst-uit-voordat-je-de-logjes-plaatst!!#msg-4625317

    Daarna de 2 gevraagde (nieuwe) logjes plaatsen.

    Succes,

    Huib:)

  • Juut

    Hallo, daar ben ik weer.

    Het is me gelukt om een mbamlog en een combofixlog te maken.

    Hier de mbamlog:

    Malwarebytes' Anti-Malware 1.45

    www.malwarebytes.org

    Databaseversie: 3930

    Windows 5.1.2600 Service Pack 2

    Internet Explorer 8.0.6001.18702

    18-4-2010 22:37:18

    mbam-log-2010-04-18 (22-37-18).txt

    Scantype: Volledige scan (C:\|)

    Objecten gescand: 165525

    Verstreken tijd: 1 uur/uren, 19 minuut/minuten, 0 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 0

    Registerwaarden geïnfecteerd: 0

    Registerdata geïnfecteerd: 0

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 1

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden geïnfecteerd:

    C:\Documents and Settings\Juut\Favorieten\Mp3 Download Free.url (Rogue.Link) -> Quarantined and deleted successfully.

  • Juut

    en hier de combofixlog:

    ComboFix 10-04-17.02 - Juut 18-04-2010 20:37:13.6.1 - x86

    Microsoft Windows XP Professional 5.1.2600.2.1252.31.1043.18.382.74

    Gestart vanuit: c:\documents and settings\Juut\Bureaublad\ComboFix.exe

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2010-03-18 to 2010-04-18 ))))))))))))))))))))))))))))))

    .

    2010-04-18 11:43 . 2010-04-18 11:43 ——– d—–w- c:\documents and settings\Juut\Application Data\Malwarebytes

    2010-04-18 11:42 . 2010-03-29 22:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys

    2010-04-18 11:42 . 2010-04-18 11:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes

    2010-04-18 11:42 . 2010-03-29 22:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys

    2010-04-18 11:42 . 2010-04-18 11:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware

    2010-04-17 19:54 . 2010-02-05 09:03 15880 —-a-w- c:\windows\system32\lsdelete.exe

    2010-04-17 01:37 . 2010-04-17 01:37 ——– d–h–r- c:\documents and settings\Juut\Onlangs geopend

    2010-04-16 23:20 . 2010-02-05 09:03 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys

    2010-04-16 23:19 . 2010-04-16 23:19 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys

    2010-04-16 23:14 . 2010-04-16 23:15 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{52AC600B-5800-407E-99FF-83CD0669760B}

    2010-04-16 22:17 . 2010-04-16 22:17 ——– d—–w- C:\$AVG

    2010-04-16 21:47 . 2010-04-16 21:48 12464 —-a-w- c:\windows\system32\avgrsstx.dll

    2010-04-16 21:47 . 2010-04-16 21:47 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys

    2010-04-16 21:47 . 2010-04-16 21:47 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys

    2010-04-16 21:47 . 2010-04-16 21:47 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys

    2010-04-16 21:47 . 2010-04-17 10:19 ——– d—–w- c:\windows\system32\drivers\Avg

    2010-04-16 21:41 . 2010-04-16 21:41 ——– d—–w- c:\program files\AVG

    2010-04-16 21:40 . 2010-04-16 21:41 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9

    2010-04-16 21:34 . 2010-04-12 15:29 411368 —-a-w- c:\windows\system32\deployJava1.dll

    2010-04-16 20:50 . 2010-04-16 20:53 ——– dc-h–w- c:\windows\ie8

    2010-04-16 19:09 . 2010-04-17 19:29 ——– d—–w- c:\program files\Spybot - Search & Destroy

    2010-04-16 19:05 . 2010-04-17 22:35 ——– d–h–r- c:\documents and settings\Administrator.MADELON-OE8BVVF\Onlangs geopend

    2010-04-16 19:04 . 2010-04-17 01:30 ——– d—–w- c:\program files\CCleaner

    2010-04-16 18:21 . 2010-04-16 18:21 ——– d—–w- c:\documents and settings\Administrator.MADELON-OE8BVVF\Local Settings\Application Data\Downloaded Installations

    2010-04-16 18:14 . 2010-04-16 18:14 ——– d-sh–w- c:\documents and settings\Administrator.MADELON-OE8BVVF\PrivacIE

    2010-04-16 18:06 . 2010-04-16 18:06 ——– d—–w- c:\windows\system32\wbem\Repository

    2010-04-16 17:57 . 2010-04-16 17:57 20144 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

    2010-04-16 17:57 . 2010-04-16 17:57 ——– d—–w- c:\documents and settings\Administrator\PrivacIE

    2010-04-16 17:56 . 2010-04-16 17:56 ——– d—–w- c:\documents and settings\Administrator\IETldCache

    2010-04-16 17:55 . 2010-04-16 18:03 ——– d-s—w- c:\documents and settings\Administrator

    2010-04-16 17:55 . 2010-04-16 18:03 ——– d—–w- c:\documents and settings\Administrator\Sjablonen

    2010-04-16 17:55 . 2010-04-16 18:03 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft

    2010-04-16 17:55 . 2010-04-16 17:56 ——– d—–w- c:\documents and settings\Administrator\Favorieten

    2010-04-16 17:52 . 2010-04-16 17:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2010-04-17 22:35 . 2008-08-30 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

    2010-04-16 23:15 . 2007-04-01 13:14 ——– d—–w- c:\program files\Lavasoft

    2010-04-16 21:35 . 2010-04-16 21:35 503808 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3b61523a-n\msvcp71.dll

    2010-04-16 21:35 . 2010-04-16 21:35 499712 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3b61523a-n\jmc.dll

    2010-04-16 21:35 . 2010-04-16 21:35 348160 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3b61523a-n\msvcr71.dll

    2010-04-16 21:35 . 2010-04-16 21:35 61440 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f8b854d-n\decora-sse.dll

    2010-04-16 21:35 . 2010-04-16 21:35 12800 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f8b854d-n\decora-d3d.dll

    2010-04-16 21:32 . 2009-06-12 15:10 ——– d—–w- c:\program files\Java

    2010-04-16 21:08 . 2010-04-16 21:08 79488 —-a-w- c:\documents and settings\Juut\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll

    2010-04-16 21:01 . 2009-10-15 16:16 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys

    2010-04-16 21:01 . 2001-09-07 12:00 86256 —-a-w- c:\windows\system32\perfc013.dat

    2010-04-16 21:01 . 2001-09-07 12:00 499226 —-a-w- c:\windows\system32\perfh013.dat

    2010-04-16 20:38 . 2007-04-02 15:24 ——– d—–w- c:\program files\Eset

    2010-03-10 06:17 . 2004-08-03 23:03 420352 —-a-w- c:\windows\system32\vbscript.dll

    2010-03-08 15:54 . 2010-03-08 15:54 20 —-a-w- c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

    2010-03-08 15:36 . 2010-03-08 15:36 20 —-a-w- c:\documents and settings\Juut\Application Data\rbuwzv.dat

    2010-03-02 16:39 . 2008-06-16 16:39 ——– d—–w- c:\documents and settings\Juut\Application Data\Canon

    2010-02-25 06:20 . 2004-08-03 23:03 916480 —-a-w- c:\windows\system32\wininet.dll

    2010-02-24 12:31 . 2004-08-03 21:15 454016 —-a-w- c:\windows\system32\drivers\mrxsmb.sys

    2010-02-16 19:35 . 2004-08-03 22:58 2185728 —-a-w- c:\windows\system32\ntoskrnl.exe

    2010-02-16 19:35 . 2004-08-04 00:58 2062720 —-a-w- c:\windows\system32\ntkrnlpa.exe

    2010-02-12 04:47 . 2004-08-03 23:03 100864 —-a-w- c:\windows\system32\6to4svc.dll

    2010-02-11 12:01 . 2004-08-03 21:07 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys

    2010-02-05 09:04 . 2010-04-16 23:14 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{52AC600B-5800-407E-99FF-83CD0669760B}\Ad-AwareInstaller.exe

    .

    ——- Sigcheck ——-

    2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . . . c:\windows\erdnt\cache\atapi.sys

    2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . . . c:\windows\system32\drivers\atapi.sys

    2004-08-03 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . . . c:\windows\erdnt\cache\asyncmac.sys

    2004-08-03 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . . . c:\windows\system32\dllcache\asyncmac.sys

    2004-08-03 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . . . c:\windows\system32\drivers\asyncmac.sys

    2001-09-07 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . . . c:\windows\erdnt\cache\beep.sys

    2001-09-07 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . . . c:\windows\system32\dllcache\beep.sys

    2001-09-07 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . . . c:\windows\system32\drivers\beep.sys

    2004-08-03 . 59549E9180CE29D832289E1A1D9E3C60 . 25216 . . . . c:\windows\erdnt\cache\kbdclass.sys

    2004-08-03 . 59549E9180CE29D832289E1A1D9E3C60 . 25216 . . . . c:\windows\system32\drivers\kbdclass.sys

    2004-08-03 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . . . c:\windows\erdnt\cache\ndis.sys

    2004-08-03 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . . . c:\windows\system32\dllcache\ndis.sys

    2004-08-03 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . . . c:\windows\system32\drivers\ndis.sys

    2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys

    2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . . . c:\windows\erdnt\cache\ntfs.sys

    2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . . . c:\windows\system32\dllcache\ntfs.sys

    2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . . . c:\windows\system32\drivers\ntfs.sys

    2004-08-03 . B78BE402C3F63DD55521F73876951CDD . 574592 . . . . c:\windows\$NtUninstallKB930916$\ntfs.sys

    2001-09-07 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . . . c:\windows\erdnt\cache\null.sys

    2001-09-07 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . . . c:\windows\system32\dllcache\null.sys

    2001-09-07 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . . . c:\windows\system32\drivers\null.sys

    2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

    2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys

    2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . . . c:\windows\erdnt\cache\tcpip.sys

    2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . . . c:\windows\system32\dllcache\tcpip.sys

    2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . . . c:\windows\system32\drivers\tcpip.sys

    2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys

    2007-10-30 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . . . c:\windows\$NtUninstallKB951748$\tcpip.sys

    2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys

    2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys

    2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . . . c:\windows\$NtUninstallKB941644$\tcpip.sys

    2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . . . c:\windows\$NtUninstallKB917953$\tcpip.sys

    2004-08-03 . 195B1255D9383AEFFBDFA8A11AE4D282 . 77312 . . . . c:\windows\erdnt\cache\browser.dll

    2004-08-03 . 195B1255D9383AEFFBDFA8A11AE4D282 . 77312 . . . . c:\windows\system32\browser.dll

    2004-08-03 . 195B1255D9383AEFFBDFA8A11AE4D282 . 77312 . . . . c:\windows\system32\dllcache\browser.dll

    2004-08-03 . 34A82DEBEFB057FCCCBE15F619FC98A7 . 13312 . . . . c:\windows\erdnt\cache\lsass.exe

    2004-08-03 . 34A82DEBEFB057FCCCBE15F619FC98A7 . 13312 . . . . c:\windows\system32\lsass.exe

    2004-08-03 . 34A82DEBEFB057FCCCBE15F619FC98A7 . 13312 . . . . c:\windows\system32\dllcache\lsass.exe

    2005-08-22 . F32049792BCBF64954FF964508E47AFB . 197632 . . . . c:\windows\erdnt\cache\netman.dll

    2005-08-22 . F32049792BCBF64954FF964508E47AFB . 197632 . . . . c:\windows\system32\netman.dll

    2005-08-22 . F32049792BCBF64954FF964508E47AFB . 197632 . . . . c:\windows\system32\dllcache\netman.dll

    2005-08-22 . 269182FF03F1FDD0EF803AEB63C01080 . 197632 . . . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll

    2004-08-03 . B2665A1B502EC037388B7919CBD58C28 . 198144 . . . . c:\windows\$NtUninstallKB905414$\netman.dll

    2004-08-03 . 772027CC5FFAEA3E7D10AF2691EE7095 . 382464 . . . . c:\windows\erdnt\cache\qmgr.dll

    2004-08-03 . 772027CC5FFAEA3E7D10AF2691EE7095 . 382464 . . . . c:\windows\system32\qmgr.dll

    2004-08-03 . 772027CC5FFAEA3E7D10AF2691EE7095 . 382464 . . . . c:\windows\system32\dllcache\qmgr.dll

    2009-02-09 . D8D28F6CABEC7D42B8E487E290563B9A . 401408 . . . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll

    2009-02-09 . D9883335CC1C17AFC3A09C8AC3E4DBE4 . 401408 . . . . c:\windows\$hf_mig$\KB956572\SP3GDR\rpcss.dll

    2009-02-09 . 75A47F738E7DB78000A55D743BDEE275 . 399360 . . . . c:\windows\erdnt\cache\rpcss.dll

    2009-02-09 . 75A47F738E7DB78000A55D743BDEE275 . 399360 . . . . c:\windows\system32\rpcss.dll

    2009-02-09 . 75A47F738E7DB78000A55D743BDEE275 . 399360 . . . . c:\windows\system32\dllcache\rpcss.dll

    2009-02-09 . 72C2074FFA3B38078173A11008198019 . 401408 . . . . c:\windows\$hf_mig$\KB956572\SP2QFE\rpcss.dll

    2005-07-26 . B52BD9DB0BD6D01BDB01B0DBFBB804CD . 397824 . . . . c:\windows\$NtUninstallKB956572$\rpcss.dll

    2005-07-26 . 23B465FD2354D83218AC091D0EE6D91B . 398336 . . . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll

    2005-04-28 . 6D61211D515EA7E31FDB7B0FA9CEF878 . 396288 . . . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll

    2005-04-28 . 0468AA524F6912F449BC14CF7DACAF68 . 395776 . . . . c:\windows\$NtUninstallKB902400$\rpcss.dll

    2004-08-03 . DDE0457B7706C3AD4E5AFDD502698A06 . 395776 . . . . c:\windows\$NtUninstallKB894391$\rpcss.dll

    2009-02-09 . 657B69389B893F440B07590C9E963F23 . 111104 . . . . c:\windows\$hf_mig$\KB956572\SP3GDR\services.exe

    2009-02-09 . D98A222A707FFE40043E533FE7A6BA24 . 111104 . . . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe

    2009-02-09 . 1A00FCECA4E29A6B4B33A9D0B3E7CBA0 . 111104 . . . . c:\windows\erdnt\cache\services.exe

    2009-02-09 . 1A00FCECA4E29A6B4B33A9D0B3E7CBA0 . 111104 . . . . c:\windows\system32\services.exe

    2009-02-09 . 1A00FCECA4E29A6B4B33A9D0B3E7CBA0 . 111104 . . . . c:\windows\system32\dllcache\services.exe

    2009-02-09 . CE06E39F34BBF6B0ADA70F37F70CF0D8 . 111104 . . . . c:\windows\$hf_mig$\KB956572\SP2QFE\services.exe

    2004-08-03 . 39991CD3C17B7529D039151A88E84499 . 108544 . . . . c:\windows\$NtUninstallKB956572$\services.exe

    2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe

    2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . . . c:\windows\erdnt\cache\spoolsv.exe

    2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . . . c:\windows\system32\spoolsv.exe

    2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . . . c:\windows\system32\dllcache\spoolsv.exe

    2004-08-03 . CCCB8B94B17466EFB9DC27F42625B0E5 . 57856 . . . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

    2004-08-03 . 732ED791711DF9C9DD15E5515BC681B8 . 504832 . . . . c:\windows\erdnt\cache\winlogon.exe

    2004-08-03 . 732ED791711DF9C9DD15E5515BC681B8 . 504832 . . . . c:\windows\system32\winlogon.exe

    2004-08-03 . 732ED791711DF9C9DD15E5515BC681B8 . 504832 . . . . c:\windows\system32\dllcache\winlogon.exe

    2006-08-25 . F67AE54BCA3873D48A1AC722A9CA70BF . 617472 . . . . c:\windows\erdnt\cache\comctl32.dll

    2006-08-25 . F67AE54BCA3873D48A1AC722A9CA70BF . 617472 . . . . c:\windows\system32\comctl32.dll

    2006-08-25 . F67AE54BCA3873D48A1AC722A9CA70BF . 617472 . . . . c:\windows\system32\dllcache\comctl32.dll

    2004-08-03 . 8A473F553E9E45DB4EF6FF11AB54E4E1 . 611328 . . . . c:\windows\$NtUninstallKB923191$\comctl32.dll

    2004-08-03 . 5F321535D399516B6D780FF9EF8D8B7A . 60416 . . . . c:\windows\erdnt\cache\cryptsvc.dll

    2004-08-03 . 5F321535D399516B6D780FF9EF8D8B7A . 60416 . . . . c:\windows\system32\cryptsvc.dll

    2004-08-03 . 5F321535D399516B6D780FF9EF8D8B7A . 60416 . . . . c:\windows\system32\dllcache\cryptsvc.dll

    2008-07-07 20:32 . 68180553F674B487BE777CFD6BE70726 . 253952 . . . . c:\windows\erdnt\cache\es.dll

    2008-07-07 20:32 . 68180553F674B487BE777CFD6BE70726 . 253952 . . . . c:\windows\system32\es.dll

    2008-07-07 20:32 . 68180553F674B487BE777CFD6BE70726 . 253952 . . . . c:\windows\system32\dllcache\es.dll

    2008-07-07 20:30 . 97912DC0679D2DA60CCE589BBC196D72 . 253952 . . . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll

    2008-07-07 20:26 . F6C37073A269C163A5FDAE5BFF47F367 . 253952 . . . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll

    2008-07-07 20:23 . B3A4422CBD8DAA6710431F67C679DA24 . 253952 . . . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll

    2005-07-26 04:42 . 094ECC4FB57ABA154F840C8414867E90 . 243200 . . . . c:\windows\$NtUninstallKB950974$\es.dll

    2005-07-26 04:36 . 3732BE0811CE6E15A56AD1CEC02CF532 . 243200 . . . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll

    2004-08-03 23:03 . 3F59BCDFAC47550F43001C4CE8CB0B91 . 243200 . . . . c:\windows\$NtUninstallKB902400$\es.dll

    2004-08-03 . 7ADE4584ED6657CAE3D523CF101992BD . 110080 . . . . c:\windows\erdnt\cache\imm32.dll

    2004-08-03 . 7ADE4584ED6657CAE3D523CF101992BD . 110080 . . . . c:\windows\system32\imm32.dll

    2004-08-03 . 7ADE4584ED6657CAE3D523CF101992BD . 110080 . . . . c:\windows\system32\dllcache\imm32.dll

    2009-03-21 . B30975B6B1B08A5A18AAC7E3577C7C53 . 1027072 . . . . c:\windows\erdnt\cache\kernel32.dll

    2009-03-21 . B30975B6B1B08A5A18AAC7E3577C7C53 . 1027072 . . . . c:\windows\system32\kernel32.dll

    2009-03-21 . B30975B6B1B08A5A18AAC7E3577C7C53 . 1027072 . . . . c:\windows\system32\dllcache\kernel32.dll

    2009-03-21 . CE7EFE07C7119C8CD09D953AD9ECA7CD . 1030656 . . . . c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll

    2009-03-21 . 93E2307273AE7B2D5418E132902373A7 . 1032704 . . . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll

    2009-03-21 . 67A29642EC9A1ADA0768605B21AA4552 . 1030144 . . . . c:\windows\$hf_mig$\KB959426\SP2QFE\kernel32.dll

    2007-04-16 . 68757F5935D6D76DD10975B7B7A9751D . 1027072 . . . . c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll

    2007-04-16 . 6557EA471552BB9AF16B66902D572BD5 . 1025536 . . . . c:\windows\$NtUninstallKB959426$\kernel32.dll

    2006-07-05 . 8672CE1E9BAF84EC0665D73DB8849EDB . 1026048 . . . . c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll

    2006-07-05 . F2352FB7D9E5C70374568724A32B5CB7 . 1025024 . . . . c:\windows\$NtUninstallKB935839$\kernel32.dll

    2004-08-03 . 54379BD67780FDBBE1590EEC142A659C . 1024512 . . . . c:\windows\$NtUninstallKB917422$\kernel32.dll

    2005-09-01 . BDF49EB509B446650A752F751634AA1C . 19968 . . . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll

    2005-09-01 . 74B59D2B62583D3932FCE6CBB6EB5F77 . 19968 . . . . c:\windows\erdnt\cache\linkinfo.dll

    2005-09-01 . 74B59D2B62583D3932FCE6CBB6EB5F77 . 19968 . . . . c:\windows\system32\linkinfo.dll

    2005-09-01 . 74B59D2B62583D3932FCE6CBB6EB5F77 . 19968 . . . . c:\windows\system32\dllcache\linkinfo.dll

    2004-08-03 . 5B42639BE48C8E84FD52C66958A44427 . 18944 . . . . c:\windows\$NtUninstallKB900725$\linkinfo.dll

    2004-08-03 . 8DF7AC820F9B3FD5E713E9A74827931C . 22016 . . . . c:\windows\erdnt\cache\lpk.dll

    2004-08-03 . 8DF7AC820F9B3FD5E713E9A74827931C . 22016 . . . . c:\windows\system32\lpk.dll

    2004-08-03 . 8DF7AC820F9B3FD5E713E9A74827931C . 22016 . . . . c:\windows\system32\dllcache\lpk.dll

    2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . . . c:\windows\erdnt\cache\mshtml.dll

    2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . . . c:\windows\SoftwareDistribution\Download\91c291a86d685093ffe1fda43df36102\SP3GDR\mshtml.dll

    2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . . . c:\windows\system32\mshtml.dll

    2010-02-25 . A38971E011619C2CF1B87ADE965F5DD4 . 5944832 . . . . c:\windows\system32\dllcache\mshtml.dll

    2010-02-25 . 2399C13AE076A84037794AA0E9BF152A . 5946880 . . . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll

    2010-02-25 . 2399C13AE076A84037794AA0E9BF152A . 5946880 . . . . c:\windows\SoftwareDistribution\Download\91c291a86d685093ffe1fda43df36102\SP3QFE\mshtml.dll

    2009-12-21 . 585A8B2FD6373FC06D6893867754CF74 . 5945856 . . . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll

    2009-10-29 . 6D626567986D37E021F44EE66446D515 . 5944320 . . . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll

    2009-10-22 . A7A81279E5D4E79886EB3EE0D8C0B5B0 . 5943296 . . . . c:\windows\$hf_mig$\KB976749-IE8\SP3QFE\mshtml.dll

    2009-08-29 . 618B612AC467401AAF9DE95EC8927372 . 5942272 . . . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\mshtml.dll

    2009-07-19 . 2644060A699C0654B609F24CE5A322D8 . 5938176 . . . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\mshtml.dll

    2009-05-13 . 099182C5D0A74802A9818C510B870124 . 5936128 . . . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\mshtml.dll

    2009-04-29 . D987EC1A7B0E44BA64B4F3F9FA2FC675 . 3596288 . . . . c:\windows\ie8\mshtml.dll

    2009-04-29 . 65B7FE26ABEC85DCAA6EB610D7AFA544 . 3598336 . . . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\mshtml.dll

    2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . . . c:\windows\ie8updates\KB980182-IE8\mshtml.dll

    2009-02-21 . ED8D8B5B74BC2F3F62DC3136294334F5 . 3596800 . . . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll

    2009-02-20 . 48CB187C52D11616A96EDE7E02FEFFB6 . 3595264 . . . . c:\windows\ie7updates\KB969897-IE7\mshtml.dll

    2009-01-16 . A1F6948767628BBFCA8E91D5D41A2B24 . 3594752 . . . . c:\windows\ie7updates\KB963027-IE7\mshtml.dll

    2009-01-16 . 8DA948871A1664116F51E4149963E4DA . 3596288 . . . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll

    2008-12-13 . A2D4AE79DB67AC64BCA2551942417334 . 3593216 . . . . c:\windows\ie7updates\KB961260-IE7\mshtml.dll

    2008-12-13 . B621B834A8F81D4D4550B91760261B77 . 3594752 . . . . c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll

    2008-10-17 . CDBF095A4621CBA1F8DAB87CEEE9C5F5 . 3593216 . . . . c:\windows\ie7updates\KB960714-IE7\mshtml.dll

    2008-10-16 . EE6E909D702975A8DC842B45832AF5B7 . 3595264 . . . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll

    2008-08-27 . 4681D5AF0FAE690BA98C6020DC717FAA . 3593216 . . . . c:\windows\ie7updates\KB958215-IE7\mshtml.dll

    2008-08-26 . 5BE5C242C6ABF45CB3195CA6751D0272 . 3594752 . . . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll

    2008-06-25 . 0DF998D5B19A8A3463F8E38402A026EC . 3088896 . . . . c:\windows\$hf_mig$\KB953838\SP3QFE\mshtml.dll

    2008-06-24 . C9EE3EB15A2B15BED93CA8E74757E68D . 3592192 . . . . c:\windows\ie7updates\KB956390-IE7\mshtml.dll

    2008-06-24 . C9EE3EB15A2B15BED93CA8E74757E68D . 3592192 . . . . c:\windows\SoftwareDistribution\Download\ea4772a3e9d8b534362bbf4723756836\SP2GDR\mshtml.dll

    2008-06-23 . 6975533B9EDB4A5963E688F7B22C3F79 . 3088384 . . . . c:\windows\$hf_mig$\KB953838\SP2QFE\mshtml.dll

    2008-06-23 . 7853E46554A5D637D8AAD55FB0C4EE7E . 3594240 . . . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll

    2008-06-23 . 7853E46554A5D637D8AAD55FB0C4EE7E . 3594240 . . . . c:\windows\SoftwareDistribution\Download\ea4772a3e9d8b534362bbf4723756836\SP2QFE\mshtml.dll

    2008-06-23 . E3B8523B3F422A8D3C8908F831B53975 . 3080704 . . . . c:\windows\ie7\mshtml.dll

    2008-06-23 . CC51CAD063737BC57732638C990C255B . 3088384 . . . . c:\windows\$hf_mig$\KB953838\SP3GDR\mshtml.dll

    2008-04-21 . B9117A41CA0D9AE3A03756552854E253 . 3080704 . . . . c:\windows\$NtUninstallKB953838$\mshtml.dll

    2008-04-21 . 3F63F6905BE003FA3AA87D91C5997F43 . 3087872 . . . . c:\windows\$hf_mig$\KB950759\SP2QFE\mshtml.dll

    2008-04-21 . A7C4AB35FCAF4BB70D57D74C3602C701 . 3087872 . . . . c:\windows\$hf_mig$\KB950759\SP3GDR\mshtml.dll

    2008-04-21 . 672278873C3BB6898FAFF498C78A99F8 . 3088384 . . . . c:\windows\$hf_mig$\KB950759\SP3QFE\mshtml.dll

    2008-02-16 . A74A1BE8470E8394385DD1192FB7BDB4 . 3080704 . . . . c:\windows\$NtUninstallKB950759$\mshtml.dll

    2008-02-16 . 23EBCD729D2C9E24CF87B6FA0704FDFC . 3087872 . . . . c:\windows\$hf_mig$\KB947864\SP2QFE\mshtml.dll

    2007-12-07 . F0AD6251355086D982EA099963538C95 . 3080192 . . . . c:\windows\$NtUninstallKB947864$\mshtml.dll

    2007-12-07 . 669809D47AE91A47633C0471083E09E7 . 3087360 . . . . c:\windows\$hf_mig$\KB944533\SP2QFE\mshtml.dll

    2007-10-30 . EEE0A2828E50C0452168FB1564AC8055 . 3079680 . . . . c:\windows\$NtUninstallKB944533$\mshtml.dll

    2007-10-30 . 36B42273942F82DA277A15509E8A8F2E . 3086848 . . . . c:\windows\$hf_mig$\KB942615\SP2QFE\mshtml.dll

    2007-08-22 . 272FFF49BD65AA83995D697BB5B5C357 . 3079168 . . . . c:\windows\$NtUninstallKB942615$\mshtml.dll

    2007-08-22 . CCDF2AEC8C6AEB51EE6C4BBFDBB8897E . 3085824 . . . . c:\windows\$hf_mig$\KB939653\SP2QFE\mshtml.dll

    2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . . . c:\windows\ie7updates\KB953838-IE7\mshtml.dll

    2007-06-15 . 34AF8680725DD035053A920683C373BB . 3085312 . . . . c:\windows\$hf_mig$\KB937143\SP2QFE\mshtml.dll

    2007-06-14 . 683372B959D5F69CE3B96266F757FE0B . 3079680 . . . . c:\windows\$NtUninstallKB939653$\mshtml.dll

    2007-05-04 . D9B1913BA7F86A3758A2EAA2E8548A1D . 3085312 . . . . c:\windows\$hf_mig$\KB933566\SP2QFE\mshtml.dll

    2007-05-04 . BFA1BA84ADE42D2F2F8A79D06B44A53A . 3079680 . . . . c:\windows\$NtUninstallKB937143$\mshtml.dll

    2007-02-19 . 4E7FF99E55197D1A772A2152EE7BCB80 . 3077632 . . . . c:\windows\$NtUninstallKB933566$\mshtml.dll

    2007-02-19 . 58777FEFC19FDDE25CB613EFC2B79605 . 3084288 . . . . c:\windows\$hf_mig$\KB931768\SP2QFE\mshtml.dll

    2007-01-04 . 51E8C6369DB16D9F42826DC272C7CC09 . 3083264 . . . . c:\windows\$hf_mig$\KB928090\SP2QFE\mshtml.dll

    2007-01-04 . 3B25611555C91AF75B1AE6E9E46F2674 . 3077632 . . . . c:\windows\$NtUninstallKB931768$\mshtml.dll

    2004-08-03 . 43E31383850CFEA3C0F445BED9A700F4 . 3003392 . . . . c:\windows\$NtUninstallKB928090$\mshtml.dll

    2004-08-03 . 687ABDBF4790F907FB0D3A50B8D9FE3A . 343040 . . . . c:\windows\erdnt\cache\msvcrt.dll

    2004-08-03 . 687ABDBF4790F907FB0D3A50B8D9FE3A . 343040 . . . . c:\windows\system32\msvcrt.dll

    2004-08-03 . 687ABDBF4790F907FB0D3A50B8D9FE3A . 343040 . . . . c:\windows\system32\dllcache\msvcrt.dll

    2008-06-20 . 74816260AECBE87C473962A359007EEB . 247296 . . . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll

    2008-06-20 . 18740E8EC5BE4B6D66FA0E4CBFD3B9C6 . 247296 . . . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll

    2008-06-20 . FF59588E31F864FED9D0258969559A4B . 247296 . . . . c:\windows\erdnt\cache\mswsock.dll

    2008-06-20 . FF59588E31F864FED9D0258969559A4B . 247296 . . . . c:\windows\system32\mswsock.dll

    2008-06-20 . FF59588E31F864FED9D0258969559A4B . 247296 . . . . c:\windows\system32\dllcache\mswsock.dll

    2008-06-20 . 71AB52C70B9436C0A0B704FDE9D1A7CD . 247296 . . . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll

    2004-08-03 . 0C53DB0671AB5A93D169DAFFC8DA11CF . 247296 . . . . c:\windows\$NtUninstallKB951748$\mswsock.dll

    2009-02-06 . 45AE58ACDD9B4A8767064544533F94E2 . 408064 . . . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll

    2009-02-06 . 45AE58ACDD9B4A8767064544533F94E2 . 408064 . . . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll

    2004-08-03 . B3FDAC7A518B6B684BEFE792DC1DC560 . 407040 . . . . c:\windows\erdnt\cache\netlogon.dll

    2004-08-03 . B3FDAC7A518B6B684BEFE792DC1DC560 . 407040 . . . . c:\windows\system32\netlogon.dll

    2004-08-03 . B3FDAC7A518B6B684BEFE792DC1DC560 . 407040 . . . . c:\windows\system32\dllcache\netlogon.dll

    2010-02-17 . FD62829F3524A1BE95FD384A3C445AAB . 2194304 . . . . c:\windows\$hf_mig$\KB979683\SP3GDR\ntoskrnl.exe

    2010-02-17 . FD62829F3524A1BE95FD384A3C445AAB . 2194304 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP3GDR\ntoskrnl.exe

    2010-02-16 . E6CA0044BAC297BE280BCD5AB04B44F6 . 2185728 . . . . c:\windows\Driver Cache\i386\ntoskrnl.exe

    2010-02-16 . E6CA0044BAC297BE280BCD5AB04B44F6 . 2185728 . . . . c:\windows\erdnt\cache\ntoskrnl.exe

    2010-02-16 . E6CA0044BAC297BE280BCD5AB04B44F6 . 2185728 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP2GDR\ntoskrnl.exe

    2010-02-16 . E6CA0044BAC297BE280BCD5AB04B44F6 . 2185728 . . . . c:\windows\system32\ntoskrnl.exe

    2010-02-16 . E6CA0044BAC297BE280BCD5AB04B44F6 . 2185728 . . . . c:\windows\system32\dllcache\ntoskrnl.exe

    2010-02-16 . 481961F97B0526A66EF676E0D00C4180 . 2191232 . . . . c:\windows\$hf_mig$\KB979683\SP2QFE\ntoskrnl.exe

    2010-02-16 . 481961F97B0526A66EF676E0D00C4180 . 2191232 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP2QFE\ntoskrnl.exe

    2010-02-16 . B79C48187CA08D2EC27DA4939953F082 . 2194432 . . . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe

    2010-02-16 . B79C48187CA08D2EC27DA4939953F082 . 2194432 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP3QFE\ntoskrnl.exe

    2009-08-04 . 270DE336026B0815F064BB8BD4CFD336 . 2193536 . . . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntoskrnl.exe

    2009-08-04 . 2F1443AB72A64182FD8258BBAE801EA7 . 2193664 . . . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe

    2009-08-04 . 2FFA33C4FF60E1976FB8C14264215642 . 2190336 . . . . c:\windows\$hf_mig$\KB971486\SP2QFE\ntoskrnl.exe

    2009-08-04 . AF78FB8501887B5F12D6F16811680CEF . 2184704 . . . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe

    2009-02-10 . 7625D5BAFD2A4A8458468B139C893BB7 . 2193536 . . . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe

    2009-02-09 . 0F1A4A14A22DC4B839052DE174B57A33 . 2184832 . . . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe

    2009-02-09 . 35BEF358DAB3E53ADF93AAE4D64F4852 . 2190464 . . . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe

    2009-02-09 . 27380B877348030B0662A39C47AAEC11 . 2193408 . . . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe

    2008-08-14 . E332B6DE826D4222A758E3264AD8D520 . 2193536 . . . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe

    2008-08-14 . 8A22E65D66B3AB7E7F07C290F435629F . 2184704 . . . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe

    2008-08-14 . ACA664BEAF80F85C4BB4A4D86F3DF519 . 2190336 . . . . c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe

    2008-08-14 . 3E5E63D926C5E9F81045F3646815D2A1 . 2193536 . . . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe

    2007-02-28 . 59DCA97DC201792C1CCF9FE621EE5ED7 . 2186496 . . . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe

    2007-02-28 . CAAA8FD3C034A227691A43B60873F097 . 2184704 . . . . c:\windows\$NtUninstallKB956841$\ntoskrnl.exe

    2006-12-19 . 4CB6C3B16587971C56AAA8A9B0511BC7 . 2186368 . . . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe

    2006-12-19 . F609063BAE4D058A4019C4D99A1FD8DD . 2184704 . . . . c:\windows\$NtUninstallKB931784$\ntoskrnl.exe

    2005-03-02 . 5DB3E8DEC987B5D350E4A105DCEAEE6A . 2183936 . . . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe

    2005-03-02 . 281A1E82F5F8FC0B2F4B57EF296A4240 . 2183680 . . . . c:\windows\$NtUninstallKB929338$\ntoskrnl.exe

    2004-08-03 . 87AAEA3908E069FB1BE37380C895DFB8 . 2185344 . . . . c:\windows\$NtUninstallKB890859$\ntoskrnl.exe

    2004-08-03 . D5A792DB732622A393A0469FE6EAA728 . 17408 . . . . c:\windows\erdnt\cache\powrprof.dll

    2004-08-03 . D5A792DB732622A393A0469FE6EAA728 . 17408 . . . . c:\windows\system32\powrprof.dll

    2004-08-03 . D5A792DB732622A393A0469FE6EAA728 . 17408 . . . . c:\windows\system32\dllcache\powrprof.dll

    2004-08-03 . 5AE934F6837B5A583DED535C4BE5A804 . 184832 . . . . c:\windows\erdnt\cache\scecli.dll

    2004-08-03 . 5AE934F6837B5A583DED535C4BE5A804 . 184832 . . . . c:\windows\system32\scecli.dll

    2004-08-03 . 5AE934F6837B5A583DED535C4BE5A804 . 184832 . . . . c:\windows\system32\dllcache\scecli.dll

    2004-08-03 . 0B10A3122527910CE60D23A7F29C28B1 . 5120 . . . . c:\windows\erdnt\cache\sfc.dll

    2004-08-03 . 0B10A3122527910CE60D23A7F29C28B1 . 5120 . . . . c:\windows\system32\sfc.dll

    2004-08-03 . 0B10A3122527910CE60D23A7F29C28B1 . 5120 . . . . c:\windows\system32\dllcache\sfc.dll

    2004-08-03 . AB8C6D89A897BACBA4657FDF00E344A6 . 14336 . . . . c:\windows\erdnt\cache\svchost.exe

    2004-08-03 . AB8C6D89A897BACBA4657FDF00E344A6 . 14336 . . . . c:\windows\system32\svchost.exe

    2004-08-03 . AB8C6D89A897BACBA4657FDF00E344A6 . 14336 . . . . c:\windows\system32\dllcache\svchost.exe

    2005-07-08 . 5A145DBF2916F583921BB27B91B2DC0B . 249344 . . . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll

    2005-07-08 . C2A4E29888F45E7FC1FD64C83D5EA669 . 249344 . . . . c:\windows\erdnt\cache\tapisrv.dll

    2005-07-08 . C2A4E29888F45E7FC1FD64C83D5EA669 . 249344 . . . . c:\windows\system32\tapisrv.dll

    2005-07-08 . C2A4E29888F45E7FC1FD64C83D5EA669 . 249344 . . . . c:\windows\system32\dllcache\tapisrv.dll

    2004-08-03 . F38C48EE55AD051BF5474F5BDD69C846 . 246272 . . . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

    2007-03-08 . FA35431E333943F4B2A6D33FA4EE3CE9 . 579584 . . . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll

    2007-03-08 . CB18F701A5D55A6308FAB8D18322C060 . 579072 . . . . c:\windows\erdnt\cache\user32.dll

    2007-03-08 . CB18F701A5D55A6308FAB8D18322C060 . 579072 . . . . c:\windows\system32\user32.dll

    2007-03-08 . CB18F701A5D55A6308FAB8D18322C060 . 579072 . . . . c:\windows\system32\dllcache\user32.dll

    2005-03-02 . 0B62745CE93E8C6F56547F70269DBABC . 578560 . . . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll

    2005-03-02 . A9F2EBFC6EF9C1FB38CEDCF747162B6C . 578560 . . . . c:\windows\$NtUninstallKB925902$\user32.dll

    2004-08-03 . 8E5D344FD717D35EE7ED1C8E0AD0CBE6 . 578560 . . . . c:\windows\$NtUninstallKB890859$\user32.dll

  • Juut

    deel 2

    2004-08-03 . DE7A0EE4A6A28E6DFE3118EB22468DA6 . 24576 . . . . c:\windows\erdnt\cache\userinit.exe

    2004-08-03 . DE7A0EE4A6A28E6DFE3118EB22468DA6 . 24576 . . . . c:\windows\system32\userinit.exe

    2004-08-03 . DE7A0EE4A6A28E6DFE3118EB22468DA6 . 24576 . . . . c:\windows\system32\dllcache\userinit.exe

    2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . . . c:\windows\erdnt\cache\wininet.dll

    2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . . . c:\windows\SoftwareDistribution\Download\91c291a86d685093ffe1fda43df36102\SP3GDR\wininet.dll

    2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . . . c:\windows\system32\wininet.dll

    2010-02-25 . 2A850B8F7B435ACFB9DCD0A566FD720C . 916480 . . . . c:\windows\system32\dllcache\wininet.dll

    2010-02-25 . BB424C9406140FEAFB4732025BEBB69B . 919040 . . . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll

    2010-02-25 . BB424C9406140FEAFB4732025BEBB69B . 919040 . . . . c:\windows\SoftwareDistribution\Download\91c291a86d685093ffe1fda43df36102\SP3QFE\wininet.dll

    2009-12-21 . 4C145AB616871611FCE38F053C75807C . 916480 . . . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll

    2009-10-29 . D906535CAB4BB8A60AC060351EDE159F . 916480 . . . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll

    2009-08-29 . 977886782C8F7ACA874BE770C48FF75C . 916480 . . . . c:\windows\$hf_mig$\KB974455-IE8\SP3QFE\wininet.dll

    2009-07-03 . AE9E8D0E50D9D874B5AAFB8B74E9FAAC . 915456 . . . . c:\windows\$hf_mig$\KB972260-IE8\SP3QFE\wininet.dll

    2009-05-13 . 4BF497D1787B9B72DB6083395A1789D8 . 915456 . . . . c:\windows\$hf_mig$\KB969897-IE8\SP3QFE\wininet.dll

    2009-04-29 . D5E276ADDE1400549B5678873A804E6F . 827392 . . . . c:\windows\ie8\wininet.dll

    2009-04-29 . 478A5E95C6121A98673EE33DFCBE3400 . 828928 . . . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll

    2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . . . c:\windows\ie8updates\KB980182-IE8\wininet.dll

    2009-03-03 . 78B519AC87AD7256C24EF44279EFD694 . 828416 . . . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll

    2009-03-03 . C2A37E9F4096B019694A7519C5FFB2A0 . 826368 . . . . c:\windows\ie7updates\KB969897-IE7\wininet.dll

    2008-12-20 . 6A77C48E137A73FFD1408F1A71C5184C . 827904 . . . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll

    2008-12-20 . DB4777DBC853EAC790E3DBDB68FFB1A1 . 826368 . . . . c:\windows\ie7updates\KB963027-IE7\wininet.dll

    2008-10-16 . FE082C9C1190051D8DA700C65A49C649 . 826368 . . . . c:\windows\ie7updates\KB961260-IE7\wininet.dll

    2008-10-16 . C5C71C8265D07F52E304EE906332BEEE . 827904 . . . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll

    2008-08-26 . 8B421DDF376F3D042EC616994E6E7896 . 827904 . . . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll

    2008-08-26 . 5A1BB22BDFE98B2639A6D29E8CFB3BA4 . 826368 . . . . c:\windows\ie7updates\KB958215-IE7\wininet.dll

    2008-06-23 . 68FA9EED5B05EE48CDE843901C35E74A . 826368 . . . . c:\windows\ie7updates\KB956390-IE7\wininet.dll

    2008-06-23 . 68FA9EED5B05EE48CDE843901C35E74A . 826368 . . . . c:\windows\SoftwareDistribution\Download\ea4772a3e9d8b534362bbf4723756836\SP2GDR\wininet.dll

    2008-06-23 . 745795941F497E1CB3918A4AD3BEDEEE . 670208 . . . . c:\windows\$hf_mig$\KB953838\SP2QFE\wininet.dll

    2008-06-23 . AA8521032671FEFA0C99ACFC62BE26DA . 827904 . . . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll

    2008-06-23 . AA8521032671FEFA0C99ACFC62BE26DA . 827904 . . . . c:\windows\SoftwareDistribution\Download\ea4772a3e9d8b534362bbf4723756836\SP2QFE\wininet.dll

    2008-06-23 . B6BF5FB5CCAFD118EDEBDF38E82DEE41 . 662528 . . . . c:\windows\ie7\wininet.dll

    2008-06-23 . 8ADFF2F029A90FED04A322CBF084F3EA . 669184 . . . . c:\windows\$hf_mig$\KB953838\SP3GDR\wininet.dll

    2008-06-23 . AE1A6AEA7F65F452C0916FB1399D832E . 669696 . . . . c:\windows\$hf_mig$\KB953838\SP3QFE\wininet.dll

    2008-04-21 . B3E4295CA4A5B3639DE3DA1F95E78F29 . 662528 . . . . c:\windows\$NtUninstallKB953838$\wininet.dll

    2008-04-21 . 20238850AFE4A19A885CD5658433D60D . 669696 . . . . c:\windows\$hf_mig$\KB950759\SP2QFE\wininet.dll

    2008-04-21 . 0E4C070B2D83D7D76CF2A0384FA50750 . 669184 . . . . c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll

    2008-04-21 . 438F668DDACCAD59F934772EE894A704 . 669696 . . . . c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll

    2008-02-16 . C683F6CF71EDFCB8708BDF2C5DD1BA13 . 669184 . . . . c:\windows\$hf_mig$\KB947864\SP2QFE\wininet.dll

    2008-02-16 . 1D77F302BBFE2D407DD67C5CB098EA95 . 662528 . . . . c:\windows\$NtUninstallKB950759$\wininet.dll

    2007-12-07 . 5D5186CBF1E73BB62FCC5A02BE72506C . 662528 . . . . c:\windows\$NtUninstallKB947864$\wininet.dll

    2007-12-07 . 29DB45091E96459C99F5863B9B0E70FC . 669184 . . . . c:\windows\$hf_mig$\KB944533\SP2QFE\wininet.dll

    2007-10-11 . 23BBECA3DEFF67EE5B4C444A143E45A6 . 662528 . . . . c:\windows\$NtUninstallKB944533$\wininet.dll

    2007-10-11 . 9142B3C4732F906E45529F29B0546390 . 669184 . . . . c:\windows\$hf_mig$\KB942615\SP2QFE\wininet.dll

    2007-08-22 . 476470C5E47F78455399CB3E5C298021 . 662016 . . . . c:\windows\$NtUninstallKB942615$\wininet.dll

    2007-08-22 . 1577844C62558C9838526B3CC114695B . 668672 . . . . c:\windows\$hf_mig$\KB939653\SP2QFE\wininet.dll

    2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . . . c:\windows\ie7updates\KB953838-IE7\wininet.dll

    2007-06-26 . 7A0C9A702ED8F8695AC925C5B1850A07 . 668672 . . . . c:\windows\$hf_mig$\KB937143\SP2QFE\wininet.dll

    2007-06-26 . 514AD1D91EE71CF2D93E6DD5423F5C13 . 662016 . . . . c:\windows\$NtUninstallKB939653$\wininet.dll

    2007-04-18 . B2219D7AF938DE9372EB159C68FF83B5 . 668672 . . . . c:\windows\$hf_mig$\KB933566\SP2QFE\wininet.dll

    2007-04-18 . 6B755E9D272AF1DAA6FA618329D2AB18 . 662016 . . . . c:\windows\$NtUninstallKB937143$\wininet.dll

    2007-02-19 . 48E1C53BA8C6267BB97925EF729BDE90 . 668672 . . . . c:\windows\$hf_mig$\KB931768\SP2QFE\wininet.dll

    2007-02-19 . 55BE69A43120FDA4CFB7C0C1F305DB1A . 662016 . . . . c:\windows\$NtUninstallKB933566$\wininet.dll

    2007-01-04 . 243988BB76262D72A48E8312BF8A0231 . 668160 . . . . c:\windows\$hf_mig$\KB928090\SP2QFE\wininet.dll

    2007-01-04 . 366EC67E75F81D891ADFCC9941F1DE45 . 662016 . . . . c:\windows\$NtUninstallKB931768$\wininet.dll

    2004-08-03 . 6C7E1322898378C30BCD9F779A2621EE . 659456 . . . . c:\windows\$NtUninstallKB928090$\wininet.dll

    2004-08-03 . 06EBCBE58321E924980148B7E3DBD753 . 82944 . . . . c:\windows\erdnt\cache\ws2_32.dll

    2004-08-03 . 06EBCBE58321E924980148B7E3DBD753 . 82944 . . . . c:\windows\system32\ws2_32.dll

    2004-08-03 . 06EBCBE58321E924980148B7E3DBD753 . 82944 . . . . c:\windows\system32\dllcache\ws2_32.dll

    2007-06-13 . 147E95A42A58CE99E403F7F57656BBEB . 1036800 . . . . c:\windows\explorer.exe

    2007-06-13 . 147E95A42A58CE99E403F7F57656BBEB . 1036800 . . . . c:\windows\erdnt\cache\explorer.exe

    2007-06-13 . 147E95A42A58CE99E403F7F57656BBEB . 1036800 . . . . c:\windows\system32\dllcache\explorer.exe

    2007-06-13 . 1D6245AFBD3FAABC16A885116BE1874D . 1036800 . . . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

    2004-08-03 . A1D7304A87FC3093150F5E3CC7B0F338 . 1035776 . . . . c:\windows\$NtUninstallKB938828$\explorer.exe

    2004-08-03 . 0B96A1E4252F663222C9C3BAC89F596C . 170496 . . . . c:\windows\erdnt\cache\srsvc.dll

    2004-08-03 . 0B96A1E4252F663222C9C3BAC89F596C . 170496 . . . . c:\windows\system32\srsvc.dll

    2004-08-03 . 0B96A1E4252F663222C9C3BAC89F596C . 170496 . . . . c:\windows\system32\dllcache\srsvc.dll

    2004-08-03 . D6381A7C1704BE7A8FD5EFDFD9F1463B . 13824 . . . . c:\windows\erdnt\cache\wscntfy.exe

    2004-08-03 . D6381A7C1704BE7A8FD5EFDFD9F1463B . 13824 . . . . c:\windows\system32\wscntfy.exe

    2004-08-03 . D6381A7C1704BE7A8FD5EFDFD9F1463B . 13824 . . . . c:\windows\system32\dllcache\wscntfy.exe

    2004-08-03 . F4C8D4B0A294AAF37FE50C407B6E03F9 . 129536 . . . . c:\windows\erdnt\cache\xmlprov.dll

    2004-08-03 . F4C8D4B0A294AAF37FE50C407B6E03F9 . 129536 . . . . c:\windows\system32\xmlprov.dll

    2004-08-03 . F4C8D4B0A294AAF37FE50C407B6E03F9 . 129536 . . . . c:\windows\system32\dllcache\xmlprov.dll

    2004-08-03 . F1720914CAB06FDE4BE250E3767713CF . 55808 . . . . c:\windows\erdnt\cache\eventlog.dll

    2004-08-03 . F1720914CAB06FDE4BE250E3767713CF . 55808 . . . . c:\windows\system32\eventlog.dll

    2004-08-03 . F1720914CAB06FDE4BE250E3767713CF . 55808 . . . . c:\windows\system32\dllcache\eventlog.dll

    2004-08-03 . 486594A19F7AEDEBEA600855FFD5E914 . 1548288 . . . . c:\windows\erdnt\cache\sfcfiles.dll

    2004-08-03 . 486594A19F7AEDEBEA600855FFD5E914 . 1548288 . . . . c:\windows\system32\sfcfiles.dll

    2004-08-03 . 486594A19F7AEDEBEA600855FFD5E914 . 1548288 . . . . c:\windows\system32\dllcache\sfcfiles.dll

    2004-08-03 . 7DE46C9C40ABB58C8FDFE0212A3BF2B4 . 15360 . . . . c:\windows\erdnt\cache\ctfmon.exe

    2004-08-03 . 7DE46C9C40ABB58C8FDFE0212A3BF2B4 . 15360 . . . . c:\windows\system32\ctfmon.exe

    2004-08-03 . 7DE46C9C40ABB58C8FDFE0212A3BF2B4 . 15360 . . . . c:\windows\system32\dllcache\ctfmon.exe

    2006-12-19 . D6F2B8963663F2014FAFCD8E15E4E778 . 135168 . . . . c:\windows\erdnt\cache\shsvcs.dll

    2006-12-19 . D6F2B8963663F2014FAFCD8E15E4E778 . 135168 . . . . c:\windows\system32\shsvcs.dll

    2006-12-19 . D6F2B8963663F2014FAFCD8E15E4E778 . 135168 . . . . c:\windows\system32\dllcache\shsvcs.dll

    2006-12-19 . 20A1DFA416579DACEE28E15E331C3930 . 135680 . . . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll

    2004-08-03 . 394FD6CE1AC84BB318B806A6F8D90F66 . 135168 . . . . c:\windows\$NtUninstallKB928255$\shsvcs.dll

    2004-08-03 . D01BB100558945178E4BCB33B0FE9364 . 59904 . . . . c:\windows\erdnt\cache\regsvc.dll

    2004-08-03 . D01BB100558945178E4BCB33B0FE9364 . 59904 . . . . c:\windows\system32\regsvc.dll

    2004-08-03 . D01BB100558945178E4BCB33B0FE9364 . 59904 . . . . c:\windows\system32\dllcache\regsvc.dll

    2004-08-03 . D245B3E32F8AB3B2FB576AFCFDEC105E . 192000 . . . . c:\windows\erdnt\cache\schedsvc.dll

    2004-08-03 . D245B3E32F8AB3B2FB576AFCFDEC105E . 192000 . . . . c:\windows\system32\schedsvc.dll

    2004-08-03 . D245B3E32F8AB3B2FB576AFCFDEC105E . 192000 . . . . c:\windows\system32\dllcache\schedsvc.dll

    2004-08-03 . B02FDCE64F64CDE3AA809D28D25D2A12 . 71680 . . . . c:\windows\erdnt\cache\ssdpsrv.dll

    2004-08-03 . B02FDCE64F64CDE3AA809D28D25D2A12 . 71680 . . . . c:\windows\system32\ssdpsrv.dll

    2004-08-03 . B02FDCE64F64CDE3AA809D28D25D2A12 . 71680 . . . . c:\windows\system32\dllcache\ssdpsrv.dll

    2004-08-03 . E2CE999886A4636026F157DEB886AA94 . 297472 . . . . c:\windows\erdnt\cache\termsrv.dll

    2004-08-03 . E2CE999886A4636026F157DEB886AA94 . 297472 . . . . c:\windows\system32\termsrv.dll

    2004-08-03 . E2CE999886A4636026F157DEB886AA94 . 297472 . . . . c:\windows\system32\dllcache\termsrv.dll

    2004-08-03 . CC888653E0DEC81B525B956C77960F88 . 175616 . . . . c:\windows\erdnt\cache\appmgmts.dll

    2004-08-03 . CC888653E0DEC81B525B956C77960F88 . 175616 . . . . c:\windows\system32\appmgmts.dll

    2004-08-03 . CC888653E0DEC81B525B956C77960F88 . 175616 . . . . c:\windows\system32\dllcache\appmgmts.dll

    2001-09-07 . 63F517B1A87DABF3F5ACB8A7952FC1D1 . 12032 . . . . c:\windows\erdnt\cache\acpiec.sys

    2001-09-07 . 63F517B1A87DABF3F5ACB8A7952FC1D1 . 12032 . . . . c:\windows\system32\drivers\acpiec.sys

    2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys

    2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . . . c:\windows\Driver Cache\i386\aec.sys

    2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . . . c:\windows\erdnt\cache\aec.sys

    2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . . . c:\windows\system32\drivers\aec.sys

    2004-08-03 23:14 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . . . c:\windows\$NtUninstallKB900485$\aec.sys

    2004-08-03 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . . . c:\windows\erdnt\cache\agp440.sys

    2004-08-03 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . . . c:\windows\system32\drivers\agp440.sys

    2004-08-03 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . . . c:\windows\erdnt\cache\ip6fw.sys

    2004-08-03 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . . . c:\windows\system32\dllcache\ip6fw.sys

    2004-08-03 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . . . c:\windows\system32\drivers\ip6fw.sys

    2006-11-01 19:19 . 13E52326F0F19A1A8D34681E3444E8D1 . 927504 . . . . c:\windows\erdnt\cache\mfc40u.dll

    2006-11-01 19:19 . 13E52326F0F19A1A8D34681E3444E8D1 . 927504 . . . . c:\windows\system32\mfc40u.dll

    2006-11-01 19:19 . 13E52326F0F19A1A8D34681E3444E8D1 . 927504 . . . . c:\windows\system32\dllcache\mfc40u.dll

    2001-09-07 11:00 . 8EED1D71C14C356684E586B0A7DB6BCE . 924432 . . . . c:\windows\$NtUninstallKB924667$\mfc40u.dll

    2004-08-03 . 1405B1431F51CAB25FE9B2ECF13CB198 . 33792 . . . . c:\windows\erdnt\cache\msgsvc.dll

    2004-08-03 . 1405B1431F51CAB25FE9B2ECF13CB198 . 33792 . . . . c:\windows\system32\msgsvc.dll

    2004-08-03 . 1405B1431F51CAB25FE9B2ECF13CB198 . 33792 . . . . c:\windows\system32\dllcache\msgsvc.dll

    2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . . . c:\windows\erdnt\cache\mspmsnsv.dll

    2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . . . c:\windows\system32\mspmsnsv.dll

    2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . . . c:\windows\system32\dllcache\mspmsnsv.dll

    2004-08-03 23:03 . 2706E00334C86DD2E5279A47600C916A . 52736 . . . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll

    2010-02-17 . 1BA87670B4305072123A0CC0F478A340 . 2068096 . . . . c:\windows\$hf_mig$\KB979683\SP2QFE\ntkrnlpa.exe

    2010-02-17 . 1BA87670B4305072123A0CC0F478A340 . 2068096 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP2QFE\ntkrnlpa.exe

    2010-02-16 . 9F4BED5BFCA2291BA1AD16BB7F0A6E60 . 2062720 . . . . c:\windows\Driver Cache\i386\ntkrnlpa.exe

    2010-02-16 . 9F4BED5BFCA2291BA1AD16BB7F0A6E60 . 2062720 . . . . c:\windows\erdnt\cache\ntkrnlpa.exe

    2010-02-16 . 9F4BED5BFCA2291BA1AD16BB7F0A6E60 . 2062720 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP2GDR\ntkrnlpa.exe

    2010-02-16 . 9F4BED5BFCA2291BA1AD16BB7F0A6E60 . 2062720 . . . . c:\windows\system32\ntkrnlpa.exe

    2010-02-16 . 9F4BED5BFCA2291BA1AD16BB7F0A6E60 . 2062720 . . . . c:\windows\system32\dllcache\ntkrnlpa.exe

    2010-02-16 . F6049CA4515D37D5DA502D162E9B6AA0 . 2071168 . . . . c:\windows\$hf_mig$\KB979683\SP3GDR\ntkrnlpa.exe

    2010-02-16 . F6049CA4515D37D5DA502D162E9B6AA0 . 2071168 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP3GDR\ntkrnlpa.exe

    2010-02-16 . 7C4F935FC449E4D27C685A5BC1792664 . 2071296 . . . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe

    2010-02-16 . 7C4F935FC449E4D27C685A5BC1792664 . 2071296 . . . . c:\windows\SoftwareDistribution\Download\f7508e5e1ca4973a4a40720633483451\SP3QFE\ntkrnlpa.exe

    2009-08-04 . AB21A63A3B15653043E71126E5BBE3DE . 2070528 . . . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe

    2009-08-04 . BF6965EA17CC1E48DA287783AEEF3CDB . 2070400 . . . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntkrnlpa.exe

    2009-08-04 . 255FC496463193E7B2003B8EC677A0BA . 2067328 . . . . c:\windows\$hf_mig$\KB971486\SP2QFE\ntkrnlpa.exe

    2009-08-04 . 2D3902940A5D103CABFF9D68753F5ADB . 2062080 . . . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe

    2009-02-10 . 6A94A7317E28B6543D94174F9016BB68 . 2070400 . . . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntkrnlpa.exe

    2009-02-09 . 06A467DC3FF07102B058B2B41104662F . 2062080 . . . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe

    2009-02-09 . E03AE5E3171A627D58957B0437DEE4F9 . 2067328 . . . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntkrnlpa.exe

    2009-02-09 . 07EE73D79A7CA142463470AEF230082B . 2070528 . . . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe

    2008-08-14 . DE961B54D30C7DD6AA6C3BD27D584E30 . 2070400 . . . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe

    2008-08-14 . 423B3DB6D565D24C1D4C97136AE6F42D . 2062080 . . . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe

    2008-08-14 . 3D9893723A1AEBF96A11E7E7514FF021 . 2067328 . . . . c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe

    2008-08-14 . C92E65CBB38161373319BB11340DE919 . 2070400 . . . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe

    2007-02-28 . F51B8D8B0703518349096604E788B83E . 2063744 . . . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe

    2007-02-28 . 57B09AD681C1D8DB77CCC3E92D8F5D14 . 2061952 . . . . c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe

    2006-12-19 . 4BF54C0431A9BB0BCE6C821CD4018F7D . 2063744 . . . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe

    2006-12-19 . 6D080DDC482E83A69C9A862C247FA50D . 2061952 . . . . c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe

    2005-03-02 . C26D84B802567E629D42861A11C7EC04 . 2061312 . . . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe

    2005-03-02 . C6CF1974ACDB8329DAF9D001C0937CB0 . 2061184 . . . . c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe

    2004-08-03 . E0399688D466B7C3AFDFFB5A2ED9F351 . 2061184 . . . . c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe

    2004-08-03 23:03 . AC75E028773CBBD7D8B1313F382E7C05 . 437248 . . . . c:\windows\erdnt\cache\ntmssvc.dll

    2004-08-03 23:03 . AC75E028773CBBD7D8B1313F382E7C05 . 437248 . . . . c:\windows\system32\ntmssvc.dll

    2004-08-03 23:03 . AC75E028773CBBD7D8B1313F382E7C05 . 437248 . . . . c:\windows\system32\dllcache\ntmssvc.dll

    2007-02-05 . 063B30C37E3902760919D3E5D98CC7C9 . 185344 . . . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll

    2007-02-05 . DE0A3D72D98A08A115300E2B2DC4374B . 185344 . . . . c:\windows\erdnt\cache\upnphost.dll

    2007-02-05 . DE0A3D72D98A08A115300E2B2DC4374B . 185344 . . . . c:\windows\system32\upnphost.dll

    2007-02-05 . DE0A3D72D98A08A115300E2B2DC4374B . 185344 . . . . c:\windows\system32\dllcache\upnphost.dll

    2004-08-03 . 348B60067B10EFA7D7763EE44674108C . 185344 . . . . c:\windows\$NtUninstallKB931261$\upnphost.dll

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    “Easy-PrintToolBox”=“c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE”

    “CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE”

    “PcSync”=“c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe”

    “msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe”

    “{51C55F9E-C308-4c95-89AB-8858D8AFD819}”= “c:\program files\ParetoLogic\Anti-Spyware\PASShlExt.dll”

    2010-04-16 21:48 12464 —-a-w- c:\windows\system32\avgrsstx.dll

    @=“Service”

    path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\Microsoft Office.lnk

    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    2008-01-11 21:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    2007-01-23 09:19 223232 —-a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

    2008-05-06 08:42 202088 —-a-w- c:\program files\TomTom HOME 2\HOMERunner.exe

    “c:\\WINDOWS\\system32\\dpvsetup.exe”=

    “c:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe”=

    “%windir%\\Network Diagnostic\\xpnetdiag.exe”=

    “c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe”=

    “c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=

    “c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe”=

    “c:\\WINDOWS\\system32\\sessmgr.exe”=

    “c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe”=

    “c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe”=

    “c:\\Program Files\\AVG\\AVG9\\avgupd.exe”=

    “c:\\Program Files\\AVG\\AVG9\\avgnsx.exe”=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys

    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys

    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe

    S?4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys

    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe

    S3 DCamUSBPremier;Digital Camera;c:\windows\system32\drivers\MPIXVID.SYS

    S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys

    — Andere Services/Drivers In Geheugen —

    *NewlyCreated* - MBAMSWISSARMY

    .

    Inhoud van de ‘Gedeelde Taken’ map

    2010-04-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job

    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe

    2010-04-18 c:\windows\Tasks\OGALogon.job

    - c:\windows\system32\OGAEXEC.exe

    2007-04-02 c:\windows\Tasks\ParetoLogic Anti-Spyware.job

    - c:\program files\ParetoLogic\Anti-Spyware\Pareto_AS.exe

    2010-04-16 c:\windows\Tasks\ParetoLogic Update.job

    - c:\program files\Common Files\ParetoLogic\UUS\Pareto_Update.exe

    2010-04-18 c:\windows\Tasks\User_Feed_Synchronization-{4B0DDB84-E04A-4021-AAAE-A5C899315309}.job

    - c:\windows\system32\msfeedssync.exe

    .

    .

    ——- Bijkomende Scan ——-

    .

    uStart Page = about:blank

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

    uInternet Connection Wizard,ShellNext = iexplore

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

    IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

    IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

    IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

    IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

    Trusted Zone: 0.0.0.0

    Trusted Zone: ziggo.nl\thuishelp

    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab

    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

    DPF: {068BFA33-99F4-4BA9-887D-182386FA2931} - hxxp://download.playfirst.com/play/game/spongebobdash/SpongeBobDinerDashWeb.1.0.0.17.cab

    DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} - hxxp://www.king.com/ctl/kingcomie.cab

    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game12.zylom.com/activex/zylomgamesplayer.cab

    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2010-04-18 20:49

    Windows 5.1.2600 Service Pack 2 NTFS

    scannen van verborgen processen …

    scannen van verborgen autostart items …

    scannen van verborgen bestanden …

    Scan succesvol afgerond

    verborgen bestanden: 0

    **************************************************************************

    .

    ——————— DLLs Geladen Onder Lopende Processen ———————

    - - - - - - - > ‘explorer.exe’(2384)

    c:\windows\system32\webcheck.dll

    c:\windows\system32\WPDShServiceObj.dll

    c:\windows\system32\PortableDeviceTypes.dll

    c:\windows\system32\PortableDeviceApi.dll

    .

    Voltooingstijd: 2010-04-18 21:01:02

    ComboFix-quarantined-files.txt 2010-04-18 19:00

    ComboFix2.txt 2010-04-18 02:29

    ComboFix3.txt 2010-04-17 22:35

    ComboFix4.txt 2010-04-16 18:59

    ComboFix5.txt 2010-04-18 18:34

    Pre-Run: 8.913.432.576 bytes beschikbaar

    Post-Run: 8.906.829.824 bytes beschikbaar

    - - End Of File - - B1ED3850A80F6A438137077D43B03C04

    Groetjes,

    Juut

  • fazantje

    Hoi Juut,

    Waarom heb je nog steeds geen SP3 voor windows.

    Ik mis ook nog het nieuwe HijackThis logje, graag ook een HijackThis logje van Madelon.

    Er zijn n.l. 2 gebruikers/accounts dus dan ook 2 HijackThis logjes.

    Draai combo niet zomaar zonder dat je weet wat het kan doen!!!

    Graag even een antwoord op deze vraag

    Groetjes Huib:)

  • Jos H

    Juut heeft het echt opgegeven.?

  • fazantje

    Denk het welX(

  • juut

    Idd ik geef het op. Ik heb gelukkig mijn documenten kunnen redden, die zijn virusvrij, voor de rest denk ik dat mijn systeem zo erg beschadigd is dat opnieuw installeren de beste optie is.

    sp3 binnenhalen lukt ook niet omdat de download iedere keer mislukt.

    Allen iig bedankt voor de reacties.

    Groeten Juut