adsko utworzono 22 maja 2010 utworzono 22 maja 2010 (edytowane) Witam, mam problem ponieważ mój komputer działa ostatnio jak czołg czyli powolnie. Nie wiem co się z nim dzieje wcześniej tak nie było. Proszę o sprawdzenie logów: [log]OTL logfile created on: 2010-05-22 22:25:31 - Run 2 OTL by OldTimer - Version 3.2.5.0 Folder = F:\ Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 81,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 3,19 Gb Free Space | 8,17% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 210,25 Gb Total Space | 22,21 Gb Free Space | 10,56% Space Free | Partition Type: NTFS Drive F: | 216,44 Gb Total Space | 0,27 Gb Free Space | 0,12% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PIETRZAKA Current User Name: Ram Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 60 Days Output = Standard [color=#E56717]========== Processes (All) ==========[/color] PRC - [2010-05-22 22:24:08 | 000,571,904 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2010-05-11 17:38:20 | 006,644,736 | ---- | M] (Creative Team S.A.) -- F:\Program Files\WapSter\WapSter AQQ\AQQ.exe PRC - [2010-04-26 21:11:45 | 001,682,944 | ---- | M] (Curse) -- C:\Documents and Settings\Ram\Ustawienia lokalne\Apps\2.0\DD9XQZ00.468\JQCDNN3J.1WB\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe PRC - [2010-04-02 16:20:32 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2010-01-08 01:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe PRC - [2009-11-25 05:09:04 | 000,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe PRC - [2009-11-01 18:29:27 | 000,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe PRC - [2009-10-22 08:10:31 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2009-10-22 08:10:30 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2009-03-29 08:22:49 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2009-03-29 08:22:49 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\javaw.exe PRC - [2009-03-05 20:02:50 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009-03-02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2009-02-09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe PRC - [2008-10-16 18:22:20 | 000,464,264 | ---- | M] () -- C:\Program Files\AskBardis\bar\bin\AskService.exe PRC - [2008-05-13 18:07:24 | 000,080,392 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe PRC - [2008-04-17 19:13:44 | 005,750,784 | ---- | M] () -- E:\xampp\mysql\bin\mysqld-nt.exe PRC - [2008-04-14 22:51:52 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe PRC - [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe PRC - [2008-04-14 22:51:44 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe PRC - [2008-04-14 22:51:44 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [IMGSVC] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH] PRC - [2008-04-14 22:51:24 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-04-14 22:51:12 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe PRC - [2008-04-14 22:51:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe PRC - [2008-04-14 22:51:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe PRC - [2007-01-11 06:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE PRC - [2006-03-04 18:40:30 | 000,882,176 | ---- | M] () -- F:\Program Files\Kalendarz XP\Kalendarz.exe PRC - [2005-01-28 14:44:28 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe PRC - [2004-04-13 06:07:18 | 000,069,632 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe PRC - [2003-12-15 15:29:00 | 000,516,096 | ---- | M] () -- C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe PRC - [2003-06-19 23:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE PRC - [2002-08-21 07:13:12 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WISPTIS.EXE [color=#E56717]========== Modules (All) ==========[/color] MOD - [2010-05-22 22:24:08 | 000,571,904 | ---- | M] (OldTimer Tools) -- F:\OTL.exe MOD - [2009-12-08 11:25:45 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll MOD - [2009-06-25 10:27:54 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll MOD - [2009-04-15 16:54:38 | 000,585,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll MOD - [2009-03-21 16:08:59 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll MOD - [2009-02-09 12:53:44 | 000,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll MOD - [2009-02-09 12:53:43 | 000,722,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll MOD - [2008-10-23 14:42:41 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll MOD - [2008-06-17 21:03:15 | 008,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll MOD - [2008-04-14 22:51:58 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv MOD - [2008-04-14 22:50:58 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll MOD - [2008-04-14 22:50:58 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll MOD - [2008-04-14 22:50:58 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll MOD - [2008-04-14 22:50:58 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll MOD - [2008-04-14 22:50:48 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll MOD - [2008-04-14 22:50:46 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll MOD - [2008-04-14 22:50:46 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll MOD - [2008-04-14 22:50:46 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll MOD - [2008-04-14 22:50:46 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll MOD - [2008-04-14 22:50:40 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll MOD - [2008-04-14 22:50:38 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTF.dll MOD - [2008-04-14 22:50:34 | 000,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll MOD - [2008-04-14 22:50:32 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll MOD - [2008-04-14 22:50:16 | 000,822,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comres.dll MOD - [2008-04-14 22:50:14 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll MOD - [2008-04-14 22:50:12 | 000,498,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\clbcatq.dll MOD - [2008-04-14 22:50:00 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\apphelp.dll MOD - [2008-04-14 22:46:34 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx MOD - [2008-04-14 22:43:00 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTFIME.IME MOD - [2008-04-14 22:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (avupdate) SRV - [2010-01-08 01:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2009-10-22 08:10:31 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2009-10-22 08:10:30 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2008-10-16 18:22:20 | 000,464,264 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBardis\bar\bin\AskService.exe -- (ASKService) SRV - [2008-05-13 18:07:24 | 000,080,392 | ---- | M] () [Auto | Running] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service) SRV - [2008-04-17 19:13:44 | 005,750,784 | ---- | M] () [Auto | Running] -- E:\xampp\mysql\bin\mysqld-nt.exe -- (mysql) SRV - [2007-01-11 06:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) SRV - [2005-11-14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-05-22 21:54:59 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - [2009-12-07 21:17:25 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009-11-25 05:50:16 | 004,463,104 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2009-10-29 15:11:54 | 000,002,368 | ---- | M] (AntiCracking) [Kernel | Auto | Running] -- C:\WINDOWS\system32\SVKP.sys -- (SVKP) DRV - [2009-10-22 08:10:31 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2009-10-22 08:10:31 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009-09-27 17:12:22 | 007,655,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2009-02-21 00:22:15 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2009-02-13 11:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008-11-21 23:17:17 | 000,682,232 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2008-05-20 13:53:36 | 000,093,696 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV - [2008-05-07 13:21:40 | 004,739,072 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-04-13 23:10:32 | 000,096,512 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atapi.sys -- (atapi) DRV - [2008-04-13 22:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008-01-03 16:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-06-18 15:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem) DRV - [2006-09-24 15:28:47 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan) DRV - [2005-02-01 16:55:40 | 000,037,009 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- F:\Dark Kdr\npkcusb.sys -- (npkcusb) DRV - [2005-02-01 16:55:40 | 000,021,442 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- F:\Dark Kdr\npkcrypt.sys -- (npkcrypt) DRV - [2004-04-30 10:37:02 | 000,160,640 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\a347bus.sys -- (a347bus) DRV - [2004-04-30 10:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\a347scsi.sys -- (a347scsi) DRV - [2003-07-17 17:40:06 | 000,265,728 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX) DRV - [2003-07-17 14:02:08 | 000,017,097 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\PONDIS5.sys -- (PONDIS5) DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Winamp Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.1 FF - prefs.js..extensions.enabledItems: refspoof@mozdev.org:0.9.5 FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3 FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789 FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.5.6.0 FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5 FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009-03-05 20:02:56 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-25 16:58:14 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-25 16:58:14 | 000,000,000 | ---D | M] [2008-12-28 11:59:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Extensions [2010-05-22 10:02:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions [2010-03-06 17:53:32 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-03-21 12:13:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-01-29 21:49:24 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} [2009-10-19 21:50:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} [2010-02-26 15:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\personas@christopher.beard [2009-12-06 20:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\refspoof@mozdev.org [2009-12-27 20:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\yasearch@yandex.ru [2009-12-27 20:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\yasearch@yandex.ru\chrome\skin\extensions-hacks [2009-10-06 17:10:14 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\conduit.xml [2010-03-06 18:08:20 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\winamp-search.xml [2010-05-22 22:20:33 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2009-08-28 14:41:29 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\arcabit@www.arcabit.pl [2008-09-04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll [2010-03-14 17:45:03 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-03-14 17:45:03 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-03-14 17:45:03 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-03-14 17:45:03 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-03-14 17:45:03 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-03-14 17:45:03 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-03-01 16:21:46 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com) O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com) O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [KernelFaultCheck] File not found O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found O4 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004..\Run: [AQQ] F:\Program Files\WapSter\WapSter AQQ\AQQ.exe (Creative Team S.A.) O4 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004..\Run: [Steam] F:\Program Files\Steam\Steam.exe (Valve Corporation) O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk = F:\Program Files\Kalendarz XP\Kalendarz.exe () O4 - Startup: C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip () O4 - Startup: C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\Skrót (2) do JDownloader.exe.lnk = F:\Moje Dokumenty\JDownloader 0.8.9\JDownloader.exe (AppWork UG (haftungsbeschränkt)) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O9 - Extra Button: ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - E:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - F:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - C:\WINDOWS\system32\ias [2008-09-25 18:19:57 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - StartUpFolder: C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe - (LogMeIn Inc.) MsConfig - StartUpReg: [b]Skype[/b] - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 2 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: vsmon - Service SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color] [2010-05-10 13:46:00 | 000,000,000 | ---D | C] -- C:\Program Files\YASAVOB2MPEG [2010-05-02 22:09:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\stale_pliki [2010-04-30 23:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder(3) [2010-04-30 23:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder(2) [2010-04-30 23:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder [2010-04-26 20:25:57 | 001,430,522 | ---- | C] (Artur Sikora ) -- C:\Documents and Settings\Ram\subedit_b4072_install.exe [2010-04-26 19:52:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\VSO [2010-04-26 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid [2010-04-26 19:48:33 | 000,652,794 | ---- | C] (Xvid team ) -- C:\Documents and Settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe [2010-04-26 19:01:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS [2010-04-26 18:50:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Dane aplikacji\AVI ReComp [2010-04-26 18:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2010-04-26 18:50:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVI ReComp [2010-04-25 17:43:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Dane aplikacji\WinAVI [2010-04-25 17:43:11 | 000,000,000 | ---D | C] -- C:\Program Files\WinAVI Video Converter [2010-04-25 16:54:36 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDubMod [2010-04-25 15:37:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\Free_Zune_Video_Converter [2010-04-25 15:28:12 | 000,000,000 | ---D | C] -- C:\Program Files\mkvtoavi [2010-04-25 15:26:30 | 001,411,043 | ---- | C] (DigitByte Studio ) -- C:\Documents and Settings\Ram\Pulpit\mkvtoavi.exe [2010-04-17 18:29:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\Zuma Deluxe [2010-04-17 18:28:30 | 000,000,000 | ---D | C] -- F:\Moje Dokumenty\MumboJumbo [2010-04-17 18:28:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\MumboJumbo [2010-04-16 17:14:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\praca [2010-04-13 17:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\Dżala-dżala [2010-04-12 17:51:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard Entertainment [2010-04-11 20:29:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Pulpit\_2005__Unikaty [2010-04-11 14:49:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard [2010-04-04 01:01:30 | 002,512,754 | ---- | C] ( ) -- C:\Documents and Settings\Ram\Pulpit\NapiProjekt1.0.6.9_(programs.pl).exe [2009-12-28 10:18:55 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys [2009-12-28 10:18:55 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\Ram\Pulpit\*.tmp files -> C:\Documents and Settings\Ram\Pulpit\*.tmp -> ] [color=#E56717]========== Files - Modified Within 60 Days ==========[/color] [2010-05-22 22:16:54 | 000,209,572 | ---- | M] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal..0002.mdi [2010-05-22 22:07:11 | 000,151,838 | ---- | M] () -- F:\Moje Dokumenty\kolin.mdi [2010-05-22 21:56:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job [2010-05-22 21:53:49 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-05-22 21:53:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-05-22 21:51:11 | 013,893,632 | -H-- | M] () -- C:\Documents and Settings\Ram\NTUSER.DAT [2010-05-22 21:51:11 | 000,000,292 | -HS- | M] () -- C:\Documents and Settings\Ram\ntuser.ini [2010-05-21 13:21:35 | 000,208,744 | ---- | M] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal..0001.mdi [2010-05-20 15:25:19 | 000,151,974 | ---- | M] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal...mdi [2010-05-20 15:03:09 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010-05-20 14:47:13 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI [2010-05-19 15:05:28 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-05-15 09:09:04 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-05-14 19:08:50 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Curriculum Vitae.doc [2010-05-13 22:50:24 | 216,465,408 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\A Nightmare On Elm Street [Eng][2010.TS.XVID-PrisM]._5fantastic.pl_.rar.part [2010-05-13 21:01:46 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\A Nightmare On Elm Street [Eng][2010.TS.XVID-PrisM]._5fantastic.pl_.rar [2010-05-13 20:34:26 | 000,000,675 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\AQQ.lnk [2010-05-13 17:49:56 | 000,015,270 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Nightmare_on_Elm_Street_A_(NAPiSY-115103).NS.zip [2010-05-10 19:47:19 | 016,970,572 | ---- | M] () -- F:\Moje Dokumenty\img114.jpg [2010-05-10 19:44:16 | 000,124,803 | ---- | M] () -- F:\Moje Dokumenty\img113.jpg [2010-05-10 18:32:14 | 000,012,435 | ---- | M] () -- F:\Moje Dokumenty\img112.jpg [2010-05-10 14:18:26 | 002,742,646 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Pazera_Free_Video_to_iPod_Converter.zip [2010-05-10 13:46:01 | 000,000,723 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\YASA VOB to MPEG Converter.lnk [2010-05-10 13:37:27 | 003,058,127 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Pazera_Free_MOV_to_AVI_Converter.zip [2010-05-09 18:37:22 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\List motywacyjny.doc [2010-05-09 17:38:44 | 000,038,400 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\CURRICULUM VITAE dida.doc [2010-05-09 16:47:16 | 000,009,538 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\2.zip [2010-05-05 21:50:32 | 000,586,018 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-05-05 21:50:32 | 000,515,952 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-05-05 21:50:32 | 000,109,654 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-05-05 21:50:32 | 000,086,760 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-05-05 21:50:31 | 001,315,428 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010-05-05 17:38:16 | 000,087,040 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Moja posrana praca maturalna.doc [2010-05-03 22:23:30 | 000,778,240 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Praca asd.doc [2010-05-03 19:45:53 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$stale.doc [2010-05-03 19:45:20 | 000,778,240 | ---- | M] () -- F:\Moje Dokumenty\Praca asd.doc [2010-05-03 19:29:19 | 000,195,751 | ---- | M] () -- F:\Moje Dokumenty\img111.jpg [2010-05-03 19:13:05 | 000,400,510 | ---- | M] () -- F:\Moje Dokumenty\img110.jpg [2010-05-02 22:52:48 | 000,399,796 | ---- | M] () -- F:\Moje Dokumenty\img109.jpg [2010-05-02 22:09:24 | 000,101,243 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\stale.htm [2010-04-29 21:55:20 | 002,629,183 | ---- | M] () -- F:\Moje Dokumenty\img108.jpg [2010-04-29 21:54:17 | 002,441,032 | ---- | M] () -- F:\Moje Dokumenty\img107.jpg [2010-04-29 21:53:12 | 002,495,417 | ---- | M] () -- F:\Moje Dokumenty\img106.jpg [2010-04-29 21:52:05 | 002,951,331 | ---- | M] () -- F:\Moje Dokumenty\img105.jpg [2010-04-29 21:51:00 | 002,714,493 | ---- | M] () -- F:\Moje Dokumenty\img104.jpg [2010-04-29 21:49:51 | 002,953,724 | ---- | M] () -- F:\Moje Dokumenty\img103.jpg [2010-04-28 16:59:27 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$an wypowiedzi.doc [2010-04-26 23:28:21 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Steam.lnk [2010-04-26 21:12:13 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip [2010-04-26 21:11:48 | 000,000,312 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Curse Client.appref-ms [2010-04-26 20:38:47 | 000,000,500 | -H-- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi.ini [2010-04-26 20:35:06 | 000,080,757 | ---- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.ssa [2010-04-26 20:27:38 | 000,000,687 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\SubEdit-Player.lnk [2010-04-26 20:27:22 | 001,430,522 | ---- | M] (Artur Sikora ) -- C:\Documents and Settings\Ram\subedit_b4072_install.exe [2010-04-26 19:49:02 | 000,652,794 | ---- | M] (Xvid team ) -- C:\Documents and Settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe [2010-04-26 19:43:12 | 000,892,475 | ---- | M] () -- C:\Documents and Settings\Ram\xvidcore-1.2.2.zip [2010-04-26 19:01:14 | 000,018,172 | ---- | M] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip [2010-04-26 19:00:16 | 000,018,569 | ---- | M] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-26 18:50:09 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\AVI ReComp.lnk [2010-04-26 07:09:35 | 000,047,616 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\o dzizas.doc [2010-04-26 07:07:02 | 000,039,936 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Magdalena Dabrowska - Plan ramowy.doc [2010-04-25 23:04:52 | 000,012,615 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 23:04:52 | 000,012,615 | ---- | M] () -- C:\Documents and Settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 23:04:44 | 000,015,465 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Clash_of_the_Titans_2010_(NAPiSY-114734).NS.zip [2010-04-25 20:50:44 | 000,018,569 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-25 20:47:10 | 1324,066,182 | ---- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi [2010-04-25 18:00:27 | 1370,011,442 | ---- | M] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.avi [2010-04-25 17:43:13 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\WinAVI Video Converter.lnk [2010-04-25 17:11:59 | 003,958,982 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\MatroskaPackFull_1.1.2.zip [2010-04-25 17:10:49 | 004,168,805 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\ffdshow-rev3355_20100411.zip [2010-04-25 16:54:37 | 000,000,813 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod.lnk [2010-04-25 16:50:46 | 001,668,886 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod_1.5.10.2_PL[www.instalki.pl].exe [2010-04-25 15:37:12 | 002,903,629 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Free_Zune_Video_Converter.zip [2010-04-25 15:27:23 | 001,411,043 | ---- | M] (DigitByte Studio ) -- C:\Documents and Settings\Ram\Pulpit\mkvtoavi.exe [2010-04-22 17:25:39 | 000,048,640 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\plan wypowiedzi.doc [2010-04-22 16:10:29 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$bliografia 3 i pół.doc [2010-04-22 09:15:15 | 000,000,040 | ---- | M] () -- C:\Session.xml [2010-04-21 22:14:25 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\bibliografia 3 i pół.doc [2010-04-21 22:14:08 | 000,037,888 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Plan prezentacji.doc [2010-04-21 20:48:41 | 000,156,160 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Czasownik modalny.ppt [2010-04-18 20:14:09 | 007,826,286 | ---- | M] () -- F:\Moje Dokumenty\Moje Dokumenty.rar [2010-04-18 20:13:53 | 001,191,443 | ---- | M] () -- F:\Moje Dokumenty\img102.jpg [2010-04-18 20:11:32 | 001,111,104 | ---- | M] () -- F:\Moje Dokumenty\img101.jpg [2010-04-18 20:08:28 | 001,151,387 | ---- | M] () -- F:\Moje Dokumenty\img100.jpg [2010-04-18 20:07:26 | 001,172,591 | ---- | M] () -- F:\Moje Dokumenty\img099.jpg [2010-04-18 20:06:01 | 001,628,270 | ---- | M] () -- F:\Moje Dokumenty\img098.jpg [2010-04-18 20:05:00 | 001,641,778 | ---- | M] () -- F:\Moje Dokumenty\img097.jpg [2010-04-17 22:43:34 | 004,776,544 | -H-- | M] () -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\IconCache.db [2010-04-17 18:30:45 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat [2010-04-17 11:04:33 | 000,138,384 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2010-04-17 11:04:24 | 000,215,128 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2010-04-17 10:59:58 | 000,000,772 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\EA Download Manager.lnk [2010-04-16 18:40:14 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$ES IRAE.doc [2010-04-16 17:15:17 | 000,000,110 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\praca.zip [2010-04-16 16:37:13 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$razy z dziejow Polski i Polakow.doc [2010-04-16 16:36:41 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ram\Pulpit\~$da- prezentacja maturalna2.doc [2010-04-15 19:36:04 | 000,007,224 | ---- | M] () -- F:\Moje Dokumenty\ZBYCHU UWAZAJ KIJ.rtf [2010-04-14 17:07:05 | 000,402,432 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Köln.doc [2010-04-13 14:27:26 | 000,859,694 | ---- | M] () -- F:\Moje Dokumenty\KolinS.rar [2010-04-13 14:26:40 | 000,340,888 | ---- | M] () -- F:\Moje Dokumenty\img096.jpg [2010-04-13 14:25:19 | 000,275,763 | ---- | M] () -- F:\Moje Dokumenty\img095.jpg [2010-04-13 14:24:23 | 000,590,720 | ---- | M] () -- F:\Moje Dokumenty\img094.jpg [2010-04-12 21:37:57 | 000,000,823 | ---- | M] () -- C:\Documents and Settings\Ram\.recently-used.xbel [2010-04-12 17:21:33 | 003,453,000 | ---- | M] () -- F:\Moje Dokumenty\Kolin.rar [2010-04-12 16:33:33 | 000,753,831 | ---- | M] () -- F:\Moje Dokumenty\img093.jpg [2010-04-12 16:32:24 | 001,115,221 | ---- | M] () -- F:\Moje Dokumenty\img092.jpg [2010-04-12 16:31:01 | 000,861,479 | ---- | M] () -- F:\Moje Dokumenty\img091.jpg [2010-04-12 16:28:26 | 000,853,962 | ---- | M] () -- F:\Moje Dokumenty\img090.jpg [2010-04-12 15:58:27 | 000,908,716 | ---- | M] () -- F:\Moje Dokumenty\img089.jpg [2010-04-12 15:57:07 | 000,849,473 | ---- | M] () -- F:\Moje Dokumenty\img088.jpg [2010-04-10 22:08:33 | 085,259,676 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\_2005__Unikaty.rar [2010-04-10 21:07:01 | 209,715,200 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\UP.upload.by.Mi.Ma.part1.rar [2010-04-09 21:21:32 | 000,085,504 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-04-09 21:21:32 | 000,000,547 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2010-04-04 01:01:48 | 002,512,754 | ---- | M] ( ) -- C:\Documents and Settings\Ram\Pulpit\NapiProjekt1.0.6.9_(programs.pl).exe [2010-03-29 22:35:58 | 000,023,040 | ---- | M] () -- F:\Moje Dokumenty\Adam Pietrzak CV.doc [2010-03-29 21:59:51 | 000,020,480 | ---- | M] () -- F:\Moje Dokumenty\Adam Pietrzak Podanie.doc [2010-03-29 21:59:30 | 000,020,992 | ---- | M] () -- F:\Moje Dokumenty\Adam Pietrzak zyciorys.doc [2010-03-29 21:54:15 | 000,022,528 | ---- | M] () -- F:\Moje Dokumenty\Referencje.doc [2010-03-25 17:26:02 | 000,032,768 | ---- | M] () -- F:\Moje Dokumenty\bibliografia 3.doc [2010-03-25 17:19:20 | 000,032,768 | ---- | M] () -- F:\Moje Dokumenty\bibliografia 2.doc [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\Ram\Pulpit\*.tmp files -> C:\Documents and Settings\Ram\Pulpit\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-05-22 22:16:53 | 000,209,572 | ---- | C] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal..0002.mdi [2010-05-22 22:06:38 | 000,151,838 | ---- | C] () -- F:\Moje Dokumenty\kolin.mdi [2010-05-21 13:21:34 | 000,208,744 | ---- | C] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal..0001.mdi [2010-05-20 14:41:47 | 000,151,974 | ---- | C] () -- F:\Moje Dokumenty\Nabór Szkoła Ponadgimnazjal...mdi [2010-05-13 21:01:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\A Nightmare On Elm Street [Eng][2010.TS.XVID-PrisM]._5fantastic.pl_.rar [2010-05-13 21:01:41 | 216,465,408 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\A Nightmare On Elm Street [Eng][2010.TS.XVID-PrisM]._5fantastic.pl_.rar.part [2010-05-13 17:49:54 | 000,015,270 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Nightmare_on_Elm_Street_A_(NAPiSY-115103).NS.zip [2010-05-10 19:47:06 | 016,970,572 | ---- | C] () -- F:\Moje Dokumenty\img114.jpg [2010-05-10 19:44:16 | 000,124,803 | ---- | C] () -- F:\Moje Dokumenty\img113.jpg [2010-05-10 18:32:14 | 000,012,435 | ---- | C] () -- F:\Moje Dokumenty\img112.jpg [2010-05-10 14:18:06 | 002,742,646 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Pazera_Free_Video_to_iPod_Converter.zip [2010-05-10 13:46:01 | 000,000,723 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\YASA VOB to MPEG Converter.lnk [2010-05-10 13:37:02 | 003,058,127 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Pazera_Free_MOV_to_AVI_Converter.zip [2010-05-09 18:37:22 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\List motywacyjny.doc [2010-05-09 17:38:44 | 000,038,400 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\CURRICULUM VITAE dida.doc [2010-05-09 16:47:15 | 000,009,538 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\2.zip [2010-05-03 19:45:53 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$stale.doc [2010-05-03 19:45:35 | 000,778,240 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Praca asd.doc [2010-05-03 19:45:19 | 000,778,240 | ---- | C] () -- F:\Moje Dokumenty\Praca asd.doc [2010-05-03 19:16:56 | 000,195,751 | ---- | C] () -- F:\Moje Dokumenty\img111.jpg [2010-05-03 19:13:02 | 000,400,510 | ---- | C] () -- F:\Moje Dokumenty\img110.jpg [2010-05-02 22:52:48 | 000,399,796 | ---- | C] () -- F:\Moje Dokumenty\img109.jpg [2010-05-02 22:09:24 | 000,101,243 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\stale.htm [2010-04-29 21:55:19 | 002,629,183 | ---- | C] () -- F:\Moje Dokumenty\img108.jpg [2010-04-29 21:54:16 | 002,441,032 | ---- | C] () -- F:\Moje Dokumenty\img107.jpg [2010-04-29 21:53:11 | 002,495,417 | ---- | C] () -- F:\Moje Dokumenty\img106.jpg [2010-04-29 21:52:04 | 002,951,331 | ---- | C] () -- F:\Moje Dokumenty\img105.jpg [2010-04-29 21:50:56 | 002,714,493 | ---- | C] () -- F:\Moje Dokumenty\img104.jpg [2010-04-29 21:49:50 | 002,953,724 | ---- | C] () -- F:\Moje Dokumenty\img103.jpg [2010-04-28 16:59:27 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$an wypowiedzi.doc [2010-04-26 22:11:33 | 000,161,144 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2010-04-26 21:12:13 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip [2010-04-26 20:35:20 | 000,080,757 | ---- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.ssa [2010-04-26 20:28:01 | 000,000,500 | -H-- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi.ini [2010-04-26 20:27:38 | 000,000,687 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\SubEdit-Player.lnk [2010-04-26 20:11:34 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-04-26 20:11:34 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2010-04-26 19:42:57 | 000,892,475 | ---- | C] () -- C:\Documents and Settings\Ram\xvidcore-1.2.2.zip [2010-04-26 18:50:09 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\AVI ReComp.lnk [2010-04-26 18:30:08 | 000,018,172 | ---- | C] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip [2010-04-26 07:09:35 | 000,047,616 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\o dzizas.doc [2010-04-25 23:05:00 | 000,012,615 | ---- | C] () -- C:\Documents and Settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 23:04:52 | 000,012,615 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 20:53:22 | 000,027,703 | ---- | C] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.txt [2010-04-25 20:51:13 | 000,018,569 | ---- | C] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-25 20:50:40 | 000,018,569 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-25 20:26:03 | 1324,066,182 | ---- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi [2010-04-25 17:44:14 | 1370,011,442 | ---- | C] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.avi [2010-04-25 17:43:13 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\WinAVI Video Converter.lnk [2010-04-25 17:11:06 | 003,958,982 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\MatroskaPackFull_1.1.2.zip [2010-04-25 17:08:46 | 004,168,805 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\ffdshow-rev3355_20100411.zip [2010-04-25 16:54:37 | 000,000,813 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod.lnk [2010-04-25 16:50:35 | 001,668,886 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod_1.5.10.2_PL[www.instalki.pl].exe [2010-04-25 15:36:42 | 002,903,629 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Free_Zune_Video_Converter.zip [2010-04-22 17:38:24 | 000,015,465 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Clash_of_the_Titans_2010_(NAPiSY-114734).NS.zip [2010-04-22 17:25:39 | 000,048,640 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\plan wypowiedzi.doc [2010-04-22 16:10:29 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$bliografia 3 i pół.doc [2010-04-21 20:48:41 | 000,156,160 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Czasownik modalny.ppt [2010-04-21 17:58:29 | 000,035,840 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\bibliografia 3 i pół.doc [2010-04-21 17:38:48 | 000,039,936 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Magdalena Dabrowska - Plan ramowy.doc [2010-04-18 20:14:06 | 007,826,286 | ---- | C] () -- F:\Moje Dokumenty\Moje Dokumenty.rar [2010-04-18 20:13:53 | 001,191,443 | ---- | C] () -- F:\Moje Dokumenty\img102.jpg [2010-04-18 20:11:28 | 001,111,104 | ---- | C] () -- F:\Moje Dokumenty\img101.jpg [2010-04-18 20:08:28 | 001,151,387 | ---- | C] () -- F:\Moje Dokumenty\img100.jpg [2010-04-18 20:07:25 | 001,172,591 | ---- | C] () -- F:\Moje Dokumenty\img099.jpg [2010-04-18 20:06:00 | 001,628,270 | ---- | C] () -- F:\Moje Dokumenty\img098.jpg [2010-04-18 20:04:53 | 001,641,778 | ---- | C] () -- F:\Moje Dokumenty\img097.jpg [2010-04-17 18:30:45 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat [2010-04-16 18:47:20 | 000,087,040 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Moja posrana praca maturalna.doc [2010-04-16 18:40:14 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$ES IRAE.doc [2010-04-16 17:06:45 | 000,000,110 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\praca.zip [2010-04-16 16:37:13 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$razy z dziejow Polski i Polakow.doc [2010-04-16 16:36:41 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ram\Pulpit\~$da- prezentacja maturalna2.doc [2010-04-15 19:18:06 | 000,007,224 | ---- | C] () -- F:\Moje Dokumenty\ZBYCHU UWAZAJ KIJ.rtf [2010-04-14 17:07:04 | 000,402,432 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Köln.doc [2010-04-13 14:27:26 | 000,859,694 | ---- | C] () -- F:\Moje Dokumenty\KolinS.rar [2010-04-13 14:26:40 | 000,340,888 | ---- | C] () -- F:\Moje Dokumenty\img096.jpg [2010-04-13 14:25:13 | 000,275,763 | ---- | C] () -- F:\Moje Dokumenty\img095.jpg [2010-04-13 14:24:23 | 000,590,720 | ---- | C] () -- F:\Moje Dokumenty\img094.jpg [2010-04-12 21:37:57 | 000,000,823 | ---- | C] () -- C:\Documents and Settings\Ram\.recently-used.xbel [2010-04-12 17:21:32 | 003,453,000 | ---- | C] () -- F:\Moje Dokumenty\Kolin.rar [2010-04-12 16:33:33 | 000,753,831 | ---- | C] () -- F:\Moje Dokumenty\img093.jpg [2010-04-12 16:32:23 | 001,115,221 | ---- | C] () -- F:\Moje Dokumenty\img092.jpg [2010-04-12 16:31:01 | 000,861,479 | ---- | C] () -- F:\Moje Dokumenty\img091.jpg [2010-04-12 16:28:26 | 000,853,962 | ---- | C] () -- F:\Moje Dokumenty\img090.jpg [2010-04-12 15:58:26 | 000,908,716 | ---- | C] () -- F:\Moje Dokumenty\img089.jpg [2010-04-12 15:57:07 | 000,849,473 | ---- | C] () -- F:\Moje Dokumenty\img088.jpg [2010-04-10 21:46:35 | 085,259,676 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\_2005__Unikaty.rar [2010-04-10 20:19:32 | 209,715,200 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\UP.upload.by.Mi.Ma.part1.rar [2010-04-08 10:04:51 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Curriculum Vitae.doc [2010-04-03 19:36:31 | 000,037,888 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Plan prezentacji.doc [2010-03-29 21:59:51 | 000,020,480 | ---- | C] () -- F:\Moje Dokumenty\Adam Pietrzak Podanie.doc [2010-03-29 21:59:30 | 000,020,992 | ---- | C] () -- F:\Moje Dokumenty\Adam Pietrzak zyciorys.doc [2010-03-29 21:56:59 | 000,023,040 | ---- | C] () -- F:\Moje Dokumenty\Adam Pietrzak CV.doc [2010-03-29 21:54:14 | 000,022,528 | ---- | C] () -- F:\Moje Dokumenty\Referencje.doc [2010-03-25 17:26:02 | 000,032,768 | ---- | C] () -- F:\Moje Dokumenty\bibliografia 3.doc [2009-12-11 15:51:00 | 000,001,225 | ---- | C] () -- C:\WINDOWS\kaillera.ini [2009-12-06 21:26:41 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2009-11-01 18:33:02 | 000,138,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-10-27 21:13:44 | 000,000,086 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2009-10-15 02:01:24 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2009-09-30 14:18:33 | 008,676,883 | ---- | C] () -- C:\WINDOWS\System32\NCMedia2.dll [2009-09-30 14:18:33 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009-09-30 14:18:33 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009-09-29 15:30:57 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Worldbuilder.INI [2009-07-23 18:29:40 | 000,040,160 | ---- | C] () -- C:\WINDOWS\php.ini [2009-07-23 18:29:40 | 000,000,488 | ---- | C] () -- C:\WINDOWS\my.ini [2009-07-05 19:37:50 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini [2009-05-29 11:32:40 | 000,000,245 | ---- | C] () -- C:\WINDOWS\game.ini [2009-03-05 20:03:13 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2009-02-21 15:36:00 | 001,867,776 | ---- | C] () -- C:\WINDOWS\python24.dll [2009-01-16 21:07:32 | 000,001,503 | ---- | C] () -- C:\WINDOWS\ReVoltX.ini [2009-01-13 20:28:03 | 000,000,743 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini [2009-01-13 20:27:45 | 000,003,090 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2009-01-10 09:47:47 | 000,000,943 | ---- | C] () -- C:\WINDOWS\VPlayer.INI [2008-10-24 22:43:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008-09-28 21:59:51 | 000,000,649 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008-09-27 10:15:58 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2008-09-26 14:22:31 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2008-09-26 14:14:18 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CDE DX4400DEFGIPS.ini [2008-09-26 14:04:04 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2008-04-14 00:10:32 | 000,096,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys [2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [1996-04-03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys [color=#E56717]========== LOP Check ==========[/color] [2009-08-28 14:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit [2009-08-11 21:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software [2009-11-17 18:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2010-02-19 10:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts [2008-09-26 14:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON [2009-02-22 21:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GlobalSCAPE [2010-04-17 18:28:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MumboJumbo [2008-10-16 16:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2009-04-17 21:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TrackMania [2008-09-26 14:24:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\UDL [2009-08-28 14:43:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\ArcaBit [2010-02-04 11:14:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\abgx360 [2009-05-29 11:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Activision [2010-04-26 20:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\AVI ReComp [2009-10-17 19:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\BitTorrent [2009-03-08 19:28:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\COWON [2009-04-22 18:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Dev-Cpp [2009-04-28 20:19:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\DNA [2009-11-06 08:49:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\EPSON [2010-05-05 12:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\EurekaLog [2009-12-10 22:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\fltk.org [2008-12-29 00:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Gadu-Gadu [2009-04-19 17:32:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\GetRightToGo [2009-02-22 21:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\GlobalSCAPE [2010-02-14 14:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\gtk-2.0 [2009-12-28 21:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\ImgBurn [2009-10-14 19:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Moje pliki zapisu Bitwy o Śródziemie [2010-01-16 19:38:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\pdfforge [2009-01-07 19:32:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\RapidGet [2010-01-16 19:38:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Search Settings [2009-04-12 13:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Soldat [2009-07-31 18:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Tibia [2010-04-26 19:53:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\VSO [2010-04-25 17:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\WinAVI [2009-02-13 16:46:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\WypasOTS Client [2010-05-22 21:56:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009-10-13 17:04:32 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2001-07-22 02:13:54 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2010-03-01 16:25:15 | 000,019,275 | ---- | M] () -- C:\ComboFix.txt [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2010-05-10 13:56:33 | 000,019,274 | ---- | M] () -- C:\debug.log [2008-09-25 18:20:16 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009-12-07 17:27:26 | 005,503,655 | ---- | M] () -- C:\JPEG_Output.PDF [2009-12-07 17:38:38 | 004,965,049 | ---- | M] () -- C:\JPEG_Output.rar [2009-04-12 13:27:00 | 000,000,000 | R--- | M] () -- C:\logwmemory.bin [2008-09-25 18:20:16 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008-04-14 00:02:00 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-05-22 21:53:45 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [2010-05-22 21:54:57 | 000,000,129 | ---- | M] () -- C:\service.log [2010-04-22 09:15:15 | 000,000,040 | ---- | M] () -- C:\Session.xml [2009-02-21 22:29:52 | 000,051,371 | -H-- | M] () -- C:\treeinfo.wc [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008-04-14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [2008-04-14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [2008-04-13 23:10:32 | 000,096,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drivers\atapi.sys [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2009-08-28 20:33:42 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys [2009-08-28 20:33:42 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys [2008-04-14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color] [2008-04-14 22:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ERDNT\cache\eventlog.dll [2008-04-14 22:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2008-04-14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys [2008-04-14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ERDNT\cache\winlogon.exe [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\system32\winlogon.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8C35AEA7 < End of report > [/log] //P.S zaraz dam log z Combo Fix'a Oto log z niego: [log]ComboFix 10-05-22.01 - Ram 2010-05-22 22:40:25.8.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2046.1587 [GMT 2:00] Uruchomiony z: F:\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: ArcaFirewall 2008 *enabled* {B640009B-6FF6-4CA7-9CE8-7DA160B95A5B} UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Ram\Dane aplikacji\EurekaLog . ((((((((((((((((((((((((( Pliki utworzone od 2010-04-22 do 2010-05-22 ))))))))))))))))))))))))))))))) . 2010-05-10 11:46 . 2010-05-10 11:46 -------- d-----w- c:\program files\YASAVOB2MPEG 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(3) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(2) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder 2010-04-26 20:11 . 2010-05-20 13:31 161144 ----a-w- c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat 2010-04-26 18:25 . 2010-04-26 18:27 1430522 ----a-w- c:\documents and settings\Ram\subedit_b4072_install.exe 2010-04-26 18:11 . 2010-04-09 19:21 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2010-04-26 17:52 . 2010-04-26 17:52 -------- d-----w- c:\documents and settings\Ram\Ustawienia lokalne\Dane aplikacji\VSO 2010-04-26 17:50 . 2010-04-26 17:50 -------- d-----w- c:\program files\Xvid 2010-04-26 17:48 . 2010-04-26 17:49 652794 ----a-w- c:\documents and settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe 2010-04-26 17:42 . 2010-04-26 17:43 892475 ----a-w- c:\documents and settings\Ram\xvidcore-1.2.2.zip 2010-04-26 17:01 . 2010-04-26 17:01 -------- d-----w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS 2010-04-26 16:50 . 2010-04-26 18:39 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\AVI ReComp 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AviSynth 2.5 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AVI ReComp 2010-04-26 16:30 . 2010-04-26 17:01 18172 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip 2010-04-25 21:05 . 2010-04-25 21:04 12615 ----a-w- c:\documents and settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip 2010-04-25 18:51 . 2010-04-26 17:00 18569 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\WinAVI 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\program files\WinAVI Video Converter 2010-04-25 14:54 . 2010-04-25 14:57 -------- d-----w- c:\program files\VirtualDubMod 2010-04-25 13:28 . 2010-04-25 13:36 -------- d-----w- c:\program files\mkvtoavi . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-22 20:46 . 2008-09-25 16:28 16608 ----a-w- c:\windows\gdrv.sys 2010-05-17 17:06 . 2010-03-16 18:59 439816 ----a-w- c:\documents and settings\Ram\Dane aplikacji\Real\Update\setup3.10\setup.exe 2010-05-14 13:58 . 2008-09-25 16:29 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-05-05 19:50 . 2001-10-26 18:15 586018 ----a-w- c:\windows\system32\perfh015.dat 2010-05-05 19:50 . 2001-10-26 18:15 109654 ----a-w- c:\windows\system32\perfc015.dat 2010-04-26 17:53 . 2009-04-19 15:33 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\VSO 2010-04-17 16:30 . 2010-04-17 16:30 10 ----a-w- c:\windows\popcinfo.dat 2010-04-17 16:28 . 2010-04-17 16:28 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\MumboJumbo 2010-04-17 09:04 . 2009-11-01 16:33 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-04-17 09:04 . 2009-11-01 16:29 215128 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-04-12 15:51 . 2010-04-12 15:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard Entertainment 2010-04-11 12:49 . 2010-04-11 12:49 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard 2010-04-04 21:07 . 2009-02-28 10:37 -------- d-----w- c:\program files\NAPI-PROJEKT 2009-08-28 07:07 . 2009-08-28 07:07 13439 ----a-w- c:\program files\Common Files\awabifal.db . ------- Sigcheck ------- [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [-] 2008-04-13 19:10 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys [-] 2008-05-30 . C8BDAD4065118558B3DC360FC96D81DB . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2010-03-01_14.22.18 ))))))))))))))))))))))))))))))))))))))))) . + 2010-05-22 20:45 . 2010-05-22 20:45 16384 c:\windows\Temp\Perflib_Perfdata_750.dat + 2010-05-22 20:45 . 2010-05-22 20:45 16384 c:\windows\Temp\Perflib_Perfdata_71c.dat + 2008-07-18 21:10 . 2009-08-06 18:24 44768 c:\windows\system32\wups2.dll + 2008-09-25 16:18 . 2009-08-06 18:24 35552 c:\windows\system32\wups.dll + 2008-09-25 16:18 . 2009-08-06 18:24 53472 c:\windows\system32\wuauclt.exe + 2005-01-28 12:44 . 2005-01-28 12:44 10752 c:\windows\system32\wpdtrace.dll + 2005-01-28 12:44 . 2005-01-28 12:44 66560 c:\windows\system32\wpdmtpus.dll + 2005-01-28 12:44 . 2005-01-28 12:44 61952 c:\windows\system32\wpdconns.dll + 2005-01-28 12:44 . 2005-01-28 12:44 38912 c:\windows\system32\wpd_ci.dll + 2008-04-14 20:50 . 2005-01-28 12:44 33792 c:\windows\system32\WMDMPS.dll + 2008-04-14 20:50 . 2005-01-28 12:44 28160 c:\windows\system32\WMDMLOG.dll + 2008-04-14 20:50 . 2009-06-25 08:27 54272 c:\windows\system32\wdigest.dll + 2005-01-28 12:44 . 2005-01-28 12:44 38912 c:\windows\system32\wdfmgr.exe + 2005-01-28 12:44 . 2005-01-28 12:44 15872 c:\windows\system32\wdfapi.dll + 2010-03-06 15:50 . 2009-04-28 20:20 96752 c:\windows\system32\vxblock.dll + 2005-01-28 12:44 . 2005-01-28 12:44 47104 c:\windows\system32\uwdf.exe + 2008-04-14 20:51 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe + 2008-04-14 20:51 . 2009-06-15 10:45 82944 c:\windows\system32\tlntsess.exe + 2008-04-14 20:51 . 2009-06-15 10:45 78336 c:\windows\system32\telnet.exe + 2008-04-14 20:50 . 2009-10-21 05:40 75776 c:\windows\system32\strmfilt.dll - 2008-04-14 20:50 . 2008-04-14 20:50 75776 c:\windows\system32\strmfilt.dll + 2008-12-02 09:56 . 2008-07-09 07:57 26488 c:\windows\system32\spupdsvc.exe - 2008-12-02 09:56 . 2007-11-30 11:18 26488 c:\windows\system32\spupdsvc.exe + 2008-09-25 16:20 . 2009-05-26 11:43 19320 c:\windows\system32\spmsg.dll + 2010-03-21 07:43 . 2009-08-06 18:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll + 2010-03-21 07:43 . 2009-08-06 18:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll + 2008-04-14 20:50 . 2009-06-25 08:27 56832 c:\windows\system32\secur32.dll + 2001-10-26 19:30 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe + 2008-04-14 20:50 . 2009-10-12 13:40 79872 c:\windows\system32\raschap.dll - 2008-04-14 20:50 . 2008-04-14 20:50 79872 c:\windows\system32\raschap.dll + 2010-03-06 15:50 . 2009-04-28 20:20 66032 c:\windows\system32\pxinsa64.exe + 2010-03-06 15:50 . 2009-04-28 20:20 72176 c:\windows\system32\pxhpinst.exe + 2010-03-06 15:50 . 2009-04-28 20:20 66544 c:\windows\system32\pxcpya64.exe + 2008-05-30 13:20 . 2010-01-05 09:57 44544 c:\windows\system32\pngfilt.dll - 2008-05-30 13:20 . 2008-10-16 20:33 44544 c:\windows\system32\pngfilt.dll + 2001-08-17 23:30 . 2010-05-05 19:50 86760 c:\windows\system32\perfc009.dat - 2008-09-25 16:17 . 2008-04-14 20:50 91648 c:\windows\system32\mtxoci.dll + 2008-09-25 16:17 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll - 2008-04-14 20:50 . 2008-04-14 20:50 66560 c:\windows\system32\mtxclu.dll + 2008-04-14 20:50 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll + 2008-04-14 22:50 . 2009-11-27 17:14 17920 c:\windows\system32\msyuv.dll + 2001-10-26 19:29 . 2009-11-27 16:09 28672 c:\windows\system32\msvidc32.dll + 2008-04-14 20:50 . 2009-11-27 16:09 11264 c:\windows\system32\msrle32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 11264 c:\windows\system32\msrle32.dll + 2008-04-14 20:50 . 2005-01-28 12:44 25088 c:\windows\system32\MsPMSNSv.dll - 2008-05-30 13:20 . 2008-10-16 20:33 52224 c:\windows\system32\msfeedsbs.dll + 2008-05-30 13:20 . 2010-01-05 09:57 52224 c:\windows\system32\msfeedsbs.dll + 2008-09-25 16:17 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll - 2008-09-25 16:17 . 2008-04-14 20:50 58880 c:\windows\system32\msdtclog.dll + 2008-04-14 20:50 . 2009-09-04 21:05 58880 c:\windows\system32\msasn1.dll + 2008-04-14 20:51 . 2008-06-10 04:52 96768 c:\windows\system32\logagent.exe + 2008-05-30 13:20 . 2010-01-05 09:57 27648 c:\windows\system32\jsproxy.dll - 2008-05-30 13:20 . 2008-10-16 20:33 27648 c:\windows\system32\jsproxy.dll + 2008-04-14 22:50 . 2009-11-27 16:09 48128 c:\windows\system32\iyuv_32.dll + 2008-05-30 13:20 . 2009-12-31 15:35 13824 c:\windows\system32\ieudinit.exe - 2008-05-30 13:20 . 2008-10-16 13:11 13824 c:\windows\system32\ieudinit.exe + 2008-05-30 13:20 . 2010-01-05 09:57 44544 c:\windows\system32\iernonce.dll - 2008-05-30 13:20 . 2008-10-16 20:33 44544 c:\windows\system32\iernonce.dll - 2008-05-30 13:20 . 2008-05-30 13:20 78336 c:\windows\system32\ieencode.dll + 2008-05-30 13:20 . 2010-01-05 09:57 78336 c:\windows\system32\ieencode.dll - 2008-05-30 13:19 . 2008-10-16 13:15 70656 c:\windows\system32\ie4uinit.exe + 2008-05-30 13:19 . 2009-12-31 15:35 70656 c:\windows\system32\ie4uinit.exe - 2008-05-30 13:19 . 2008-10-16 20:33 63488 c:\windows\system32\icardie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 63488 c:\windows\system32\icardie.dll + 2008-04-14 20:50 . 2009-10-21 05:40 25088 c:\windows\system32\httpapi.dll + 2008-04-14 20:50 . 2009-10-15 16:33 81920 c:\windows\system32\fontsub.dll + 2008-04-14 20:50 . 2005-01-28 12:44 96768 c:\windows\system32\drmstor.dll + 2005-01-28 12:44 . 2005-01-28 12:44 18944 c:\windows\system32\drivers\wpdusb.sys + 2010-03-06 15:50 . 2009-04-28 20:20 44944 c:\windows\system32\drivers\PxHelp20.sys + 2008-04-13 22:01 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys + 2009-06-25 08:27 . 2009-06-25 08:27 54272 c:\windows\system32\dllcache\wdigest.dll + 2009-06-15 10:45 . 2009-06-15 10:45 82944 c:\windows\system32\dllcache\tlntsess.exe + 2009-06-15 10:45 . 2009-06-15 10:45 78336 c:\windows\system32\dllcache\telnet.exe + 2009-10-21 05:40 . 2009-10-21 05:40 75776 c:\windows\system32\dllcache\strmfilt.dll + 2009-06-25 08:27 . 2009-06-25 08:27 56832 c:\windows\system32\dllcache\secur32.dll + 2010-03-21 07:54 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe + 2009-10-12 13:40 . 2009-10-12 13:40 79872 c:\windows\system32\dllcache\raschap.dll + 2008-08-26 08:27 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\pngfilt.dll - 2008-08-26 08:27 . 2008-10-16 20:33 44544 c:\windows\system32\dllcache\pngfilt.dll + 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll + 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll + 2009-11-27 17:14 . 2009-11-27 17:14 17920 c:\windows\system32\dllcache\msyuv.dll + 2009-11-27 16:09 . 2009-11-27 16:09 28672 c:\windows\system32\dllcache\msvidc32.dll + 2009-11-27 16:09 . 2009-11-27 16:09 11264 c:\windows\system32\dllcache\msrle32.dll + 2008-08-26 08:26 . 2010-01-05 09:57 52224 c:\windows\system32\dllcache\msfeedsbs.dll - 2008-08-26 08:26 . 2008-10-16 20:33 52224 c:\windows\system32\dllcache\msfeedsbs.dll + 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll + 2009-09-04 21:05 . 2009-09-04 21:05 58880 c:\windows\system32\dllcache\msasn1.dll + 2008-04-14 20:51 . 2008-06-10 04:52 96768 c:\windows\system32\dllcache\logagent.exe + 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys - 2008-08-26 08:26 . 2008-10-16 20:33 27648 c:\windows\system32\dllcache\jsproxy.dll + 2008-08-26 08:26 . 2010-01-05 09:57 27648 c:\windows\system32\dllcache\jsproxy.dll + 2009-11-27 16:09 . 2009-11-27 16:09 48128 c:\windows\system32\dllcache\iyuv_32.dll + 2008-08-25 08:38 . 2009-12-31 15:35 13824 c:\windows\system32\dllcache\ieudinit.exe - 2008-08-25 08:38 . 2008-10-16 13:11 13824 c:\windows\system32\dllcache\ieudinit.exe - 2008-08-26 08:26 . 2008-10-16 20:33 44544 c:\windows\system32\dllcache\iernonce.dll + 2008-08-26 08:26 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\iernonce.dll + 2010-01-05 09:57 . 2010-01-05 09:57 78336 c:\windows\system32\dllcache\ieencode.dll + 2008-08-25 08:42 . 2009-12-31 15:35 70656 c:\windows\system32\dllcache\ie4uinit.exe - 2008-08-25 08:42 . 2008-10-16 13:15 70656 c:\windows\system32\dllcache\ie4uinit.exe + 2008-08-26 08:26 . 2010-01-05 09:57 63488 c:\windows\system32\dllcache\icardie.dll - 2008-08-26 08:26 . 2008-10-16 20:33 63488 c:\windows\system32\dllcache\icardie.dll + 2009-10-21 05:40 . 2009-10-21 05:40 25088 c:\windows\system32\dllcache\httpapi.dll + 2010-03-21 07:55 . 2009-10-15 16:33 81920 c:\windows\system32\dllcache\fontsub.dll + 2009-12-14 07:10 . 2009-12-14 07:10 33280 c:\windows\system32\dllcache\csrsrv.dll + 2010-01-05 09:57 . 2010-01-05 09:57 17408 c:\windows\system32\dllcache\corpol.dll + 2009-11-27 16:09 . 2009-11-27 16:09 84992 c:\windows\system32\dllcache\avifil32.dll + 2009-07-17 19:04 . 2009-07-17 19:04 58880 c:\windows\system32\dllcache\atl.dll + 2008-04-14 20:50 . 2009-12-14 07:10 33280 c:\windows\system32\csrsrv.dll + 2008-05-30 13:19 . 2010-01-05 09:57 17408 c:\windows\system32\corpol.dll - 2008-05-30 13:19 . 2008-05-30 13:19 17408 c:\windows\system32\corpol.dll + 2008-04-14 20:50 . 2009-08-06 18:24 96480 c:\windows\system32\cdm.dll - 2008-04-14 20:50 . 2008-04-14 20:50 84992 c:\windows\system32\avifil32.dll + 2008-04-14 20:50 . 2009-11-27 16:09 84992 c:\windows\system32\avifil32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 58880 c:\windows\system32\atl.dll + 2008-04-14 20:50 . 2009-07-17 19:04 58880 c:\windows\system32\atl.dll + 2009-12-01 19:05 . 2009-10-18 11:53 65536 c:\windows\system\vdsvrlnk.dll + 2009-12-01 19:05 . 2009-10-18 11:54 73728 c:\windows\system\vdremote.dll + 2010-03-06 15:53 . 2005-01-28 12:44 96768 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmstor.dll + 2010-03-06 15:53 . 2008-04-14 20:50 87040 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmstor.dll + 2010-03-06 15:53 . 2005-01-28 12:44 96768 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\logagent.exe + 2010-03-06 15:53 . 2005-01-28 12:44 18944 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdusb.sys + 2010-03-06 15:53 . 2005-01-28 12:44 10752 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdtrace.dll + 2010-03-06 15:53 . 2005-01-28 12:44 66560 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpus.dll + 2010-03-06 15:53 . 2005-01-28 12:44 61952 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdconns.dll + 2010-03-06 15:53 . 2005-01-28 12:44 38912 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpd_ci.dll + 2010-03-06 15:53 . 2005-01-28 12:44 38912 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe + 2010-03-06 15:53 . 2005-01-28 12:44 15872 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfapi.dll + 2010-03-06 15:53 . 2005-01-28 12:44 47104 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\uwdf.exe + 2010-03-06 15:53 . 2005-01-28 12:44 33792 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMPS.dll + 2010-03-06 15:53 . 2005-01-28 12:44 28160 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMLOG.dll + 2010-03-06 15:53 . 2005-01-28 12:44 25088 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll + 2010-03-06 15:53 . 2008-04-14 20:50 23552 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMPS.dll + 2010-03-06 15:53 . 2008-04-14 20:50 27136 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMLOG.dll + 2010-03-06 15:53 . 2008-04-14 20:50 52736 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll + 2008-11-25 03:59 . 2008-11-25 03:59 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2010-04-17 08:59 . 2010-04-17 08:59 21504 c:\windows\Installer\c66d4.msi + 2010-03-21 08:57 . 2008-10-16 20:33 44544 c:\windows\ie7updates\KB978207-IE7\pngfilt.dll + 2010-03-21 08:57 . 2008-10-16 20:33 52224 c:\windows\ie7updates\KB978207-IE7\msfeedsbs.dll + 2010-03-21 08:57 . 2008-10-16 20:33 27648 c:\windows\ie7updates\KB978207-IE7\jsproxy.dll + 2010-03-21 08:57 . 2008-10-16 13:11 13824 c:\windows\ie7updates\KB978207-IE7\ieudinit.exe + 2010-03-21 08:57 . 2008-10-16 20:33 44544 c:\windows\ie7updates\KB978207-IE7\iernonce.dll + 2010-03-21 08:57 . 2008-05-30 13:20 78336 c:\windows\ie7updates\KB978207-IE7\ieencode.dll + 2010-03-21 08:57 . 2008-10-16 13:15 70656 c:\windows\ie7updates\KB978207-IE7\ie4uinit.exe + 2010-03-21 08:57 . 2008-10-16 20:33 63488 c:\windows\ie7updates\KB978207-IE7\icardie.dll + 2010-03-21 08:57 . 2008-05-30 13:19 17408 c:\windows\ie7updates\KB978207-IE7\corpol.dll + 2008-09-26 12:04 . 2009-11-27 17:14 17920 c:\windows\Driver Cache\i386\msyuv.dll + 2009-11-27 16:09 . 2009-11-27 16:09 48128 c:\windows\Driver Cache\i386\iyuv_32.dll + 2010-03-21 09:18 . 2010-03-21 09:18 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\b4a9e413d5cd6d6ec2d50aa05381e293\UIAutomationProvider.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\8acb476a0d4ee17a12881e17ae74a6af\System.Windows.Presentation.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\4b87ca3482a3c0ee733e028ecee7de65\System.Web.DynamicData.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\a0c71055364bd356971791284c3fb910\System.ComponentModel.DataAnnotations.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f9a75bbdc2ce7db578b5977766a09b99\System.AddIn.Contract.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\3dd0f86c966c75755d62eab8ddf0634c\PresentationFontCache.ni.exe + 2010-03-21 09:16 . 2010-03-21 09:16 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\034d081fe294bab1ee1ecc98c1181424\PresentationCFFRasterizer.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2673aec397c52796aef05bb9d2668df\Microsoft.Vsa.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d513fe1a81c441e7656a9b062cff4e9f\Microsoft.Build.Framework.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\c5d504724d7f351b1d034615dbb72a2a\Microsoft.Build.Framework.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a664ccab020f93f1d533919f57131190\dfsvc.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2010-03-21 09:04 . 2010-03-21 09:04 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll - 2010-01-20 12:03 . 2010-01-20 12:03 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll - 2010-01-20 12:03 . 2010-01-20 12:03 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2010-03-21 09:04 . 2010-03-21 09:04 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2010-03-21 09:04 . 2010-03-21 09:04 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2010-01-20 12:03 . 2010-01-20 12:03 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2010-01-20 12:03 . 2010-01-20 12:03 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-03-21 09:04 . 2010-03-21 09:04 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll - 2010-01-20 12:03 . 2010-01-20 12:03 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-03-21 09:04 . 2010-03-21 09:04 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2010-01-20 12:03 . 2010-01-20 12:03 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2010-01-20 12:03 . 2010-01-20 12:03 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2010-03-21 09:04 . 2010-03-21 09:04 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2010-01-20 12:03 . 2010-01-20 12:03 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-03-21 09:04 . 2010-03-21 09:04 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll - 2010-01-20 12:03 . 2010-01-20 12:03 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-03-21 09:04 . 2010-03-21 09:04 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-03-21 08:57 . 2008-10-23 10:06 62976 c:\windows\$NtUninstallKB979306$\tzchange.exe + 2010-03-21 08:57 . 2010-01-23 10:43 16896 c:\windows\$NtUninstallKB979306$\spuninst\tzchange.dll + 2010-03-21 09:02 . 2008-04-14 20:50 32256 c:\windows\$NtUninstallKB978037$\csrsrv.dll + 2010-03-21 08:58 . 2001-10-26 19:29 25600 c:\windows\$NtUninstallKB977914$\msvidc32.dll + 2010-03-21 08:58 . 2008-04-14 20:50 11264 c:\windows\$NtUninstallKB977914$\msrle32.dll + 2010-03-21 08:58 . 2008-04-14 21:09 47616 c:\windows\$NtUninstallKB977914$\iyuv_32.dll + 2010-03-21 08:58 . 2008-04-14 20:50 84992 c:\windows\$NtUninstallKB977914$\avifil32.dll + 2010-03-21 08:59 . 2008-04-14 21:09 16896 c:\windows\$NtUninstallKB975560$\msyuv.dll + 2010-03-21 08:59 . 2008-04-14 20:50 57344 c:\windows\$NtUninstallKB974571$\msasn1.dll + 2010-03-21 09:02 . 2008-04-14 20:50 79872 c:\windows\$NtUninstallKB974318$\raschap.dll + 2010-03-21 08:59 . 2008-04-14 20:50 58880 c:\windows\$NtUninstallKB973507$\atl.dll + 2010-03-21 09:02 . 2008-04-14 20:50 80896 c:\windows\$NtUninstallKB972270$\fontsub.dll + 2010-03-22 06:47 . 2008-04-14 20:50 75776 c:\windows\$NtUninstallKB970430$\strmfilt.dll + 2010-03-22 06:47 . 2008-04-14 20:50 24576 c:\windows\$NtUninstallKB970430$\httpapi.dll + 2010-03-21 08:57 . 2008-04-14 20:50 49152 c:\windows\$NtUninstallKB968389$\wdigest.dll + 2010-03-21 08:57 . 2008-04-14 20:50 56320 c:\windows\$NtUninstallKB968389$\secur32.dll + 2010-03-21 08:57 . 2008-04-13 22:01 92288 c:\windows\$NtUninstallKB968389$\ksecdd.sys + 2010-03-21 09:04 . 2008-04-14 20:51 80384 c:\windows\$NtUninstallKB960859$\tlntsess.exe + 2010-03-21 09:04 . 2008-04-14 20:51 77824 c:\windows\$NtUninstallKB960859$\telnet.exe + 2010-03-21 09:00 . 2001-10-26 19:30 31232 c:\windows\$NtUninstallKB956572$\sc.exe + 2010-03-21 08:59 . 2008-04-14 20:50 91648 c:\windows\$NtUninstallKB952004$\mtxoci.dll + 2010-03-21 08:59 . 2008-04-14 20:50 66560 c:\windows\$NtUninstallKB952004$\mtxclu.dll + 2010-03-21 08:59 . 2008-04-14 20:50 58880 c:\windows\$NtUninstallKB952004$\msdtclog.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978706\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978706\spmsg.dll + 2010-03-21 09:04 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978262\update\spcustom.dll + 2010-03-21 09:04 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978262\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978251\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978251\spmsg.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978207-IE7\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978207-IE7\spmsg.dll + 2010-01-05 09:49 . 2010-01-05 09:49 44544 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\pngfilt.dll + 2010-01-05 09:49 . 2010-01-05 09:49 52224 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msfeedsbs.dll + 2010-01-05 09:49 . 2010-01-05 09:49 27648 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\jsproxy.dll + 2010-01-01 06:58 . 2010-01-01 06:58 13824 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieudinit.exe + 2010-01-05 09:49 . 2010-01-05 09:49 44544 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iernonce.dll + 2010-01-05 09:49 . 2010-01-05 09:49 78336 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieencode.dll + 2010-01-01 06:58 . 2010-01-01 06:58 70656 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ie4uinit.exe + 2010-01-05 09:49 . 2010-01-05 09:49 63488 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\icardie.dll + 2010-01-05 09:49 . 2010-01-05 09:49 17408 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\corpol.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978037\update\spcustom.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978037\spmsg.dll + 2009-12-14 07:11 . 2009-12-14 07:11 33280 c:\windows\$hf_mig$\KB978037\SP3QFE\csrsrv.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB977914\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB977914\spmsg.dll + 2009-11-27 16:29 . 2009-11-27 16:29 28672 c:\windows\$hf_mig$\KB977914\SP3QFE\msvidc32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 11264 c:\windows\$hf_mig$\KB977914\SP3QFE\msrle32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 48128 c:\windows\$hf_mig$\KB977914\SP3QFE\iyuv_32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 84992 c:\windows\$hf_mig$\KB977914\SP3QFE\avifil32.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB977165-v2\update\spcustom.dll + 2010-03-21 07:56 . 2010-02-24 15:25 16896 c:\windows\$hf_mig$\KB977165-v2\update\mpsyschk.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB977165-v2\spmsg.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975713\update\spcustom.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975713\spmsg.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB975561\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB975561\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975560\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975560\spmsg.dll + 2009-11-27 17:25 . 2009-11-27 17:25 17920 c:\windows\$hf_mig$\KB975560\SP3QFE\msyuv.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB975467\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB975467\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975025\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975025\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974571\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974571\spmsg.dll + 2009-09-04 21:01 . 2009-09-04 21:01 58880 c:\windows\$hf_mig$\KB974571\SP3QFE\msasn1.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974392\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974392\spmsg.dll + 2010-03-21 09:03 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974318\update\spcustom.dll + 2010-03-21 09:03 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974318\spmsg.dll + 2009-10-12 13:33 . 2009-10-12 13:33 79872 c:\windows\$hf_mig$\KB974318\SP3QFE\raschap.dll + 2010-03-21 09:00 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974112\update\spcustom.dll + 2010-03-21 09:00 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974112\spmsg.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973904\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973904\spmsg.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB973869\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB973869\spmsg.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973815\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973815\spmsg.dll + 2010-03-21 08:58 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB973687\update\spcustom.dll + 2010-03-21 08:58 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB973687\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973507\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973507\spmsg.dll + 2009-07-17 19:28 . 2009-07-17 19:28 58880 c:\windows\$hf_mig$\KB973507\SP3QFE\atl.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973354\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973354\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB972270\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB972270\spmsg.dll + 2010-03-21 07:55 . 2009-10-15 16:40 81920 c:\windows\$hf_mig$\KB972270\SP3QFE\fontsub.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB971961\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB971961\spmsg.dll + 2010-03-22 06:47 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971737\update\spcustom.dll + 2010-03-22 06:47 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971737\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971657\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971657\spmsg.dll + 2010-03-21 09:03 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971468\update\spcustom.dll + 2010-03-21 09:03 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971468\spmsg.dll + 2010-03-22 06:47 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB970430\update\spcustom.dll + 2010-03-22 06:47 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB970430\spmsg.dll + 2009-10-21 05:42 . 2009-10-21 05:42 75776 c:\windows\$hf_mig$\KB970430\SP3QFE\strmfilt.dll + 2009-10-21 05:42 . 2009-10-21 05:42 25088 c:\windows\$hf_mig$\KB970430\SP3QFE\httpapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB970238\update\spcustom.dll + 2010-03-21 08:58 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB970238\spmsg.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB969947\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB969947\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB969059\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB969059\spmsg.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB968389\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB968389\spmsg.dll + 2009-06-25 08:42 . 2009-06-25 08:42 54272 c:\windows\$hf_mig$\KB968389\SP3QFE\wdigest.dll + 2009-06-25 08:42 . 2009-06-25 08:42 56832 c:\windows\$hf_mig$\KB968389\SP3QFE\secur32.dll + 2009-06-24 10:28 . 2009-06-24 10:28 92928 c:\windows\$hf_mig$\KB968389\SP3QFE\ksecdd.sys + 2010-03-21 08:58 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB967715\update\spcustom.dll + 2010-03-21 08:58 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB967715\spmsg.dll + 2010-03-21 08:59 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB961501\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB961501\spmsg.dll + 2010-03-21 09:04 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB960859\update\spcustom.dll + 2010-03-21 09:04 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB960859\spmsg.dll + 2009-06-15 11:14 . 2009-06-15 11:14 82944 c:\windows\$hf_mig$\KB960859\SP3QFE\tlntsess.exe + 2009-06-15 11:14 . 2009-06-15 11:14 78336 c:\windows\$hf_mig$\KB960859\SP3QFE\telnet.exe + 2010-03-21 08:57 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB960803\update\spcustom.dll + 2010-03-21 08:57 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB960803\spmsg.dll + 2010-03-21 09:02 . 2007-11-30 11:21 26488 c:\windows\$hf_mig$\KB960225\update\spcustom.dll + 2010-03-21 09:02 . 2007-11-30 11:21 19320 c:\windows\$hf_mig$\KB960225\spmsg.dll + 2010-03-21 09:04 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB959426\update\spcustom.dll + 2010-03-21 09:04 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB959426\spmsg.dll + 2009-02-04 09:17 . 2009-02-04 09:17 56832 c:\windows\$hf_mig$\KB959426\SP3QFE\secur32.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB956844\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB956844\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB956744\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB956744\spmsg.dll + 2010-03-21 09:00 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB956572\update\spcustom.dll + 2010-03-21 09:00 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB956572\spmsg.dll + 2010-03-21 07:54 . 2009-02-06 10:36 35328 c:\windows\$hf_mig$\KB956572\SP3QFE\sc.exe + 2010-03-21 09:03 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB955759\update\spcustom.dll + 2010-03-21 09:03 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB955759\spmsg.dll + 2010-03-21 08:59 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB952004\update\spcustom.dll + 2010-03-21 08:59 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB952004\spmsg.dll + 2008-06-12 14:11 . 2008-06-12 14:11 91648 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxoci.dll + 2008-06-12 14:11 . 2008-06-12 14:11 66560 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxclu.dll + 2008-06-12 14:11 . 2008-06-12 14:11 58880 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtclog.dll + 2010-03-21 08:58 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB951748\update\spcustom.dll + 2010-03-21 08:58 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB951748\spmsg.dll + 2010-03-21 08:57 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB923561\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB923561\spmsg.dll + 2010-03-21 09:04 . 2010-03-21 09:04 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll - 2010-01-20 12:03 . 2010-01-20 12:03 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2008-05-05 06:25 . 2008-05-05 06:25 3072 c:\windows\system32\xpsp4res.dll + 2001-10-26 17:29 . 2009-11-27 16:09 8704 c:\windows\system32\tsbyuv.dll - 2008-04-14 20:50 . 2008-04-14 20:50 6656 c:\windows\system32\laprxy.dll + 2008-04-14 20:50 . 2005-01-28 12:44 6656 c:\windows\system32\laprxy.dll + 2010-03-06 15:50 . 2009-04-28 20:20 9200 c:\windows\system32\drivers\cdralw2k.sys + 2010-03-06 15:50 . 2009-04-28 20:20 9072 c:\windows\system32\drivers\cdr4_xp.sys + 2009-11-27 16:09 . 2009-11-27 16:09 8704 c:\windows\system32\dllcache\tsbyuv.dll + 2010-03-06 15:53 . 2005-01-28 12:44 6656 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\laprxy.dll + 2010-03-06 15:53 . 2008-04-14 20:50 6656 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\laprxy.dll + 2009-11-27 16:09 . 2009-11-27 16:09 8704 c:\windows\Driver Cache\i386\tsbyuv.dll - 2010-01-20 12:03 . 2010-01-20 12:03 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-03-21 09:04 . 2010-03-21 09:04 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2010-01-20 12:03 . 2010-01-20 12:03 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2010-01-20 12:03 . 2010-01-20 12:03 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-03-21 09:04 . 2010-03-21 09:04 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-03-21 09:04 . 2010-03-21 09:04 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2010-01-20 12:03 . 2010-01-20 12:03 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll + 2010-03-21 08:58 . 2001-10-26 20:03 8192 c:\windows\$NtUninstallKB977914$\tsbyuv.dll + 2009-11-27 16:29 . 2009-11-27 16:29 8704 c:\windows\$hf_mig$\KB977914\SP3QFE\tsbyuv.dll + 2010-03-21 07:46 . 2008-05-05 06:25 3072 c:\windows\$hf_mig$\KB923561\SP3QFE\sprv0415.dll + 2010-03-21 09:04 . 2010-03-21 09:04 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2009-09-30 12:18 . 2009-06-07 14:24 180224 c:\windows\system32\xvidvfw.dll - 2009-09-30 12:18 . 2008-12-04 19:46 180224 c:\windows\system32\xvidvfw.dll + 2009-09-30 12:18 . 2009-06-07 14:16 819200 c:\windows\system32\xvidcore.dll + 2008-09-25 16:18 . 2009-08-06 18:24 209632 c:\windows\system32\wuweb.dll + 2008-09-25 16:18 . 2009-08-06 18:24 327896 c:\windows\system32\wucltui.dll + 2008-09-25 16:18 . 2009-08-06 18:23 575704 c:\windows\system32\wuapi.dll + 2005-01-28 12:44 . 2005-01-28 12:44 331264 c:\windows\system32\wpdsp.dll + 2005-01-28 12:44 . 2005-01-28 12:44 331776 c:\windows\system32\wpdmtpdr.dll + 2005-01-28 12:44 . 2005-01-28 12:44 114176 c:\windows\system32\wpdmtp.dll + 2008-04-14 20:51 . 2005-01-28 12:44 895736 c:\windows\system32\wmvdmod.dll + 2008-04-14 20:51 . 2005-01-28 12:44 940544 c:\windows\system32\wmspdmoe.dll + 2008-04-14 20:51 . 2009-04-10 00:01 413032 c:\windows\system32\wmspdmod.dll + 2008-04-14 20:51 . 2005-01-28 12:44 774904 c:\windows\system32\wmsdmod.dll + 2010-03-07 07:39 . 2008-04-14 20:51 221184 c:\windows\system32\wmpns.dll - 2008-04-14 20:51 . 2008-04-14 20:51 233472 c:\windows\system32\wmpdxm.dll + 2008-04-14 20:51 . 2009-07-12 11:21 233472 c:\windows\system32\wmpdxm.dll + 2008-04-14 20:51 . 2005-01-28 12:44 150016 c:\windows\system32\wmidx.dll + 2005-01-28 12:44 . 2005-01-28 12:44 290816 c:\windows\system32\WMDRMNet.dll + 2005-01-28 12:44 . 2005-01-28 12:44 335872 c:\windows\system32\WMDRMdev.dll + 2008-04-14 20:50 . 2007-10-20 04:01 227328 c:\windows\system32\wmasf.dll + 2008-04-14 20:50 . 2005-01-28 12:44 716288 c:\windows\system32\wmadmoe.dll + 2008-04-14 20:50 . 2005-01-28 12:44 396528 c:\windows\system32\wmadmod.dll + 2008-04-14 20:50 . 2009-06-10 06:16 132096 c:\windows\system32\wkssvc.dll - 2008-04-14 20:50 . 2008-04-14 20:50 132096 c:\windows\system32\wkssvc.dll + 2008-05-30 13:21 . 2010-01-05 09:57 832512 c:\windows\system32\wininet.dll + 2008-04-14 20:50 . 2009-08-25 09:19 354816 c:\windows\system32\winhttp.dll + 2008-05-30 13:21 . 2010-01-05 09:57 233472 c:\windows\system32\webcheck.dll - 2008-05-30 13:21 . 2008-10-16 20:33 233472 c:\windows\system32\webcheck.dll + 2008-09-25 16:17 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe + 2008-09-25 16:17 . 2009-02-09 10:53 453120 c:\windows\system32\wbem\wmiprvsd.dll + 2008-09-25 16:17 . 2009-02-09 10:53 473600 c:\windows\system32\wbem\fastprox.dll - 2008-05-30 13:20 . 2008-10-16 20:33 105984 c:\windows\system32\url.dll + 2008-05-30 13:20 . 2010-01-05 09:57 105984 c:\windows\system32\url.dll + 2008-04-14 20:50 . 2009-10-15 16:33 119808 c:\windows\system32\t2embed.dll + 2008-04-14 20:50 . 2009-08-26 08:02 247326 c:\windows\system32\strmdll.dll - 2008-04-14 20:50 . 2008-10-03 10:04 247326 c:\windows\system32\strmdll.dll - 2008-04-14 20:50 . 2008-04-14 20:50 474112 c:\windows\system32\shlwapi.dll + 2008-04-14 20:50 . 2009-12-08 09:25 474112 c:\windows\system32\shlwapi.dll + 2008-04-14 20:51 . 2009-02-09 11:25 111104 c:\windows\system32\services.exe + 2008-04-14 20:50 . 2009-06-25 08:27 147456 c:\windows\system32\schannel.dll + 2008-04-14 20:50 . 2009-02-09 10:53 401408 c:\windows\system32\rpcss.dll + 2008-04-14 20:50 . 2009-04-15 14:54 585216 c:\windows\system32\rpcrt4.dll + 2008-04-14 20:50 . 2009-10-12 13:40 150016 c:\windows\system32\rastls.dll + 2008-04-14 20:50 . 2005-01-28 12:44 221184 c:\windows\system32\qasf.dll + 2010-03-06 15:50 . 2009-04-28 20:20 436720 c:\windows\system32\pxwave.dll + 2010-03-06 15:50 . 2009-04-28 20:20 219632 c:\windows\system32\pxmas.dll + 2010-03-06 15:50 . 2009-04-28 20:20 551408 c:\windows\system32\pxdrv.dll + 2010-03-06 15:50 . 2009-04-28 20:20 129520 c:\windows\system32\pxafs.dll + 2010-03-06 15:50 . 2009-04-28 20:20 670192 c:\windows\system32\px.dll + 2001-08-17 23:30 . 2010-05-05 19:50 515952 c:\windows\system32\perfh009.dat - 2008-04-14 20:50 . 2008-04-14 20:50 285696 c:\windows\system32\pdh.dll + 2008-04-14 20:50 . 2009-03-06 14:22 285696 c:\windows\system32\pdh.dll + 2008-05-30 13:20 . 2010-01-05 09:57 102912 c:\windows\system32\occache.dll - 2008-05-30 13:20 . 2008-10-16 20:33 102912 c:\windows\system32\occache.dll + 2008-04-14 20:50 . 2009-10-13 10:34 271360 c:\windows\system32\oakley.dll - 2008-04-14 20:50 . 2008-04-14 20:50 271360 c:\windows\system32\oakley.dll + 2008-04-14 20:49 . 2009-02-09 10:53 722944 c:\windows\system32\ntdll.dll + 2008-04-14 20:50 . 2008-06-20 17:48 246784 c:\windows\system32\mswsock.dll - 2008-04-14 20:50 . 2008-04-14 20:50 246784 c:\windows\system32\mswsock.dll + 2008-04-14 20:50 . 2005-01-28 12:44 315904 c:\windows\system32\MSWMDM.dll + 2008-04-14 20:50 . 2009-08-05 09:01 205312 c:\windows\system32\mswebdvd.dll + 2008-04-14 20:50 . 2009-09-11 14:19 136192 c:\windows\system32\msv1_0.dll - 2008-05-30 13:20 . 2008-10-16 20:33 671232 c:\windows\system32\mstime.dll + 2008-05-30 13:20 . 2010-01-05 09:57 671232 c:\windows\system32\mstime.dll + 2008-04-14 20:52 . 2005-01-28 12:44 364784 c:\windows\system32\MSSCP.dll - 2008-05-30 13:20 . 2008-10-16 20:33 193024 c:\windows\system32\msrating.dll + 2008-05-30 13:20 . 2010-01-05 09:57 193024 c:\windows\system32\msrating.dll + 2008-04-14 20:50 . 2005-01-28 12:44 173568 c:\windows\system32\MsPMSP.dll - 2008-09-25 16:17 . 2008-04-14 20:51 345088 c:\windows\system32\mspaint.exe + 2008-09-25 16:17 . 2009-12-17 07:42 345088 c:\windows\system32\mspaint.exe + 2008-04-14 20:52 . 2005-01-28 12:44 142336 c:\windows\system32\msnetobj.dll + 2008-05-30 13:20 . 2010-01-05 09:57 477696 c:\windows\system32\mshtmled.dll - 2008-05-30 13:20 . 2008-10-16 20:33 477696 c:\windows\system32\mshtmled.dll + 2008-05-30 13:20 . 2010-01-05 09:57 459264 c:\windows\system32\msfeeds.dll - 2008-05-30 13:20 . 2008-10-16 20:33 459264 c:\windows\system32\msfeeds.dll - 2008-09-25 16:17 . 2008-04-14 20:50 161792 c:\windows\system32\msdtcuiu.dll + 2008-09-25 16:17 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll - 2008-09-25 16:17 . 2008-04-14 20:50 956928 c:\windows\system32\msdtctm.dll + 2008-09-25 16:17 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll + 2008-09-25 16:17 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll + 2008-04-14 20:50 . 2009-06-25 08:27 732160 c:\windows\system32\lsasrv.dll + 2008-04-14 20:50 . 2009-05-07 15:34 347648 c:\windows\system32\localspl.dll + 2008-04-14 20:50 . 2009-06-25 08:27 301568 c:\windows\system32\kerberos.dll + 2010-03-21 09:03 . 2009-03-10 21:18 455048 c:\windows\system32\KB905474\wgasetup.exe + 2008-04-14 20:50 . 2009-08-13 15:24 512000 c:\windows\system32\jscript.dll - 2008-04-14 20:50 . 2008-05-09 10:56 512000 c:\windows\system32\jscript.dll + 2008-05-30 13:20 . 2010-01-05 09:57 268288 c:\windows\system32\iertutil.dll + 2008-05-30 13:20 . 2010-01-05 09:57 192512 c:\windows\system32\iepeers.dll + 2008-05-30 13:19 . 2010-01-05 09:57 385024 c:\windows\system32\iedkcs32.dll + 2008-05-30 13:19 . 2010-01-05 09:57 380928 c:\windows\system32\ieapfltr.dll - 2008-05-30 13:19 . 2008-10-15 07:04 161792 c:\windows\system32\ieakui.dll + 2008-05-30 13:19 . 2009-12-18 13:04 161792 c:\windows\system32\ieakui.dll - 2008-05-30 13:19 . 2008-10-16 20:33 230400 c:\windows\system32\ieaksie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 230400 c:\windows\system32\ieaksie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 153088 c:\windows\system32\ieakeng.dll - 2008-05-30 13:19 . 2008-10-16 20:33 153088 c:\windows\system32\ieakeng.dll - 2008-09-25 18:12 . 2010-01-20 12:09 273376 c:\windows\system32\FNTCACHE.DAT + 2008-09-25 18:12 . 2010-03-21 09:15 273376 c:\windows\system32\FNTCACHE.DAT + 2008-05-30 13:19 . 2010-01-05 09:57 133120 c:\windows\system32\extmgr.dll - 2008-05-30 13:19 . 2008-10-16 20:33 133120 c:\windows\system32\extmgr.dll + 2008-05-30 13:19 . 2010-01-05 09:57 214528 c:\windows\system32\dxtrans.dll - 2008-05-30 13:19 . 2008-10-16 20:33 214528 c:\windows\system32\dxtrans.dll - 2008-05-30 13:19 . 2008-10-16 20:33 347136 c:\windows\system32\dxtmsft.dll + 2008-05-30 13:19 . 2010-01-05 09:57 347136 c:\windows\system32\dxtmsft.dll + 2008-04-14 20:52 . 2005-01-28 12:44 502272 c:\windows\system32\drmv2clt.dll + 2008-04-14 20:52 . 2005-01-28 12:44 258296 c:\windows\system32\drmclien.dll + 2008-04-13 22:30 . 2008-06-20 11:08 225856 c:\windows\system32\drivers\tcpip6.sys + 2008-04-13 22:50 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys + 2008-04-13 22:45 . 2009-12-31 16:50 353792 c:\windows\system32\drivers\srv.sys + 2008-04-13 22:47 . 2009-12-04 18:22 455424 c:\windows\system32\drivers\mrxsmb.sys + 2008-04-13 22:23 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys - 2008-04-14 20:50 . 2008-04-14 20:50 147968 c:\windows\system32\dnsapi.dll + 2008-04-14 20:50 . 2008-06-20 17:48 147968 c:\windows\system32\dnsapi.dll + 2010-03-21 07:46 . 2008-04-21 21:16 218112 c:\windows\system32\dllcache\wordpad.exe + 2009-04-10 00:01 . 2009-04-10 00:01 413032 c:\windows\system32\dllcache\wmspdmod.dll + 2009-07-12 11:21 . 2009-07-12 11:21 233472 c:\windows\system32\dllcache\wmpdxm.dll + 2010-03-21 07:54 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe + 2010-03-21 07:54 . 2009-02-09 10:53 453120 c:\windows\system32\dllcache\wmiprvsd.dll + 2010-03-21 07:45 . 2007-10-20 04:01 227328 c:\windows\system32\dllcache\wmasf.dll + 2009-06-10 06:16 . 2009-06-10 06:16 132096 c:\windows\system32\dllcache\wkssvc.dll + 2008-08-26 08:27 . 2010-01-05 09:57 832512 c:\windows\system32\dllcache\wininet.dll + 2008-12-16 12:32 . 2009-08-25 09:19 354816 c:\windows\system32\dllcache\winhttp.dll + 2008-08-26 08:27 . 2010-01-05 09:57 233472 c:\windows\system32\dllcache\webcheck.dll - 2008-08-26 08:27 . 2008-10-16 20:33 233472 c:\windows\system32\dllcache\webcheck.dll - 2008-08-26 08:27 . 2008-10-16 20:33 105984 c:\windows\system32\dllcache\url.dll + 2008-08-26 08:27 . 2010-01-05 09:57 105984 c:\windows\system32\dllcache\url.dll + 2010-03-21 07:53 . 2009-06-21 21:48 153088 c:\windows\system32\dllcache\triedit.dll + 2010-03-21 07:45 . 2008-06-20 11:08 225856 c:\windows\system32\dllcache\tcpip6.sys + 2010-03-21 07:45 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys + 2010-03-21 07:55 . 2009-10-15 16:33 119808 c:\windows\system32\dllcache\t2embed.dll - 2008-12-09 20:53 . 2008-10-03 10:04 247326 c:\windows\system32\dllcache\strmdll.dll + 2008-12-09 20:53 . 2009-08-26 08:02 247326 c:\windows\system32\dllcache\strmdll.dll + 2008-12-02 11:26 . 2009-12-31 16:50 353792 c:\windows\system32\dllcache\srv.sys + 2009-12-08 09:25 . 2009-12-08 09:25 474112 c:\windows\system32\dllcache\shlwapi.dll + 2010-03-21 07:54 . 2009-02-09 11:25 111104 c:\windows\system32\dllcache\services.exe + 2009-06-25 08:27 . 2009-06-25 08:27 147456 c:\windows\system32\dllcache\schannel.dll + 2010-03-21 07:54 . 2009-02-09 10:53 401408 c:\windows\system32\dllcache\rpcss.dll + 2009-04-15 14:54 . 2009-04-15 14:54 585216 c:\windows\system32\dllcache\rpcrt4.dll + 2009-10-12 13:40 . 2009-10-12 13:40 150016 c:\windows\system32\dllcache\rastls.dll + 2008-04-14 20:50 . 2005-01-28 12:44 221184 c:\windows\system32\dllcache\qasf.dll + 2010-03-21 07:54 . 2009-03-06 14:22 285696 c:\windows\system32\dllcache\pdh.dll - 2008-08-26 08:27 . 2008-10-16 20:33 102912 c:\windows\system32\dllcache\occache.dll + 2008-08-26 08:27 . 2010-01-05 09:57 102912 c:\windows\system32\dllcache\occache.dll + 2009-10-13 10:34 . 2009-10-13 10:34 271360 c:\windows\system32\dllcache\oakley.dll + 2010-03-21 07:54 . 2009-02-09 10:53 722944 c:\windows\system32\dllcache\ntdll.dll + 2010-03-21 07:45 . 2008-06-20 17:48 246784 c:\windows\system32\dllcache\mswsock.dll + 2008-09-26 12:04 . 2009-08-05 09:01 205312 c:\windows\system32\dllcache\mswebdvd.dll + 2009-06-25 08:27 . 2009-09-11 14:19 136192 c:\windows\system32\dllcache\msv1_0.dll - 2008-08-26 08:27 . 2008-10-16 20:33 671232 c:\windows\system32\dllcache\mstime.dll + 2008-08-26 08:27 . 2010-01-05 09:57 671232 c:\windows\system32\dllcache\mstime.dll - 2008-08-26 08:27 . 2008-10-16 20:33 193024 c:\windows\system32\dllcache\msrating.dll + 2008-08-26 08:27 . 2010-01-05 09:57 193024 c:\windows\system32\dllcache\msrating.dll + 2009-12-17 07:42 . 2009-12-17 07:42 345088 c:\windows\system32\dllcache\mspaint.exe - 2008-08-26 08:27 . 2008-10-16 20:33 477696 c:\windows\system32\dllcache\mshtmled.dll + 2008-08-26 08:27 . 2010-01-05 09:57 477696 c:\windows\system32\dllcache\mshtmled.dll - 2008-08-26 08:26 . 2008-10-16 20:33 459264 c:\windows\system32\dllcache\msfeeds.dll + 2008-08-26 08:26 . 2010-01-05 09:57 459264 c:\windows\system32\dllcache\msfeeds.dll + 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll + 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll + 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll + 2008-12-02 10:03 . 2009-12-04 18:22 455424 c:\windows\system32\dllcache\mrxsmb.sys + 2009-06-25 08:27 . 2009-06-25 08:27 732160 c:\windows\system32\dllcache\lsasrv.dll + 2009-05-07 15:34 . 2009-05-07 15:34 347648 c:\windows\system32\dllcache\localspl.dll + 2009-06-25 08:27 . 2009-06-25 08:27 301568 c:\windows\system32\dllcache\kerberos.dll - 2008-05-09 10:56 . 2008-05-09 10:56 512000 c:\windows\system32\dllcache\jscript.dll + 2008-05-09 10:56 . 2009-08-13 15:24 512000 c:\windows\system32\dllcache\jscript.dll + 2008-08-23 05:56 . 2009-12-18 13:05 634648 c:\windows\system32\dllcache\iexplore.exe + 2008-08-26 08:26 . 2010-01-05 09:57 268288 c:\windows\system32\dllcache\iertutil.dll + 2010-01-05 09:57 . 2010-01-05 09:57 192512 c:\windows\system32\dllcache\iepeers.dll + 2008-08-26 08:26 . 2010-01-05 09:57 385024 c:\windows\system32\dllcache\iedkcs32.dll + 2008-08-26 08:26 . 2010-01-05 09:57 380928 c:\windows\system32\dllcache\ieapfltr.dll + 2008-08-23 05:54 . 2009-12-18 13:04 161792 c:\windows\system32\dllcache\ieakui.dll - 2008-08-23 05:54 . 2008-10-15 07:04 161792 c:\windows\system32\dllcache\ieakui.dll - 2008-08-26 08:26 . 2008-10-16 20:33 230400 c:\windows\system32\dllcache\ieaksie.dll + 2008-08-26 08:26 . 2010-01-05 09:57 230400 c:\windows\system32\dllcache\ieaksie.dll - 2008-08-26 08:26 . 2008-10-16 20:33 153088 c:\windows\system32\dllcache\ieakeng.dll + 2008-08-26 08:26 . 2010-01-05 09:57 153088 c:\windows\system32\dllcache\ieakeng.dll + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys + 2010-03-21 07:54 . 2009-02-09 10:53 473600 c:\windows\system32\dllcache\fastprox.dll + 2008-08-26 08:26 . 2010-01-05 09:57 133120 c:\windows\system32\dllcache\extmgr.dll - 2008-08-26 08:26 . 2008-10-16 20:33 133120 c:\windows\system32\dllcache\extmgr.dll + 2008-08-26 08:26 . 2010-01-05 09:57 214528 c:\windows\system32\dllcache\dxtrans.dll - 2008-08-26 08:26 . 2008-10-16 20:33 214528 c:\windows\system32\dllcache\dxtrans.dll - 2008-08-26 08:26 . 2008-10-16 20:33 347136 c:\windows\system32\dllcache\dxtmsft.dll + 2008-08-26 08:26 . 2010-01-05 09:57 347136 c:\windows\system32\dllcache\dxtmsft.dll + 2010-03-21 07:45 . 2008-06-20 17:48 147968 c:\windows\system32\dllcache\dnsapi.dll - 2008-08-26 08:26 . 2008-10-16 20:33 124928 c:\windows\system32\dllcache\advpack.dll + 2008-08-26 08:26 . 2010-01-05 09:57 124928 c:\windows\system32\dllcache\advpack.dll + 2010-03-21 07:54 . 2009-02-09 10:53 686592 c:\windows\system32\dllcache\advapi32.dll + 2010-03-21 08:02 . 2009-11-21 16:03 471552 c:\windows\system32\dllcache\aclayers.dll + 2004-02-22 08:11 . 2004-02-22 08:11 719872 c:\windows\system32\devil.dll + 2008-04-14 20:50 . 2005-01-28 12:44 164864 c:\windows\system32\cewmdm.dll + 2008-04-14 20:50 . 2005-01-28 12:44 294912 c:\windows\system32\blackbox.dll + 2008-12-21 21:46 . 2008-12-21 21:46 351744 c:\windows\system32\avisynth.dll - 2008-05-30 13:19 . 2008-10-16 20:33 124928 c:\windows\system32\advpack.dll + 2008-05-30 13:19 . 2010-01-05 09:57 124928 c:\windows\system32\advpack.dll + 2008-04-14 20:50 . 2009-02-09 10:53 686592 c:\windows\system32\advapi32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 686592 c:\windows\system32\advapi32.dll + 2010-03-06 15:53 . 2005-01-28 12:44 142336 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\msnetobj.dll + 2010-03-06 15:53 . 2005-01-28 12:44 502272 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmv2clt.dll + 2010-03-06 15:53 . 2005-01-28 12:44 258296 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmclien.dll + 2010-03-06 15:53 . 2005-01-28 12:44 294912 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\blackbox.dll + 2010-03-06 15:53 . 2008-04-14 20:52 259072 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\msnetobj.dll + 2010-03-06 15:53 . 2008-04-14 20:52 695808 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmv2clt.dll + 2010-03-06 15:53 . 2008-04-14 20:52 299520 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmclien.dll + 2010-03-06 15:53 . 2008-04-14 20:50 286720 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\blackbox.dll + 2010-03-06 15:53 . 2005-01-28 12:44 940544 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmspdmoe.dll + 2010-03-06 15:53 . 2005-01-28 12:44 150016 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmidx.dll + 2010-03-06 15:53 . 2005-01-28 12:44 290816 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMNet.dll + 2010-03-06 15:53 . 2005-01-28 12:44 335872 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMdev.dll + 2010-03-06 15:53 . 2005-01-28 12:44 224768 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmasf.dll + 2010-03-06 15:53 . 2005-01-28 12:44 716288 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmadmoe.dll + 2010-03-06 15:53 . 2005-01-28 12:44 221184 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\qasf.dll + 2010-03-06 15:53 . 2008-04-14 20:51 897024 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmspdmoe.dll + 2010-03-06 15:53 . 2008-04-14 20:51 151552 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmidx.dll + 2010-03-06 15:53 . 2008-04-14 20:50 230912 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmasf.dll + 2010-03-06 15:53 . 2008-04-14 20:50 670720 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmadmoe.dll + 2010-03-06 15:53 . 2008-04-14 20:50 237568 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\qasf.dll + 2010-03-06 15:53 . 2008-06-10 02:11 103936 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\logagent.exe + 2010-03-06 15:53 . 2005-01-28 12:44 895736 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 413944 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmspdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 774904 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmsdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 396528 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmadmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 809984 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmvdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 485376 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmspdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 759296 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmsdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:50 408064 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmadmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 331264 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdsp.dll + 2010-03-06 15:53 . 2005-01-28 12:44 331776 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpdr.dll + 2010-03-06 15:53 . 2005-01-28 12:44 114176 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtp.dll + 2010-03-06 15:53 . 2005-01-28 12:44 315904 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSWMDM.dll + 2010-03-06 15:53 . 2005-01-28 12:44 364784 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSSCP.dll + 2010-03-06 15:53 . 2005-01-28 12:44 173568 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSP.dll + 2010-03-06 15:53 . 2005-01-28 12:44 164864 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\cewmdm.dll + 2010-03-06 15:53 . 2008-04-14 20:50 246272 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSWMDM.dll + 2010-03-06 15:53 . 2008-04-14 20:52 356352 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSSCP.dll + 2010-03-06 15:53 . 2008-04-14 20:50 201728 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSP.dll + 2010-03-06 15:53 . 2008-04-14 20:50 159232 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\cewmdm.dll + 2008-11-25 03:59 . 2008-11-25 03:59 436040 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2008-11-25 03:59 . 2008-11-25 03:59 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll - 2008-07-25 10:17 . 2008-07-25 10:17 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll + 2008-11-25 03:59 . 2008-11-25 03:59 364872 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2009-08-07 22:51 . 2009-08-07 22:51 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2008-12-13 08:58 . 2008-12-13 08:58 754688 c:\windows\Installer\47607b.msp + 2009-03-20 10:48 . 2009-03-20 10:48 183808 c:\windows\Installer\476051.msp + 2010-03-21 08:57 . 2008-10-16 20:33 826368 c:\windows\ie7updates\KB978207-IE7\wininet.dll + 2010-03-21 08:57 . 2008-10-16 20:33 233472 c:\windows\ie7updates\KB978207-IE7\webcheck.dll + 2010-03-21 08:57 . 2008-10-16 20:33 105984 c:\windows\ie7updates\KB978207-IE7\url.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\ie7updates\KB978207-IE7\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\ie7updates\KB978207-IE7\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-10-16 20:33 102912 c:\windows\ie7updates\KB978207-IE7\occache.dll + 2010-03-21 08:57 . 2008-10-16 20:33 671232 c:\windows\ie7updates\KB978207-IE7\mstime.dll + 2010-03-21 08:57 . 2008-10-16 20:33 193024 c:\windows\ie7updates\KB978207-IE7\msrating.dll + 2010-03-21 08:57 . 2008-10-16 20:33 477696 c:\windows\ie7updates\KB978207-IE7\mshtmled.dll + 2010-03-21 08:57 . 2008-10-16 20:33 459264 c:\windows\ie7updates\KB978207-IE7\msfeeds.dll + 2010-03-21 08:57 . 2008-10-15 07:06 633632 c:\windows\ie7updates\KB978207-IE7\iexplore.exe + 2010-03-21 08:57 . 2008-10-16 20:33 267776 c:\windows\ie7updates\KB978207-IE7\iertutil.dll + 2010-03-21 08:57 . 2008-05-30 13:20 191488 c:\windows\ie7updates\KB978207-IE7\iepeers.dll + 2010-03-21 08:57 . 2008-10-16 20:33 384512 c:\windows\ie7updates\KB978207-IE7\iedkcs32.dll + 2010-03-21 08:57 . 2008-10-16 20:33 383488 c:\windows\ie7updates\KB978207-IE7\ieapfltr.dll + 2010-03-21 08:57 . 2008-10-15 07:04 161792 c:\windows\ie7updates\KB978207-IE7\ieakui.dll + 2010-03-21 08:57 . 2008-10-16 20:33 230400 c:\windows\ie7updates\KB978207-IE7\ieaksie.dll + 2010-03-21 08:57 . 2008-10-16 20:33 153088 c:\windows\ie7updates\KB978207-IE7\ieakeng.dll + 2010-03-21 08:57 . 2008-10-16 20:33 133120 c:\windows\ie7updates\KB978207-IE7\extmgr.dll + 2010-03-21 08:57 . 2008-10-16 20:33 214528 c:\windows\ie7updates\KB978207-IE7\dxtrans.dll + 2010-03-21 08:57 . 2008-10-16 20:33 347136 c:\windows\ie7updates\KB978207-IE7\dxtmsft.dll + 2010-03-21 08:57 . 2008-10-16 20:33 124928 c:\windows\ie7updates\KB978207-IE7\advpack.dll + 2008-12-02 10:03 . 2009-12-04 18:22 455424 c:\windows\Driver Cache\i386\mrxsmb.sys + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys + 2010-03-21 13:31 . 2010-03-21 13:31 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\e2098e43d115155d6ba91ba3a7e577cf\WsatConfig.ni.exe + 2010-03-21 09:18 . 2010-03-21 09:18 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bf92bc207f927cbbd6dfc9dc0c3eae68\WindowsFormsIntegration.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\6f488b7644dc50a083868e91a4014466\UIAutomationTypes.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\c2fbf25609b704061a93500efa6f241d\UIAutomationClient.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\eb23b78564687badff1bd1f1d0a0ec97\System.Xml.Linq.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\e7666364bf9f3ba5f4833c9efedd8218\System.Web.Routing.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5f1b8791e6c47e5bd5e7018c346c586\System.Web.RegularExpressions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\884eacddf339b8b342f66aedff5f8ef9\System.Web.Extensions.Design.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\9e199645bd26f1afe58ebe185d1e7f0f\System.Web.Entity.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\652017ebe962ab2eb271c2524f31cd61\System.Web.Entity.Design.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\d0070c1c1a642ae30394e00bc0d82336\System.Web.DynamicData.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\1896753d02d146be1988d32241300f51\System.Web.Abstractions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\408e637346ef628a3f54fb1b9b83ac9f\System.Transactions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\a9e9b885a6601469c4058375cc74d856\System.Security.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9bc34a79af9c3ed2cf17a0226c769b4c\System.Runtime.Serialization.Formatters.Soap.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\5f74a84e9d28c2332c51f6e30da0e125\System.Net.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\818b20a7c6f3b2fe97bf008ca24080c1\System.Management.Instrumentation.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\6c273eb9d1ee8b66b5ecb073de4b785d\System.IO.Log.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\7222db518afb4eaaa138824278249bc7\System.IdentityModel.Selectors.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.Wrapper.dll + 2010-03-21 22:18 . 2010-03-21 22:18 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\ca6d7208c0fb72ff97429f2636ced321\System.Drawing.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c92fc19800e701c90f90ab7a2ab44c47\System.DirectoryServices.AccountManagement.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\a601f47a98ee67df424685c9a66ea449\System.DirectoryServices.Protocols.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\b91b44015859163646f210d284f7166a\System.Data.Services.Client.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1b35297e07b85071daecdb06f96750a1\System.Data.Services.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\cf906bf9146d1f0013451ec63b58e064\System.Data.Entity.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4ff4134b0d490c090e03d74e104517c4\System.Data.DataSetExtensions.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\443e3a85c491b2de4a2ac654cb957484\System.Configuration.Install.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\cba35f47925431a54d0e6ae147a292f1\System.AddIn.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6af32fe5cbec0aa54e2efa6910c73651\SMSvcHost.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a23dc25782df04533a13e348203e4dc5\ServiceModelReg.ni.exe + 2010-03-21 09:17 . 2010-03-21 09:17 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\96f74da5fc40b92f09069230bc0df4f0\PresentationFramework.Royale.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bb4d16b042b72c2c85a0f8ac9d48f28\PresentationFramework.Luna.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\30c5c2682d3c5bdaa83bb9a36ee48afa\PresentationFramework.Aero.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07e952efd70f5608e221a008e6231ace\PresentationFramework.Classic.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\eade8c1c9c1e8e5ffb50e6c9b9af0f6a\MSBuild.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fc4d66e0a92b3767006a84f2519d2457\Microsoft.Transactions.Bridge.Dtc.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\58ca3ecc52b7246b448c109817198a0b\Microsoft.Build.Utilities.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4dd43724dd92026577c6f588270137a0\Microsoft.Build.Utilities.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8c651f75bb741330370986dcad8e9e5b\Microsoft.Build.Engine.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a6dcbae619ccd938bfe808c54d6d3ae0\Microsoft.Build.Conversion.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\77688ce14f221ed94a9f442ae4736123\CustomMarshalers.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a17c65f0cffaa4f792dd38d50df9d526\ComSvcConfig.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\85d7c111956b478766d90625b35d963f\AspNetMMCExt.ni.dll - 2010-01-20 12:03 . 2010-01-20 12:03 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-03-21 09:04 . 2010-03-21 09:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-03-21 09:04 . 2010-03-21 09:04 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2010-01-20 12:03 . 2010-01-20 12:03 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2010-01-20 12:06 . 2010-01-20 12:06 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll + 2010-03-21 09:02 . 2010-03-21 09:02 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll + 2010-03-21 09:02 . 2010-03-21 09:02 229376 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll - 2010-01-20 12:03 . 2010-01-20 12:03 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2010-03-21 09:04 . 2010-03-21 09:04 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2010-03-21 09:04 . 2010-03-21 09:04 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2010-01-20 12:03 . 2010-01-20 12:03 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2010-01-20 12:03 . 2010-01-20 12:03 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll + 2010-03-21 09:04 . 2010-03-21 09:04 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll - 2010-01-20 12:03 . 2010-01-20 12:03 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-03-21 09:04 . 2010-03-21 09:04 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-03-21 09:04 . 2010-03-21 09:04 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2010-01-20 12:03 . 2010-01-20 12:03 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2010-01-20 12:03 . 2010-01-20 12:03 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2010-03-21 09:04 . 2010-03-21 09:04 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2010-03-21 09:04 . 2010-03-21 09:04 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll - 2010-01-20 12:03 . 2010-01-20 12:03 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2010-03-21 09:04 . 2010-03-21 09:04 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2010-03-21 09:04 . 2010-03-21 09:04 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll - 2010-01-20 12:03 . 2010-01-20 12:03 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2010-03-21 09:02 . 2010-03-21 09:02 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll - 2010-01-20 12:06 . 2010-01-20 12:06 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll + 2010-03-21 09:02 . 2010-03-21 09:02 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll - 2010-01-20 12:06 . 2010-01-20 12:06 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll - 2010-01-20 12:03 . 2010-01-20 12:03 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2010-03-21 09:04 . 2010-03-21 09:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll - 2010-01-20 12:03 . 2010-01-20 12:03 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2010-03-21 09:04 . 2010-03-21 09:04 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll - 2010-01-20 12:03 . 2010-01-20 12:03 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2010-03-21 09:04 . 2010-03-21 09:04 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2010-01-20 12:03 . 2010-01-20 12:03 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2010-03-21 09:04 . 2010-03-21 09:04 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll - 2010-01-20 12:03 . 2010-01-20 12:03 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2010-01-20 12:03 . 2010-01-20 12:03 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2010-03-21 09:04 . 2010-03-21 09:04 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2010-01-20 12:03 . 2010-01-20 12:03 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2010-01-20 12:03 . 2010-01-20 12:03 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2010-03-21 09:04 . 2010-03-21 09:04 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll - 2010-01-20 12:03 . 2010-01-20 12:03 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2010-03-21 09:04 . 2010-03-21 09:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2010-03-21 09:04 . 2010-03-21 09:04 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll - 2010-01-20 12:03 . 2010-01-20 12:03 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2010-03-21 09:04 . 2010-03-21 09:04 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2010-03-21 09:04 . 2010-03-21 09:04 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2008-04-14 20:49 . 2009-11-21 16:03 471552 c:\windows\AppPatch\aclayers.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB979306$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB979306$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978706$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978706$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:51 345088 c:\windows\$NtUninstallKB978706$\mspaint.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978262$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978262$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978251$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978251$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-10-24 11:21 455296 c:\windows\$NtUninstallKB978251$\mrxsmb.sys + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978037$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978037$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB977914$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB977914$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB977165-v2$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB977165-v2$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975713$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975713$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 474112 c:\windows\$NtUninstallKB975713$\shlwapi.dll + 2010-03-21 08:59 . 2009-05-26 16:13 398200 c:\windows\$NtUninstallKB975561$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB975561$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975560$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975560$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975467$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB975467$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-06-25 08:27 136192 c:\windows\$NtUninstallKB975467$\msv1_0.dll + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975025$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975025$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974571$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974571$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974392$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974392$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 271360 c:\windows\$NtUninstallKB974392$\oakley.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974318$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974318$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 150528 c:\windows\$NtUninstallKB974318$\rastls.dll + 2010-03-21 09:00 . 2008-10-03 10:04 247326 c:\windows\$NtUninstallKB974112$\strmdll.dll + 2010-03-21 09:00 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974112$\spuninst\updspapi.dll + 2010-03-21 09:00 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974112$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973904$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973904$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2005-03-25 16:43 116424 c:\windows\$NtUninstallKB973904$\msconv97.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB973869$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB973869$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973815$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973815$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 204288 c:\windows\$NtUninstallKB973815$\mswebdvd.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973687$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB973687$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:51 233472 c:\windows\$NtUninstallKB973540_WM9$\wmpdxm.dll + 2010-03-21 08:58 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB973540_WM9$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-07-27 07:36 234360 c:\windows\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973507$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973507$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973354$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973354$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 117760 c:\windows\$NtUninstallKB972270$\t2embed.dll + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB972270$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB972270$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971961$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB971961$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-05-09 10:56 512000 c:\windows\$NtUninstallKB971961$\jscript.dll + 2010-03-22 06:47 . 2008-12-16 12:32 354304 c:\windows\$NtUninstallKB971737$\winhttp.dll + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971737$\spuninst\updspapi.dll + 2010-03-22 06:47 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971737$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 132096 c:\windows\$NtUninstallKB971657$\wkssvc.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971657$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971657$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2008-09-08 10:41 333824 c:\windows\$NtUninstallKB971468$\srv.sys + 2010-03-21 09:03 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB971468$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971468$\spuninst\spuninst.exe + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB970430$\spuninst\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB970430$\spuninst\spuninst.exe + 2010-03-22 06:47 . 2008-04-13 22:23 264832 c:\windows\$NtUninstallKB970430$\http.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB970238$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB970238$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 584704 c:\windows\$NtUninstallKB970238$\rpcrt4.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB969947$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB969947$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB969059$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB969059$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB968816_WM9$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-07-27 09:41 231288 c:\windows\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB968389$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB968389$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 144384 c:\windows\$NtUninstallKB968389$\schannel.dll + 2010-03-21 08:57 . 2008-04-14 20:50 132608 c:\windows\$NtUninstallKB968389$\msv1_0.dll + 2010-03-21 08:57 . 2008-04-14 20:50 730112 c:\windows\$NtUninstallKB968389$\lsasrv.dll + 2010-03-21 08:57 . 2008-04-14 20:50 299520 c:\windows\$NtUninstallKB968389$\kerberos.dll + 2010-03-21 08:58 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB967715$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB967715$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB961501$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB961501$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 345088 c:\windows\$NtUninstallKB961501$\localspl.dll + 2010-03-21 09:02 . 2007-11-30 11:21 398200 c:\windows\$NtUninstallKB961118$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$NtUninstallKB961118$\spuninst\spuninst.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB960859$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB960859$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 354304 c:\windows\$NtUninstallKB960803$\winhttp.dll + 2010-03-21 08:57 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB960803$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB960803$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB960225$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$NtUninstallKB960225$\spuninst\spuninst.exe + 2010-03-21 09:04 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB959426$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB959426$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB958869$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB958869$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 153088 c:\windows\$NtUninstallKB956844$\triedit.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB956844$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB956844$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB956744$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB956744$\spuninst\spuninst.exe + 2010-03-21 09:00 . 2008-04-14 20:51 218112 c:\windows\$NtUninstallKB956572$\wmiprvse.exe + 2010-03-21 09:00 . 2008-04-14 20:51 437248 c:\windows\$NtUninstallKB956572$\wmiprvsd.dll + 2010-03-21 09:00 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB956572$\spuninst\updspapi.dll + 2010-03-21 09:00 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB956572$\spuninst\spuninst.exe + 2010-03-21 09:00 . 2008-04-14 20:51 109056 c:\windows\$NtUninstallKB956572$\services.exe + 2010-03-21 09:00 . 2008-04-14 20:50 399360 c:\windows\$NtUninstallKB956572$\rpcss.dll + 2010-03-21 09:00 . 2008-04-14 20:50 285696 c:\windows\$NtUninstallKB956572$\pdh.dll + 2010-03-21 09:00 . 2008-04-14 20:49 714240 c:\windows\$NtUninstallKB956572$\ntdll.dll + 2010-03-21 09:00 . 2008-04-14 20:50 472064 c:\windows\$NtUninstallKB956572$\fastprox.dll + 2010-03-21 09:00 . 2008-04-14 20:50 686592 c:\windows\$NtUninstallKB956572$\advapi32.dll + 2010-03-21 09:03 . 2009-05-26 16:13 398200 c:\windows\$NtUninstallKB955759$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB955759$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2008-04-14 20:49 451072 c:\windows\$NtUninstallKB955759$\aclayers.dll + 2010-03-21 09:02 . 2005-01-28 12:44 413944 c:\windows\$NtUninstallKB954155_WM9$\wmspdmod.dll + 2010-03-21 09:02 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB954155_WM9$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-07-27 07:36 234360 c:\windows\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB952004$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB952004$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 161792 c:\windows\$NtUninstallKB952004$\msdtcuiu.dll + 2010-03-21 08:59 . 2008-04-14 20:50 956928 c:\windows\$NtUninstallKB952004$\msdtctm.dll + 2010-03-21 08:59 . 2008-04-14 20:50 427008 c:\windows\$NtUninstallKB952004$\msdtcprx.dll + 2010-03-21 08:58 . 2008-04-13 22:30 225664 c:\windows\$NtUninstallKB951748$\tcpip6.sys + 2010-03-21 08:58 . 2008-04-13 22:50 361344 c:\windows\$NtUninstallKB951748$\tcpip.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB951748$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB951748$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 246784 c:\windows\$NtUninstallKB951748$\mswsock.dll + 2010-03-21 08:58 . 2008-04-14 20:50 147968 c:\windows\$NtUninstallKB951748$\dnsapi.dll + 2010-03-21 08:59 . 2005-01-28 12:44 224768 c:\windows\$NtUninstallKB941569$\wmasf.dll + 2010-03-21 08:59 . 2005-06-28 08:23 371424 c:\windows\$NtUninstallKB941569$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2005-06-28 08:23 216288 c:\windows\$NtUninstallKB941569$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:51 217088 c:\windows\$NtUninstallKB923561$\wordpad.exe + 2010-03-21 08:57 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB923561$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB923561$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978706\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978706\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978706\spuninst.exe + 2009-12-17 07:39 . 2009-12-17 07:39 345088 c:\windows\$hf_mig$\KB978706\SP3QFE\mspaint.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978262\update\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978262\update\update.exe + 2010-03-21 09:04 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978262\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978251\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978251\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978251\spuninst.exe + 2010-03-21 07:53 . 2009-12-04 17:25 456832 c:\windows\$hf_mig$\KB978251\SP3QFE\mrxsmb.sys + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978207-IE7\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978207-IE7\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978207-IE7\spuninst.exe + 2010-01-05 09:49 . 2010-01-05 09:49 841216 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\wininet.dll + 2010-01-05 09:49 . 2010-01-05 09:49 233472 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\webcheck.dll + 2010-01-05 09:49 . 2010-01-05 09:49 105984 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\url.dll + 2010-01-05 09:49 . 2010-01-05 09:49 102912 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\occache.dll + 2010-01-05 09:49 . 2010-01-05 09:49 671232 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mstime.dll + 2010-01-05 09:49 . 2010-01-05 09:49 193024 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msrating.dll + 2010-01-05 09:49 . 2010-01-05 09:49 477696 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtmled.dll + 2010-01-05 09:49 . 2010-01-05 09:49 459264 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msfeeds.dll + 2009-12-18 07:00 . 2009-12-18 07:00 634632 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe + 2010-01-05 09:49 . 2010-01-05 09:49 268288 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iertutil.dll + 2010-01-05 09:49 . 2010-01-05 09:49 193024 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iepeers.dll + 2010-01-05 09:49 . 2010-01-05 09:49 388608 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iedkcs32.dll + 2010-01-05 09:49 . 2010-01-05 09:49 380928 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieapfltr.dll + 2009-12-18 06:58 . 2009-12-18 06:58 161792 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieakui.dll + 2010-01-05 09:49 . 2010-01-05 09:49 230400 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieaksie.dll + 2010-01-05 09:49 . 2010-01-05 09:49 153088 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieakeng.dll + 2010-01-05 09:49 . 2010-01-05 09:49 132608 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\extmgr.dll + 2010-01-05 09:49 . 2010-01-05 09:49 214528 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\dxtrans.dll + 2010-01-05 09:49 . 2010-01-05 09:49 347136 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\dxtmsft.dll + 2010-01-05 09:49 . 2010-01-05 09:49 124928 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\advpack.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978037\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978037\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978037\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB977914\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB977914\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB977914\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB977165-v2\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB977165-v2\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB977165-v2\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975713\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975713\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975713\spuninst.exe + 2009-12-08 09:03 . 2009-12-08 09:03 474112 c:\windows\$hf_mig$\KB975713\SP3QFE\shlwapi.dll + 2010-03-21 08:59 . 2009-05-26 16:13 398200 c:\windows\$hf_mig$\KB975561\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975561\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB975561\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975560\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975560\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975560\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975467\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975467\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB975467\spuninst.exe + 2009-09-11 14:15 . 2009-09-11 14:15 136704 c:\windows\$hf_mig$\KB975467\SP3QFE\msv1_0.dll + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975025\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975025\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975025\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974571\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974571\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974571\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974392\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974392\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974392\spuninst.exe + 2009-10-13 10:39 . 2009-10-13 10:39 271360 c:\windows\$hf_mig$\KB974392\SP3QFE\oakley.dll + 2010-03-21 09:03 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974318\update\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974318\update\update.exe + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974318\spuninst.exe + 2009-10-12 13:33 . 2009-10-12 13:33 150528 c:\windows\$hf_mig$\KB974318\SP3QFE\rastls.dll + 2010-03-21 09:00 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974112\update\updspapi.dll + 2010-03-21 09:00 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974112\update\update.exe + 2010-03-21 09:00 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974112\spuninst.exe + 2009-08-26 08:03 . 2009-08-26 08:03 247326 c:\windows\$hf_mig$\KB974112\SP3QFE\strmdll.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973904\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973904\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973904\spuninst.exe + 2010-03-21 07:52 . 2009-07-29 14:01 119648 c:\windows\$hf_mig$\KB973904\SP3QFE\msconv97.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB973869\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB973869\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB973869\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973815\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973815\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973815\spuninst.exe + 2009-08-05 08:53 . 2009-08-05 08:53 205312 c:\windows\$hf_mig$\KB973815\SP3QFE\mswebdvd.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973687\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973687\update\update.exe + 2010-03-21 08:58 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB973687\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973507\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973507\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973507\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973354\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973354\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973354\spuninst.exe + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB972270\update\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB972270\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB972270\spuninst.exe + 2010-03-21 07:55 . 2009-10-15 16:40 119808 c:\windows\$hf_mig$\KB972270\SP3QFE\t2embed.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971961\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971961\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB971961\spuninst.exe + 2010-03-21 07:46 . 2009-08-13 15:04 512000 c:\windows\$hf_mig$\KB971961\SP3QFE\jscript.dll + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971737\update\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971737\update\update.exe + 2010-03-22 06:47 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971737\spuninst.exe + 2009-08-25 09:31 . 2009-08-25 09:31 354816 c:\windows\$hf_mig$\KB971737\SP3QFE\winhttp.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971657\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971657\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971657\spuninst.exe + 2009-06-10 06:20 . 2009-06-10 06:20 134144 c:\windows\$hf_mig$\KB971657\SP3QFE\wkssvc.dll + 2010-03-21 09:03 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB971468\update\updspapi.dll + 2010-03-21 09:03 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB971468\update\update.exe + 2010-03-21 09:03 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971468\spuninst.exe + 2010-03-21 08:02 . 2010-01-01 07:58 353792 c:\windows\$hf_mig$\KB971468\SP3QFE\srv.sys + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB970430\update\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB970430\update\update.exe + 2010-03-22 06:47 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB970430\spuninst.exe + 2009-10-20 15:21 . 2009-10-20 15:21 265728 c:\windows\$hf_mig$\KB970430\SP3QFE\http.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB970238\update\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB970238\update\update.exe + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB970238\spuninst.exe + 2009-04-15 15:26 . 2009-04-15 15:26 585216 c:\windows\$hf_mig$\KB970238\SP3QFE\rpcrt4.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB969947\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB969947\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB969947\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB969059\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB969059\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB969059\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB968389\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB968389\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB968389\spuninst.exe + 2009-06-25 08:42 . 2009-06-25 08:42 147456 c:\windows\$hf_mig$\KB968389\SP3QFE\schannel.dll + 2009-06-25 08:42 . 2009-06-25 08:42 136704 c:\windows\$hf_mig$\KB968389\SP3QFE\msv1_0.dll + 2009-06-26 09:42 . 2009-06-26 09:42 732160 c:\windows\$hf_mig$\KB968389\SP3QFE\lsasrv.dll + 2009-06-25 08:42 . 2009-06-25 08:42 301568 c:\windows\$hf_mig$\KB968389\SP3QFE\kerberos.dll + 2010-03-21 08:58 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB967715\update\updspapi.dll + 2010-03-21 08:58 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB967715\update\update.exe + 2010-03-21 08:58 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB967715\spuninst.exe + 2010-03-21 08:59 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB961501\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB961501\update\update.exe + 2010-03-21 08:59 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB961501\spuninst.exe + 2009-05-07 15:16 . 2009-05-07 15:16 348160 c:\windows\$hf_mig$\KB961501\SP3QFE\localspl.dll + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB960859\update\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB960859\update\update.exe + 2010-03-21 09:04 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB960859\spuninst.exe + 2010-03-21 08:57 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB960803\update\updspapi.dll + 2010-03-21 08:57 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB960803\update\update.exe + 2010-03-21 08:57 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB960803\spuninst.exe + 2008-12-16 12:23 . 2008-12-16 12:23 354304 c:\windows\$hf_mig$\KB960803\SP3QFE\winhttp.dll + 2010-03-21 09:02 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB960225\update\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB960225\update\update.exe + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$hf_mig$\KB960225\spuninst.exe + 2008-12-05 07:01 . 2008-12-05 07:01 144896 c:\windows\$hf_mig$\KB960225\SP3QFE\schannel.dll + 2010-03-21 09:04 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB959426\update\updspapi.dll + 2010-03-21 09:04 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB959426\update\update.exe + 2010-03-21 09:04 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB959426\spuninst.exe + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB956844\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB956844\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB956844\spuninst.exe + 2010-03-21 07:53 . 2009-06-21 21:50 153088 c:\windows\$hf_mig$\KB956844\SP3QFE\triedit.dll + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB956744\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB956744\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB956744\spuninst.exe + 2010-03-21 09:00 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB956572\update\updspapi.dll + 2010-03-21 09:00 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB956572\update\update.exe + 2010-03-21 09:00 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB956572\spuninst.exe + 2010-03-21 07:54 . 2009-02-06 10:15 227840 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe + 2010-03-21 07:54 . 2009-02-09 11:00 453120 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvsd.dll + 2010-03-21 07:54 . 2009-02-09 11:19 111104 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe + 2010-03-21 07:54 . 2009-02-09 11:00 401408 c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll + 2010-03-21 07:54 . 2009-03-06 13:51 285696 c:\windows\$hf_mig$\KB956572\SP3QFE\pdh.dll + 2010-03-21 07:54 . 2009-02-09 11:00 723456 c:\windows\$hf_mig$\KB956572\SP3QFE\ntdll.dll + 2010-03-21 07:54 . 2009-02-09 11:00 731136 c:\windows\$hf_mig$\KB956572\SP3QFE\lsasrv.dll + 2010-03-21 07:54 . 2009-02-09 11:00 473600 c:\windows\$hf_mig$\KB956572\SP3QFE\fastprox.dll + 2009-02-10 18:30 . 2009-02-10 18:30 686592 c:\windows\$hf_mig$\KB956572\SP3QFE\advapi32.dll + 2010-03-21 09:03 . 2009-05-26 16:13 398200 c:\windows\$hf_mig$\KB955759\update\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB955759\update\update.exe + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB955759\spuninst.exe + 2010-03-21 08:02 . 2009-11-21 15:50 471552 c:\windows\$hf_mig$\KB955759\SP3QFE\aclayers.dll + 2010-03-21 08:59 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB952004\update\updspapi.dll + 2010-03-21 08:59 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB952004\update\update.exe + 2010-03-21 08:59 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB952004\spuninst.exe + 2008-06-12 14:11 . 2008-06-12 14:11 161792 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcuiu.dll + 2008-06-12 14:11 . 2008-06-12 14:11 956928 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtctm.dll + 2008-06-12 14:11 . 2008-06-12 14:11 428032 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcprx.dll + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB951748\update\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB951748\update\update.exe + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB951748\spuninst.exe + 2010-03-21 07:45 . 2008-06-20 11:16 225856 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys + 2010-03-21 07:45 . 2008-06-20 11:59 361600 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys + 2010-03-21 07:45 . 2008-06-20 17:44 246784 c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll + 2010-03-21 07:45 . 2008-06-20 17:44 147968 c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll + 2010-03-21 07:45 . 2008-06-20 11:48 138496 c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys + 2010-03-21 08:57 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB923561\update\updspapi.dll + 2010-03-21 08:57 . 2008-11-15 17:19 763256 c:\windows\$hf_mig$\KB923561\update\update.exe + 2010-03-21 08:57 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB923561\spuninst.exe + 2010-03-21 07:46 . 2008-04-21 21:12 218112 c:\windows\$hf_mig$\KB923561\SP3QFE\wordpad.exe + 2010-03-21 08:02 . 2009-08-13 13:56 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll + 2008-09-25 16:18 . 2009-08-06 18:23 1929952 c:\windows\system32\wuaueng.dll + 2008-04-14 20:51 . 2005-01-28 12:44 1003008 c:\windows\system32\wmvdmoe2.dll + 2008-04-14 20:52 . 2009-05-20 11:24 2373504 c:\windows\system32\WMVCore.dll + 2005-01-28 12:44 . 2005-01-28 12:44 1512448 c:\windows\system32\WMVADVE.DLL + 2005-01-28 12:44 . 2005-01-28 12:44 1218808 c:\windows\system32\wmvadvd.dll + 2008-04-14 20:51 . 2005-01-28 12:44 1119744 c:\windows\system32\wmsdmoe2.dll - 2008-04-14 20:51 . 2008-04-14 20:51 1119744 c:\windows\system32\wmsdmoe2.dll - 2008-04-14 20:51 . 2008-04-14 20:51 4874240 c:\windows\system32\wmp.dll + 2008-04-14 20:51 . 2009-07-12 11:21 4874240 c:\windows\system32\wmp.dll + 2008-04-14 20:51 . 2008-06-10 05:28 1028096 c:\windows\system32\WMNetmgr.dll + 2008-04-14 19:35 . 2009-08-14 15:15 1850880 c:\windows\system32\win32k.sys + 2008-05-30 13:20 . 2010-01-05 09:57 1168384 c:\windows\system32\urlmon.dll - 2008-04-14 20:50 . 2008-04-14 20:50 8489984 c:\windows\system32\shell32.dll + 2008-04-14 20:50 . 2008-06-17 19:03 8489984 c:\windows\system32\shell32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 1439744 c:\windows\system32\query.dll + 2008-04-14 20:50 . 2009-07-17 16:17 1439744 c:\windows\system32\query.dll + 2008-04-14 20:50 . 2009-11-27 17:14 1295360 c:\windows\system32\quartz.dll + 2010-03-06 15:50 . 2009-04-28 20:20 1858032 c:\windows\system32\pxsfs.dll - 2008-04-14 19:59 . 2008-08-14 13:26 2146816 c:\windows\system32\ntoskrnl.exe + 2008-04-14 19:59 . 2009-12-09 10:11 2146816 c:\windows\system32\ntoskrnl.exe + 2008-04-14 21:59 . 2009-12-09 10:11 2025472 c:\windows\system32\ntkrnlpa.exe - 2008-04-14 21:59 . 2008-08-14 13:26 2025472 c:\windows\system32\ntkrnlpa.exe + 2008-04-14 20:50 . 2009-07-31 09:05 1372672 c:\windows\system32\msxml6.dll + 2008-04-14 20:50 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll + 2008-09-25 16:17 . 2009-06-10 08:22 2066432 c:\windows\system32\mstscax.dll + 2008-05-30 13:20 . 2010-01-05 09:57 3599360 c:\windows\system32\mshtml.dll - 2008-04-14 20:50 . 2008-04-14 20:50 1018368 c:\windows\system32\kernel32.dll + 2008-04-14 20:50 . 2009-03-21 14:08 1018368 c:\windows\system32\kernel32.dll + 2010-03-21 09:03 . 2009-03-10 21:26 1436544 c:\windows\system32\KB905474\wganotifypackageinner.exe + 2008-05-30 13:20 . 2010-01-05 09:57 6067200 c:\windows\system32\ieframe.dll + 2008-05-30 13:19 . 2009-06-29 08:33 2452872 c:\windows\system32\ieapfltr.dat + 2008-04-14 20:52 . 2009-05-20 11:24 2373504 c:\windows\system32\dllcache\WMVCore.dll + 2009-07-12 11:21 . 2009-07-12 11:21 4874240 c:\windows\system32\dllcache\wmp.dll + 2008-04-14 20:51 . 2008-06-10 05:28 1028096 c:\windows\system32\dllcache\WMNetmgr.dll + 2008-12-02 11:24 . 2009-08-14 15:15 1850880 c:\windows\system32\dllcache\win32k.sys + 2008-08-26 08:27 . 2010-01-05 09:57 1168384 c:\windows\system32\dllcache\urlmon.dll + 2008-06-17 19:03 . 2008-06-17 19:03 8489984 c:\windows\system32\dllcache\shell32.dll + 2009-07-17 16:17 . 2009-07-17 16:17 1439744 c:\windows\system32\dllcache\query.dll + 2008-09-26 12:04 . 2009-11-27 17:14 1295360 c:\windows\system32\dllcache\quartz.dll + 2008-12-02 10:05 . 2009-12-09 10:11 2190464 c:\windows\system32\dllcache\ntoskrnl.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2190464 c:\windows\system32\dllcache\ntoskrnl.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2025472 c:\windows\system32\dllcache\ntkrpamp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2025472 c:\windows\system32\dllcache\ntkrpamp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2067328 c:\windows\system32\dllcache\ntkrnlpa.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2067328 c:\windows\system32\dllcache\ntkrnlpa.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2146816 c:\windows\system32\dllcache\ntkrnlmp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2146816 c:\windows\system32\dllcache\ntkrnlmp.exe + 2008-09-10 01:15 . 2009-07-31 09:05 1372672 c:\windows\system32\dllcache\msxml6.dll + 2008-12-02 10:01 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll + 2009-06-10 08:22 . 2009-06-10 08:22 2066432 c:\windows\system32\dllcache\mstscax.dll + 2010-03-21 07:52 . 2009-07-10 13:31 1315328 c:\windows\system32\dllcache\msoe.dll + 2008-08-27 09:27 . 2010-01-05 09:57 3599360 c:\windows\system32\dllcache\mshtml.dll + 2010-03-21 07:53 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe + 2009-03-21 14:08 . 2009-03-21 14:08 1018368 c:\windows\system32\dllcache\kernel32.dll + 2008-10-03 17:26 . 2010-01-05 09:57 6067200 c:\windows\system32\dllcache\ieframe.dll + 2007-04-17 09:32 . 2009-06-29 08:33 2452872 c:\windows\system32\dllcache\ieapfltr.dat + 2010-03-06 15:53 . 2005-01-28 12:44 1003008 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvdmoe2.dll + 2010-03-06 15:53 . 2005-01-28 12:44 2370296 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvcore.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1512448 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMVADVE.DLL + 2010-03-06 15:53 . 2005-01-28 12:44 1119744 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmsdmoe2.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1027072 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmnetmgr.dll + 2010-03-06 15:53 . 2008-04-14 20:51 1001472 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvdmoe2.dll + 2010-03-06 15:53 . 2008-11-07 15:45 2174976 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvcore.dll + 2010-03-06 15:53 . 2008-04-14 20:51 1119744 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmsdmoe2.dll + 2010-03-06 15:53 . 2008-06-10 05:11 1053696 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmnetmgr.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1218808 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvadvd.dll + 2008-12-05 18:35 . 2008-12-05 18:35 1736528 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll - 2008-07-29 18:16 . 2008-07-29 18:16 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll + 2008-12-05 19:12 . 2008-12-05 19:12 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll + 2008-11-25 03:59 . 2008-11-25 03:59 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll - 2008-07-25 10:17 . 2008-07-25 10:17 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll + 2008-11-25 03:59 . 2008-11-25 03:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2009-08-07 22:51 . 2009-08-07 22:51 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - 2008-07-25 10:17 . 2008-07-25 10:17 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2009-08-07 22:51 . 2009-08-07 22:51 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2008-12-13 08:57 . 2008-12-13 08:57 8397824 c:\windows\Installer\476062.msp + 2010-03-21 08:57 . 2008-10-16 20:33 1160192 c:\windows\ie7updates\KB978207-IE7\urlmon.dll + 2010-03-21 08:57 . 2008-10-17 01:03 3593216 c:\windows\ie7updates\KB978207-IE7\mshtml.dll + 2010-03-21 08:57 . 2008-10-16 20:33 6066176 c:\windows\ie7updates\KB978207-IE7\ieframe.dll + 2010-03-21 08:57 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB978207-IE7\ieapfltr.dat - 2008-12-02 10:05 . 2008-08-14 13:26 2190464 c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2190464 c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2025472 c:\windows\Driver Cache\i386\ntkrpamp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2025472 c:\windows\Driver Cache\i386\ntkrpamp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2067328 c:\windows\Driver Cache\i386\ntkrnlpa.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2067328 c:\windows\Driver Cache\i386\ntkrnlpa.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2146816 c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2146816 c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2010-03-21 09:16 . 2010-03-21 09:16 3313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\204d6e5b335134f23ca37638b9227ecf\WindowsBase.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\0f2ed6a204eb13841e99b77025464afc\UIAutomationClientsideProviders.ni.dll + 2010-03-21 09:15 . 2010-03-21 09:15 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\3de5bd01124463d7862bd173af90bc83\System.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5913d3f81e77194ec833991b1047a532\System.Xml.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\fa48917b13629d8effa80dd4a2f2973d\System.WorkflowServices.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6fe66ee6f3c81996bc148f1ebe7ec030\System.Workflow.Runtime.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\9d0b61f2f1ebdc300bd970f594c422ef\System.Workflow.ComponentModel.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\65328898148a720d394f802f192fc2a0\System.Workflow.Activities.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\ea07ac791bb5cb9f83679e3dd1a0c0cc\System.Web.Services.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\29e2f8b1fb691ced973acf49fcee6ec1\System.Web.Mobile.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\981dea02bc63c0c083e335adf9018788\System.Web.Extensions.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\99594bae1d022502925f5b9dfcdaae9a\System.Speech.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\67ad55827f2542552b576170f0a7dc56\System.Runtime.Serialization.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\e5313735a40c0800f116e27fba4754db\System.Printing.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c3b18fef5c6dc3bcdbe5df699fd21a55\System.IdentityModel.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\abb2ac7e08bee026f857d8fa36f9fe6f\System.Drawing.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f47ebb9db460874b1bcbfc391dc970b1\System.DirectoryServices.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c94a427baa7683f4221b91f90c18461b\System.Deployment.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\694c07365e0fd6bba0bc304d4d2404a7\System.Data.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\272152f0cc139490729e215611a4b244\System.Data.SqlXml.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\112a48e34620a0210eb850040da8a31b\System.Data.Services.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\32788c58ff9f8324460604cf1fe7681b\System.Data.Linq.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\9012cac7819660f61f1c69cf8e4f2ccf\System.Data.Entity.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\c0a42d2ad8a4078040b334f6770ea11f\System.Core.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\954685c29689d2a6126ceca1fd55e904\ReachFramework.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\a3a6f52ce1d09a7bdccc8e7fc664792d\PresentationUI.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\f906701365083c1473db31519147e263\PresentationBuildTasks.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6eee9b772b6d12d3dbd82f118c2ab2e5\Microsoft.VisualBasic.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f19e9b439636d0744597fff1331cad04\Microsoft.Transactions.Bridge.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\5b1af7b5be24c7ace065fe1c81c2b650\Microsoft.JScript.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9eec1cc7ac37e0c7f3205e8156149c5a\Microsoft.Build.Tasks.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\28c0730288453d57d5dcd62903c4d31b\Microsoft.Build.Tasks.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5dd4f58999eed37c12aee7ea9f9863ac\Microsoft.Build.Engine.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll - 2010-01-20 12:03 . 2010-01-20 12:03 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2010-03-21 09:04 . 2010-03-21 09:04 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll - 2010-01-20 12:03 . 2010-01-20 12:03 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2010-01-20 12:03 . 2010-01-20 12:03 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2010-01-20 12:06 . 2010-01-20 12:06 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll + 2010-03-21 09:02 . 2010-03-21 09:02 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll + 2010-03-21 09:01 . 2010-03-21 09:01 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll - 2010-01-20 12:05 . 2010-01-20 12:05 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll - 2010-01-20 12:03 . 2010-01-20 12:03 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll - 2010-01-20 12:05 . 2010-01-20 12:05 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll + 2010-03-21 09:01 . 2010-03-21 09:01 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2010-01-20 12:03 . 2010-01-20 12:03 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll - 2010-01-20 12:03 . 2010-01-20 12:03 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2010-03-21 09:02 . 2009-02-09 11:26 2146816 c:\windows\$NtUninstallKB977165-v2$\ntoskrnl.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2025472 c:\windows\$NtUninstallKB977165-v2$\ntkrpamp.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2025472 c:\windows\$NtUninstallKB977165-v2$\ntkrnlpa.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2146816 c:\windows\$NtUninstallKB977165-v2$\ntkrnlmp.exe + 2010-03-21 08:59 . 2008-04-14 20:51 3558912 c:\windows\$NtUninstallKB975561$\moviemk.exe + 2010-03-21 08:59 . 2008-05-07 05:12 1291776 c:\windows\$NtUninstallKB975560$\quartz.dll + 2010-03-21 08:58 . 2008-09-10 01:15 1307648 c:\windows\$NtUninstallKB973687$\msxml6.dll + 2010-03-21 08:58 . 2008-09-04 17:17 1106944 c:\windows\$NtUninstallKB973687$\msxml3.dll + 2010-03-21 08:58 . 2008-04-14 20:51 4874240 c:\windows\$NtUninstallKB973540_WM9$\wmp.dll + 2010-03-21 08:58 . 2008-04-14 20:50 1314816 c:\windows\$NtUninstallKB973354$\msoe.dll + 2010-03-21 08:57 . 2008-09-15 15:27 1846656 c:\windows\$NtUninstallKB969947$\win32k.sys + 2010-03-21 09:02 . 2008-04-14 20:50 1439744 c:\windows\$NtUninstallKB969059$\query.dll + 2010-03-21 09:02 . 2008-06-10 06:07 2376760 c:\windows\$NtUninstallKB968816_WM9$\wmvcore.dll + 2010-03-21 08:58 . 2008-04-14 20:50 8489984 c:\windows\$NtUninstallKB967715$\shell32.dll + 2010-03-21 09:04 . 2008-04-14 20:50 1018368 c:\windows\$NtUninstallKB959426$\kernel32.dll + 2010-03-21 09:02 . 2008-04-14 20:50 2061824 c:\windows\$NtUninstallKB956744$\mstscax.dll + 2010-03-21 09:00 . 2008-08-14 13:26 2146816 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2025472 c:\windows\$NtUninstallKB956572$\ntkrpamp.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2025472 c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2146816 c:\windows\$NtUninstallKB956572$\ntkrnlmp.exe + 2010-01-05 09:49 . 2010-01-05 09:49 1170944 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\urlmon.dll + 2010-01-05 09:49 . 2010-01-05 09:49 3602944 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtml.dll + 2010-01-05 09:49 . 2010-01-05 09:49 6071296 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieframe.dll + 2009-06-29 07:24 . 2009-06-29 07:24 2452872 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieapfltr.dat + 2009-12-10 04:04 . 2009-12-10 04:04 2190592 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntoskrnl.exe + 2010-03-21 07:56 . 2009-12-09 10:03 2025472 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrpamp.exe + 2009-12-10 04:04 . 2009-12-10 04:04 2067456 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlpa.exe + 2010-03-21 07:56 . 2009-12-09 10:03 2146816 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlmp.exe + 2010-03-21 07:53 . 2009-10-23 14:53 3558912 c:\windows\$hf_mig$\KB975561\SP3QFE\moviemk.exe + 2009-11-27 17:25 . 2009-11-27 17:25 1295360 c:\windows\$hf_mig$\KB975560\SP3QFE\quartz.dll + 2010-03-21 07:52 . 2009-07-31 04:30 1447424 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml6.dll + 2010-03-21 07:52 . 2009-07-31 04:30 1172480 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml3.dll + 2009-07-10 17:55 . 2009-07-10 17:55 1315328 c:\windows\$hf_mig$\KB973354\SP3QFE\msoe.dll + 2009-08-14 16:00 . 2009-08-14 16:00 1859968 c:\windows\$hf_mig$\KB969947\SP3QFE\win32k.sys + 2009-07-17 16:02 . 2009-07-17 16:02 1439744 c:\windows\$hf_mig$\KB969059\SP3QFE\query.dll + 2008-06-17 19:04 . 2008-06-17 19:04 8490496 c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll + 2009-03-21 14:04 . 2009-03-21 14:04 1020416 c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll + 2010-03-21 07:55 . 2009-06-09 15:23 2067968 c:\windows\$hf_mig$\KB956744\SP3QFE\lhmstscx.dll + 2009-02-10 18:19 . 2009-02-10 18:19 2190464 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2025472 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrpamp.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2067456 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2146816 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlmp.exe + 2009-08-14 19:32 . 2009-08-14 19:32 11110912 c:\windows\Installer\476086.msp + 2008-12-13 09:21 . 2008-12-13 09:21 10473472 c:\windows\Installer\47606e.msp + 2010-03-21 09:18 . 2010-03-21 09:18 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d2ea8d76f015817db1607075812b555f\System.Windows.Forms.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 11796992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5cea03cfb008f2eac1439a9905467f37\System.Web.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 17317888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\8b82e08c008924d51833cb0884bcbfc5\System.Design.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\58c7ac6b6054038dc9346d7ec8e32b4c\PresentationFramework.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\94badbd64df59de7da249f71da38b1c2\PresentationCore.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 11486720 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll . -- Migawka wyzerowana -- . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] [HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-10-16 16:22 333192 ----a-w- c:\program files\AskBardis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] 2010-02-22 20:13 2349080 ----a-w- c:\program files\XfireXO\tbXfi1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AQQ"="f:\progra~1\WapSter\WAPSTE~1\AQQ.exe" [2010-05-11 6644736] "Steam"="f:\program files\Steam\Steam.exe" [2010-05-07 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-05 198160] "QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-08 974848] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] c:\documents and settings\Ram\Menu Start\Programy\Autostart\ CurseClientStartup.ccip [2010-4-26 0] Skr˘t (2) do JDownloader.exe.lnk - f:\moje dokumenty\JDownloader 0.8.9\JDownloader.exe [2009-10-8 214528] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk - c:\program files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe [2003-12-15 516096] Kalendarz XP.lnk - f:\program files\Kalendarz XP\Kalendarz.exe [2009-12-11 882176] [HKLM\~\startupfolder\C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk] path=c:\documents and settings\Ram\Menu Start\Programy\Autostart\hamachi.lnk backup=c:\windows\pss\hamachi.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2009-07-16 11:20 25604904 ----a-r- c:\program files\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\GIGABYTE\\EnergySaver\\run.exe"= "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"= "e:\\fear\\fpupdate.exe"= "e:\\fear\\FEAR.exe"= "e:\\fear\\FEARMP.exe"= "f:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"= "e:\\Soldat\\Soldat.exe"= "e:\\BOS I\\game.dat"= "c:\\Program Files\\DNA\\btdna.exe"= "e:\\Program Files\\BitTorrent\\bittorrent.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\lithtech.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\avp2.exe"= "c:\\Program Files\\Hamachi\\hamachi.exe"= "c:\\totalcmd\\TOTALCMD.EXE"= "c:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Home\\ftpte.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "e:\\Warcraft III na Adsko (Zzz-a61d285dbe5)\\Warcraft III.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Documents and Settings\\Ram\\Pulpit\\RoXoR 8.42\\RoXoR.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "f:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "e:\\Program Files\\Electronic Arts\\Battlefield 2142 Deluxe Edition\\BF2142.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "e:\\NW2FR\\nwn2main.exe"= "e:\\NW2FR\\nwn2main_amdxp.exe"= "e:\\NW2FR\\nwupdate.exe"= "e:\\NW2FR\\nwn2server.exe"= "f:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "f:\\Program Files\\Kalendarz XP\\Kalendarz.exe"= "f:\\Program Files\\Steam\\Steam.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\condition zero\\hl.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\dreamkiller.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\localized_readme.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\counter-strike\\hl.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "7171:UDP"= 7171:UDP:tibia "53:TCP"= 53:TCP:XBOX "3074:TCP"= 3074:TCP:XBOX "3074:UDP"= 3074:UDP:XBOX "3330:TCP"= 3330:TCP:XBOX "3330:UDP"= 3330:UDP:XBOX "88:TCP"= 88:TCP:XBOX "88:UDP"= 88:UDP:XBOX "53:UDP"= 53:UDP:XBOX R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2009-12-28 160640] R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2009-12-28 5248] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-18 108289] R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928] R2 ASKService;ASKService;c:\program files\AskBardis\bar\bin\AskService.exe [2009-10-19 464264] R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-09-25 80392] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2009-10-29 2368] R3 PONDIS5;PONDIS5 NDIS Protocol Driver;c:\windows\system32\PONDIS5.sys [2003-07-17 17097] S2 avupdate;ArcaBit Update Service;c:\progra~1\ArcaBit\ARCAUP~1\update.exe --> c:\progra~1\ArcaBit\ARCAUP~1\update.exe [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-11-21 682232] . Zawartość folderu 'Zaplanowane zadania' 2010-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2010-05-22 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2010-03-21 21:18] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com IE: &Winamp Search - c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{40525a66-db98-480d-bcf9-7af88c1af438} - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - c:\program files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll FF - ProfilePath - c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query= FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - component: c:\program files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll FF - component: c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin2.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin3.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin4.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin5.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin6.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin7.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX - SPOSÓB POSTĘPOWANIA ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - USUNIĘTO PUSTE WPISY - - - - URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file) BHO-{B922D405-6D13-4A2B-AE89-08A030DA4402} - c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll Toolbar-{B922D405-6D13-4A2B-AE89-08A030DA4402} - c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe AddRemove-HaaliMkx - e:\program files\Matroska Pack\haali\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-05-22 22:46 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A051E68]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf74ebf28 \Driver\ACPI -> ACPI.sys @ 0xf7335cb8 \Driver\atapi -> 0x8a051e68 IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 NDIS: Siemens Gigaset PCI Card 54 -> SendCompleteHandler -> NDIS.sys @ 0xf71bbbb0 PacketIndicateHandler -> NDIS.sys @ 0xf71c8a21 SendHandler -> NDIS.sys @ 0xf71a687b Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c9,6c,9b,07,f7,24,c0,fa,e5,e3,75,89,de,cb,e1,93,99,86,4d,ab,be,92,56, e0,8f,32,30,c1,5d,8a,3a,a5,43,65,ef,d5,5c,7b,00,db,3f,c6,ea,f4,2a,d8,5d,eb,\ "??"=hex:43,47,ee,52,ce,4e,24,0c,c9,24,8c,5a,8c,15,4f,92 [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\License information*] "datasecu"=hex:02,14,3c,00,79,1b,4e,b3,ab,7b,9e,01,f7,e3,7a,33,70,bf,51,2a,56, e3,90,0a,07,37,54,c5,af,3e,6c,d6,f1,16,e1,23,28,fe,fa,98,3a,1e,fb,40,4a,e9,\ "rkeysecu"=hex:17,0c,8b,a8,75,cb,05,56,56,b0,06,85,72,9c,ba,40 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > 'winlogon.exe'(1260) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2744) c:\windows\system32\WININET.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe c:\program files\Java\jre6\bin\javaw.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\documents and settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE e:\xampp\mysql\bin\mysqld-nt.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Czas ukończenia: 2010-05-22 22:48:51 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2010-05-22 20:48 ComboFix2.txt 2010-03-01 14:25 Przed: 3 398 959 104 bajtów wolnych Po: 3 491 786 752 bajtów wolnych - - End Of File - - 21D3CAE0E80EAB0A54017B153227EF35 [/log]
Tomek01 komentarz 26 maja 2010 komentarz 26 maja 2010 (edytowane) Odinstaluj z dodaj usuń (jeśli będą): XfireXO Toolbar, AskBar (AskBarDis, Ask toolbar), pdfforge Toolbar, Winamp Toolbar, EPSON Web-To-Page, Search Settings, ZoneAlarm Spy Blocker Toolbar W OTL, w oknie Custom scan/fixes wklej: [code]:Processes Explorer.exe FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" [2010-01-29 21:49:24 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}[2009-10-06 17:10:14 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\conduit.xmlO2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com)O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com) O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll File not found O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBardis\bar\bin\askBar.dll (Ask.com) O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfi1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - E:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - F:\autorun.inf -- [ NTFS ]C:\Documents and Settings\Ram\Dane aplikacji\pdfforge C:\Documents and Settings\Ram\Dane aplikacji\Search Settings :Commands [emptytemp] [start explorer] [Reboot][/code] Klikasz run fix, komputer uruchamia się ponownie. Załącz log z usuwania oraz nowy log OTL z 3 miesięcy oraz log RSIT i Reglooks.
adsko komentarz 26 maja 2010 Autor komentarz 26 maja 2010 Log z usuwania: [log]All processes killed ========== PROCESSES ========== No active process named Explorer.exe was found! No active process named FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" was found! No active process named winamptb.dll was found! No active process named tbXfi1.dll was found! No active process named pdfforgeToolbarIE.dll File not found was found! No active process named EPSON Web-To-Page.dll was found! No active process named askBar.dll was found! No active process named tbXfi1.dll was found! No active process named pdfforgeToolbarIE.dll File not found was found! No active process named winamptb.dll was found! No active process named askBar.dll was found! No active process named tbXfi1.dll was found! No active process named autorun.inf -- [ NTFS ] was found!'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''' No active process named autorun.inf -- [ NTFS ] was found! No active process named Search Settings was found! ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: Dida User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Ram ->Temp folder emptied: 4309142 bytes ->Temporary Internet Files folder emptied: 1615737 bytes ->Java cache emptied: 8250614 bytes ->FireFox cache emptied: 49021271 bytes ->Flash cache emptied: 109933 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2352022 bytes %systemroot%\System32 .tmp files removed: 2596 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 49152 bytes RecycleBin emptied: 3242822884 bytes Total Files Cleaned = 3 155,00 mb OTL by OldTimer - Version 3.2.5.0 log created on 05262010_231909 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\Ram\Ustawienia lokalne\Temp\Perflib_Perfdata_1289c.dat not found! Registry entries deleted on Reboot... [/log] log OTL 3miechów: [log]OTL logfile created on: 2010-05-26 23:29:18 - Run 3 OTL by OldTimer - Version 3.2.5.0 Folder = F:\ Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 66,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 85,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 13,15 Gb Free Space | 33,68% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 210,25 Gb Total Space | 121,13 Gb Free Space | 57,61% Space Free | Partition Type: NTFS Drive F: | 216,44 Gb Total Space | 125,34 Gb Free Space | 57,91% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PIETRZAKA Current User Name: Ram Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 90 Days Output = Standard [color=#E56717]========== Processes (All) ==========[/color] PRC - [2010-05-22 22:24:08 | 000,571,904 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2010-04-02 16:20:32 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-11-25 05:09:04 | 000,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe PRC - [2009-11-01 18:29:27 | 000,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe PRC - [2009-10-22 08:10:31 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2009-10-22 08:10:30 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2009-08-06 20:24:06 | 000,053,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauclt.exe PRC - [2009-03-29 08:22:49 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2009-03-29 08:22:49 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\javaw.exe PRC - [2009-03-05 20:02:50 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2009-03-02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2009-02-09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe PRC - [2008-07-25 12:16:46 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe PRC - [2008-05-13 18:07:24 | 000,080,392 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe PRC - [2008-04-17 19:13:44 | 005,750,784 | ---- | M] () -- E:\xampp\mysql\bin\mysqld-nt.exe PRC - [2008-04-14 22:51:52 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe PRC - [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe PRC - [2008-04-14 22:51:44 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe PRC - [2008-04-14 22:51:44 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [IMGSVC] PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH] PRC - [2008-04-14 22:51:32 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\notepad.exe PRC - [2008-04-14 22:51:24 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-04-14 22:51:12 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe PRC - [2008-04-14 22:51:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe PRC - [2008-04-14 22:51:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe PRC - [2007-01-11 06:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE PRC - [2006-03-04 18:40:30 | 000,882,176 | ---- | M] () -- F:\Program Files\Kalendarz XP\Kalendarz.exe PRC - [2005-01-28 14:44:28 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe PRC - [2004-04-13 06:07:18 | 000,069,632 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe PRC - [2003-12-15 15:29:00 | 000,516,096 | ---- | M] () -- C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe PRC - [2003-06-19 23:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [color=#E56717]========== Modules (All) ==========[/color] MOD - [2010-05-22 22:24:08 | 000,571,904 | ---- | M] (OldTimer Tools) -- F:\OTL.exe MOD - [2009-12-08 11:25:45 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll MOD - [2009-06-25 10:27:54 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll MOD - [2009-04-15 16:54:38 | 000,585,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll MOD - [2009-03-21 16:08:59 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll MOD - [2009-02-09 12:53:44 | 000,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll MOD - [2009-02-09 12:53:43 | 000,722,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll MOD - [2008-10-23 14:42:41 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll MOD - [2008-06-17 21:03:15 | 008,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll MOD - [2008-04-14 22:51:58 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv MOD - [2008-04-14 22:50:58 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll MOD - [2008-04-14 22:50:58 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll MOD - [2008-04-14 22:50:58 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll MOD - [2008-04-14 22:50:58 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll MOD - [2008-04-14 22:50:48 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll MOD - [2008-04-14 22:50:46 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll MOD - [2008-04-14 22:50:46 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll MOD - [2008-04-14 22:50:46 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll MOD - [2008-04-14 22:50:46 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll MOD - [2008-04-14 22:50:40 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll MOD - [2008-04-14 22:50:38 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTF.dll MOD - [2008-04-14 22:50:34 | 000,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll MOD - [2008-04-14 22:50:32 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll MOD - [2008-04-14 22:50:16 | 000,822,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comres.dll MOD - [2008-04-14 22:50:14 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll MOD - [2008-04-14 22:50:12 | 000,498,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\clbcatq.dll MOD - [2008-04-14 22:50:00 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\apphelp.dll MOD - [2008-04-14 22:46:34 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx MOD - [2008-04-14 22:43:00 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTFIME.IME MOD - [2008-04-14 22:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (avupdate) SRV - [2009-10-22 08:10:31 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2009-10-22 08:10:30 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2008-05-13 18:07:24 | 000,080,392 | ---- | M] () [Auto | Running] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service) SRV - [2008-04-17 19:13:44 | 005,750,784 | ---- | M] () [Auto | Running] -- E:\xampp\mysql\bin\mysqld-nt.exe -- (mysql) SRV - [2007-01-11 06:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) SRV - [2005-11-14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-05-26 23:25:16 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - [2009-12-07 21:17:25 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt) DRV - [2009-11-25 05:50:16 | 004,463,104 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2009-10-29 15:11:54 | 000,002,368 | ---- | M] (AntiCracking) [Kernel | Auto | Running] -- C:\WINDOWS\system32\SVKP.sys -- (SVKP) DRV - [2009-10-22 08:10:31 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb) DRV - [2009-10-22 08:10:31 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009-09-27 17:12:22 | 007,655,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2009-02-21 00:22:15 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2009-02-13 11:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio) DRV - [2008-11-21 23:17:17 | 000,682,232 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2008-05-20 13:53:36 | 000,093,696 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV - [2008-05-07 13:21:40 | 004,739,072 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-04-13 22:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008-04-13 21:10:32 | 000,096,512 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atapi.sys -- (atapi) DRV - [2008-01-03 16:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-06-18 15:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem) DRV - [2006-09-24 15:28:47 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan) DRV - [2005-02-01 16:55:40 | 000,037,009 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- F:\Dark Kdr\npkcusb.sys -- (npkcusb) DRV - [2005-02-01 16:55:40 | 000,021,442 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- F:\Dark Kdr\npkcrypt.sys -- (npkcrypt) DRV - [2004-04-30 10:37:02 | 000,160,640 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\a347bus.sys -- (a347bus) DRV - [2004-04-30 10:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\a347scsi.sys -- (a347scsi) DRV - [2003-07-17 17:40:06 | 000,265,728 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX) DRV - [2003-07-17 14:02:08 | 000,017,097 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\PONDIS5.sys -- (PONDIS5) DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Winamp Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.5.1 FF - prefs.js..extensions.enabledItems: refspoof@mozdev.org:0.9.5 FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789 FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.5.6.0 FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009-03-05 20:02:56 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-25 16:58:14 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-25 16:58:14 | 000,000,000 | ---D | M] [2008-12-28 11:59:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Extensions [2010-05-26 23:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions [2010-03-06 17:53:32 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-03-21 12:13:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-01-29 21:49:24 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} [2010-02-26 15:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\personas@christopher.beard [2009-12-06 20:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\refspoof@mozdev.org [2009-12-27 20:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\yasearch@yandex.ru [2009-12-27 20:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\yasearch@yandex.ru\chrome\skin\extensions-hacks [2009-10-06 17:10:14 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\conduit.xml [2010-03-06 18:08:20 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\winamp-search.xml [2010-05-26 23:26:20 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2009-08-28 14:41:29 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\arcabit@www.arcabit.pl [2008-09-04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll [2010-03-14 17:45:03 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-03-14 17:45:03 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-03-14 17:45:03 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-03-14 17:45:03 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-03-14 17:45:03 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-03-14 17:45:03 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-05-22 22:44:48 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004..\Run: [AQQ] F:\Program Files\WapSter\WapSter AQQ\AQQ.exe (Creative Team S.A.) O4 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004..\Run: [Steam] F:\Program Files\Steam\Steam.exe (Valve Corporation) O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk = F:\Program Files\Kalendarz XP\Kalendarz.exe () O4 - Startup: C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip () O4 - Startup: C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\Skrót (2) do JDownloader.exe.lnk = F:\Moje Dokumenty\JDownloader 0.8.9\JDownloader.exe (AppWork UG (haftungsbeschränkt)) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-2025429265-1450960922-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - E:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2008-09-27 12:15:10 | 000,000,000 | ---D | M] - F:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - C:\WINDOWS\system32\ias [2008-09-25 18:19:57 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - StartUpFolder: C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe - (LogMeIn Inc.) MsConfig - StartUpReg: [b]Skype[/b] - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 2 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: vsmon - Service SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices [color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color] [2010-05-23 11:50:33 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010-05-22 22:36:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2010-05-22 22:36:16 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2010-05-22 22:36:16 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2010-05-22 22:36:16 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2010-05-22 22:36:12 | 000,000,000 | ---D | C] -- C:\ComboFix [2010-05-10 13:46:00 | 000,000,000 | ---D | C] -- C:\Program Files\YASAVOB2MPEG [2010-04-30 23:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder(3) [2010-04-30 23:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder(2) [2010-04-30 23:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Nowy folder [2010-04-26 20:25:57 | 001,430,522 | ---- | C] (Artur Sikora ) -- C:\Documents and Settings\Ram\subedit_b4072_install.exe [2010-04-26 19:52:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\VSO [2010-04-26 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid [2010-04-26 19:48:33 | 000,652,794 | ---- | C] (Xvid team ) -- C:\Documents and Settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe [2010-04-26 19:01:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS [2010-04-26 18:50:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Dane aplikacji\AVI ReComp [2010-04-26 18:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2010-04-26 18:50:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVI ReComp [2010-04-25 17:43:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ram\Dane aplikacji\WinAVI [2010-04-25 17:43:11 | 000,000,000 | ---D | C] -- C:\Program Files\WinAVI Video Converter [2010-04-25 16:54:36 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDubMod [2010-04-25 15:28:12 | 000,000,000 | ---D | C] -- C:\Program Files\mkvtoavi [2010-04-17 18:28:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\MumboJumbo [2010-04-12 17:51:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard Entertainment [2010-04-11 14:49:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard [2010-03-21 11:03:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\KB905474 [2010-03-06 20:59:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Real [2009-12-28 10:18:55 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys [2009-12-28 10:18:55 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys [color=#E56717]========== Files - Modified Within 90 Days ==========[/color] [2010-05-26 23:24:17 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job [2010-05-26 23:24:11 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-05-26 23:24:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-05-26 23:23:08 | 013,893,632 | -H-- | M] () -- C:\Documents and Settings\Ram\NTUSER.DAT [2010-05-26 23:23:08 | 000,000,292 | -HS- | M] () -- C:\Documents and Settings\Ram\ntuser.ini [2010-05-26 12:02:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-05-24 22:17:36 | 000,000,645 | ---- | M] () -- C:\WINDOWS\win.ini [2010-05-23 12:50:27 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Wotlk!~!.lnk [2010-05-23 12:12:20 | 000,047,616 | ---- | M] () -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-05-22 22:45:32 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2010-05-22 22:44:48 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010-05-20 15:03:09 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010-05-20 14:47:13 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI [2010-05-13 20:34:26 | 000,000,675 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\AQQ.lnk [2010-05-10 13:46:01 | 000,000,723 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\YASA VOB to MPEG Converter.lnk [2010-05-05 21:50:32 | 000,586,018 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-05-05 21:50:32 | 000,515,952 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-05-05 21:50:32 | 000,109,654 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-05-05 21:50:32 | 000,086,760 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-05-05 21:50:31 | 001,315,428 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010-04-26 23:28:21 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Steam.lnk [2010-04-26 21:12:13 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip [2010-04-26 21:11:48 | 000,000,312 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Curse Client.appref-ms [2010-04-26 20:38:47 | 000,000,500 | -H-- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi.ini [2010-04-26 20:35:06 | 000,080,757 | ---- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.ssa [2010-04-26 20:27:38 | 000,000,687 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\SubEdit-Player.lnk [2010-04-26 20:27:22 | 001,430,522 | ---- | M] (Artur Sikora ) -- C:\Documents and Settings\Ram\subedit_b4072_install.exe [2010-04-26 19:49:02 | 000,652,794 | ---- | M] (Xvid team ) -- C:\Documents and Settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe [2010-04-26 19:43:12 | 000,892,475 | ---- | M] () -- C:\Documents and Settings\Ram\xvidcore-1.2.2.zip [2010-04-26 19:01:14 | 000,018,172 | ---- | M] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip [2010-04-26 19:00:16 | 000,018,569 | ---- | M] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-26 18:50:09 | 000,001,758 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\AVI ReComp.lnk [2010-04-26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe [2010-04-25 23:04:52 | 000,012,615 | ---- | M] () -- C:\Documents and Settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 20:47:10 | 1324,066,182 | ---- | M] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi [2010-04-25 18:00:27 | 1370,011,442 | ---- | M] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.avi [2010-04-25 17:43:13 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\WinAVI Video Converter.lnk [2010-04-25 16:54:37 | 000,000,813 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod.lnk [2010-04-22 09:15:15 | 000,000,040 | ---- | M] () -- C:\Session.xml [2010-04-17 22:43:34 | 004,776,544 | -H-- | M] () -- C:\Documents and Settings\Ram\Ustawienia lokalne\Dane aplikacji\IconCache.db [2010-04-17 18:30:45 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat [2010-04-17 11:04:33 | 000,138,384 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2010-04-17 11:04:24 | 000,215,128 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2010-04-17 10:59:58 | 000,000,772 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\EA Download Manager.lnk [2010-04-12 21:37:57 | 000,000,823 | ---- | M] () -- C:\Documents and Settings\Ram\.recently-used.xbel [2010-04-09 21:21:32 | 000,085,504 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-04-09 21:21:32 | 000,000,547 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2010-03-22 08:47:35 | 000,000,584 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2010-03-21 11:15:01 | 000,273,376 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-03-12 21:14:28 | 000,000,603 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\Subtitle Studio 2.0.lnk [2010-03-06 17:53:21 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx [2010-03-05 14:04:58 | 000,000,517 | ---- | M] () -- C:\Documents and Settings\Ram\Pulpit\abgx360 GUI (2).lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-05-23 12:50:27 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Wotlk!~!.lnk [2010-05-22 22:36:16 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010-05-22 22:36:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010-05-22 22:36:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010-05-22 22:36:16 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010-05-22 22:36:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010-05-10 13:46:01 | 000,000,723 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\YASA VOB to MPEG Converter.lnk [2010-04-26 22:11:33 | 000,161,144 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2010-04-26 21:12:13 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip [2010-04-26 20:35:20 | 000,080,757 | ---- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.ssa [2010-04-26 20:28:01 | 000,000,500 | -H-- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi.ini [2010-04-26 20:27:38 | 000,000,687 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\SubEdit-Player.lnk [2010-04-26 20:11:34 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-04-26 20:11:34 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2010-04-26 19:42:57 | 000,892,475 | ---- | C] () -- C:\Documents and Settings\Ram\xvidcore-1.2.2.zip [2010-04-26 18:50:09 | 000,001,758 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\AVI ReComp.lnk [2010-04-26 18:30:08 | 000,018,172 | ---- | C] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip [2010-04-25 23:05:00 | 000,012,615 | ---- | C] () -- C:\Documents and Settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip [2010-04-25 20:53:22 | 000,027,703 | ---- | C] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.txt [2010-04-25 20:51:13 | 000,018,569 | ---- | C] () -- C:\Documents and Settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip [2010-04-25 20:26:03 | 1324,066,182 | ---- | C] () -- C:\Documents and Settings\Ram\How.To.Train.Your.Dragon.2010.TS.XviD-PrisM.avi [2010-04-25 17:44:14 | 1370,011,442 | ---- | C] () -- C:\Documents and Settings\Ram\Clash.Of.The.Titans.2010.TS.x264.AAC.avi [2010-04-25 17:43:13 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\WinAVI Video Converter.lnk [2010-04-25 16:54:37 | 000,000,813 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\VirtualDubMod.lnk [2010-04-17 18:30:45 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat [2010-04-12 21:37:57 | 000,000,823 | ---- | C] () -- C:\Documents and Settings\Ram\.recently-used.xbel [2010-03-21 11:03:04 | 000,000,260 | ---- | C] () -- C:\WINDOWS\tasks\WGASetup.job [2010-03-12 21:14:28 | 000,000,603 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\Subtitle Studio 2.0.lnk [2010-03-05 14:04:58 | 000,000,517 | ---- | C] () -- C:\Documents and Settings\Ram\Pulpit\abgx360 GUI (2).lnk [2009-12-11 15:51:00 | 000,001,225 | ---- | C] () -- C:\WINDOWS\kaillera.ini [2009-12-06 21:26:41 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2009-11-01 18:33:02 | 000,138,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-10-27 21:13:44 | 000,000,086 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2009-10-15 02:01:24 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2009-09-30 14:18:33 | 008,676,883 | ---- | C] () -- C:\WINDOWS\System32\NCMedia2.dll [2009-09-30 14:18:33 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009-09-30 14:18:33 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009-09-29 15:30:57 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Worldbuilder.INI [2009-07-23 18:29:40 | 000,040,160 | ---- | C] () -- C:\WINDOWS\php.ini [2009-07-23 18:29:40 | 000,000,488 | ---- | C] () -- C:\WINDOWS\my.ini [2009-07-05 19:37:50 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini [2009-05-29 11:32:40 | 000,000,245 | ---- | C] () -- C:\WINDOWS\game.ini [2009-03-05 20:03:13 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2009-02-21 15:36:00 | 001,867,776 | ---- | C] () -- C:\WINDOWS\python24.dll [2009-01-16 21:07:32 | 000,001,503 | ---- | C] () -- C:\WINDOWS\ReVoltX.ini [2009-01-13 20:28:03 | 000,000,743 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini [2009-01-13 20:27:45 | 000,003,090 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2009-01-10 09:47:47 | 000,000,943 | ---- | C] () -- C:\WINDOWS\VPlayer.INI [2008-10-24 22:43:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008-09-28 21:59:51 | 000,000,649 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008-09-27 10:15:58 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2008-09-26 14:22:31 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2008-09-26 14:14:18 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CDE DX4400DEFGIPS.ini [2008-09-26 14:04:04 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2008-04-13 22:10:32 | 000,096,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys [2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [1996-04-03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys [color=#E56717]========== LOP Check ==========[/color] [2009-08-28 14:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit [2009-08-11 21:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software [2009-11-17 18:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2010-02-19 10:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts [2008-09-26 14:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EPSON [2009-02-22 21:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GlobalSCAPE [2010-04-17 18:28:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MumboJumbo [2008-10-16 16:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2009-04-17 21:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TrackMania [2008-09-26 14:24:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\UDL [2009-08-28 14:43:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\ArcaBit [2010-02-04 11:14:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\abgx360 [2009-05-29 11:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Activision [2010-04-26 20:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\AVI ReComp [2009-10-17 19:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\BitTorrent [2009-03-08 19:28:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\COWON [2009-04-22 18:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Dev-Cpp [2009-04-28 20:19:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\DNA [2009-11-06 08:49:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\EPSON [2009-12-10 22:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\fltk.org [2008-12-29 00:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Gadu-Gadu [2009-04-19 17:32:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\GetRightToGo [2009-02-22 21:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\GlobalSCAPE [2010-02-14 14:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\gtk-2.0 [2009-12-28 21:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\ImgBurn [2009-10-14 19:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Moje pliki zapisu Bitwy o Śródziemie [2009-01-07 19:32:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\RapidGet [2009-04-12 13:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Soldat [2009-07-31 18:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\Tibia [2010-04-26 19:53:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\VSO [2010-04-25 17:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\WinAVI [2009-02-13 16:46:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ram\Dane aplikacji\WypasOTS Client [2010-05-26 23:24:17 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009-10-13 17:04:32 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2001-07-22 02:13:54 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2010-05-22 22:48:51 | 000,169,537 | ---- | M] () -- C:\ComboFix.txt [2008-09-25 18:20:16 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2010-05-10 13:56:33 | 000,019,274 | ---- | M] () -- C:\debug.log [2008-09-25 18:20:16 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009-12-07 17:27:26 | 005,503,655 | ---- | M] () -- C:\JPEG_Output.PDF [2009-12-07 17:38:38 | 004,965,049 | ---- | M] () -- C:\JPEG_Output.rar [2009-04-12 13:27:00 | 000,000,000 | R--- | M] () -- C:\logwmemory.bin [2008-09-25 18:20:16 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008-04-14 00:02:00 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-05-26 23:24:06 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [2010-05-26 23:25:15 | 000,000,129 | ---- | M] () -- C:\service.log [2010-04-22 09:15:15 | 000,000,040 | ---- | M] () -- C:\Session.xml [2009-02-21 22:29:52 | 000,051,371 | -H-- | M] () -- C:\treeinfo.wc [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008-04-14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [2008-04-14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [2008-04-13 21:10:32 | 000,096,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drivers\atapi.sys [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2009-08-28 20:33:42 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys [2009-08-28 20:33:42 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2008-04-14 23:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys [2008-04-14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color] [2008-04-14 22:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ERDNT\cache\eventlog.dll [2008-04-14 22:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2008-04-14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys [2008-04-14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ERDNT\cache\winlogon.exe [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\system32\winlogon.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8C35AEA7 < End of report > [/log] Reszte dam jutro.
Tomek01 komentarz 27 maja 2010 komentarz 27 maja 2010 Używałeś Combofix'a więc pokaz jeszcze log z niego: Combofix.txt Natępnie go odinstaluj ComboFix’a [code]Start >>> Uruchom >>> combofix /u [i naciskasz OK][/code] Usuń kwarantannę C:\Qoobox W OTL, w oknie Custom scan/fixes wklej: [code]:Processes Explorer.exe :OTL FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" [2010-03-06 17:53:32 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-01-29 21:49:24 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} [2009-10-06 17:10:14 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\conduit.xml O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] File not found :Commands [emptytemp] [start explorer] [Reboot][/code] Załącz log z OTL.
adsko komentarz 28 maja 2010 Autor komentarz 28 maja 2010 (edytowane) [log]ComboFix 10-05-22.01 - Ram 2010-05-22 22:40:25.8.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2046.1587 [GMT 2:00] Uruchomiony z: F:\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: ArcaFirewall 2008 *enabled* {B640009B-6FF6-4CA7-9CE8-7DA160B95A5B} UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Ram\Dane aplikacji\EurekaLog . ((((((((((((((((((((((((( Pliki utworzone od 2010-04-22 do 2010-05-22 ))))))))))))))))))))))))))))))) . 2010-05-10 11:46 . 2010-05-10 11:46 -------- d-----w- c:\program files\YASAVOB2MPEG 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(3) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(2) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder 2010-04-26 20:11 . 2010-05-20 13:31 161144 ----a-w- c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat 2010-04-26 18:25 . 2010-04-26 18:27 1430522 ----a-w- c:\documents and settings\Ram\subedit_b4072_install.exe 2010-04-26 18:11 . 2010-04-09 19:21 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2010-04-26 17:52 . 2010-04-26 17:52 -------- d-----w- c:\documents and settings\Ram\Ustawienia lokalne\Dane aplikacji\VSO 2010-04-26 17:50 . 2010-04-26 17:50 -------- d-----w- c:\program files\Xvid 2010-04-26 17:48 . 2010-04-26 17:49 652794 ----a-w- c:\documents and settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe 2010-04-26 17:42 . 2010-04-26 17:43 892475 ----a-w- c:\documents and settings\Ram\xvidcore-1.2.2.zip 2010-04-26 17:01 . 2010-04-26 17:01 -------- d-----w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS 2010-04-26 16:50 . 2010-04-26 18:39 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\AVI ReComp 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AviSynth 2.5 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AVI ReComp 2010-04-26 16:30 . 2010-04-26 17:01 18172 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip 2010-04-25 21:05 . 2010-04-25 21:04 12615 ----a-w- c:\documents and settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip 2010-04-25 18:51 . 2010-04-26 17:00 18569 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\WinAVI 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\program files\WinAVI Video Converter 2010-04-25 14:54 . 2010-04-25 14:57 -------- d-----w- c:\program files\VirtualDubMod 2010-04-25 13:28 . 2010-04-25 13:36 -------- d-----w- c:\program files\mkvtoavi . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-22 20:46 . 2008-09-25 16:28 16608 ----a-w- c:\windows\gdrv.sys 2010-05-17 17:06 . 2010-03-16 18:59 439816 ----a-w- c:\documents and settings\Ram\Dane aplikacji\Real\Update\setup3.10\setup.exe 2010-05-14 13:58 . 2008-09-25 16:29 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-05-05 19:50 . 2001-10-26 18:15 586018 ----a-w- c:\windows\system32\perfh015.dat 2010-05-05 19:50 . 2001-10-26 18:15 109654 ----a-w- c:\windows\system32\perfc015.dat 2010-04-26 17:53 . 2009-04-19 15:33 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\VSO 2010-04-17 16:30 . 2010-04-17 16:30 10 ----a-w- c:\windows\popcinfo.dat 2010-04-17 16:28 . 2010-04-17 16:28 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\MumboJumbo 2010-04-17 09:04 . 2009-11-01 16:33 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-04-17 09:04 . 2009-11-01 16:29 215128 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-04-12 15:51 . 2010-04-12 15:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard Entertainment 2010-04-11 12:49 . 2010-04-11 12:49 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard 2010-04-04 21:07 . 2009-02-28 10:37 -------- d-----w- c:\program files\NAPI-PROJEKT 2009-08-28 07:07 . 2009-08-28 07:07 13439 ----a-w- c:\program files\Common Files\awabifal.db . ------- Sigcheck ------- [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [-] 2008-04-13 19:10 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys [-] 2008-05-30 . C8BDAD4065118558B3DC360FC96D81DB . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2010-03-01_14.22.18 ))))))))))))))))))))))))))))))))))))))))) . + 2010-05-22 20:45 . 2010-05-22 20:45 16384 c:\windows\Temp\Perflib_Perfdata_750.dat + 2010-05-22 20:45 . 2010-05-22 20:45 16384 c:\windows\Temp\Perflib_Perfdata_71c.dat + 2008-07-18 21:10 . 2009-08-06 18:24 44768 c:\windows\system32\wups2.dll + 2008-09-25 16:18 . 2009-08-06 18:24 35552 c:\windows\system32\wups.dll + 2008-09-25 16:18 . 2009-08-06 18:24 53472 c:\windows\system32\wuauclt.exe + 2005-01-28 12:44 . 2005-01-28 12:44 10752 c:\windows\system32\wpdtrace.dll + 2005-01-28 12:44 . 2005-01-28 12:44 66560 c:\windows\system32\wpdmtpus.dll + 2005-01-28 12:44 . 2005-01-28 12:44 61952 c:\windows\system32\wpdconns.dll + 2005-01-28 12:44 . 2005-01-28 12:44 38912 c:\windows\system32\wpd_ci.dll + 2008-04-14 20:50 . 2005-01-28 12:44 33792 c:\windows\system32\WMDMPS.dll + 2008-04-14 20:50 . 2005-01-28 12:44 28160 c:\windows\system32\WMDMLOG.dll + 2008-04-14 20:50 . 2009-06-25 08:27 54272 c:\windows\system32\wdigest.dll + 2005-01-28 12:44 . 2005-01-28 12:44 38912 c:\windows\system32\wdfmgr.exe + 2005-01-28 12:44 . 2005-01-28 12:44 15872 c:\windows\system32\wdfapi.dll + 2010-03-06 15:50 . 2009-04-28 20:20 96752 c:\windows\system32\vxblock.dll + 2005-01-28 12:44 . 2005-01-28 12:44 47104 c:\windows\system32\uwdf.exe + 2008-04-14 20:51 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe + 2008-04-14 20:51 . 2009-06-15 10:45 82944 c:\windows\system32\tlntsess.exe + 2008-04-14 20:51 . 2009-06-15 10:45 78336 c:\windows\system32\telnet.exe + 2008-04-14 20:50 . 2009-10-21 05:40 75776 c:\windows\system32\strmfilt.dll - 2008-04-14 20:50 . 2008-04-14 20:50 75776 c:\windows\system32\strmfilt.dll + 2008-12-02 09:56 . 2008-07-09 07:57 26488 c:\windows\system32\spupdsvc.exe - 2008-12-02 09:56 . 2007-11-30 11:18 26488 c:\windows\system32\spupdsvc.exe + 2008-09-25 16:20 . 2009-05-26 11:43 19320 c:\windows\system32\spmsg.dll + 2010-03-21 07:43 . 2009-08-06 18:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll + 2010-03-21 07:43 . 2009-08-06 18:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll + 2008-04-14 20:50 . 2009-06-25 08:27 56832 c:\windows\system32\secur32.dll + 2001-10-26 19:30 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe + 2008-04-14 20:50 . 2009-10-12 13:40 79872 c:\windows\system32\raschap.dll - 2008-04-14 20:50 . 2008-04-14 20:50 79872 c:\windows\system32\raschap.dll + 2010-03-06 15:50 . 2009-04-28 20:20 66032 c:\windows\system32\pxinsa64.exe + 2010-03-06 15:50 . 2009-04-28 20:20 72176 c:\windows\system32\pxhpinst.exe + 2010-03-06 15:50 . 2009-04-28 20:20 66544 c:\windows\system32\pxcpya64.exe + 2008-05-30 13:20 . 2010-01-05 09:57 44544 c:\windows\system32\pngfilt.dll - 2008-05-30 13:20 . 2008-10-16 20:33 44544 c:\windows\system32\pngfilt.dll + 2001-08-17 23:30 . 2010-05-05 19:50 86760 c:\windows\system32\perfc009.dat - 2008-09-25 16:17 . 2008-04-14 20:50 91648 c:\windows\system32\mtxoci.dll + 2008-09-25 16:17 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll - 2008-04-14 20:50 . 2008-04-14 20:50 66560 c:\windows\system32\mtxclu.dll + 2008-04-14 20:50 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll + 2008-04-14 22:50 . 2009-11-27 17:14 17920 c:\windows\system32\msyuv.dll + 2001-10-26 19:29 . 2009-11-27 16:09 28672 c:\windows\system32\msvidc32.dll + 2008-04-14 20:50 . 2009-11-27 16:09 11264 c:\windows\system32\msrle32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 11264 c:\windows\system32\msrle32.dll + 2008-04-14 20:50 . 2005-01-28 12:44 25088 c:\windows\system32\MsPMSNSv.dll - 2008-05-30 13:20 . 2008-10-16 20:33 52224 c:\windows\system32\msfeedsbs.dll + 2008-05-30 13:20 . 2010-01-05 09:57 52224 c:\windows\system32\msfeedsbs.dll + 2008-09-25 16:17 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll - 2008-09-25 16:17 . 2008-04-14 20:50 58880 c:\windows\system32\msdtclog.dll + 2008-04-14 20:50 . 2009-09-04 21:05 58880 c:\windows\system32\msasn1.dll + 2008-04-14 20:51 . 2008-06-10 04:52 96768 c:\windows\system32\logagent.exe + 2008-05-30 13:20 . 2010-01-05 09:57 27648 c:\windows\system32\jsproxy.dll - 2008-05-30 13:20 . 2008-10-16 20:33 27648 c:\windows\system32\jsproxy.dll + 2008-04-14 22:50 . 2009-11-27 16:09 48128 c:\windows\system32\iyuv_32.dll + 2008-05-30 13:20 . 2009-12-31 15:35 13824 c:\windows\system32\ieudinit.exe - 2008-05-30 13:20 . 2008-10-16 13:11 13824 c:\windows\system32\ieudinit.exe + 2008-05-30 13:20 . 2010-01-05 09:57 44544 c:\windows\system32\iernonce.dll - 2008-05-30 13:20 . 2008-10-16 20:33 44544 c:\windows\system32\iernonce.dll - 2008-05-30 13:20 . 2008-05-30 13:20 78336 c:\windows\system32\ieencode.dll + 2008-05-30 13:20 . 2010-01-05 09:57 78336 c:\windows\system32\ieencode.dll - 2008-05-30 13:19 . 2008-10-16 13:15 70656 c:\windows\system32\ie4uinit.exe + 2008-05-30 13:19 . 2009-12-31 15:35 70656 c:\windows\system32\ie4uinit.exe - 2008-05-30 13:19 . 2008-10-16 20:33 63488 c:\windows\system32\icardie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 63488 c:\windows\system32\icardie.dll + 2008-04-14 20:50 . 2009-10-21 05:40 25088 c:\windows\system32\httpapi.dll + 2008-04-14 20:50 . 2009-10-15 16:33 81920 c:\windows\system32\fontsub.dll + 2008-04-14 20:50 . 2005-01-28 12:44 96768 c:\windows\system32\drmstor.dll + 2005-01-28 12:44 . 2005-01-28 12:44 18944 c:\windows\system32\drivers\wpdusb.sys + 2010-03-06 15:50 . 2009-04-28 20:20 44944 c:\windows\system32\drivers\PxHelp20.sys + 2008-04-13 22:01 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys + 2009-06-25 08:27 . 2009-06-25 08:27 54272 c:\windows\system32\dllcache\wdigest.dll + 2009-06-15 10:45 . 2009-06-15 10:45 82944 c:\windows\system32\dllcache\tlntsess.exe + 2009-06-15 10:45 . 2009-06-15 10:45 78336 c:\windows\system32\dllcache\telnet.exe + 2009-10-21 05:40 . 2009-10-21 05:40 75776 c:\windows\system32\dllcache\strmfilt.dll + 2009-06-25 08:27 . 2009-06-25 08:27 56832 c:\windows\system32\dllcache\secur32.dll + 2010-03-21 07:54 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe + 2009-10-12 13:40 . 2009-10-12 13:40 79872 c:\windows\system32\dllcache\raschap.dll + 2008-08-26 08:27 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\pngfilt.dll - 2008-08-26 08:27 . 2008-10-16 20:33 44544 c:\windows\system32\dllcache\pngfilt.dll + 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll + 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll + 2009-11-27 17:14 . 2009-11-27 17:14 17920 c:\windows\system32\dllcache\msyuv.dll + 2009-11-27 16:09 . 2009-11-27 16:09 28672 c:\windows\system32\dllcache\msvidc32.dll + 2009-11-27 16:09 . 2009-11-27 16:09 11264 c:\windows\system32\dllcache\msrle32.dll + 2008-08-26 08:26 . 2010-01-05 09:57 52224 c:\windows\system32\dllcache\msfeedsbs.dll - 2008-08-26 08:26 . 2008-10-16 20:33 52224 c:\windows\system32\dllcache\msfeedsbs.dll + 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll + 2009-09-04 21:05 . 2009-09-04 21:05 58880 c:\windows\system32\dllcache\msasn1.dll + 2008-04-14 20:51 . 2008-06-10 04:52 96768 c:\windows\system32\dllcache\logagent.exe + 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys - 2008-08-26 08:26 . 2008-10-16 20:33 27648 c:\windows\system32\dllcache\jsproxy.dll + 2008-08-26 08:26 . 2010-01-05 09:57 27648 c:\windows\system32\dllcache\jsproxy.dll + 2009-11-27 16:09 . 2009-11-27 16:09 48128 c:\windows\system32\dllcache\iyuv_32.dll + 2008-08-25 08:38 . 2009-12-31 15:35 13824 c:\windows\system32\dllcache\ieudinit.exe - 2008-08-25 08:38 . 2008-10-16 13:11 13824 c:\windows\system32\dllcache\ieudinit.exe - 2008-08-26 08:26 . 2008-10-16 20:33 44544 c:\windows\system32\dllcache\iernonce.dll + 2008-08-26 08:26 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\iernonce.dll + 2010-01-05 09:57 . 2010-01-05 09:57 78336 c:\windows\system32\dllcache\ieencode.dll + 2008-08-25 08:42 . 2009-12-31 15:35 70656 c:\windows\system32\dllcache\ie4uinit.exe - 2008-08-25 08:42 . 2008-10-16 13:15 70656 c:\windows\system32\dllcache\ie4uinit.exe + 2008-08-26 08:26 . 2010-01-05 09:57 63488 c:\windows\system32\dllcache\icardie.dll - 2008-08-26 08:26 . 2008-10-16 20:33 63488 c:\windows\system32\dllcache\icardie.dll + 2009-10-21 05:40 . 2009-10-21 05:40 25088 c:\windows\system32\dllcache\httpapi.dll + 2010-03-21 07:55 . 2009-10-15 16:33 81920 c:\windows\system32\dllcache\fontsub.dll + 2009-12-14 07:10 . 2009-12-14 07:10 33280 c:\windows\system32\dllcache\csrsrv.dll + 2010-01-05 09:57 . 2010-01-05 09:57 17408 c:\windows\system32\dllcache\corpol.dll + 2009-11-27 16:09 . 2009-11-27 16:09 84992 c:\windows\system32\dllcache\avifil32.dll + 2009-07-17 19:04 . 2009-07-17 19:04 58880 c:\windows\system32\dllcache\atl.dll + 2008-04-14 20:50 . 2009-12-14 07:10 33280 c:\windows\system32\csrsrv.dll + 2008-05-30 13:19 . 2010-01-05 09:57 17408 c:\windows\system32\corpol.dll - 2008-05-30 13:19 . 2008-05-30 13:19 17408 c:\windows\system32\corpol.dll + 2008-04-14 20:50 . 2009-08-06 18:24 96480 c:\windows\system32\cdm.dll - 2008-04-14 20:50 . 2008-04-14 20:50 84992 c:\windows\system32\avifil32.dll + 2008-04-14 20:50 . 2009-11-27 16:09 84992 c:\windows\system32\avifil32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 58880 c:\windows\system32\atl.dll + 2008-04-14 20:50 . 2009-07-17 19:04 58880 c:\windows\system32\atl.dll + 2009-12-01 19:05 . 2009-10-18 11:53 65536 c:\windows\system\vdsvrlnk.dll + 2009-12-01 19:05 . 2009-10-18 11:54 73728 c:\windows\system\vdremote.dll + 2010-03-06 15:53 . 2005-01-28 12:44 96768 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmstor.dll + 2010-03-06 15:53 . 2008-04-14 20:50 87040 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmstor.dll + 2010-03-06 15:53 . 2005-01-28 12:44 96768 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\logagent.exe + 2010-03-06 15:53 . 2005-01-28 12:44 18944 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdusb.sys + 2010-03-06 15:53 . 2005-01-28 12:44 10752 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdtrace.dll + 2010-03-06 15:53 . 2005-01-28 12:44 66560 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpus.dll + 2010-03-06 15:53 . 2005-01-28 12:44 61952 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdconns.dll + 2010-03-06 15:53 . 2005-01-28 12:44 38912 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpd_ci.dll + 2010-03-06 15:53 . 2005-01-28 12:44 38912 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe + 2010-03-06 15:53 . 2005-01-28 12:44 15872 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfapi.dll + 2010-03-06 15:53 . 2005-01-28 12:44 47104 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\uwdf.exe + 2010-03-06 15:53 . 2005-01-28 12:44 33792 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMPS.dll + 2010-03-06 15:53 . 2005-01-28 12:44 28160 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMLOG.dll + 2010-03-06 15:53 . 2005-01-28 12:44 25088 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll + 2010-03-06 15:53 . 2008-04-14 20:50 23552 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMPS.dll + 2010-03-06 15:53 . 2008-04-14 20:50 27136 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMLOG.dll + 2010-03-06 15:53 . 2008-04-14 20:50 52736 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll + 2008-11-25 03:59 . 2008-11-25 03:59 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2010-04-17 08:59 . 2010-04-17 08:59 21504 c:\windows\Installer\c66d4.msi + 2010-03-21 08:57 . 2008-10-16 20:33 44544 c:\windows\ie7updates\KB978207-IE7\pngfilt.dll + 2010-03-21 08:57 . 2008-10-16 20:33 52224 c:\windows\ie7updates\KB978207-IE7\msfeedsbs.dll + 2010-03-21 08:57 . 2008-10-16 20:33 27648 c:\windows\ie7updates\KB978207-IE7\jsproxy.dll + 2010-03-21 08:57 . 2008-10-16 13:11 13824 c:\windows\ie7updates\KB978207-IE7\ieudinit.exe + 2010-03-21 08:57 . 2008-10-16 20:33 44544 c:\windows\ie7updates\KB978207-IE7\iernonce.dll + 2010-03-21 08:57 . 2008-05-30 13:20 78336 c:\windows\ie7updates\KB978207-IE7\ieencode.dll + 2010-03-21 08:57 . 2008-10-16 13:15 70656 c:\windows\ie7updates\KB978207-IE7\ie4uinit.exe + 2010-03-21 08:57 . 2008-10-16 20:33 63488 c:\windows\ie7updates\KB978207-IE7\icardie.dll + 2010-03-21 08:57 . 2008-05-30 13:19 17408 c:\windows\ie7updates\KB978207-IE7\corpol.dll + 2008-09-26 12:04 . 2009-11-27 17:14 17920 c:\windows\Driver Cache\i386\msyuv.dll + 2009-11-27 16:09 . 2009-11-27 16:09 48128 c:\windows\Driver Cache\i386\iyuv_32.dll + 2010-03-21 09:18 . 2010-03-21 09:18 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\b4a9e413d5cd6d6ec2d50aa05381e293\UIAutomationProvider.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\8acb476a0d4ee17a12881e17ae74a6af\System.Windows.Presentation.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\4b87ca3482a3c0ee733e028ecee7de65\System.Web.DynamicData.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\a0c71055364bd356971791284c3fb910\System.ComponentModel.DataAnnotations.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f9a75bbdc2ce7db578b5977766a09b99\System.AddIn.Contract.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\3dd0f86c966c75755d62eab8ddf0634c\PresentationFontCache.ni.exe + 2010-03-21 09:16 . 2010-03-21 09:16 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\034d081fe294bab1ee1ecc98c1181424\PresentationCFFRasterizer.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2673aec397c52796aef05bb9d2668df\Microsoft.Vsa.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d513fe1a81c441e7656a9b062cff4e9f\Microsoft.Build.Framework.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\c5d504724d7f351b1d034615dbb72a2a\Microsoft.Build.Framework.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a664ccab020f93f1d533919f57131190\dfsvc.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2010-03-21 09:04 . 2010-03-21 09:04 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll - 2010-01-20 12:03 . 2010-01-20 12:03 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll - 2010-01-20 12:03 . 2010-01-20 12:03 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2010-03-21 09:04 . 2010-03-21 09:04 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2010-03-21 09:04 . 2010-03-21 09:04 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2010-01-20 12:03 . 2010-01-20 12:03 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2010-01-20 12:03 . 2010-01-20 12:03 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2010-03-21 09:04 . 2010-03-21 09:04 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll - 2010-01-20 12:03 . 2010-01-20 12:03 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-03-21 09:04 . 2010-03-21 09:04 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2010-01-20 12:03 . 2010-01-20 12:03 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2010-01-20 12:03 . 2010-01-20 12:03 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2010-01-20 12:03 . 2010-01-20 12:03 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2010-03-21 09:04 . 2010-03-21 09:04 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2010-01-20 12:03 . 2010-01-20 12:03 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2010-03-21 09:04 . 2010-03-21 09:04 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll - 2010-01-20 12:03 . 2010-01-20 12:03 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-03-21 09:04 . 2010-03-21 09:04 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2010-03-21 08:57 . 2008-10-23 10:06 62976 c:\windows\$NtUninstallKB979306$\tzchange.exe + 2010-03-21 08:57 . 2010-01-23 10:43 16896 c:\windows\$NtUninstallKB979306$\spuninst\tzchange.dll + 2010-03-21 09:02 . 2008-04-14 20:50 32256 c:\windows\$NtUninstallKB978037$\csrsrv.dll + 2010-03-21 08:58 . 2001-10-26 19:29 25600 c:\windows\$NtUninstallKB977914$\msvidc32.dll + 2010-03-21 08:58 . 2008-04-14 20:50 11264 c:\windows\$NtUninstallKB977914$\msrle32.dll + 2010-03-21 08:58 . 2008-04-14 21:09 47616 c:\windows\$NtUninstallKB977914$\iyuv_32.dll + 2010-03-21 08:58 . 2008-04-14 20:50 84992 c:\windows\$NtUninstallKB977914$\avifil32.dll + 2010-03-21 08:59 . 2008-04-14 21:09 16896 c:\windows\$NtUninstallKB975560$\msyuv.dll + 2010-03-21 08:59 . 2008-04-14 20:50 57344 c:\windows\$NtUninstallKB974571$\msasn1.dll + 2010-03-21 09:02 . 2008-04-14 20:50 79872 c:\windows\$NtUninstallKB974318$\raschap.dll + 2010-03-21 08:59 . 2008-04-14 20:50 58880 c:\windows\$NtUninstallKB973507$\atl.dll + 2010-03-21 09:02 . 2008-04-14 20:50 80896 c:\windows\$NtUninstallKB972270$\fontsub.dll + 2010-03-22 06:47 . 2008-04-14 20:50 75776 c:\windows\$NtUninstallKB970430$\strmfilt.dll + 2010-03-22 06:47 . 2008-04-14 20:50 24576 c:\windows\$NtUninstallKB970430$\httpapi.dll + 2010-03-21 08:57 . 2008-04-14 20:50 49152 c:\windows\$NtUninstallKB968389$\wdigest.dll + 2010-03-21 08:57 . 2008-04-14 20:50 56320 c:\windows\$NtUninstallKB968389$\secur32.dll + 2010-03-21 08:57 . 2008-04-13 22:01 92288 c:\windows\$NtUninstallKB968389$\ksecdd.sys + 2010-03-21 09:04 . 2008-04-14 20:51 80384 c:\windows\$NtUninstallKB960859$\tlntsess.exe + 2010-03-21 09:04 . 2008-04-14 20:51 77824 c:\windows\$NtUninstallKB960859$\telnet.exe + 2010-03-21 09:00 . 2001-10-26 19:30 31232 c:\windows\$NtUninstallKB956572$\sc.exe + 2010-03-21 08:59 . 2008-04-14 20:50 91648 c:\windows\$NtUninstallKB952004$\mtxoci.dll + 2010-03-21 08:59 . 2008-04-14 20:50 66560 c:\windows\$NtUninstallKB952004$\mtxclu.dll + 2010-03-21 08:59 . 2008-04-14 20:50 58880 c:\windows\$NtUninstallKB952004$\msdtclog.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978706\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978706\spmsg.dll + 2010-03-21 09:04 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978262\update\spcustom.dll + 2010-03-21 09:04 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978262\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978251\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978251\spmsg.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978207-IE7\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978207-IE7\spmsg.dll + 2010-01-05 09:49 . 2010-01-05 09:49 44544 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\pngfilt.dll + 2010-01-05 09:49 . 2010-01-05 09:49 52224 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msfeedsbs.dll + 2010-01-05 09:49 . 2010-01-05 09:49 27648 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\jsproxy.dll + 2010-01-01 06:58 . 2010-01-01 06:58 13824 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieudinit.exe + 2010-01-05 09:49 . 2010-01-05 09:49 44544 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iernonce.dll + 2010-01-05 09:49 . 2010-01-05 09:49 78336 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieencode.dll + 2010-01-01 06:58 . 2010-01-01 06:58 70656 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ie4uinit.exe + 2010-01-05 09:49 . 2010-01-05 09:49 63488 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\icardie.dll + 2010-01-05 09:49 . 2010-01-05 09:49 17408 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\corpol.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB978037\update\spcustom.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB978037\spmsg.dll + 2009-12-14 07:11 . 2009-12-14 07:11 33280 c:\windows\$hf_mig$\KB978037\SP3QFE\csrsrv.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB977914\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB977914\spmsg.dll + 2009-11-27 16:29 . 2009-11-27 16:29 28672 c:\windows\$hf_mig$\KB977914\SP3QFE\msvidc32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 11264 c:\windows\$hf_mig$\KB977914\SP3QFE\msrle32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 48128 c:\windows\$hf_mig$\KB977914\SP3QFE\iyuv_32.dll + 2009-11-27 16:29 . 2009-11-27 16:29 84992 c:\windows\$hf_mig$\KB977914\SP3QFE\avifil32.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB977165-v2\update\spcustom.dll + 2010-03-21 07:56 . 2010-02-24 15:25 16896 c:\windows\$hf_mig$\KB977165-v2\update\mpsyschk.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB977165-v2\spmsg.dll + 2010-03-21 09:02 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975713\update\spcustom.dll + 2010-03-21 09:02 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975713\spmsg.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB975561\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB975561\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975560\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975560\spmsg.dll + 2009-11-27 17:25 . 2009-11-27 17:25 17920 c:\windows\$hf_mig$\KB975560\SP3QFE\msyuv.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB975467\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB975467\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB975025\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB975025\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974571\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974571\spmsg.dll + 2009-09-04 21:01 . 2009-09-04 21:01 58880 c:\windows\$hf_mig$\KB974571\SP3QFE\msasn1.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974392\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974392\spmsg.dll + 2010-03-21 09:03 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974318\update\spcustom.dll + 2010-03-21 09:03 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974318\spmsg.dll + 2009-10-12 13:33 . 2009-10-12 13:33 79872 c:\windows\$hf_mig$\KB974318\SP3QFE\raschap.dll + 2010-03-21 09:00 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB974112\update\spcustom.dll + 2010-03-21 09:00 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB974112\spmsg.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973904\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973904\spmsg.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB973869\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB973869\spmsg.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973815\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973815\spmsg.dll + 2010-03-21 08:58 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB973687\update\spcustom.dll + 2010-03-21 08:58 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB973687\spmsg.dll + 2010-03-21 08:59 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973507\update\spcustom.dll + 2010-03-21 08:59 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973507\spmsg.dll + 2009-07-17 19:28 . 2009-07-17 19:28 58880 c:\windows\$hf_mig$\KB973507\SP3QFE\atl.dll + 2010-03-21 08:58 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB973354\update\spcustom.dll + 2010-03-21 08:58 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB973354\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB972270\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB972270\spmsg.dll + 2010-03-21 07:55 . 2009-10-15 16:40 81920 c:\windows\$hf_mig$\KB972270\SP3QFE\fontsub.dll + 2010-03-21 08:57 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB971961\update\spcustom.dll + 2010-03-21 08:57 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB971961\spmsg.dll + 2010-03-22 06:47 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971737\update\spcustom.dll + 2010-03-22 06:47 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971737\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971657\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971657\spmsg.dll + 2010-03-21 09:03 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB971468\update\spcustom.dll + 2010-03-21 09:03 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB971468\spmsg.dll + 2010-03-22 06:47 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB970430\update\spcustom.dll + 2010-03-22 06:47 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB970430\spmsg.dll + 2009-10-21 05:42 . 2009-10-21 05:42 75776 c:\windows\$hf_mig$\KB970430\SP3QFE\strmfilt.dll + 2009-10-21 05:42 . 2009-10-21 05:42 25088 c:\windows\$hf_mig$\KB970430\SP3QFE\httpapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB970238\update\spcustom.dll + 2010-03-21 08:58 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB970238\spmsg.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB969947\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB969947\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB969059\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB969059\spmsg.dll + 2010-03-21 08:57 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB968389\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB968389\spmsg.dll + 2009-06-25 08:42 . 2009-06-25 08:42 54272 c:\windows\$hf_mig$\KB968389\SP3QFE\wdigest.dll + 2009-06-25 08:42 . 2009-06-25 08:42 56832 c:\windows\$hf_mig$\KB968389\SP3QFE\secur32.dll + 2009-06-24 10:28 . 2009-06-24 10:28 92928 c:\windows\$hf_mig$\KB968389\SP3QFE\ksecdd.sys + 2010-03-21 08:58 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB967715\update\spcustom.dll + 2010-03-21 08:58 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB967715\spmsg.dll + 2010-03-21 08:59 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB961501\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB961501\spmsg.dll + 2010-03-21 09:04 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB960859\update\spcustom.dll + 2010-03-21 09:04 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB960859\spmsg.dll + 2009-06-15 11:14 . 2009-06-15 11:14 82944 c:\windows\$hf_mig$\KB960859\SP3QFE\tlntsess.exe + 2009-06-15 11:14 . 2009-06-15 11:14 78336 c:\windows\$hf_mig$\KB960859\SP3QFE\telnet.exe + 2010-03-21 08:57 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB960803\update\spcustom.dll + 2010-03-21 08:57 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB960803\spmsg.dll + 2010-03-21 09:02 . 2007-11-30 11:21 26488 c:\windows\$hf_mig$\KB960225\update\spcustom.dll + 2010-03-21 09:02 . 2007-11-30 11:21 19320 c:\windows\$hf_mig$\KB960225\spmsg.dll + 2010-03-21 09:04 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB959426\update\spcustom.dll + 2010-03-21 09:04 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB959426\spmsg.dll + 2009-02-04 09:17 . 2009-02-04 09:17 56832 c:\windows\$hf_mig$\KB959426\SP3QFE\secur32.dll + 2010-03-21 08:59 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB956844\update\spcustom.dll + 2010-03-21 08:59 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB956844\spmsg.dll + 2010-03-21 09:02 . 2008-07-08 13:20 26488 c:\windows\$hf_mig$\KB956744\update\spcustom.dll + 2010-03-21 09:02 . 2008-07-08 13:20 19320 c:\windows\$hf_mig$\KB956744\spmsg.dll + 2010-03-21 09:00 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB956572\update\spcustom.dll + 2010-03-21 09:00 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB956572\spmsg.dll + 2010-03-21 07:54 . 2009-02-06 10:36 35328 c:\windows\$hf_mig$\KB956572\SP3QFE\sc.exe + 2010-03-21 09:03 . 2009-05-26 11:43 26488 c:\windows\$hf_mig$\KB955759\update\spcustom.dll + 2010-03-21 09:03 . 2009-05-26 11:43 19320 c:\windows\$hf_mig$\KB955759\spmsg.dll + 2010-03-21 08:59 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB952004\update\spcustom.dll + 2010-03-21 08:59 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB952004\spmsg.dll + 2008-06-12 14:11 . 2008-06-12 14:11 91648 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxoci.dll + 2008-06-12 14:11 . 2008-06-12 14:11 66560 c:\windows\$hf_mig$\KB952004\SP3QFE\mtxclu.dll + 2008-06-12 14:11 . 2008-06-12 14:11 58880 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtclog.dll + 2010-03-21 08:58 . 2007-11-30 12:40 26488 c:\windows\$hf_mig$\KB951748\update\spcustom.dll + 2010-03-21 08:58 . 2007-11-30 12:40 19320 c:\windows\$hf_mig$\KB951748\spmsg.dll + 2010-03-21 08:57 . 2008-07-09 07:57 26488 c:\windows\$hf_mig$\KB923561\update\spcustom.dll + 2010-03-21 08:57 . 2008-07-09 07:57 19320 c:\windows\$hf_mig$\KB923561\spmsg.dll + 2010-03-21 09:04 . 2010-03-21 09:04 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll - 2010-01-20 12:03 . 2010-01-20 12:03 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2008-05-05 06:25 . 2008-05-05 06:25 3072 c:\windows\system32\xpsp4res.dll + 2001-10-26 17:29 . 2009-11-27 16:09 8704 c:\windows\system32\tsbyuv.dll - 2008-04-14 20:50 . 2008-04-14 20:50 6656 c:\windows\system32\laprxy.dll + 2008-04-14 20:50 . 2005-01-28 12:44 6656 c:\windows\system32\laprxy.dll + 2010-03-06 15:50 . 2009-04-28 20:20 9200 c:\windows\system32\drivers\cdralw2k.sys + 2010-03-06 15:50 . 2009-04-28 20:20 9072 c:\windows\system32\drivers\cdr4_xp.sys + 2009-11-27 16:09 . 2009-11-27 16:09 8704 c:\windows\system32\dllcache\tsbyuv.dll + 2010-03-06 15:53 . 2005-01-28 12:44 6656 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\laprxy.dll + 2010-03-06 15:53 . 2008-04-14 20:50 6656 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\laprxy.dll + 2009-11-27 16:09 . 2009-11-27 16:09 8704 c:\windows\Driver Cache\i386\tsbyuv.dll - 2010-01-20 12:03 . 2010-01-20 12:03 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-03-21 09:04 . 2010-03-21 09:04 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2010-01-20 12:03 . 2010-01-20 12:03 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2010-01-20 12:03 . 2010-01-20 12:03 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-03-21 09:04 . 2010-03-21 09:04 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2010-03-21 09:04 . 2010-03-21 09:04 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2010-01-20 12:03 . 2010-01-20 12:03 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll + 2010-03-21 08:58 . 2001-10-26 20:03 8192 c:\windows\$NtUninstallKB977914$\tsbyuv.dll + 2009-11-27 16:29 . 2009-11-27 16:29 8704 c:\windows\$hf_mig$\KB977914\SP3QFE\tsbyuv.dll + 2010-03-21 07:46 . 2008-05-05 06:25 3072 c:\windows\$hf_mig$\KB923561\SP3QFE\sprv0415.dll + 2010-03-21 09:04 . 2010-03-21 09:04 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2009-09-30 12:18 . 2009-06-07 14:24 180224 c:\windows\system32\xvidvfw.dll - 2009-09-30 12:18 . 2008-12-04 19:46 180224 c:\windows\system32\xvidvfw.dll + 2009-09-30 12:18 . 2009-06-07 14:16 819200 c:\windows\system32\xvidcore.dll + 2008-09-25 16:18 . 2009-08-06 18:24 209632 c:\windows\system32\wuweb.dll + 2008-09-25 16:18 . 2009-08-06 18:24 327896 c:\windows\system32\wucltui.dll + 2008-09-25 16:18 . 2009-08-06 18:23 575704 c:\windows\system32\wuapi.dll + 2005-01-28 12:44 . 2005-01-28 12:44 331264 c:\windows\system32\wpdsp.dll + 2005-01-28 12:44 . 2005-01-28 12:44 331776 c:\windows\system32\wpdmtpdr.dll + 2005-01-28 12:44 . 2005-01-28 12:44 114176 c:\windows\system32\wpdmtp.dll + 2008-04-14 20:51 . 2005-01-28 12:44 895736 c:\windows\system32\wmvdmod.dll + 2008-04-14 20:51 . 2005-01-28 12:44 940544 c:\windows\system32\wmspdmoe.dll + 2008-04-14 20:51 . 2009-04-10 00:01 413032 c:\windows\system32\wmspdmod.dll + 2008-04-14 20:51 . 2005-01-28 12:44 774904 c:\windows\system32\wmsdmod.dll + 2010-03-07 07:39 . 2008-04-14 20:51 221184 c:\windows\system32\wmpns.dll - 2008-04-14 20:51 . 2008-04-14 20:51 233472 c:\windows\system32\wmpdxm.dll + 2008-04-14 20:51 . 2009-07-12 11:21 233472 c:\windows\system32\wmpdxm.dll + 2008-04-14 20:51 . 2005-01-28 12:44 150016 c:\windows\system32\wmidx.dll + 2005-01-28 12:44 . 2005-01-28 12:44 290816 c:\windows\system32\WMDRMNet.dll + 2005-01-28 12:44 . 2005-01-28 12:44 335872 c:\windows\system32\WMDRMdev.dll + 2008-04-14 20:50 . 2007-10-20 04:01 227328 c:\windows\system32\wmasf.dll + 2008-04-14 20:50 . 2005-01-28 12:44 716288 c:\windows\system32\wmadmoe.dll + 2008-04-14 20:50 . 2005-01-28 12:44 396528 c:\windows\system32\wmadmod.dll + 2008-04-14 20:50 . 2009-06-10 06:16 132096 c:\windows\system32\wkssvc.dll - 2008-04-14 20:50 . 2008-04-14 20:50 132096 c:\windows\system32\wkssvc.dll + 2008-05-30 13:21 . 2010-01-05 09:57 832512 c:\windows\system32\wininet.dll + 2008-04-14 20:50 . 2009-08-25 09:19 354816 c:\windows\system32\winhttp.dll + 2008-05-30 13:21 . 2010-01-05 09:57 233472 c:\windows\system32\webcheck.dll - 2008-05-30 13:21 . 2008-10-16 20:33 233472 c:\windows\system32\webcheck.dll + 2008-09-25 16:17 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe + 2008-09-25 16:17 . 2009-02-09 10:53 453120 c:\windows\system32\wbem\wmiprvsd.dll + 2008-09-25 16:17 . 2009-02-09 10:53 473600 c:\windows\system32\wbem\fastprox.dll - 2008-05-30 13:20 . 2008-10-16 20:33 105984 c:\windows\system32\url.dll + 2008-05-30 13:20 . 2010-01-05 09:57 105984 c:\windows\system32\url.dll + 2008-04-14 20:50 . 2009-10-15 16:33 119808 c:\windows\system32\t2embed.dll + 2008-04-14 20:50 . 2009-08-26 08:02 247326 c:\windows\system32\strmdll.dll - 2008-04-14 20:50 . 2008-10-03 10:04 247326 c:\windows\system32\strmdll.dll - 2008-04-14 20:50 . 2008-04-14 20:50 474112 c:\windows\system32\shlwapi.dll + 2008-04-14 20:50 . 2009-12-08 09:25 474112 c:\windows\system32\shlwapi.dll + 2008-04-14 20:51 . 2009-02-09 11:25 111104 c:\windows\system32\services.exe + 2008-04-14 20:50 . 2009-06-25 08:27 147456 c:\windows\system32\schannel.dll + 2008-04-14 20:50 . 2009-02-09 10:53 401408 c:\windows\system32\rpcss.dll + 2008-04-14 20:50 . 2009-04-15 14:54 585216 c:\windows\system32\rpcrt4.dll + 2008-04-14 20:50 . 2009-10-12 13:40 150016 c:\windows\system32\rastls.dll + 2008-04-14 20:50 . 2005-01-28 12:44 221184 c:\windows\system32\qasf.dll + 2010-03-06 15:50 . 2009-04-28 20:20 436720 c:\windows\system32\pxwave.dll + 2010-03-06 15:50 . 2009-04-28 20:20 219632 c:\windows\system32\pxmas.dll + 2010-03-06 15:50 . 2009-04-28 20:20 551408 c:\windows\system32\pxdrv.dll + 2010-03-06 15:50 . 2009-04-28 20:20 129520 c:\windows\system32\pxafs.dll + 2010-03-06 15:50 . 2009-04-28 20:20 670192 c:\windows\system32\px.dll + 2001-08-17 23:30 . 2010-05-05 19:50 515952 c:\windows\system32\perfh009.dat - 2008-04-14 20:50 . 2008-04-14 20:50 285696 c:\windows\system32\pdh.dll + 2008-04-14 20:50 . 2009-03-06 14:22 285696 c:\windows\system32\pdh.dll + 2008-05-30 13:20 . 2010-01-05 09:57 102912 c:\windows\system32\occache.dll - 2008-05-30 13:20 . 2008-10-16 20:33 102912 c:\windows\system32\occache.dll + 2008-04-14 20:50 . 2009-10-13 10:34 271360 c:\windows\system32\oakley.dll - 2008-04-14 20:50 . 2008-04-14 20:50 271360 c:\windows\system32\oakley.dll + 2008-04-14 20:49 . 2009-02-09 10:53 722944 c:\windows\system32\ntdll.dll + 2008-04-14 20:50 . 2008-06-20 17:48 246784 c:\windows\system32\mswsock.dll - 2008-04-14 20:50 . 2008-04-14 20:50 246784 c:\windows\system32\mswsock.dll + 2008-04-14 20:50 . 2005-01-28 12:44 315904 c:\windows\system32\MSWMDM.dll + 2008-04-14 20:50 . 2009-08-05 09:01 205312 c:\windows\system32\mswebdvd.dll + 2008-04-14 20:50 . 2009-09-11 14:19 136192 c:\windows\system32\msv1_0.dll - 2008-05-30 13:20 . 2008-10-16 20:33 671232 c:\windows\system32\mstime.dll + 2008-05-30 13:20 . 2010-01-05 09:57 671232 c:\windows\system32\mstime.dll + 2008-04-14 20:52 . 2005-01-28 12:44 364784 c:\windows\system32\MSSCP.dll - 2008-05-30 13:20 . 2008-10-16 20:33 193024 c:\windows\system32\msrating.dll + 2008-05-30 13:20 . 2010-01-05 09:57 193024 c:\windows\system32\msrating.dll + 2008-04-14 20:50 . 2005-01-28 12:44 173568 c:\windows\system32\MsPMSP.dll - 2008-09-25 16:17 . 2008-04-14 20:51 345088 c:\windows\system32\mspaint.exe + 2008-09-25 16:17 . 2009-12-17 07:42 345088 c:\windows\system32\mspaint.exe + 2008-04-14 20:52 . 2005-01-28 12:44 142336 c:\windows\system32\msnetobj.dll + 2008-05-30 13:20 . 2010-01-05 09:57 477696 c:\windows\system32\mshtmled.dll - 2008-05-30 13:20 . 2008-10-16 20:33 477696 c:\windows\system32\mshtmled.dll + 2008-05-30 13:20 . 2010-01-05 09:57 459264 c:\windows\system32\msfeeds.dll - 2008-05-30 13:20 . 2008-10-16 20:33 459264 c:\windows\system32\msfeeds.dll - 2008-09-25 16:17 . 2008-04-14 20:50 161792 c:\windows\system32\msdtcuiu.dll + 2008-09-25 16:17 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll - 2008-09-25 16:17 . 2008-04-14 20:50 956928 c:\windows\system32\msdtctm.dll + 2008-09-25 16:17 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll + 2008-09-25 16:17 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll + 2008-04-14 20:50 . 2009-06-25 08:27 732160 c:\windows\system32\lsasrv.dll + 2008-04-14 20:50 . 2009-05-07 15:34 347648 c:\windows\system32\localspl.dll + 2008-04-14 20:50 . 2009-06-25 08:27 301568 c:\windows\system32\kerberos.dll + 2010-03-21 09:03 . 2009-03-10 21:18 455048 c:\windows\system32\KB905474\wgasetup.exe + 2008-04-14 20:50 . 2009-08-13 15:24 512000 c:\windows\system32\jscript.dll - 2008-04-14 20:50 . 2008-05-09 10:56 512000 c:\windows\system32\jscript.dll + 2008-05-30 13:20 . 2010-01-05 09:57 268288 c:\windows\system32\iertutil.dll + 2008-05-30 13:20 . 2010-01-05 09:57 192512 c:\windows\system32\iepeers.dll + 2008-05-30 13:19 . 2010-01-05 09:57 385024 c:\windows\system32\iedkcs32.dll + 2008-05-30 13:19 . 2010-01-05 09:57 380928 c:\windows\system32\ieapfltr.dll - 2008-05-30 13:19 . 2008-10-15 07:04 161792 c:\windows\system32\ieakui.dll + 2008-05-30 13:19 . 2009-12-18 13:04 161792 c:\windows\system32\ieakui.dll - 2008-05-30 13:19 . 2008-10-16 20:33 230400 c:\windows\system32\ieaksie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 230400 c:\windows\system32\ieaksie.dll + 2008-05-30 13:19 . 2010-01-05 09:57 153088 c:\windows\system32\ieakeng.dll - 2008-05-30 13:19 . 2008-10-16 20:33 153088 c:\windows\system32\ieakeng.dll - 2008-09-25 18:12 . 2010-01-20 12:09 273376 c:\windows\system32\FNTCACHE.DAT + 2008-09-25 18:12 . 2010-03-21 09:15 273376 c:\windows\system32\FNTCACHE.DAT + 2008-05-30 13:19 . 2010-01-05 09:57 133120 c:\windows\system32\extmgr.dll - 2008-05-30 13:19 . 2008-10-16 20:33 133120 c:\windows\system32\extmgr.dll + 2008-05-30 13:19 . 2010-01-05 09:57 214528 c:\windows\system32\dxtrans.dll - 2008-05-30 13:19 . 2008-10-16 20:33 214528 c:\windows\system32\dxtrans.dll - 2008-05-30 13:19 . 2008-10-16 20:33 347136 c:\windows\system32\dxtmsft.dll + 2008-05-30 13:19 . 2010-01-05 09:57 347136 c:\windows\system32\dxtmsft.dll + 2008-04-14 20:52 . 2005-01-28 12:44 502272 c:\windows\system32\drmv2clt.dll + 2008-04-14 20:52 . 2005-01-28 12:44 258296 c:\windows\system32\drmclien.dll + 2008-04-13 22:30 . 2008-06-20 11:08 225856 c:\windows\system32\drivers\tcpip6.sys + 2008-04-13 22:50 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys + 2008-04-13 22:45 . 2009-12-31 16:50 353792 c:\windows\system32\drivers\srv.sys + 2008-04-13 22:47 . 2009-12-04 18:22 455424 c:\windows\system32\drivers\mrxsmb.sys + 2008-04-13 22:23 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys - 2008-04-14 20:50 . 2008-04-14 20:50 147968 c:\windows\system32\dnsapi.dll + 2008-04-14 20:50 . 2008-06-20 17:48 147968 c:\windows\system32\dnsapi.dll + 2010-03-21 07:46 . 2008-04-21 21:16 218112 c:\windows\system32\dllcache\wordpad.exe + 2009-04-10 00:01 . 2009-04-10 00:01 413032 c:\windows\system32\dllcache\wmspdmod.dll + 2009-07-12 11:21 . 2009-07-12 11:21 233472 c:\windows\system32\dllcache\wmpdxm.dll + 2010-03-21 07:54 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe + 2010-03-21 07:54 . 2009-02-09 10:53 453120 c:\windows\system32\dllcache\wmiprvsd.dll + 2010-03-21 07:45 . 2007-10-20 04:01 227328 c:\windows\system32\dllcache\wmasf.dll + 2009-06-10 06:16 . 2009-06-10 06:16 132096 c:\windows\system32\dllcache\wkssvc.dll + 2008-08-26 08:27 . 2010-01-05 09:57 832512 c:\windows\system32\dllcache\wininet.dll + 2008-12-16 12:32 . 2009-08-25 09:19 354816 c:\windows\system32\dllcache\winhttp.dll + 2008-08-26 08:27 . 2010-01-05 09:57 233472 c:\windows\system32\dllcache\webcheck.dll - 2008-08-26 08:27 . 2008-10-16 20:33 233472 c:\windows\system32\dllcache\webcheck.dll - 2008-08-26 08:27 . 2008-10-16 20:33 105984 c:\windows\system32\dllcache\url.dll + 2008-08-26 08:27 . 2010-01-05 09:57 105984 c:\windows\system32\dllcache\url.dll + 2010-03-21 07:53 . 2009-06-21 21:48 153088 c:\windows\system32\dllcache\triedit.dll + 2010-03-21 07:45 . 2008-06-20 11:08 225856 c:\windows\system32\dllcache\tcpip6.sys + 2010-03-21 07:45 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys + 2010-03-21 07:55 . 2009-10-15 16:33 119808 c:\windows\system32\dllcache\t2embed.dll - 2008-12-09 20:53 . 2008-10-03 10:04 247326 c:\windows\system32\dllcache\strmdll.dll + 2008-12-09 20:53 . 2009-08-26 08:02 247326 c:\windows\system32\dllcache\strmdll.dll + 2008-12-02 11:26 . 2009-12-31 16:50 353792 c:\windows\system32\dllcache\srv.sys + 2009-12-08 09:25 . 2009-12-08 09:25 474112 c:\windows\system32\dllcache\shlwapi.dll + 2010-03-21 07:54 . 2009-02-09 11:25 111104 c:\windows\system32\dllcache\services.exe + 2009-06-25 08:27 . 2009-06-25 08:27 147456 c:\windows\system32\dllcache\schannel.dll + 2010-03-21 07:54 . 2009-02-09 10:53 401408 c:\windows\system32\dllcache\rpcss.dll + 2009-04-15 14:54 . 2009-04-15 14:54 585216 c:\windows\system32\dllcache\rpcrt4.dll + 2009-10-12 13:40 . 2009-10-12 13:40 150016 c:\windows\system32\dllcache\rastls.dll + 2008-04-14 20:50 . 2005-01-28 12:44 221184 c:\windows\system32\dllcache\qasf.dll + 2010-03-21 07:54 . 2009-03-06 14:22 285696 c:\windows\system32\dllcache\pdh.dll - 2008-08-26 08:27 . 2008-10-16 20:33 102912 c:\windows\system32\dllcache\occache.dll + 2008-08-26 08:27 . 2010-01-05 09:57 102912 c:\windows\system32\dllcache\occache.dll + 2009-10-13 10:34 . 2009-10-13 10:34 271360 c:\windows\system32\dllcache\oakley.dll + 2010-03-21 07:54 . 2009-02-09 10:53 722944 c:\windows\system32\dllcache\ntdll.dll + 2010-03-21 07:45 . 2008-06-20 17:48 246784 c:\windows\system32\dllcache\mswsock.dll + 2008-09-26 12:04 . 2009-08-05 09:01 205312 c:\windows\system32\dllcache\mswebdvd.dll + 2009-06-25 08:27 . 2009-09-11 14:19 136192 c:\windows\system32\dllcache\msv1_0.dll - 2008-08-26 08:27 . 2008-10-16 20:33 671232 c:\windows\system32\dllcache\mstime.dll + 2008-08-26 08:27 . 2010-01-05 09:57 671232 c:\windows\system32\dllcache\mstime.dll - 2008-08-26 08:27 . 2008-10-16 20:33 193024 c:\windows\system32\dllcache\msrating.dll + 2008-08-26 08:27 . 2010-01-05 09:57 193024 c:\windows\system32\dllcache\msrating.dll + 2009-12-17 07:42 . 2009-12-17 07:42 345088 c:\windows\system32\dllcache\mspaint.exe - 2008-08-26 08:27 . 2008-10-16 20:33 477696 c:\windows\system32\dllcache\mshtmled.dll + 2008-08-26 08:27 . 2010-01-05 09:57 477696 c:\windows\system32\dllcache\mshtmled.dll - 2008-08-26 08:26 . 2008-10-16 20:33 459264 c:\windows\system32\dllcache\msfeeds.dll + 2008-08-26 08:26 . 2010-01-05 09:57 459264 c:\windows\system32\dllcache\msfeeds.dll + 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll + 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll + 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll + 2008-12-02 10:03 . 2009-12-04 18:22 455424 c:\windows\system32\dllcache\mrxsmb.sys + 2009-06-25 08:27 . 2009-06-25 08:27 732160 c:\windows\system32\dllcache\lsasrv.dll + 2009-05-07 15:34 . 2009-05-07 15:34 347648 c:\windows\system32\dllcache\localspl.dll + 2009-06-25 08:27 . 2009-06-25 08:27 301568 c:\windows\system32\dllcache\kerberos.dll - 2008-05-09 10:56 . 2008-05-09 10:56 512000 c:\windows\system32\dllcache\jscript.dll + 2008-05-09 10:56 . 2009-08-13 15:24 512000 c:\windows\system32\dllcache\jscript.dll + 2008-08-23 05:56 . 2009-12-18 13:05 634648 c:\windows\system32\dllcache\iexplore.exe + 2008-08-26 08:26 . 2010-01-05 09:57 268288 c:\windows\system32\dllcache\iertutil.dll + 2010-01-05 09:57 . 2010-01-05 09:57 192512 c:\windows\system32\dllcache\iepeers.dll + 2008-08-26 08:26 . 2010-01-05 09:57 385024 c:\windows\system32\dllcache\iedkcs32.dll + 2008-08-26 08:26 . 2010-01-05 09:57 380928 c:\windows\system32\dllcache\ieapfltr.dll + 2008-08-23 05:54 . 2009-12-18 13:04 161792 c:\windows\system32\dllcache\ieakui.dll - 2008-08-23 05:54 . 2008-10-15 07:04 161792 c:\windows\system32\dllcache\ieakui.dll - 2008-08-26 08:26 . 2008-10-16 20:33 230400 c:\windows\system32\dllcache\ieaksie.dll + 2008-08-26 08:26 . 2010-01-05 09:57 230400 c:\windows\system32\dllcache\ieaksie.dll - 2008-08-26 08:26 . 2008-10-16 20:33 153088 c:\windows\system32\dllcache\ieakeng.dll + 2008-08-26 08:26 . 2010-01-05 09:57 153088 c:\windows\system32\dllcache\ieakeng.dll + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys + 2010-03-21 07:54 . 2009-02-09 10:53 473600 c:\windows\system32\dllcache\fastprox.dll + 2008-08-26 08:26 . 2010-01-05 09:57 133120 c:\windows\system32\dllcache\extmgr.dll - 2008-08-26 08:26 . 2008-10-16 20:33 133120 c:\windows\system32\dllcache\extmgr.dll + 2008-08-26 08:26 . 2010-01-05 09:57 214528 c:\windows\system32\dllcache\dxtrans.dll - 2008-08-26 08:26 . 2008-10-16 20:33 214528 c:\windows\system32\dllcache\dxtrans.dll - 2008-08-26 08:26 . 2008-10-16 20:33 347136 c:\windows\system32\dllcache\dxtmsft.dll + 2008-08-26 08:26 . 2010-01-05 09:57 347136 c:\windows\system32\dllcache\dxtmsft.dll + 2010-03-21 07:45 . 2008-06-20 17:48 147968 c:\windows\system32\dllcache\dnsapi.dll - 2008-08-26 08:26 . 2008-10-16 20:33 124928 c:\windows\system32\dllcache\advpack.dll + 2008-08-26 08:26 . 2010-01-05 09:57 124928 c:\windows\system32\dllcache\advpack.dll + 2010-03-21 07:54 . 2009-02-09 10:53 686592 c:\windows\system32\dllcache\advapi32.dll + 2010-03-21 08:02 . 2009-11-21 16:03 471552 c:\windows\system32\dllcache\aclayers.dll + 2004-02-22 08:11 . 2004-02-22 08:11 719872 c:\windows\system32\devil.dll + 2008-04-14 20:50 . 2005-01-28 12:44 164864 c:\windows\system32\cewmdm.dll + 2008-04-14 20:50 . 2005-01-28 12:44 294912 c:\windows\system32\blackbox.dll + 2008-12-21 21:46 . 2008-12-21 21:46 351744 c:\windows\system32\avisynth.dll - 2008-05-30 13:19 . 2008-10-16 20:33 124928 c:\windows\system32\advpack.dll + 2008-05-30 13:19 . 2010-01-05 09:57 124928 c:\windows\system32\advpack.dll + 2008-04-14 20:50 . 2009-02-09 10:53 686592 c:\windows\system32\advapi32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 686592 c:\windows\system32\advapi32.dll + 2010-03-06 15:53 . 2005-01-28 12:44 142336 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\msnetobj.dll + 2010-03-06 15:53 . 2005-01-28 12:44 502272 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmv2clt.dll + 2010-03-06 15:53 . 2005-01-28 12:44 258296 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmclien.dll + 2010-03-06 15:53 . 2005-01-28 12:44 294912 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\blackbox.dll + 2010-03-06 15:53 . 2008-04-14 20:52 259072 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\msnetobj.dll + 2010-03-06 15:53 . 2008-04-14 20:52 695808 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmv2clt.dll + 2010-03-06 15:53 . 2008-04-14 20:52 299520 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmclien.dll + 2010-03-06 15:53 . 2008-04-14 20:50 286720 c:\windows\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\blackbox.dll + 2010-03-06 15:53 . 2005-01-28 12:44 940544 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmspdmoe.dll + 2010-03-06 15:53 . 2005-01-28 12:44 150016 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmidx.dll + 2010-03-06 15:53 . 2005-01-28 12:44 290816 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMNet.dll + 2010-03-06 15:53 . 2005-01-28 12:44 335872 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMdev.dll + 2010-03-06 15:53 . 2005-01-28 12:44 224768 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmasf.dll + 2010-03-06 15:53 . 2005-01-28 12:44 716288 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmadmoe.dll + 2010-03-06 15:53 . 2005-01-28 12:44 221184 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\qasf.dll + 2010-03-06 15:53 . 2008-04-14 20:51 897024 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmspdmoe.dll + 2010-03-06 15:53 . 2008-04-14 20:51 151552 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmidx.dll + 2010-03-06 15:53 . 2008-04-14 20:50 230912 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmasf.dll + 2010-03-06 15:53 . 2008-04-14 20:50 670720 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmadmoe.dll + 2010-03-06 15:53 . 2008-04-14 20:50 237568 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\qasf.dll + 2010-03-06 15:53 . 2008-06-10 02:11 103936 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\logagent.exe + 2010-03-06 15:53 . 2005-01-28 12:44 895736 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 413944 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmspdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 774904 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmsdmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 396528 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmadmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 809984 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmvdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 485376 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmspdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:51 759296 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmsdmod.dll + 2010-03-06 15:53 . 2008-04-14 20:50 408064 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmadmod.dll + 2010-03-06 15:53 . 2005-01-28 12:44 331264 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdsp.dll + 2010-03-06 15:53 . 2005-01-28 12:44 331776 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpdr.dll + 2010-03-06 15:53 . 2005-01-28 12:44 114176 c:\windows\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtp.dll + 2010-03-06 15:53 . 2005-01-28 12:44 315904 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSWMDM.dll + 2010-03-06 15:53 . 2005-01-28 12:44 364784 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSSCP.dll + 2010-03-06 15:53 . 2005-01-28 12:44 173568 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSP.dll + 2010-03-06 15:53 . 2005-01-28 12:44 164864 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\cewmdm.dll + 2010-03-06 15:53 . 2008-04-14 20:50 246272 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSWMDM.dll + 2010-03-06 15:53 . 2008-04-14 20:52 356352 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSSCP.dll + 2010-03-06 15:53 . 2008-04-14 20:50 201728 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSP.dll + 2010-03-06 15:53 . 2008-04-14 20:50 159232 c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\cewmdm.dll + 2008-11-25 03:59 . 2008-11-25 03:59 436040 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2008-11-25 03:59 . 2008-11-25 03:59 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll - 2008-07-25 10:17 . 2008-07-25 10:17 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll + 2008-11-25 03:59 . 2008-11-25 03:59 364872 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2009-08-07 22:51 . 2009-08-07 22:51 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2008-12-13 08:58 . 2008-12-13 08:58 754688 c:\windows\Installer\47607b.msp + 2009-03-20 10:48 . 2009-03-20 10:48 183808 c:\windows\Installer\476051.msp + 2010-03-21 08:57 . 2008-10-16 20:33 826368 c:\windows\ie7updates\KB978207-IE7\wininet.dll + 2010-03-21 08:57 . 2008-10-16 20:33 233472 c:\windows\ie7updates\KB978207-IE7\webcheck.dll + 2010-03-21 08:57 . 2008-10-16 20:33 105984 c:\windows\ie7updates\KB978207-IE7\url.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\ie7updates\KB978207-IE7\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\ie7updates\KB978207-IE7\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-10-16 20:33 102912 c:\windows\ie7updates\KB978207-IE7\occache.dll + 2010-03-21 08:57 . 2008-10-16 20:33 671232 c:\windows\ie7updates\KB978207-IE7\mstime.dll + 2010-03-21 08:57 . 2008-10-16 20:33 193024 c:\windows\ie7updates\KB978207-IE7\msrating.dll + 2010-03-21 08:57 . 2008-10-16 20:33 477696 c:\windows\ie7updates\KB978207-IE7\mshtmled.dll + 2010-03-21 08:57 . 2008-10-16 20:33 459264 c:\windows\ie7updates\KB978207-IE7\msfeeds.dll + 2010-03-21 08:57 . 2008-10-15 07:06 633632 c:\windows\ie7updates\KB978207-IE7\iexplore.exe + 2010-03-21 08:57 . 2008-10-16 20:33 267776 c:\windows\ie7updates\KB978207-IE7\iertutil.dll + 2010-03-21 08:57 . 2008-05-30 13:20 191488 c:\windows\ie7updates\KB978207-IE7\iepeers.dll + 2010-03-21 08:57 . 2008-10-16 20:33 384512 c:\windows\ie7updates\KB978207-IE7\iedkcs32.dll + 2010-03-21 08:57 . 2008-10-16 20:33 383488 c:\windows\ie7updates\KB978207-IE7\ieapfltr.dll + 2010-03-21 08:57 . 2008-10-15 07:04 161792 c:\windows\ie7updates\KB978207-IE7\ieakui.dll + 2010-03-21 08:57 . 2008-10-16 20:33 230400 c:\windows\ie7updates\KB978207-IE7\ieaksie.dll + 2010-03-21 08:57 . 2008-10-16 20:33 153088 c:\windows\ie7updates\KB978207-IE7\ieakeng.dll + 2010-03-21 08:57 . 2008-10-16 20:33 133120 c:\windows\ie7updates\KB978207-IE7\extmgr.dll + 2010-03-21 08:57 . 2008-10-16 20:33 214528 c:\windows\ie7updates\KB978207-IE7\dxtrans.dll + 2010-03-21 08:57 . 2008-10-16 20:33 347136 c:\windows\ie7updates\KB978207-IE7\dxtmsft.dll + 2010-03-21 08:57 . 2008-10-16 20:33 124928 c:\windows\ie7updates\KB978207-IE7\advpack.dll + 2008-12-02 10:03 . 2009-12-04 18:22 455424 c:\windows\Driver Cache\i386\mrxsmb.sys + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys + 2010-03-21 13:31 . 2010-03-21 13:31 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\e2098e43d115155d6ba91ba3a7e577cf\WsatConfig.ni.exe + 2010-03-21 09:18 . 2010-03-21 09:18 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\bf92bc207f927cbbd6dfc9dc0c3eae68\WindowsFormsIntegration.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\6f488b7644dc50a083868e91a4014466\UIAutomationTypes.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\c2fbf25609b704061a93500efa6f241d\UIAutomationClient.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\eb23b78564687badff1bd1f1d0a0ec97\System.Xml.Linq.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\e7666364bf9f3ba5f4833c9efedd8218\System.Web.Routing.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5f1b8791e6c47e5bd5e7018c346c586\System.Web.RegularExpressions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\884eacddf339b8b342f66aedff5f8ef9\System.Web.Extensions.Design.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\9e199645bd26f1afe58ebe185d1e7f0f\System.Web.Entity.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\652017ebe962ab2eb271c2524f31cd61\System.Web.Entity.Design.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\d0070c1c1a642ae30394e00bc0d82336\System.Web.DynamicData.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\1896753d02d146be1988d32241300f51\System.Web.Abstractions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\408e637346ef628a3f54fb1b9b83ac9f\System.Transactions.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\a9e9b885a6601469c4058375cc74d856\System.Security.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9bc34a79af9c3ed2cf17a0226c769b4c\System.Runtime.Serialization.Formatters.Soap.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\5f74a84e9d28c2332c51f6e30da0e125\System.Net.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\818b20a7c6f3b2fe97bf008ca24080c1\System.Management.Instrumentation.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\6c273eb9d1ee8b66b5ecb073de4b785d\System.IO.Log.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\7222db518afb4eaaa138824278249bc7\System.IdentityModel.Selectors.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.Wrapper.dll + 2010-03-21 22:18 . 2010-03-21 22:18 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\ca6d7208c0fb72ff97429f2636ced321\System.Drawing.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c92fc19800e701c90f90ab7a2ab44c47\System.DirectoryServices.AccountManagement.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\a601f47a98ee67df424685c9a66ea449\System.DirectoryServices.Protocols.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\b91b44015859163646f210d284f7166a\System.Data.Services.Client.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1b35297e07b85071daecdb06f96750a1\System.Data.Services.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\cf906bf9146d1f0013451ec63b58e064\System.Data.Entity.Design.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4ff4134b0d490c090e03d74e104517c4\System.Data.DataSetExtensions.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\443e3a85c491b2de4a2ac654cb957484\System.Configuration.Install.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\cba35f47925431a54d0e6ae147a292f1\System.AddIn.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6af32fe5cbec0aa54e2efa6910c73651\SMSvcHost.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a23dc25782df04533a13e348203e4dc5\ServiceModelReg.ni.exe + 2010-03-21 09:17 . 2010-03-21 09:17 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\96f74da5fc40b92f09069230bc0df4f0\PresentationFramework.Royale.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bb4d16b042b72c2c85a0f8ac9d48f28\PresentationFramework.Luna.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\30c5c2682d3c5bdaa83bb9a36ee48afa\PresentationFramework.Aero.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07e952efd70f5608e221a008e6231ace\PresentationFramework.Classic.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\eade8c1c9c1e8e5ffb50e6c9b9af0f6a\MSBuild.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fc4d66e0a92b3767006a84f2519d2457\Microsoft.Transactions.Bridge.Dtc.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\58ca3ecc52b7246b448c109817198a0b\Microsoft.Build.Utilities.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4dd43724dd92026577c6f588270137a0\Microsoft.Build.Utilities.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8c651f75bb741330370986dcad8e9e5b\Microsoft.Build.Engine.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a6dcbae619ccd938bfe808c54d6d3ae0\Microsoft.Build.Conversion.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\77688ce14f221ed94a9f442ae4736123\CustomMarshalers.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\a17c65f0cffaa4f792dd38d50df9d526\ComSvcConfig.ni.exe + 2010-03-21 13:31 . 2010-03-21 13:31 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\85d7c111956b478766d90625b35d963f\AspNetMMCExt.ni.dll - 2010-01-20 12:03 . 2010-01-20 12:03 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-03-21 09:04 . 2010-03-21 09:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2010-03-21 09:04 . 2010-03-21 09:04 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2010-01-20 12:03 . 2010-01-20 12:03 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2010-01-20 12:06 . 2010-01-20 12:06 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll + 2010-03-21 09:02 . 2010-03-21 09:02 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll + 2010-03-21 09:02 . 2010-03-21 09:02 229376 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll - 2010-01-20 12:03 . 2010-01-20 12:03 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2010-03-21 09:04 . 2010-03-21 09:04 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2010-03-21 09:04 . 2010-03-21 09:04 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2010-01-20 12:03 . 2010-01-20 12:03 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2010-01-20 12:03 . 2010-01-20 12:03 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll + 2010-03-21 09:04 . 2010-03-21 09:04 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll - 2010-01-20 12:03 . 2010-01-20 12:03 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-03-21 09:04 . 2010-03-21 09:04 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2010-03-21 09:04 . 2010-03-21 09:04 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2010-01-20 12:03 . 2010-01-20 12:03 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2010-01-20 12:03 . 2010-01-20 12:03 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2010-03-21 09:04 . 2010-03-21 09:04 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2010-03-21 09:04 . 2010-03-21 09:04 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll - 2010-01-20 12:03 . 2010-01-20 12:03 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2010-03-21 09:04 . 2010-03-21 09:04 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2010-03-21 09:04 . 2010-03-21 09:04 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll - 2010-01-20 12:03 . 2010-01-20 12:03 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2010-03-21 09:02 . 2010-03-21 09:02 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll - 2010-01-20 12:06 . 2010-01-20 12:06 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll + 2010-03-21 09:02 . 2010-03-21 09:02 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll - 2010-01-20 12:06 . 2010-01-20 12:06 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll - 2010-01-20 12:03 . 2010-01-20 12:03 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2010-03-21 09:04 . 2010-03-21 09:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll - 2010-01-20 12:03 . 2010-01-20 12:03 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2010-03-21 09:04 . 2010-03-21 09:04 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll - 2010-01-20 12:03 . 2010-01-20 12:03 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2010-03-21 09:04 . 2010-03-21 09:04 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2010-01-20 12:03 . 2010-01-20 12:03 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2010-03-21 09:04 . 2010-03-21 09:04 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll - 2010-01-20 12:03 . 2010-01-20 12:03 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2010-01-20 12:03 . 2010-01-20 12:03 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2010-03-21 09:04 . 2010-03-21 09:04 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2010-01-20 12:03 . 2010-01-20 12:03 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2010-01-20 12:03 . 2010-01-20 12:03 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2010-03-21 09:04 . 2010-03-21 09:04 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll - 2010-01-20 12:03 . 2010-01-20 12:03 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2010-03-21 09:04 . 2010-03-21 09:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2010-03-21 09:04 . 2010-03-21 09:04 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll - 2010-01-20 12:03 . 2010-01-20 12:03 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2010-03-21 09:04 . 2010-03-21 09:04 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll - 2010-01-20 12:03 . 2010-01-20 12:03 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2010-03-21 09:04 . 2010-03-21 09:04 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2010-01-20 12:03 . 2010-01-20 12:03 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2010-03-21 09:04 . 2010-03-21 09:04 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2008-04-14 20:49 . 2009-11-21 16:03 471552 c:\windows\AppPatch\aclayers.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB979306$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB979306$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978706$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978706$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:51 345088 c:\windows\$NtUninstallKB978706$\mspaint.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978262$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978262$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978251$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978251$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-10-24 11:21 455296 c:\windows\$NtUninstallKB978251$\mrxsmb.sys + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB978037$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB978037$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB977914$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB977914$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB977165-v2$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB977165-v2$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975713$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975713$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 474112 c:\windows\$NtUninstallKB975713$\shlwapi.dll + 2010-03-21 08:59 . 2009-05-26 16:13 398200 c:\windows\$NtUninstallKB975561$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB975561$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975560$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975560$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975467$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB975467$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-06-25 08:27 136192 c:\windows\$NtUninstallKB975467$\msv1_0.dll + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB975025$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB975025$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974571$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974571$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974392$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974392$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 271360 c:\windows\$NtUninstallKB974392$\oakley.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974318$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974318$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 150528 c:\windows\$NtUninstallKB974318$\rastls.dll + 2010-03-21 09:00 . 2008-10-03 10:04 247326 c:\windows\$NtUninstallKB974112$\strmdll.dll + 2010-03-21 09:00 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB974112$\spuninst\updspapi.dll + 2010-03-21 09:00 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB974112$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973904$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973904$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2005-03-25 16:43 116424 c:\windows\$NtUninstallKB973904$\msconv97.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB973869$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB973869$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973815$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973815$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 204288 c:\windows\$NtUninstallKB973815$\mswebdvd.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973687$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB973687$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:51 233472 c:\windows\$NtUninstallKB973540_WM9$\wmpdxm.dll + 2010-03-21 08:58 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB973540_WM9$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-07-27 07:36 234360 c:\windows\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973507$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973507$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB973354$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB973354$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 117760 c:\windows\$NtUninstallKB972270$\t2embed.dll + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB972270$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB972270$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971961$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB971961$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-05-09 10:56 512000 c:\windows\$NtUninstallKB971961$\jscript.dll + 2010-03-22 06:47 . 2008-12-16 12:32 354304 c:\windows\$NtUninstallKB971737$\winhttp.dll + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971737$\spuninst\updspapi.dll + 2010-03-22 06:47 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971737$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-04-14 20:50 132096 c:\windows\$NtUninstallKB971657$\wkssvc.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB971657$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971657$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2008-09-08 10:41 333824 c:\windows\$NtUninstallKB971468$\srv.sys + 2010-03-21 09:03 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB971468$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB971468$\spuninst\spuninst.exe + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB970430$\spuninst\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB970430$\spuninst\spuninst.exe + 2010-03-22 06:47 . 2008-04-13 22:23 264832 c:\windows\$NtUninstallKB970430$\http.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB970238$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB970238$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 584704 c:\windows\$NtUninstallKB970238$\rpcrt4.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB969947$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB969947$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB969059$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB969059$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB968816_WM9$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-07-27 09:41 231288 c:\windows\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB968389$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB968389$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 144384 c:\windows\$NtUninstallKB968389$\schannel.dll + 2010-03-21 08:57 . 2008-04-14 20:50 132608 c:\windows\$NtUninstallKB968389$\msv1_0.dll + 2010-03-21 08:57 . 2008-04-14 20:50 730112 c:\windows\$NtUninstallKB968389$\lsasrv.dll + 2010-03-21 08:57 . 2008-04-14 20:50 299520 c:\windows\$NtUninstallKB968389$\kerberos.dll + 2010-03-21 08:58 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB967715$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB967715$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB961501$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB961501$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 345088 c:\windows\$NtUninstallKB961501$\localspl.dll + 2010-03-21 09:02 . 2007-11-30 11:21 398200 c:\windows\$NtUninstallKB961118$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$NtUninstallKB961118$\spuninst\spuninst.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB960859$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB960859$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:50 354304 c:\windows\$NtUninstallKB960803$\winhttp.dll + 2010-03-21 08:57 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB960803$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB960803$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB960225$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$NtUninstallKB960225$\spuninst\spuninst.exe + 2010-03-21 09:04 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB959426$\spuninst\updspapi.dll + 2010-03-21 09:04 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB959426$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2009-05-26 11:43 398200 c:\windows\$NtUninstallKB958869$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB958869$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 153088 c:\windows\$NtUninstallKB956844$\triedit.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB956844$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB956844$\spuninst\spuninst.exe + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$NtUninstallKB956744$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$NtUninstallKB956744$\spuninst\spuninst.exe + 2010-03-21 09:00 . 2008-04-14 20:51 218112 c:\windows\$NtUninstallKB956572$\wmiprvse.exe + 2010-03-21 09:00 . 2008-04-14 20:51 437248 c:\windows\$NtUninstallKB956572$\wmiprvsd.dll + 2010-03-21 09:00 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB956572$\spuninst\updspapi.dll + 2010-03-21 09:00 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB956572$\spuninst\spuninst.exe + 2010-03-21 09:00 . 2008-04-14 20:51 109056 c:\windows\$NtUninstallKB956572$\services.exe + 2010-03-21 09:00 . 2008-04-14 20:50 399360 c:\windows\$NtUninstallKB956572$\rpcss.dll + 2010-03-21 09:00 . 2008-04-14 20:50 285696 c:\windows\$NtUninstallKB956572$\pdh.dll + 2010-03-21 09:00 . 2008-04-14 20:49 714240 c:\windows\$NtUninstallKB956572$\ntdll.dll + 2010-03-21 09:00 . 2008-04-14 20:50 472064 c:\windows\$NtUninstallKB956572$\fastprox.dll + 2010-03-21 09:00 . 2008-04-14 20:50 686592 c:\windows\$NtUninstallKB956572$\advapi32.dll + 2010-03-21 09:03 . 2009-05-26 16:13 398200 c:\windows\$NtUninstallKB955759$\spuninst\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$NtUninstallKB955759$\spuninst\spuninst.exe + 2010-03-21 09:03 . 2008-04-14 20:49 451072 c:\windows\$NtUninstallKB955759$\aclayers.dll + 2010-03-21 09:02 . 2005-01-28 12:44 413944 c:\windows\$NtUninstallKB954155_WM9$\wmspdmod.dll + 2010-03-21 09:02 . 2007-07-27 09:41 382840 c:\windows\$NtUninstallKB954155_WM9$\spuninst\updspapi.dll + 2010-03-21 09:02 . 2007-07-27 07:36 234360 c:\windows\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB952004$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB952004$\spuninst\spuninst.exe + 2010-03-21 08:59 . 2008-04-14 20:50 161792 c:\windows\$NtUninstallKB952004$\msdtcuiu.dll + 2010-03-21 08:59 . 2008-04-14 20:50 956928 c:\windows\$NtUninstallKB952004$\msdtctm.dll + 2010-03-21 08:59 . 2008-04-14 20:50 427008 c:\windows\$NtUninstallKB952004$\msdtcprx.dll + 2010-03-21 08:58 . 2008-04-13 22:30 225664 c:\windows\$NtUninstallKB951748$\tcpip6.sys + 2010-03-21 08:58 . 2008-04-13 22:50 361344 c:\windows\$NtUninstallKB951748$\tcpip.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$NtUninstallKB951748$\spuninst\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$NtUninstallKB951748$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2008-04-14 20:50 246784 c:\windows\$NtUninstallKB951748$\mswsock.dll + 2010-03-21 08:58 . 2008-04-14 20:50 147968 c:\windows\$NtUninstallKB951748$\dnsapi.dll + 2010-03-21 08:59 . 2005-01-28 12:44 224768 c:\windows\$NtUninstallKB941569$\wmasf.dll + 2010-03-21 08:59 . 2005-06-28 08:23 371424 c:\windows\$NtUninstallKB941569$\spuninst\updspapi.dll + 2010-03-21 08:59 . 2005-06-28 08:23 216288 c:\windows\$NtUninstallKB941569$\spuninst\spuninst.exe + 2010-03-21 08:57 . 2008-04-14 20:51 217088 c:\windows\$NtUninstallKB923561$\wordpad.exe + 2010-03-21 08:57 . 2008-07-09 07:57 398200 c:\windows\$NtUninstallKB923561$\spuninst\updspapi.dll + 2010-03-21 08:57 . 2008-07-09 07:57 234360 c:\windows\$NtUninstallKB923561$\spuninst\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978706\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978706\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978706\spuninst.exe + 2009-12-17 07:39 . 2009-12-17 07:39 345088 c:\windows\$hf_mig$\KB978706\SP3QFE\mspaint.exe + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978262\update\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978262\update\update.exe + 2010-03-21 09:04 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978262\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978251\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978251\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978251\spuninst.exe + 2010-03-21 07:53 . 2009-12-04 17:25 456832 c:\windows\$hf_mig$\KB978251\SP3QFE\mrxsmb.sys + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978207-IE7\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978207-IE7\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978207-IE7\spuninst.exe + 2010-01-05 09:49 . 2010-01-05 09:49 841216 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\wininet.dll + 2010-01-05 09:49 . 2010-01-05 09:49 233472 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\webcheck.dll + 2010-01-05 09:49 . 2010-01-05 09:49 105984 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\url.dll + 2010-01-05 09:49 . 2010-01-05 09:49 102912 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\occache.dll + 2010-01-05 09:49 . 2010-01-05 09:49 671232 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mstime.dll + 2010-01-05 09:49 . 2010-01-05 09:49 193024 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msrating.dll + 2010-01-05 09:49 . 2010-01-05 09:49 477696 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtmled.dll + 2010-01-05 09:49 . 2010-01-05 09:49 459264 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\msfeeds.dll + 2009-12-18 07:00 . 2009-12-18 07:00 634632 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe + 2010-01-05 09:49 . 2010-01-05 09:49 268288 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iertutil.dll + 2010-01-05 09:49 . 2010-01-05 09:49 193024 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iepeers.dll + 2010-01-05 09:49 . 2010-01-05 09:49 388608 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iedkcs32.dll + 2010-01-05 09:49 . 2010-01-05 09:49 380928 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieapfltr.dll + 2009-12-18 06:58 . 2009-12-18 06:58 161792 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieakui.dll + 2010-01-05 09:49 . 2010-01-05 09:49 230400 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieaksie.dll + 2010-01-05 09:49 . 2010-01-05 09:49 153088 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieakeng.dll + 2010-01-05 09:49 . 2010-01-05 09:49 132608 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\extmgr.dll + 2010-01-05 09:49 . 2010-01-05 09:49 214528 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\dxtrans.dll + 2010-01-05 09:49 . 2010-01-05 09:49 347136 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\dxtmsft.dll + 2010-01-05 09:49 . 2010-01-05 09:49 124928 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\advpack.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB978037\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB978037\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB978037\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB977914\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB977914\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB977914\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB977165-v2\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB977165-v2\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB977165-v2\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975713\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975713\update\update.exe + 2010-03-21 09:02 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975713\spuninst.exe + 2009-12-08 09:03 . 2009-12-08 09:03 474112 c:\windows\$hf_mig$\KB975713\SP3QFE\shlwapi.dll + 2010-03-21 08:59 . 2009-05-26 16:13 398200 c:\windows\$hf_mig$\KB975561\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975561\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB975561\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975560\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975560\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975560\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975467\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975467\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB975467\spuninst.exe + 2009-09-11 14:15 . 2009-09-11 14:15 136704 c:\windows\$hf_mig$\KB975467\SP3QFE\msv1_0.dll + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB975025\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB975025\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB975025\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974571\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974571\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974571\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974392\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974392\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974392\spuninst.exe + 2009-10-13 10:39 . 2009-10-13 10:39 271360 c:\windows\$hf_mig$\KB974392\SP3QFE\oakley.dll + 2010-03-21 09:03 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974318\update\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974318\update\update.exe + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974318\spuninst.exe + 2009-10-12 13:33 . 2009-10-12 13:33 150528 c:\windows\$hf_mig$\KB974318\SP3QFE\rastls.dll + 2010-03-21 09:00 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB974112\update\updspapi.dll + 2010-03-21 09:00 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB974112\update\update.exe + 2010-03-21 09:00 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB974112\spuninst.exe + 2009-08-26 08:03 . 2009-08-26 08:03 247326 c:\windows\$hf_mig$\KB974112\SP3QFE\strmdll.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973904\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973904\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973904\spuninst.exe + 2010-03-21 07:52 . 2009-07-29 14:01 119648 c:\windows\$hf_mig$\KB973904\SP3QFE\msconv97.dll + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB973869\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB973869\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB973869\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973815\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973815\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973815\spuninst.exe + 2009-08-05 08:53 . 2009-08-05 08:53 205312 c:\windows\$hf_mig$\KB973815\SP3QFE\mswebdvd.dll + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973687\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973687\update\update.exe + 2010-03-21 08:58 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB973687\spuninst.exe + 2010-03-21 08:59 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973507\update\updspapi.dll + 2010-03-21 08:59 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973507\update\update.exe + 2010-03-21 08:59 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973507\spuninst.exe + 2010-03-21 08:58 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB973354\update\updspapi.dll + 2010-03-21 08:58 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB973354\update\update.exe + 2010-03-21 08:58 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB973354\spuninst.exe + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB972270\update\updspapi.dll + 2010-03-21 09:02 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB972270\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB972270\spuninst.exe + 2010-03-21 07:55 . 2009-10-15 16:40 119808 c:\windows\$hf_mig$\KB972270\SP3QFE\t2embed.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971961\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971961\update\update.exe + 2010-03-21 08:57 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB971961\spuninst.exe + 2010-03-21 07:46 . 2009-08-13 15:04 512000 c:\windows\$hf_mig$\KB971961\SP3QFE\jscript.dll + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971737\update\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971737\update\update.exe + 2010-03-22 06:47 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971737\spuninst.exe + 2009-08-25 09:31 . 2009-08-25 09:31 354816 c:\windows\$hf_mig$\KB971737\SP3QFE\winhttp.dll + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB971657\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB971657\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971657\spuninst.exe + 2009-06-10 06:20 . 2009-06-10 06:20 134144 c:\windows\$hf_mig$\KB971657\SP3QFE\wkssvc.dll + 2010-03-21 09:03 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB971468\update\updspapi.dll + 2010-03-21 09:03 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB971468\update\update.exe + 2010-03-21 09:03 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB971468\spuninst.exe + 2010-03-21 08:02 . 2010-01-01 07:58 353792 c:\windows\$hf_mig$\KB971468\SP3QFE\srv.sys + 2010-03-22 06:47 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB970430\update\updspapi.dll + 2010-03-22 06:47 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB970430\update\update.exe + 2010-03-22 06:47 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB970430\spuninst.exe + 2009-10-20 15:21 . 2009-10-20 15:21 265728 c:\windows\$hf_mig$\KB970430\SP3QFE\http.sys + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB970238\update\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB970238\update\update.exe + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB970238\spuninst.exe + 2009-04-15 15:26 . 2009-04-15 15:26 585216 c:\windows\$hf_mig$\KB970238\SP3QFE\rpcrt4.dll + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB969947\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB969947\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB969947\spuninst.exe + 2010-03-21 09:02 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB969059\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB969059\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB969059\spuninst.exe + 2010-03-21 08:57 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB968389\update\updspapi.dll + 2010-03-21 08:57 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB968389\update\update.exe + 2010-03-21 08:57 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB968389\spuninst.exe + 2009-06-25 08:42 . 2009-06-25 08:42 147456 c:\windows\$hf_mig$\KB968389\SP3QFE\schannel.dll + 2009-06-25 08:42 . 2009-06-25 08:42 136704 c:\windows\$hf_mig$\KB968389\SP3QFE\msv1_0.dll + 2009-06-26 09:42 . 2009-06-26 09:42 732160 c:\windows\$hf_mig$\KB968389\SP3QFE\lsasrv.dll + 2009-06-25 08:42 . 2009-06-25 08:42 301568 c:\windows\$hf_mig$\KB968389\SP3QFE\kerberos.dll + 2010-03-21 08:58 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB967715\update\updspapi.dll + 2010-03-21 08:58 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB967715\update\update.exe + 2010-03-21 08:58 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB967715\spuninst.exe + 2010-03-21 08:59 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB961501\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB961501\update\update.exe + 2010-03-21 08:59 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB961501\spuninst.exe + 2009-05-07 15:16 . 2009-05-07 15:16 348160 c:\windows\$hf_mig$\KB961501\SP3QFE\localspl.dll + 2010-03-21 09:04 . 2009-05-26 11:43 398200 c:\windows\$hf_mig$\KB960859\update\updspapi.dll + 2010-03-21 09:04 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB960859\update\update.exe + 2010-03-21 09:04 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB960859\spuninst.exe + 2010-03-21 08:57 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB960803\update\updspapi.dll + 2010-03-21 08:57 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB960803\update\update.exe + 2010-03-21 08:57 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB960803\spuninst.exe + 2008-12-16 12:23 . 2008-12-16 12:23 354304 c:\windows\$hf_mig$\KB960803\SP3QFE\winhttp.dll + 2010-03-21 09:02 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB960225\update\updspapi.dll + 2010-03-21 09:02 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB960225\update\update.exe + 2010-03-21 09:02 . 2007-11-30 11:21 234360 c:\windows\$hf_mig$\KB960225\spuninst.exe + 2008-12-05 07:01 . 2008-12-05 07:01 144896 c:\windows\$hf_mig$\KB960225\SP3QFE\schannel.dll + 2010-03-21 09:04 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB959426\update\updspapi.dll + 2010-03-21 09:04 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB959426\update\update.exe + 2010-03-21 09:04 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB959426\spuninst.exe + 2010-03-21 08:59 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB956844\update\updspapi.dll + 2010-03-21 08:59 . 2008-07-08 13:20 763256 c:\windows\$hf_mig$\KB956844\update\update.exe + 2010-03-21 08:59 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB956844\spuninst.exe + 2010-03-21 07:53 . 2009-06-21 21:50 153088 c:\windows\$hf_mig$\KB956844\SP3QFE\triedit.dll + 2010-03-21 09:02 . 2008-07-08 13:20 398200 c:\windows\$hf_mig$\KB956744\update\updspapi.dll + 2010-03-21 09:02 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB956744\update\update.exe + 2010-03-21 09:02 . 2008-07-08 13:20 234360 c:\windows\$hf_mig$\KB956744\spuninst.exe + 2010-03-21 09:00 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB956572\update\updspapi.dll + 2010-03-21 09:00 . 2008-07-09 07:57 763256 c:\windows\$hf_mig$\KB956572\update\update.exe + 2010-03-21 09:00 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB956572\spuninst.exe + 2010-03-21 07:54 . 2009-02-06 10:15 227840 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe + 2010-03-21 07:54 . 2009-02-09 11:00 453120 c:\windows\$hf_mig$\KB956572\SP3QFE\wmiprvsd.dll + 2010-03-21 07:54 . 2009-02-09 11:19 111104 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe + 2010-03-21 07:54 . 2009-02-09 11:00 401408 c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll + 2010-03-21 07:54 . 2009-03-06 13:51 285696 c:\windows\$hf_mig$\KB956572\SP3QFE\pdh.dll + 2010-03-21 07:54 . 2009-02-09 11:00 723456 c:\windows\$hf_mig$\KB956572\SP3QFE\ntdll.dll + 2010-03-21 07:54 . 2009-02-09 11:00 731136 c:\windows\$hf_mig$\KB956572\SP3QFE\lsasrv.dll + 2010-03-21 07:54 . 2009-02-09 11:00 473600 c:\windows\$hf_mig$\KB956572\SP3QFE\fastprox.dll + 2009-02-10 18:30 . 2009-02-10 18:30 686592 c:\windows\$hf_mig$\KB956572\SP3QFE\advapi32.dll + 2010-03-21 09:03 . 2009-05-26 16:13 398200 c:\windows\$hf_mig$\KB955759\update\updspapi.dll + 2010-03-21 09:03 . 2009-05-26 11:43 763256 c:\windows\$hf_mig$\KB955759\update\update.exe + 2010-03-21 09:03 . 2009-05-26 11:43 234360 c:\windows\$hf_mig$\KB955759\spuninst.exe + 2010-03-21 08:02 . 2009-11-21 15:50 471552 c:\windows\$hf_mig$\KB955759\SP3QFE\aclayers.dll + 2010-03-21 08:59 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB952004\update\updspapi.dll + 2010-03-21 08:59 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB952004\update\update.exe + 2010-03-21 08:59 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB952004\spuninst.exe + 2008-06-12 14:11 . 2008-06-12 14:11 161792 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcuiu.dll + 2008-06-12 14:11 . 2008-06-12 14:11 956928 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtctm.dll + 2008-06-12 14:11 . 2008-06-12 14:11 428032 c:\windows\$hf_mig$\KB952004\SP3QFE\msdtcprx.dll + 2010-03-21 08:58 . 2007-11-30 12:40 398200 c:\windows\$hf_mig$\KB951748\update\updspapi.dll + 2010-03-21 08:58 . 2007-11-30 12:40 763256 c:\windows\$hf_mig$\KB951748\update\update.exe + 2010-03-21 08:58 . 2007-11-30 12:40 234360 c:\windows\$hf_mig$\KB951748\spuninst.exe + 2010-03-21 07:45 . 2008-06-20 11:16 225856 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys + 2010-03-21 07:45 . 2008-06-20 11:59 361600 c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys + 2010-03-21 07:45 . 2008-06-20 17:44 246784 c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll + 2010-03-21 07:45 . 2008-06-20 17:44 147968 c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll + 2010-03-21 07:45 . 2008-06-20 11:48 138496 c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys + 2010-03-21 08:57 . 2008-07-09 07:57 398200 c:\windows\$hf_mig$\KB923561\update\updspapi.dll + 2010-03-21 08:57 . 2008-11-15 17:19 763256 c:\windows\$hf_mig$\KB923561\update\update.exe + 2010-03-21 08:57 . 2008-07-09 07:57 234360 c:\windows\$hf_mig$\KB923561\spuninst.exe + 2010-03-21 07:46 . 2008-04-21 21:12 218112 c:\windows\$hf_mig$\KB923561\SP3QFE\wordpad.exe + 2010-03-21 08:02 . 2009-08-13 13:56 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll + 2008-09-25 16:18 . 2009-08-06 18:23 1929952 c:\windows\system32\wuaueng.dll + 2008-04-14 20:51 . 2005-01-28 12:44 1003008 c:\windows\system32\wmvdmoe2.dll + 2008-04-14 20:52 . 2009-05-20 11:24 2373504 c:\windows\system32\WMVCore.dll + 2005-01-28 12:44 . 2005-01-28 12:44 1512448 c:\windows\system32\WMVADVE.DLL + 2005-01-28 12:44 . 2005-01-28 12:44 1218808 c:\windows\system32\wmvadvd.dll + 2008-04-14 20:51 . 2005-01-28 12:44 1119744 c:\windows\system32\wmsdmoe2.dll - 2008-04-14 20:51 . 2008-04-14 20:51 1119744 c:\windows\system32\wmsdmoe2.dll - 2008-04-14 20:51 . 2008-04-14 20:51 4874240 c:\windows\system32\wmp.dll + 2008-04-14 20:51 . 2009-07-12 11:21 4874240 c:\windows\system32\wmp.dll + 2008-04-14 20:51 . 2008-06-10 05:28 1028096 c:\windows\system32\WMNetmgr.dll + 2008-04-14 19:35 . 2009-08-14 15:15 1850880 c:\windows\system32\win32k.sys + 2008-05-30 13:20 . 2010-01-05 09:57 1168384 c:\windows\system32\urlmon.dll - 2008-04-14 20:50 . 2008-04-14 20:50 8489984 c:\windows\system32\shell32.dll + 2008-04-14 20:50 . 2008-06-17 19:03 8489984 c:\windows\system32\shell32.dll - 2008-04-14 20:50 . 2008-04-14 20:50 1439744 c:\windows\system32\query.dll + 2008-04-14 20:50 . 2009-07-17 16:17 1439744 c:\windows\system32\query.dll + 2008-04-14 20:50 . 2009-11-27 17:14 1295360 c:\windows\system32\quartz.dll + 2010-03-06 15:50 . 2009-04-28 20:20 1858032 c:\windows\system32\pxsfs.dll - 2008-04-14 19:59 . 2008-08-14 13:26 2146816 c:\windows\system32\ntoskrnl.exe + 2008-04-14 19:59 . 2009-12-09 10:11 2146816 c:\windows\system32\ntoskrnl.exe + 2008-04-14 21:59 . 2009-12-09 10:11 2025472 c:\windows\system32\ntkrnlpa.exe - 2008-04-14 21:59 . 2008-08-14 13:26 2025472 c:\windows\system32\ntkrnlpa.exe + 2008-04-14 20:50 . 2009-07-31 09:05 1372672 c:\windows\system32\msxml6.dll + 2008-04-14 20:50 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll + 2008-09-25 16:17 . 2009-06-10 08:22 2066432 c:\windows\system32\mstscax.dll + 2008-05-30 13:20 . 2010-01-05 09:57 3599360 c:\windows\system32\mshtml.dll - 2008-04-14 20:50 . 2008-04-14 20:50 1018368 c:\windows\system32\kernel32.dll + 2008-04-14 20:50 . 2009-03-21 14:08 1018368 c:\windows\system32\kernel32.dll + 2010-03-21 09:03 . 2009-03-10 21:26 1436544 c:\windows\system32\KB905474\wganotifypackageinner.exe + 2008-05-30 13:20 . 2010-01-05 09:57 6067200 c:\windows\system32\ieframe.dll + 2008-05-30 13:19 . 2009-06-29 08:33 2452872 c:\windows\system32\ieapfltr.dat + 2008-04-14 20:52 . 2009-05-20 11:24 2373504 c:\windows\system32\dllcache\WMVCore.dll + 2009-07-12 11:21 . 2009-07-12 11:21 4874240 c:\windows\system32\dllcache\wmp.dll + 2008-04-14 20:51 . 2008-06-10 05:28 1028096 c:\windows\system32\dllcache\WMNetmgr.dll + 2008-12-02 11:24 . 2009-08-14 15:15 1850880 c:\windows\system32\dllcache\win32k.sys + 2008-08-26 08:27 . 2010-01-05 09:57 1168384 c:\windows\system32\dllcache\urlmon.dll + 2008-06-17 19:03 . 2008-06-17 19:03 8489984 c:\windows\system32\dllcache\shell32.dll + 2009-07-17 16:17 . 2009-07-17 16:17 1439744 c:\windows\system32\dllcache\query.dll + 2008-09-26 12:04 . 2009-11-27 17:14 1295360 c:\windows\system32\dllcache\quartz.dll + 2008-12-02 10:05 . 2009-12-09 10:11 2190464 c:\windows\system32\dllcache\ntoskrnl.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2190464 c:\windows\system32\dllcache\ntoskrnl.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2025472 c:\windows\system32\dllcache\ntkrpamp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2025472 c:\windows\system32\dllcache\ntkrpamp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2067328 c:\windows\system32\dllcache\ntkrnlpa.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2067328 c:\windows\system32\dllcache\ntkrnlpa.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2146816 c:\windows\system32\dllcache\ntkrnlmp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2146816 c:\windows\system32\dllcache\ntkrnlmp.exe + 2008-09-10 01:15 . 2009-07-31 09:05 1372672 c:\windows\system32\dllcache\msxml6.dll + 2008-12-02 10:01 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll + 2009-06-10 08:22 . 2009-06-10 08:22 2066432 c:\windows\system32\dllcache\mstscax.dll + 2010-03-21 07:52 . 2009-07-10 13:31 1315328 c:\windows\system32\dllcache\msoe.dll + 2008-08-27 09:27 . 2010-01-05 09:57 3599360 c:\windows\system32\dllcache\mshtml.dll + 2010-03-21 07:53 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe + 2009-03-21 14:08 . 2009-03-21 14:08 1018368 c:\windows\system32\dllcache\kernel32.dll + 2008-10-03 17:26 . 2010-01-05 09:57 6067200 c:\windows\system32\dllcache\ieframe.dll + 2007-04-17 09:32 . 2009-06-29 08:33 2452872 c:\windows\system32\dllcache\ieapfltr.dat + 2010-03-06 15:53 . 2005-01-28 12:44 1003008 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvdmoe2.dll + 2010-03-06 15:53 . 2005-01-28 12:44 2370296 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvcore.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1512448 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMVADVE.DLL + 2010-03-06 15:53 . 2005-01-28 12:44 1119744 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmsdmoe2.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1027072 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmnetmgr.dll + 2010-03-06 15:53 . 2008-04-14 20:51 1001472 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvdmoe2.dll + 2010-03-06 15:53 . 2008-11-07 15:45 2174976 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvcore.dll + 2010-03-06 15:53 . 2008-04-14 20:51 1119744 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmsdmoe2.dll + 2010-03-06 15:53 . 2008-06-10 05:11 1053696 c:\windows\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmnetmgr.dll + 2010-03-06 15:53 . 2005-01-28 12:44 1218808 c:\windows\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvadvd.dll + 2008-12-05 18:35 . 2008-12-05 18:35 1736528 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll - 2008-07-29 18:16 . 2008-07-29 18:16 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll + 2008-12-05 19:12 . 2008-12-05 19:12 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll + 2008-11-25 03:59 . 2008-11-25 03:59 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll - 2008-07-25 10:17 . 2008-07-25 10:17 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll + 2008-11-25 03:59 . 2008-11-25 03:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2009-08-07 22:51 . 2009-08-07 22:51 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - 2008-07-25 10:17 . 2008-07-25 10:17 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2009-08-07 22:51 . 2009-08-07 22:51 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2008-12-13 08:57 . 2008-12-13 08:57 8397824 c:\windows\Installer\476062.msp + 2010-03-21 08:57 . 2008-10-16 20:33 1160192 c:\windows\ie7updates\KB978207-IE7\urlmon.dll + 2010-03-21 08:57 . 2008-10-17 01:03 3593216 c:\windows\ie7updates\KB978207-IE7\mshtml.dll + 2010-03-21 08:57 . 2008-10-16 20:33 6066176 c:\windows\ie7updates\KB978207-IE7\ieframe.dll + 2010-03-21 08:57 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB978207-IE7\ieapfltr.dat - 2008-12-02 10:05 . 2008-08-14 13:26 2190464 c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2190464 c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2025472 c:\windows\Driver Cache\i386\ntkrpamp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2025472 c:\windows\Driver Cache\i386\ntkrpamp.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2067328 c:\windows\Driver Cache\i386\ntkrnlpa.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2067328 c:\windows\Driver Cache\i386\ntkrnlpa.exe - 2008-12-02 10:05 . 2008-08-14 13:26 2146816 c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2008-12-02 10:05 . 2009-12-09 10:11 2146816 c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2010-03-21 09:16 . 2010-03-21 09:16 3313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\204d6e5b335134f23ca37638b9227ecf\WindowsBase.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\0f2ed6a204eb13841e99b77025464afc\UIAutomationClientsideProviders.ni.dll + 2010-03-21 09:15 . 2010-03-21 09:15 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\3de5bd01124463d7862bd173af90bc83\System.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5913d3f81e77194ec833991b1047a532\System.Xml.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\fa48917b13629d8effa80dd4a2f2973d\System.WorkflowServices.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6fe66ee6f3c81996bc148f1ebe7ec030\System.Workflow.Runtime.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\9d0b61f2f1ebdc300bd970f594c422ef\System.Workflow.ComponentModel.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\65328898148a720d394f802f192fc2a0\System.Workflow.Activities.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\ea07ac791bb5cb9f83679e3dd1a0c0cc\System.Web.Services.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\29e2f8b1fb691ced973acf49fcee6ec1\System.Web.Mobile.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\981dea02bc63c0c083e335adf9018788\System.Web.Extensions.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\99594bae1d022502925f5b9dfcdaae9a\System.Speech.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\67ad55827f2542552b576170f0a7dc56\System.Runtime.Serialization.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\e5313735a40c0800f116e27fba4754db\System.Printing.ni.dll + 2010-03-21 13:30 . 2010-03-21 13:30 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c3b18fef5c6dc3bcdbe5df699fd21a55\System.IdentityModel.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\abb2ac7e08bee026f857d8fa36f9fe6f\System.Drawing.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f47ebb9db460874b1bcbfc391dc970b1\System.DirectoryServices.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c94a427baa7683f4221b91f90c18461b\System.Deployment.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\694c07365e0fd6bba0bc304d4d2404a7\System.Data.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\272152f0cc139490729e215611a4b244\System.Data.SqlXml.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\112a48e34620a0210eb850040da8a31b\System.Data.Services.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\32788c58ff9f8324460604cf1fe7681b\System.Data.Linq.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\9012cac7819660f61f1c69cf8e4f2ccf\System.Data.Entity.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\c0a42d2ad8a4078040b334f6770ea11f\System.Core.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\954685c29689d2a6126ceca1fd55e904\ReachFramework.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\a3a6f52ce1d09a7bdccc8e7fc664792d\PresentationUI.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\f906701365083c1473db31519147e263\PresentationBuildTasks.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6eee9b772b6d12d3dbd82f118c2ab2e5\Microsoft.VisualBasic.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f19e9b439636d0744597fff1331cad04\Microsoft.Transactions.Bridge.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\5b1af7b5be24c7ace065fe1c81c2b650\Microsoft.JScript.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9eec1cc7ac37e0c7f3205e8156149c5a\Microsoft.Build.Tasks.ni.dll + 2010-03-21 22:18 . 2010-03-21 22:18 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\28c0730288453d57d5dcd62903c4d31b\Microsoft.Build.Tasks.v3.5.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5dd4f58999eed37c12aee7ea9f9863ac\Microsoft.Build.Engine.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll - 2010-01-20 12:03 . 2010-01-20 12:03 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2010-03-21 09:04 . 2010-03-21 09:04 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll - 2010-01-20 12:03 . 2010-01-20 12:03 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2010-01-20 12:03 . 2010-01-20 12:03 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2010-01-20 12:06 . 2010-01-20 12:06 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll + 2010-03-21 09:02 . 2010-03-21 09:02 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll + 2010-03-21 09:01 . 2010-03-21 09:01 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll - 2010-01-20 12:05 . 2010-01-20 12:05 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll - 2010-01-20 12:03 . 2010-01-20 12:03 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll - 2010-01-20 12:05 . 2010-01-20 12:05 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll + 2010-03-21 09:01 . 2010-03-21 09:01 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll + 2010-03-21 09:04 . 2010-03-21 09:04 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2010-01-20 12:03 . 2010-01-20 12:03 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2010-03-21 09:04 . 2010-03-21 09:04 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll - 2010-01-20 12:03 . 2010-01-20 12:03 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2010-03-21 09:02 . 2009-02-09 11:26 2146816 c:\windows\$NtUninstallKB977165-v2$\ntoskrnl.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2025472 c:\windows\$NtUninstallKB977165-v2$\ntkrpamp.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2025472 c:\windows\$NtUninstallKB977165-v2$\ntkrnlpa.exe + 2010-03-21 09:02 . 2009-02-09 11:26 2146816 c:\windows\$NtUninstallKB977165-v2$\ntkrnlmp.exe + 2010-03-21 08:59 . 2008-04-14 20:51 3558912 c:\windows\$NtUninstallKB975561$\moviemk.exe + 2010-03-21 08:59 . 2008-05-07 05:12 1291776 c:\windows\$NtUninstallKB975560$\quartz.dll + 2010-03-21 08:58 . 2008-09-10 01:15 1307648 c:\windows\$NtUninstallKB973687$\msxml6.dll + 2010-03-21 08:58 . 2008-09-04 17:17 1106944 c:\windows\$NtUninstallKB973687$\msxml3.dll + 2010-03-21 08:58 . 2008-04-14 20:51 4874240 c:\windows\$NtUninstallKB973540_WM9$\wmp.dll + 2010-03-21 08:58 . 2008-04-14 20:50 1314816 c:\windows\$NtUninstallKB973354$\msoe.dll + 2010-03-21 08:57 . 2008-09-15 15:27 1846656 c:\windows\$NtUninstallKB969947$\win32k.sys + 2010-03-21 09:02 . 2008-04-14 20:50 1439744 c:\windows\$NtUninstallKB969059$\query.dll + 2010-03-21 09:02 . 2008-06-10 06:07 2376760 c:\windows\$NtUninstallKB968816_WM9$\wmvcore.dll + 2010-03-21 08:58 . 2008-04-14 20:50 8489984 c:\windows\$NtUninstallKB967715$\shell32.dll + 2010-03-21 09:04 . 2008-04-14 20:50 1018368 c:\windows\$NtUninstallKB959426$\kernel32.dll + 2010-03-21 09:02 . 2008-04-14 20:50 2061824 c:\windows\$NtUninstallKB956744$\mstscax.dll + 2010-03-21 09:00 . 2008-08-14 13:26 2146816 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2025472 c:\windows\$NtUninstallKB956572$\ntkrpamp.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2025472 c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe + 2010-03-21 09:00 . 2008-08-14 13:26 2146816 c:\windows\$NtUninstallKB956572$\ntkrnlmp.exe + 2010-01-05 09:49 . 2010-01-05 09:49 1170944 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\urlmon.dll + 2010-01-05 09:49 . 2010-01-05 09:49 3602944 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtml.dll + 2010-01-05 09:49 . 2010-01-05 09:49 6071296 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieframe.dll + 2009-06-29 07:24 . 2009-06-29 07:24 2452872 c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\ieapfltr.dat + 2009-12-10 04:04 . 2009-12-10 04:04 2190592 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntoskrnl.exe + 2010-03-21 07:56 . 2009-12-09 10:03 2025472 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrpamp.exe + 2009-12-10 04:04 . 2009-12-10 04:04 2067456 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlpa.exe + 2010-03-21 07:56 . 2009-12-09 10:03 2146816 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlmp.exe + 2010-03-21 07:53 . 2009-10-23 14:53 3558912 c:\windows\$hf_mig$\KB975561\SP3QFE\moviemk.exe + 2009-11-27 17:25 . 2009-11-27 17:25 1295360 c:\windows\$hf_mig$\KB975560\SP3QFE\quartz.dll + 2010-03-21 07:52 . 2009-07-31 04:30 1447424 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml6.dll + 2010-03-21 07:52 . 2009-07-31 04:30 1172480 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml3.dll + 2009-07-10 17:55 . 2009-07-10 17:55 1315328 c:\windows\$hf_mig$\KB973354\SP3QFE\msoe.dll + 2009-08-14 16:00 . 2009-08-14 16:00 1859968 c:\windows\$hf_mig$\KB969947\SP3QFE\win32k.sys + 2009-07-17 16:02 . 2009-07-17 16:02 1439744 c:\windows\$hf_mig$\KB969059\SP3QFE\query.dll + 2008-06-17 19:04 . 2008-06-17 19:04 8490496 c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll + 2009-03-21 14:04 . 2009-03-21 14:04 1020416 c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll + 2010-03-21 07:55 . 2009-06-09 15:23 2067968 c:\windows\$hf_mig$\KB956744\SP3QFE\lhmstscx.dll + 2009-02-10 18:19 . 2009-02-10 18:19 2190464 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2025472 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrpamp.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2067456 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe + 2010-03-21 07:54 . 2009-02-09 11:19 2146816 c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlmp.exe + 2009-08-14 19:32 . 2009-08-14 19:32 11110912 c:\windows\Installer\476086.msp + 2008-12-13 09:21 . 2008-12-13 09:21 10473472 c:\windows\Installer\47606e.msp + 2010-03-21 09:18 . 2010-03-21 09:18 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d2ea8d76f015817db1607075812b555f\System.Windows.Forms.ni.dll + 2010-03-21 22:19 . 2010-03-21 22:19 11796992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5cea03cfb008f2eac1439a9905467f37\System.Web.ni.dll + 2010-03-21 13:31 . 2010-03-21 13:31 17317888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll + 2010-03-21 09:18 . 2010-03-21 09:18 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\8b82e08c008924d51833cb0884bcbfc5\System.Design.ni.dll + 2010-03-21 09:17 . 2010-03-21 09:17 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\58c7ac6b6054038dc9346d7ec8e32b4c\PresentationFramework.ni.dll + 2010-03-21 09:16 . 2010-03-21 09:16 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\94badbd64df59de7da249f71da38b1c2\PresentationCore.ni.dll + 2010-03-21 09:04 . 2010-03-21 09:04 11486720 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll . -- Migawka wyzerowana -- . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] [HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-10-16 16:22 333192 ----a-w- c:\program files\AskBardis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] 2010-02-22 20:13 2349080 ----a-w- c:\program files\XfireXO\tbXfi1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfi1.dll" [2010-02-22 2349080] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192] [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AQQ"="f:\progra~1\WapSter\WAPSTE~1\AQQ.exe" [2010-05-11 6644736] "Steam"="f:\program files\Steam\Steam.exe" [2010-05-07 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-05 198160] "QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-08 974848] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] c:\documents and settings\Ram\Menu Start\Programy\Autostart\ CurseClientStartup.ccip [2010-4-26 0] Skr˘t (2) do JDownloader.exe.lnk - f:\moje dokumenty\JDownloader 0.8.9\JDownloader.exe [2009-10-8 214528] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk - c:\program files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe [2003-12-15 516096] Kalendarz XP.lnk - f:\program files\Kalendarz XP\Kalendarz.exe [2009-12-11 882176] [HKLM\~\startupfolder\C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk] path=c:\documents and settings\Ram\Menu Start\Programy\Autostart\hamachi.lnk backup=c:\windows\pss\hamachi.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2009-07-16 11:20 25604904 ----a-r- c:\program files\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\GIGABYTE\\EnergySaver\\run.exe"= "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"= "e:\\fear\\fpupdate.exe"= "e:\\fear\\FEAR.exe"= "e:\\fear\\FEARMP.exe"= "f:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"= "e:\\Soldat\\Soldat.exe"= "e:\\BOS I\\game.dat"= "c:\\Program Files\\DNA\\btdna.exe"= "e:\\Program Files\\BitTorrent\\bittorrent.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\lithtech.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\avp2.exe"= "c:\\Program Files\\Hamachi\\hamachi.exe"= "c:\\totalcmd\\TOTALCMD.EXE"= "c:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Home\\ftpte.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "e:\\Warcraft III na Adsko (Zzz-a61d285dbe5)\\Warcraft III.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Documents and Settings\\Ram\\Pulpit\\RoXoR 8.42\\RoXoR.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "f:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "e:\\Program Files\\Electronic Arts\\Battlefield 2142 Deluxe Edition\\BF2142.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "e:\\NW2FR\\nwn2main.exe"= "e:\\NW2FR\\nwn2main_amdxp.exe"= "e:\\NW2FR\\nwupdate.exe"= "e:\\NW2FR\\nwn2server.exe"= "f:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "f:\\Program Files\\Kalendarz XP\\Kalendarz.exe"= "f:\\Program Files\\Steam\\Steam.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\condition zero\\hl.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\dreamkiller.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\localized_readme.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\counter-strike\\hl.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "7171:UDP"= 7171:UDP:tibia "53:TCP"= 53:TCP:XBOX "3074:TCP"= 3074:TCP:XBOX "3074:UDP"= 3074:UDP:XBOX "3330:TCP"= 3330:TCP:XBOX "3330:UDP"= 3330:UDP:XBOX "88:TCP"= 88:TCP:XBOX "88:UDP"= 88:UDP:XBOX "53:UDP"= 53:UDP:XBOX R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2009-12-28 160640] R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2009-12-28 5248] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-18 108289] R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928] R2 ASKService;ASKService;c:\program files\AskBardis\bar\bin\AskService.exe [2009-10-19 464264] R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-09-25 80392] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2009-10-29 2368] R3 PONDIS5;PONDIS5 NDIS Protocol Driver;c:\windows\system32\PONDIS5.sys [2003-07-17 17097] S2 avupdate;ArcaBit Update Service;c:\progra~1\ArcaBit\ARCAUP~1\update.exe --> c:\progra~1\ArcaBit\ARCAUP~1\update.exe [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-11-21 682232] . Zawartość folderu 'Zaplanowane zadania' 2010-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2010-05-22 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2010-03-21 21:18] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com IE: &Winamp Search - c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{40525a66-db98-480d-bcf9-7af88c1af438} - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - c:\program files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll FF - ProfilePath - c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query= FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll FF - component: c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - component: c:\program files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll FF - component: c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin2.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin3.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin4.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin5.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin6.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin7.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX - SPOSÓB POSTĘPOWANIA ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - USUNIĘTO PUSTE WPISY - - - - URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file) BHO-{B922D405-6D13-4A2B-AE89-08A030DA4402} - c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll Toolbar-{B922D405-6D13-4A2B-AE89-08A030DA4402} - c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe AddRemove-HaaliMkx - e:\program files\Matroska Pack\haali\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-05-22 22:46 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A051E68]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf74ebf28 \Driver\ACPI -> ACPI.sys @ 0xf7335cb8 \Driver\atapi -> 0x8a051e68 IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 NDIS: Siemens Gigaset PCI Card 54 -> SendCompleteHandler -> NDIS.sys @ 0xf71bbbb0 PacketIndicateHandler -> NDIS.sys @ 0xf71c8a21 SendHandler -> NDIS.sys @ 0xf71a687b Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c9,6c,9b,07,f7,24,c0,fa,e5,e3,75,89,de,cb,e1,93,99,86,4d,ab,be,92,56, e0,8f,32,30,c1,5d,8a,3a,a5,43,65,ef,d5,5c,7b,00,db,3f,c6,ea,f4,2a,d8,5d,eb,\ "??"=hex:43,47,ee,52,ce,4e,24,0c,c9,24,8c,5a,8c,15,4f,92 [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\License information*] "datasecu"=hex:02,14,3c,00,79,1b,4e,b3,ab,7b,9e,01,f7,e3,7a,33,70,bf,51,2a,56, e3,90,0a,07,37,54,c5,af,3e,6c,d6,f1,16,e1,23,28,fe,fa,98,3a,1e,fb,40,4a,e9,\ "rkeysecu"=hex:17,0c,8b,a8,75,cb,05,56,56,b0,06,85,72,9c,ba,40 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > 'winlogon.exe'(1260) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2744) c:\windows\system32\WININET.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe c:\program files\Java\jre6\bin\javaw.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\documents and settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE e:\xampp\mysql\bin\mysqld-nt.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Czas ukończenia: 2010-05-22 22:48:51 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2010-05-22 20:48 ComboFix2.txt 2010-03-01 14:25 Przed: 3 398 959 104 bajtów wolnych Po: 3 491 786 752 bajtów wolnych - - End Of File - - 21D3CAE0E80EAB0A54017B153227EF35 [/log] Log z combofix [log]Logfile of random's system information tool 1.07 (written by random/random) Run by Ram at 2010-05-28 15:43:41 Microsoft Windows XP Professional Dodatek Service Pack 3 System drive C: has 13 GB (33%) free of 40 GB Total RAM: 2046 MB (40% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:43:51, on 2010-05-28 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16981) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe F:\Program Files\Steam\Steam.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe F:\Program Files\Kalendarz XP\Kalendarz.exe C:\Program Files\Java\jre6\bin\javaw.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE E:\xampp\mysql\bin\mysqld-nt.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox\firefox.exe F:\Program Files\WapSter\WapSter AQQ\AQQ.exe C:\Program Files\Windows NT\Accessories\WORDPAD.EXE F:\RSIT.exe C:\Program Files\trend micro\Ram.exe C:\WINDOWS\system32\notepad.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU\..\Run: [AQQ] F:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe O4 - HKCU\..\Run: [Steam] "F:\Program Files\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O4 - Startup: CurseClientStartup.ccip O4 - Startup: Skrót (2) do JDownloader.exe.lnk = F:\Moje Dokumenty\JDownloader 0.8.9\JDownloader.exe O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe O4 - Global Startup: Kalendarz XP.lnk = F:\Program Files\Kalendarz XP\Kalendarz.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (file missing) O9 - Extra 'Tools' menuitem: ArcaVir >> - {40525a66-db98-480d-bcf9-7af88c1af438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (file missing) O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ArcaBit Update Service (avupdate) - Unknown owner - C:\PROGRA~1\ArcaBit\ARCAUP~1\update.exe (file missing) O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: mysql - Unknown owner - E:\xampp\mysql\bin\mysqld-nt.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe -- End of file - 6597 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\WGASetup.job ======Registry dump====== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-05 198160] "QuickTime Task"=E:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696] "ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608] "ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632] "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153] "nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2009-09-24 1657448] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AQQ"=F:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe [2010-05-11 6644736] "Steam"=F:\Program Files\Steam\Steam.exe [2010-05-07 1238352] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Program Files\Skype\Phone\Skype.exe [2009-07-16 25604904] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk] C:\PROGRA~1\Hamachi\hamachi.exe [2009-02-21 625952] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart Gigaset WLAN Adapter Monitor.lnk - C:\Program Files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe Kalendarz XP.lnk - F:\Program Files\Kalendarz XP\Kalendarz.exe C:\Documents and Settings\Ram\Menu Start\Programy\Autostart CurseClientStartup.ccip Skrót (2) do JDownloader.exe.lnk - F:\Moje Dokumenty\JDownloader 0.8.9\JDownloader.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] C:\WINDOWS\system32\Ati2evxx.dll [2009-11-25 155648] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=323 "NoDriveAutoRun"=67108863 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"= "NoDriveTypeAutoRun"= "NoDrives"= "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\GIGABYTE\EnergySaver\run.exe"="C:\Program Files\GIGABYTE\EnergySaver\run.exe:*:Enabled:update" "C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade" "E:\fear\fpupdate.exe"="E:\fear\fpupdate.exe:*:Enabled:fpupdate" "E:\fear\FEAR.exe"="E:\fear\FEAR.exe:*:Enabled:FEAR" "E:\fear\FEARMP.exe"="E:\fear\FEARMP.exe:*:Enabled:FEAR" "F:\Program Files\WapSter\WapSter AQQ\AQQ.exe"="F:\Program Files\WapSter\WapSter AQQ\AQQ.exe:*:Enabled:AQQ" "E:\Soldat\Soldat.exe"="E:\Soldat\Soldat.exe:*:Enabled:Soldat" "E:\BOS I\game.dat"="E:\BOS I\game.dat:*:Enabled:Bitwa o Śródziemie (tm)" "C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA" "E:\Program Files\BitTorrent\bittorrent.exe"="E:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "E:\Program Files\FOX\Aliens vs. Predator 2\lithtech.exe"="E:\Program Files\FOX\Aliens vs. Predator 2\lithtech.exe:*:Enabled:Client" "E:\Program Files\FOX\Aliens vs. Predator 2\avp2.exe"="E:\Program Files\FOX\Aliens vs. Predator 2\avp2.exe:*:Enabled:Aliens vs. Predator 2" "C:\Program Files\Hamachi\hamachi.exe"="C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi" "C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows" "C:\Program Files\GlobalSCAPE\CuteFTP 8 Home\ftpte.exe"="C:\Program Files\GlobalSCAPE\CuteFTP 8 Home\ftpte.exe:*:Enabled:FTP Transfer Engine" "C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary" "E:\Warcraft III na Adsko (Zzz-a61d285dbe5)\Warcraft III.exe"="E:\Warcraft III na Adsko (Zzz-a61d285dbe5)\Warcraft III.exe:*:Enabled:Warcraft III" "C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe" "C:\Documents and Settings\Ram\Pulpit\RoXoR 8.42\RoXoR.exe"="C:\Documents and Settings\Ram\Pulpit\RoXoR 8.42\RoXoR.exe:*:Enabled:RoXoR" "C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test" "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype" "C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary" "C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire" "F:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="F:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) " "E:\Program Files\Electronic Arts\Battlefield 2142 Deluxe Edition\BF2142.exe"="E:\Program Files\Electronic Arts\Battlefield 2142 Deluxe Edition\BF2142.exe:*:Enabled:Battlefield 2142" "C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB" "E:\NW2FR\nwn2main.exe"="E:\NW2FR\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main" "E:\NW2FR\nwn2main_amdxp.exe"="E:\NW2FR\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD" "E:\NW2FR\nwupdate.exe"="E:\NW2FR\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater" "E:\NW2FR\nwn2server.exe"="E:\NW2FR\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server" "F:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="F:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2" "F:\Program Files\Kalendarz XP\Kalendarz.exe"="F:\Program Files\Kalendarz XP\Kalendarz.exe:*:Disabled:Kalendarz XP" "F:\Program Files\Steam\Steam.exe"="F:\Program Files\Steam\Steam.exe:*:Enabled:Steam" "F:\Program Files\Steam\steamapps\adsko1\condition zero\hl.exe"="F:\Program Files\Steam\steamapps\adsko1\condition zero\hl.exe:*:Enabled:Half-Life Launcher" "F:\Program Files\Steam\steamapps\common\dreamkiller\dreamkiller.exe"="F:\Program Files\Steam\steamapps\common\dreamkiller\dreamkiller.exe:*:Enabled:Dreamkiller" "F:\Program Files\Steam\steamapps\common\dreamkiller\localized_readme.exe"="F:\Program Files\Steam\steamapps\common\dreamkiller\localized_readme.exe:*:Enabled:Dreamkiller" "F:\Program Files\Steam\steamapps\adsko1\counter-strike\hl.exe"="F:\Program Files\Steam\steamapps\adsko1\counter-strike\hl.exe:*:Enabled:Counter-Strike" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" ======List of files/folders created in the last 3 months====== 2010-05-28 15:43:47 ----A---- C:\result.txt 2010-05-28 15:43:41 ----D---- C:\rsit 2010-05-28 15:39:45 ----SD---- C:\ComboFix 2010-05-23 11:50:33 ----SHD---- C:\RECYCLER 2010-05-22 22:48:51 ----A---- C:\ComboFix.txt 2010-05-22 22:36:16 ----A---- C:\WINDOWS\zip.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\SWXCACLS.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\SWSC.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\SWREG.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\sed.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\PEV.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\NIRCMD.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\MBR.exe 2010-05-22 22:36:16 ----A---- C:\WINDOWS\grep.exe 2010-05-10 13:46:00 ----D---- C:\Program Files\YASAVOB2MPEG 2010-04-26 20:11:34 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest 2010-04-26 20:11:34 ----A---- C:\WINDOWS\system32\ff_vfw.dll 2010-04-26 19:50:44 ----D---- C:\Program Files\Xvid 2010-04-26 18:50:59 ----D---- C:\Documents and Settings\Ram\Dane aplikacji\AVI ReComp 2010-04-26 18:50:35 ----D---- C:\Program Files\AviSynth 2.5 2010-04-26 18:50:07 ----D---- C:\Program Files\AVI ReComp 2010-04-25 17:43:14 ----D---- C:\Documents and Settings\Ram\Dane aplikacji\WinAVI 2010-04-25 17:43:11 ----D---- C:\Program Files\WinAVI Video Converter 2010-04-25 16:54:36 ----D---- C:\Program Files\VirtualDubMod 2010-04-25 15:28:12 ----D---- C:\Program Files\mkvtoavi 2010-04-17 18:28:30 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\MumboJumbo 2010-04-12 17:51:51 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard Entertainment 2010-04-11 14:49:18 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard 2010-03-22 08:47:36 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$ 2010-03-22 08:47:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$ 2010-03-21 11:04:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$ 2010-03-21 11:04:28 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$ 2010-03-21 11:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$ 2010-03-21 11:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$ 2010-03-21 11:03:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$ 2010-03-21 11:03:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$ 2010-03-21 11:03:04 ----D---- C:\WINDOWS\system32\KB905474 2010-03-21 11:02:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$ 2010-03-21 11:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$ 2010-03-21 11:02:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$ 2010-03-21 11:02:47 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$ 2010-03-21 11:02:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$ 2010-03-21 11:02:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$ 2010-03-21 11:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$ 2010-03-21 11:02:27 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$ 2010-03-21 11:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$ 2010-03-21 11:02:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$ 2010-03-21 11:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$ 2010-03-21 11:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$ 2010-03-21 11:00:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$ 2010-03-21 11:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$ 2010-03-21 10:59:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$ 2010-03-21 10:59:51 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$ 2010-03-21 10:59:48 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$ 2010-03-21 10:59:23 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$ 2010-03-21 10:59:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$ 2010-03-21 10:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$ 2010-03-21 10:59:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$ 2010-03-21 10:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$ 2010-03-21 10:59:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$ 2010-03-21 10:59:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$ 2010-03-21 10:58:59 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$ 2010-03-21 10:58:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$ 2010-03-21 10:58:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$ 2010-03-21 10:58:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$ 2010-03-21 10:58:26 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$ 2010-03-21 10:58:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$ 2010-03-21 10:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$ 2010-03-21 10:58:12 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$ 2010-03-21 10:58:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$ 2010-03-21 10:58:03 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$ 2010-03-21 10:57:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$ 2010-03-21 10:57:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$ 2010-03-21 10:57:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$ 2010-03-21 10:57:35 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$ 2010-03-21 10:57:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$ 2010-03-21 10:57:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$ 2010-03-21 10:57:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$ 2010-03-21 10:57:21 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$ 2010-03-21 10:57:14 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$ 2010-03-07 09:39:03 ----A---- C:\WINDOWS\system32\wmpns.dll 2010-03-06 20:59:24 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Real 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\vxblock.dll 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxwave.dll 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxsfs.dll 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxmas.dll 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxinsa64.exe 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxhpinst.exe 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxdrv.dll 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxcpya64.exe 2010-03-06 17:50:40 ----N---- C:\WINDOWS\system32\pxafs.dll 2010-03-06 17:50:39 ----N---- C:\WINDOWS\system32\px.dll ======List of files/folders modified in the last 3 months====== 2010-05-28 15:43:51 ----D---- C:\Program Files\Trend Micro 2010-05-28 15:43:47 ----D---- C:\WINDOWS 2010-05-28 15:42:50 ----D---- C:\WINDOWS\system32\CatRoot2 2010-05-28 15:42:44 ----D---- C:\WINDOWS\Temp 2010-05-28 15:39:48 ----D---- C:\Qoobox 2010-05-28 09:47:12 ----A---- C:\WINDOWS\SchedLgU.Txt 2010-05-26 23:19:24 ----D---- C:\WINDOWS\system32 2010-05-26 23:13:06 ----D---- C:\Program Files 2010-05-26 23:12:40 ----SHD---- C:\WINDOWS\Installer 2010-05-26 23:12:39 ----D---- C:\WINDOWS\WinSxS 2010-05-26 23:12:29 ----D---- C:\Config.Msi 2010-05-24 22:17:36 ----A---- C:\WINDOWS\win.ini 2010-05-24 13:31:42 ----D---- C:\WINDOWS\Prefetch 2010-05-22 22:48:53 ----D---- C:\WINDOWS\system32\drivers 2010-05-22 22:45:32 ----A---- C:\WINDOWS\system.ini 2010-05-22 22:42:29 ----D---- C:\WINDOWS\AppPatch 2010-05-22 22:42:26 ----D---- C:\Program Files\Common Files 2010-05-22 22:37:13 ----D---- C:\WINDOWS\system32\config 2010-05-22 22:37:08 ----D---- C:\WINDOWS\ERDNT 2010-05-20 14:47:13 ----A---- C:\WINDOWS\WORDPAD.INI 2010-05-19 11:06:00 ----D---- C:\Program Files\WinRAR 2010-05-14 15:58:05 ----HD---- C:\Program Files\InstallShield Installation Information 2010-05-05 21:50:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2010-04-26 19:53:41 ----D---- C:\Documents and Settings\Ram\Dane aplikacji\VSO 2010-04-25 17:15:35 ----D---- C:\WINDOWS\system 2010-04-17 11:04:24 ----A---- C:\WINDOWS\system32\PnkBstrB.exe 2010-04-13 11:33:56 ----D---- C:\WINDOWS\Minidump 2010-04-11 20:21:50 ----D---- C:\WINDOWS\security 2010-04-04 23:07:25 ----D---- C:\Program Files\NAPI-PROJEKT 2010-04-02 16:20:38 ----D---- C:\Program Files\Mozilla Firefox 2010-03-22 12:13:34 ----HD---- C:\WINDOWS\inf 2010-03-22 08:47:38 ----RSHDC---- C:\WINDOWS\system32\dllcache 2010-03-22 08:47:35 ----A---- C:\WINDOWS\imsins.BAK 2010-03-22 08:34:38 ----HD---- C:\WINDOWS\$hf_mig$ 2010-03-22 00:19:30 ----RSD---- C:\WINDOWS\assembly 2010-03-22 00:18:10 ----D---- C:\WINDOWS\Microsoft.NET 2010-03-21 11:15:00 ----D---- C:\WINDOWS\system32\wbem 2010-03-21 11:03:04 ----SD---- C:\WINDOWS\Tasks 2010-03-21 11:02:32 ----D---- C:\WINDOWS\system32\CatRoot 2010-03-21 10:59:49 ----D---- C:\Program Files\Movie Maker 2010-03-21 10:58:35 ----D---- C:\Program Files\Outlook Express 2010-03-21 10:57:48 ----D---- C:\WINDOWS\system32\pl-pl 2010-03-21 10:57:48 ----D---- C:\Program Files\Internet Explorer 2010-03-21 10:57:43 ----D---- C:\WINDOWS\ie7updates 2010-03-21 09:43:59 ----D---- C:\WINDOWS\Help 2010-03-07 19:54:12 ----D---- C:\Documents and Settings\Ram\Dane aplikacji\teamspeak2 2010-03-07 19:46:48 ----SD---- C:\Documents and Settings\Ram\Dane aplikacji\Microsoft 2010-03-07 19:46:47 ----D---- C:\Documents and Settings\Ram\Dane aplikacji\Ventrilo 2010-03-06 17:53:26 ----D---- C:\Program Files\Windows Media Player 2010-03-06 17:53:25 ----D---- C:\WINDOWS\RegisteredPackages 2010-03-01 15:43:01 ----D---- C:\WINDOWS\pss ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [] R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-10-22 96104] R1 intelppm;Sterownik procesora Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448] R1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720] R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-10-22 28520] R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816] R2 SVKP;SVKP; \??\C:\WINDOWS\system32\SVKP.sys [] R3 Arp1394;Protokół klienta 1394 ARP; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800] R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-11-25 4463104] R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-20 93696] R3 BCM43XX;Siemens Gigaset PCI Card 54 Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2003-07-17 265728] R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [] R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-02-21 25280] R3 HDAudBus;Sterownik magistrali Microsoft UAA dla High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384] R3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-07 4739072] R3 mouhid;Sterownik myszy HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-26 12160] R3 NIC1394;Sterownik sieci 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824] R3 PONDIS5;PONDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PONDIS5.SYS [] R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856] R3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128] R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208] R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520] R3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368] R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608] S3 Bridge;Mostek MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552] S3 BridgeMP;Miniport mostka MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552] S3 catchme;catchme; \??\C:\ComboFix\catchme.sys [] S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [] S3 motmodem;Motorola USB CDC ACM Driver; C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-06-18 23680] S3 npkcrypt;npkcrypt; \??\F:\Dark Kdr\npkcrypt.sys [] S3 npkcusb;npkcusb; \??\F:\Dark Kdr\npkcusb.sys [] S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872] S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856] S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104] S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000] S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944] S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys [] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-11-21 682232] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-10-22 108289] R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-10-22 185089] R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-11-25 602112] R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE [2007-01-11 113664] R2 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-05-13 80392] R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-29 152984] R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120] R2 mysql;mysql; E:\xampp\mysql\bin\mysqld-nt.exe [2008-04-17 5750784] R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-11-01 75064] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912] S2 avupdate;ArcaBit Update Service; C:\PROGRA~1\ArcaBit\ARCAUP~1\update.exe [] S2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100] S3 aspnet_state;Usuga stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF----------------- [/log][log]info.txt logfile of random's system information tool 1.06 2010-05-28 15:43:52 ======Uninstall list====== -->MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F} -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 3DMark06-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F3AD00A-1819-4B15-BB7D-08B3586336D7}\setup.exe" -l0x9 -removeonly abgx360 v1.0.2-->"E:\abgx360\uninstall.exe" AC3Filter 1.62b-->"C:\Program Files\AC3Filter\unins000.exe" Active Ports-->C:\WINDOWS\unvise32.exe C:\Program Files\Active Ports\uninstal.log Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7} Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723} Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 8 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A81200000003} Aktualizacja dla systemu Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB977165-v2)-->"C:\WINDOWS\$NtUninstallKB977165-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Aliens vs. Predator 2-->E:\PROGRA~1\FOX\ALIENS~1.PRE\UNWISE.EXE E:\PROGRA~1\FOX\ALIENS~1.PRE\INSTALL.LOG Allok RM RMVB to AVI MPEG DVD Converter 1.4.4-->"F:\Program Files\Allok RM RMVB to AVI MPEG DVD Converter\unins000.exe" ALLPlayer V3.X-->"C:\Program Files\ALLPlayer\unins000.exe" AMX Mod X Installer 1.8.1-->E:\AMX Mod X\uninst.exe Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033} Archiwizator WinRAR-->C:\Program Files\WinRAR\uninstall.exe ATI AVIVO Codecs-->MsiExec.exe /I{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3} ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\setup.exe -runfromtemp -l0x0015 -removeonly AVI ReComp 1.5.0-->C:\Program Files\AVI ReComp\Uninstall.exe Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe" Battlefield 2 Complete Collection-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A8DBF55D-73C0-4E37-A10E-365BFBB14119}\setup.exe" -l0x15 -removeonly Battlefield 2142 Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ED50ECE9-EC54-4C05-B5ED-EE4741A9F2EC}\setup.exe" -l0x15 -removeonly Bitwa o Śródziemie™-->E:\BOS I\EAUninstall.exe BurnInTest v5.3 Pro-->"C:\Program Files\BurnInTest\unins000.exe" Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0415 Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\SETUP.EXE" -l0x9 UNINST Condition Zero-->"F:\Program Files\Steam\steam.exe" steam://uninstall/80 Counter-Strike-->"F:\Program Files\Steam\steam.exe" steam://uninstall/10 CuteFTP 8 Home-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{949DBB22-2FB7-4DE1-804C-23D495A988D8}\Setup.exe" -l0x9 CX4300_5500_DX4400 Podręcznik-->C:\Program Files\EPSON\TPMANUAL\CX4300_5500_DX4400\POL\USE_G\DOCUNINS.EXE Dev-C++ 5 beta 9 release (4.9.9.2)-->"E:\Dev-Cpp\uninstall.exe" Dreamkiller-->"F:\Program Files\Steam\steam.exe" steam://uninstall/24500 EA Download Manager UI-->msiexec /qb /x {D5A9DA4B-E4F9-FB49-017D-769FC540F1F0} EA Download Manager UI-->MsiExec.exe /I{D5A9DA4B-E4F9-FB49-017D-769FC540F1F0} EA Download Manager-->F:\Moje Dokumenty\EADM\EADMUninstall.exe Energy Saver Advance B8.0520.1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7ED169D4-5053-4166-93DF-53B12AE6C539}\setup.exe" -l0x9 -removeonly EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\SETUP.EXE" -l0x9 UNINST EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x9 UNINST EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r ePSXe 1.5.2-->"E:\Program Files\ePSXe\unins000.exe" EVEREST Home Edition v2.20-->"E:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe" EVEREST Ultimate Edition v5.30-->"E:\EVEREST Ultimate Edition\unins000.exe" FEAR-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2B653229-9854-4989-B780-D978F5F13EAB}\setup.exe" -l0x15 /zU -removeonly ffdshow v1.1.3355 [2010-04-11]-->"E:\Program Files\Matroska Pack\ffdshow\unins000.exe" Freez FLV to AVI/MPEG/WMV Converter-->"C:\Program Files\Smallvideosoft\Freez FLV to AVI MPEG WMV Converter\unins000.exe" Gadu-Gadu 7.7-->C:\Program Files\Gadu-Gadu\Setup.exe GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG Gigaset WLAN Adapter 54-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{E1BD8B2F-0B49-47E8-B07D-DC855FBEB352} GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe" Gothic II - Noc Kruka-->C:\Program Files\InstallShield Installation Information\{6FB6D550-DDC4-4996-9CDF-91C34F0A4C4A}\setup.exe -runfromtemp -l0x0015 -removeonly Hamachi 1.0.3.0-->C:\Program Files\Hamachi\uninstall.exe Heroes of Might & Magic V: Kuźnia Przeznaczenia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACC75323-DB4A-4F7F-9AF2-1D1DEFF2D0B4}\setup.exe" -l0x15 Heroes of Might and Magic IV - Złota Edycja-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94B4E2D8-A184-415C-BF9E-F699D76466BD}\setup.exe" -l0x15 Heroes of Might and Magic V-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DE075DB-4218-4B2C-A35E-48D80BA680BB}\setup.exe" -l0x15 -removeonly HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT="" ImgBurn-->"E:\ImgBurn\uninstall.exe" Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF} jetAudio Basic-->C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe -runfromtemp -l0x0015 -removeonly Kalendarz XP v29.85-->F:\Program Files\Kalendarz XP\uninstall.exe LADSPA_plugins-win-0.4.15-->"C:\Program Files\Audacity\Plug-Ins\unins000.exe" Local Port Scanner v1.2.2-->E:\LPS\unins000.exe Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Marvel(TM) - Ultimate Alliance-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{932FB3F3-594D-4600-ABFA-F2DE80A14214} Medal of Honor Pacific Assault(tm)-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}\Setup.exe" -l0x9 -removeonly Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{2AFF2951-86B1-3C53-B34D-B440F11E7D0A} Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9} Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7} Microsoft .NET Framework 3.5 Language Pack SP1 - plk-->MsiExec.exe /I{9EFDFBA8-9174-3C61-8645-28376C5CA994} Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe" Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110415-6000-11D3-8CFE-0150048383C9} Microsoft Office Word Viewer 2003-->MsiExec.exe /I{90850415-6000-11D3-8CFE-0150048383C9} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989} Motorola Driver Installation-->MsiExec.exe /I{75A0EB9D-2D1E-4FB7-BF61-498E33C73EB4} Motorola Phone Tools-->C:\Program Files\InstallShield Installation Information\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}\setup.exe -runfromtemp -l0x0015 -removeonly Mozilla Firefox (3.6.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 6.0 Parser-->MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE} Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL Neverwinter Nights 2-->C:\Program Files\InstallShield Installation Information\{F20C1251-1D0A-4944-B2AE-678581B33B19}\setup.exe -runfromtemp -l0x0015 -removeonly NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall NWN2 AUDIO-FIX PL 2.3-->"E:\NW2FR\unins000.exe" Oprogramowanie drukarki EPSON-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - plk\setup.exe Pakiet zgodności dla systemu Office 2007-->MsiExec.exe /X{90120000-0020-0415-0000-0000000FF1CE} PDFCreator-->E:\Program Files\PDFCreator\unins000.exe Perfect Icon-->"C:\Program Files\Perfect Icon\uninstall.exe" PFPortChecker 1.0.32-->E:\PFPortChecker\uninst.exe PITy 2009 dla Windows kompilacja:1.1.2.3-->"C:\Program Files\PITy\PITy2009NG\unins000.exe" Poprawka dla systemu Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe" PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68} RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\SETUP.EXE -runfromtemp -l0x0015 -removeonly Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x15 -removeonly SIW version 2009.10.22-->"F:\SIW\unins000.exe" Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748} Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36} Soldat 1.4.2-->"E:\Soldat\unins000.exe" SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe" Spellforce 2 - Czas Mrocznych Wojen-->C:\Program Files\InstallShield Installation Information\{1A4E47DC-6701-4A85-AA16-C1F99A44598C}\setup.exe -runfromtemp -l0x0015 -removeonly Spellforce-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85DAE0C8-B3BB-11D8-88E4-0004769F25D1}\setup.exe" -l0x15 -removeonly Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3} Stronghold Crusader Extreme-->"C:\Program Files\InstallShield Installation Information\{8C3727F2-8E37-49E4-820C-03B1677F53B6}\setup.exe" -runfromtemp -l0x0009 -removeonly SubEdit-Player-->"E:\Program Files\SubEdit-Player\unins000.exe" Subtitle Studio 2.0 R-2-->"e:\Program Files\RadLight\Subtitle Studio\unins000.exe" TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe" Tibia MULTI-ip changer-->E:\Program Files\Asprate\Tibia Multi IP Changer\UNinstaller.exe Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT="" VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE} Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F} VentriloMIX-->C:\Program Files\VentriloMIX\Uninstal.exe VirtualDubMod 1.5.10.2 PL-->C:\Program Files\VirtualDubMod\Odinstaluj.exe VSO Image Resizer 2.1.8.2-->"F:\Image Resizer\unins000.exe" WapSter AQQ-->F:\Program Files\WapSter\WapSter AQQ\uninstall.exe WebServ 2.0-->"E:\WebServ\unins000.exe" WinAVI Video Converter-->"C:\Program Files\WinAVI Video Converter\unins000.exe" WinAVIVideoConverter-->F:\WinAVIVideoConverter\unins000.exe Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll WinUHA 2.0 RC1 (2005.02.27)-->E:\WinUHA\unins000.exe XAMPP 1.6.7-->"E:\xampp\uninstall.exe" Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe" XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe" Xvid 1.2.2 final uninstall-->"C:\Program Files\Xvid\unins000.exe" YASA VOB to MPEG Converter v3.2 (build 036)-->C:\PROGRA~1\YASAVO~1\UNWISE.EXE C:\PROGRA~1\YASAVO~1\INSTALL.LOG ======System event log====== Computer Name: PIETRZAKA Event Code: 7000 Message: Nie można uruchomić usługi ArcaBit Update Service z powodu następującego błędu: Nie można odnaleźć określonego pliku. Record Number: 5 Source Name: Service Control Manager Time Written: 20100519153534.000000+120 Event Type: błąd User: Computer Name: PIETRZAKA Event Code: 4201 Message: System wykrył, że karta sieciowa \DEVICE\TCPIP_{8D9A6B37-4891-4F85-82BA-A6577B27D1C0} została podłączona do sieci i ma zainicjowane normalne działanie na karcie sieciowej. Record Number: 4 Source Name: Tcpip Time Written: 20100519153458.000000+120 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 17 Message: AVGNTFLT successfully loaded Record Number: 3 Source Name: avgntflt Time Written: 20100519153458.000000+120 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 6005 Message: Uruchomiono usługę Dziennik zdarzeń. Record Number: 2 Source Name: EventLog Time Written: 20100519153428.000000+120 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 6009 Message: Microsoft (R) Windows (R) 5.01. 2600 Dodatek Service Pack 3 Multiprocessor Free. Record Number: 1 Source Name: EventLog Time Written: 20100519153428.000000+120 Event Type: informacje User: =====Application event log===== Computer Name: PIETRZAKA Event Code: 4096 Message: The AntiVir service has been started successfully! Record Number: 5 Source Name: Avira AntiVir Time Written: 20100323202514.000000+060 Event Type: informacje User: ZARZĄDZANIE NT\SYSTEM Computer Name: PIETRZAKA Event Code: 1800 Message: Usługa Centrum zabezpieczeń systemu Windows została uruchomiona. Record Number: 4 Source Name: SecurityCenter Time Written: 20100323202506.000000+060 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 1004 Message: Użytkownik zaakceptował Umowę Licencyjną Użytkownika Oprogramowania (EULA). Record Number: 3 Source Name: WgaSetup Time Written: 20100323202443.000000+060 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 1002 Message: Starting interactive setup. Record Number: 2 Source Name: WgaSetup Time Written: 20100323202443.000000+060 Event Type: informacje User: Computer Name: PIETRZAKA Event Code: 1006 Message: Umowa Licencyjna Użytkownika Oprogramowania (EULA) została wcześniej zaakceptowana. Record Number: 1 Source Name: WgaSetup Time Written: 20100323202443.000000+060 Event Type: informacje User: ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;E:\Program Files\QuickTime\QTSystem "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=6 "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel "PROCESSOR_REVISION"=170a "NUMBER_OF_PROCESSORS"=2 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip -----------------EOF-----------------[/log]Rsit [log]REGLOOKS logfile - version 0.985 Scan started: 2010-05-28 15:42:43,40 --- INFORMATION --- Manufacturer: Gigabyte Technology Co., Ltd. - Model: EP45-DS3R Operating System: Microsoft Windows XP Professional -- 5.1.2600 -- Dodatek Service Pack 3 -- Processor: Procesor Intel Pentium III Xeon Number of Processors: 2 Work Station Bootmode: Normal boot Total RAM: 2046 MB (free 755 MB - 36%) Computername: PIETRZAKA Domain: MSHOME User: Ram (Administrator account) Bootdevice: \Device\HarddiskVolume1 Systemdrive: C: Windowsdirectory: C:\WINDOWS Systemdirectory: C:\WINDOWS\system32 Internet Explorer Version: 7.0.5730.11 Antivirus Program: AntiVir Desktop 9.0.1.32 [Enabled - Updated] Firewall: ArcaFirewall 2008 2.0 [Enabled] --- SIGCHECK --- C:\WINDOWS\explorer.exe -- [1035264] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\appmgmts.dll -- [172032] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\browser.dll -- [77824] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\comres.dll -- [822272] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\comctl32.dll -- [617472] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\cryptsvc.dll -- [62464] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\ctfmon.exe -- [15360] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\es.dll -- [253952] -- [2008-07-07 22:29] -- sigcheck OK C:\WINDOWS\system32\eventlog.dll -- [56320] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\ias.dll NOT found C:\WINDOWS\system32\imm32.dll -- [110080] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\kernel32.dll -- [1018368] -- [2009-03-21 16:08] -- sigcheck OK C:\WINDOWS\system32\linkinfo.dll -- [19968] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\lpk.dll -- [22016] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\lsass.exe -- [13312] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\mfc40u.dll -- [927504] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\msgsvc.dll -- [33792] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\mshtml.dll -- [3599360] -- [2010-01-05 11:57] -- sigcheck OK C:\WINDOWS\system32\mspmsnsv.dll -- [25088] -- [2005-01-28 14:44] -- sigcheck OK C:\WINDOWS\system32\mswsock.dll -- [246784] -- [2008-06-20 19:48] -- sigcheck OK C:\WINDOWS\system32\netlogon.dll -- [407040] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\netman.dll -- [198144] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\ntkrnlpa.exe -- [2025472] -- [2009-12-09 12:11] -- sigcheck OK C:\WINDOWS\system32\ntmssvc.dll -- [435712] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\ntoskrnl.exe -- [2146816] -- [2009-12-09 12:11] -- sigcheck OK C:\WINDOWS\system32\pchsvc.dll NOT found C:\WINDOWS\system32\powrprof.dll -- [17408] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\qmgr.dll -- [409088] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\rasauto.dll -- [88576] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\regsvc.dll -- [59904] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\rpcss.dll -- [401408] -- [2009-02-09 12:53] -- sigcheck OK C:\WINDOWS\system32\scecli.dll -- [186368] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\schedsvc.dll -- [193536] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\services.exe -- [111104] -- [2009-02-09 13:25] -- sigcheck OK C:\WINDOWS\system32\sfc.dll -- [5120] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\sfcfiles.dll -- sigcheck FAILED [C:\WINDOWS\system32\sfcfiles.dll] C8BDAD4065118558B3DC360FC96D81DB -- [1571840] -- [2008-05-30 15:22] C:\WINDOWS\system32\spoolsv.exe -- [57856] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\srsvc.dll -- [171520] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\ssdpsrv.dll -- [71680] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\svchost.exe -- [14336] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\tapisrv.dll -- [249856] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\termsrv.dll -- [296448] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\upnphost.dll -- [186880] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\user32.dll -- [580096] -- [2008-04-14 22:50] -- sigcheck OK C:\WINDOWS\system32\userinit.exe -- [26624] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\wininet.dll -- [832512] -- [2010-01-05 11:57] -- sigcheck OK C:\WINDOWS\system32\winlogon.exe -- [510464] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\ws2_32.dll -- [82432] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\wscntfy.exe -- [13824] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\wuauclt.exe -- [53472] -- [2009-08-06 20:24] -- sigcheck OK C:\WINDOWS\system32\xmlprov.dll -- [129024] -- [2008-04-14 22:51] -- sigcheck OK C:\WINDOWS\system32\drivers\acpiec.sys -- [12032] -- [2001-10-26 20:46] -- sigcheck OK C:\WINDOWS\system32\drivers\aec.sys -- [142592] -- [2008-04-13 22:09] -- sigcheck OK C:\WINDOWS\system32\drivers\asyncmac.sys -- [14336] -- [2008-04-14 00:27] -- sigcheck OK C:\WINDOWS\system32\drivers\atapi.sys -- sigcheck FAILED C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys -- [96512] -- [2008-04-14 00:10] -- sigcheck OK C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys -- [96512] -- [2008-04-14 00:10] -- sigcheck OK C:\WINDOWS\system32\drivers\beep.sys -- [4224] -- [2009-08-28 20:33] -- sigcheck OK C:\WINDOWS\system32\drivers\classpnp.sys -- [49536] -- [2008-04-14 00:46] -- sigcheck OK C:\WINDOWS\system32\drivers\disk.sys -- [36352] -- [2008-04-14 00:10] -- sigcheck OK C:\WINDOWS\system32\drivers\iaStor.sys NOT found C:\WINDOWS\system32\drivers\ip6fw.sys -- [36608] -- [2008-04-14 00:23] -- sigcheck OK C:\WINDOWS\system32\drivers\kbdclass.sys -- [24960] -- [2008-04-14 21:50] -- sigcheck OK C:\WINDOWS\system32\drivers\ndis.sys -- [182656] -- [2008-04-14 00:50] -- sigcheck OK C:\WINDOWS\system32\drivers\ntfs.sys -- [574976] -- [2008-04-14 00:45] -- sigcheck OK C:\WINDOWS\system32\drivers\tcpip.sys -- [361600] -- [2008-06-20 13:51] -- sigcheck OK --- SSODL regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" -- File: %Systemroot%\system32\webcheck.dll -- [?] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" -- File: %SystemRoot%\system32\shell32.dll -- [?] "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?] "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" -- File: %systemroot%\system32\stobject.dll -- [?] --- STS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Moduł wstępnego ładowania interfejsu Browseui" -- File: %SystemRoot%\system32\browseui.dll -- [?] "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Demon buforu kategorii składników" -- File: %SystemRoot%\system32\browseui.dll -- [?] --- USERINIT regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," File: C:\WINDOWS\system32\userinit.exe -- [26624] -- [2008-04-14 22:51] --- SHELL regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="Explorer.exe" File: C:\WINDOWS\Explorer.exe -- [1035264] -- [2008-04-14 22:51] --- SYSTEM regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" --- APPINIT_DLLS regkey --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] no AppInit_DLLs regkey found --- NOTIFY regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] -- File: C:\WINDOWS\system32\Ati2evxx.dll -- [155648] -- [2009-11-25 05:10] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] -- File: C:\WINDOWS\system32\crypt32.dll -- [602624] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] -- File: C:\WINDOWS\system32\cryptnet.dll -- [64512] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] -- File: C:\WINDOWS\system32\cscdll.dll -- [102400] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy] -- File: %SystemRoot%\System32\dimsntfy.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] -- File: C:\WINDOWS\system32\sclgntfy.dll -- [22016] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] -- File: C:\WINDOWS\system32\WlNotify.dll -- [93184] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 22:50] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] -- File: C:\WINDOWS\system32\wlnotify.dll -- [93184] -- [2008-04-14 22:50] --- RUN / LOAD regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] no run / load keys found --- SHELLEXECUTEHOOKS regkey --- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" -- CLSID not found --- HKLM AUTORUN regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor] no AutoRun regkey found --- HKCU AUTORUN regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Command Processor] no AutoRun regkey found --- HKLM\RUN regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe" -- File: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot -- [?] "QuickTime Task" -- File: "E:\Program Files\QuickTime\QTTask.exe" -atboottime -- [?] "ISUSPM Startup" -- File: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup -- [?] "ISUSScheduler" -- File: "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start -- [?] "avgnt" -- File: "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min -- [?] "nwiz" -- File: C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install -- [?] "NvCplDaemon" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup -- [?] "NvMediaCenter" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit -- [?] --- HKLM\RUNONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKLM\RUNONCEEX regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] no runonceex values found --- HKLM\RUNSERVICES regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] key not found --- HKLM\RUNSERVICESONCE regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] no runservicesonce values found --- HKCU\RUN regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AQQ" -- File F:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe -- [6644736] -- [2010-05-11 17:38] "Steam" -- File: "F:\Program Files\Steam\Steam.exe" -silent -- [?] "ctfmon.exe" -- File C:\WINDOWS\system32\ctfmon.exe -- [15360] -- [2008-04-14 22:51] --- HKCU\RUNONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] no runonce values found --- HKCU\RUNONCEEX regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] key not found --- HKCU\RUNSERVICES regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] no runservices values found --- HKCU\RUNSERVICESONCE regkey --- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce] no runservicesonce values found --- HKU\.DEFAULT\Run regkeys - Default user --- [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 22:51] --- HKU\S-1-5-18\Run regkeys - user SYSTEM --- [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE" -- File C:\WINDOWS\system32\CTFMON.EXE -- [15360] -- [2008-04-14 22:51] --- HKU\S-1-5-19\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] key not found --- HKU\S-1-5-20\Run regkeys - User Lokale service --- [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] key not found --- HKLM\Explorer\Run regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] no run values found --- HKCU\Explorer\Run regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] no run values found --- Image File Execution regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] no debuggers found --- BROWSER HELPER OBJECTS regkeys --- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] no bho's found --- TOOLBAR regkeys --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] no toolbars found --- HKLM\URLSEARCHHOOKS regkeys --- [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks] no urlsearchhooks found --- HKCU\URLSEARCHHOOKS regkeys --- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] {CFBFAE00-17A6-11D0-99CB-00C04FD64497} -- File: C:\WINDOWS\system32\ieframe.dll -- [6067200] -- [2010-01-05 11:57] --- SRCEENSAVER regkey --- [HKEY_CURRENT_USER\Control Panel\Desktop] scrnsave.exe value not found --- ALTERNATESHELL regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot] File: C:\WINDOWS\system32\cmd.exe -- [396288] -- [2008-04-14 22:51] --- SECURITYPROVIDERS regkey --- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" File: C:\WINDOWS\system32\msapsspc.dll -- [86016] -- [2008-04-14 22:50] File: C:\WINDOWS\system32\schannel.dll -- [147456] -- [2009-06-25 10:27] File: C:\WINDOWS\system32\digest.dll -- [68608] -- [2008-04-14 22:50] File: C:\WINDOWS\system32\msnsspc.dll -- [290816] -- [2008-04-14 22:50] --- Active Setup\Installed Components regkey --- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] -- File: C:\WINDOWS\system32\ieudinit.exe -- [13824] -- [2009-12-31 17:35] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] -- File: C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] -- File: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] -- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}] -- filepath not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] -- File: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] -- File: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}] -- filepath not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] -- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] -- File: regsvr32.exe /s /n /i:U shell32.dll -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] -- File: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -- File: C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install -- [?] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}] -- filepath not found --- Services regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\a347bus] -- File: system32\DRIVERS\a347bus.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\a347scsi] -- File: System32\Drivers\a347scsi.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Atierecord] -- filepath not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AtiHdmiService] -- File: system32\drivers\AtiHdmi.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bridge] -- File: system32\DRIVERS\bridge.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BridgeMP] -- File: system32\DRIVERS\bridge.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dwshd] -- File: \SystemRoot\System32\drivers\dwshd.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ENTECH] -- File: \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys -- [?] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EPSON_PM_RPCV4_01] -- File: C:\Documents and Settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- [113664] -- [2007-01-11 06:02] --- SAFEBOOT MINIMAL SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal PEVSystemStart procexp90.Sys --- SAFEBOOT Network SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network DnsCache PEVSystemStart procexp90.Sys vsmon {1a3e09be-1e45-494b-9174-d7385b45bbf5} --- BOOTEXECUTE regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "BootExecute"= autocheck autochk *\0\0 --- PENDINGFILERENAMEOPERATIONS regkey --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] PendingFileRenameOperations key not found --- WOW-CMDLINE regkeys --- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW] "cmdline" = %SystemRoot%\system32\ntvdm.exe "cmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386 --- NETSVCS regkey --- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] -- NETSVCS 0WmdmPmSN --- DNS SERVER regkeys --- no "NameServer" values found --- File associations --- .BAT files: ("%1" %*) .COM files: ("%1" %*) .EXE files: ("%1" %*) .HLP files: (%SystemRoot%\System32\winhlp32.exe %1) .INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .JS files: (%SystemRoot%\System32\WScript.exe "%1" %*) .PIF files: ("%1" %*) .REG files: (regedit.exe "%1") .SCR files: ("%1" /S) .TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1) .VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*) --- STARTUP FOLDERS --- C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\CurseClientStartup.ccip -- [0] -- [2010-04-26 21:12] C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2008-09-25 18:20] C:\Documents and Settings\Ram\Menu Start\Programy\Autostart\Skrót (2) do JDownloader.exe.lnk -- [588] -- [2009-12-10 16:53] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk -- [1915] -- [2008-11-13 17:56] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2008-09-25 18:20] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk -- [601] -- [2009-12-11 20:15] C:\WINDOWS\system32\config\systemprofile\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2008-09-25 18:20] C:\WINDOWS\system32\config\systemprofile\Menu Start\Programy\Autostart\desktop.ini -- [84] -- [2008-09-25 18:20] --- TASK SCHEDULER JOBS --- C:\WINDOWS\tasks\AppleSoftwareUpdate.job -- [284] -- [2010-05-27 15:03] C:\WINDOWS\tasks\WGASetup.job -- [260] -- [2010-05-28 09:53] Scan completed: 2010-05-28 15:43:47,60 FINISHED [/log] Reg Looks //P.S zaraz dam log z usuwania [log]All processes killed ========== PROCESSES ========== No active process named Explorer.exe was found! ========== OTL ========== Prefs.js: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" removed from browser.search.defaulturl Prefs.js: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" removed from keyword.URL C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\chrome folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\searchplugin folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\META-INF folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\lib folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\defaults folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\chrome folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} folder moved successfully. C:\Documents and Settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\searchplugins\conduit.xml moved successfully. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nltide_2 deleted successfully. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nltide_2 not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Dida User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 766652 bytes User: Ram ->Temp folder emptied: 86875 bytes ->Temporary Internet Files folder emptied: 650212 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 35940529 bytes ->Flash cache emptied: 1329 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 36,00 mb OTL by OldTimer - Version 3.2.5.0 log created on 05282010_160113 [/log] log z usuwania
Tomek01 komentarz 28 maja 2010 komentarz 28 maja 2010 Hehe, czemu nie przypominasz że w pierwszym poście załączyłeś log z Combofix'a Nic to, nie myli się ten kto nie pracuje Jest czysto. Odinstalowałeś Combofix'a ?
adsko komentarz 28 maja 2010 Autor komentarz 28 maja 2010 hmm z tym jest problem bo twoja komenda go uruchamia tylko:D Aha i chce dodać że podczas wyłączenia kompa wyskakują mi czasami dziwne procesy które muszę zakończyć za pomocą "zakończ teraz"
Tomek01 komentarz 28 maja 2010 komentarz 28 maja 2010 (edytowane) A jednak coś dopatrzyłem. Masz zainfekowany plik systemowy: Atapi.sys Pobierz czystą kopie pliku atapi.sys i umieść bezpośrednio na dysku C:[url="http://www.megaupload.com/?d=YNDFFWKE"][b]Klik[/b][/url] Do notatnika systemowego wklej: [code] FCopy:: C:\atapi.sys | C:\windows\system32\dllcache\atapi.sys C:\atapi.sys | C:\windows\system32\drivers\atapi.sys [/code] Plik >>> zapisz pod nazwą CFScript.txt a nastepnie przeciągnij go i upuść na ikonę ComboFixa. Załącz wygenerowany log z niego.
adsko komentarz 29 maja 2010 Autor komentarz 29 maja 2010 [log]ComboFix 10-05-22.01 - Ram 2010-05-29 18:40:18.9.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2046.1586 [GMT 2:00] Uruchomiony z: F:\ComboFix.exe Użyto następujących komend :: F:\CFScript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: ArcaFirewall 2008 *enabled* {B640009B-6FF6-4CA7-9CE8-7DA160B95A5B} * Utworzono nowy punkt przywracania UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . --------------- FCopy --------------- c:\atapi.sys --> c:\windows\system32\dllcache\atapi.sys c:\atapi.sys --> c:\windows\system32\drivers\atapi.sys . ((((((((((((((((((((((((( Pliki utworzone od 2010-04-28 do 2010-05-29 ))))))))))))))))))))))))))))))) . 2010-05-29 16:24 . 2010-05-29 16:24 96512 ------w- C:\atapi.sys 2010-05-28 13:43 . 2010-05-28 13:43 -------- d-----w- C:\rsit 2010-05-10 11:46 . 2010-05-10 11:46 -------- d-----w- c:\program files\YASAVOB2MPEG 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(3) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder(2) 2010-04-30 21:06 . 2010-04-30 21:06 -------- d-----w- c:\documents and settings\Ram\Nowy folder . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-29 16:45 . 2008-09-25 16:28 16608 ----a-w- c:\windows\gdrv.sys 2010-05-29 16:24 . 2008-04-13 18:10 96512 ----a-w- c:\windows\system32\drivers\atapi.sys 2010-05-28 13:43 . 2009-03-01 06:06 -------- d-----w- c:\program files\Trend Micro 2010-05-20 13:31 . 2010-04-26 20:11 161144 ----a-w- c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat 2010-05-17 17:06 . 2010-03-16 18:59 439816 ----a-w- c:\documents and settings\Ram\Dane aplikacji\Real\Update\setup3.10\setup.exe 2010-05-14 13:58 . 2008-09-25 16:29 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-05-05 19:50 . 2001-10-26 18:15 586018 ----a-w- c:\windows\system32\perfh015.dat 2010-05-05 19:50 . 2001-10-26 18:15 109654 ----a-w- c:\windows\system32\perfc015.dat 2010-04-26 18:39 . 2010-04-26 16:50 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\AVI ReComp 2010-04-26 18:27 . 2010-04-26 18:25 1430522 ----a-w- c:\documents and settings\Ram\subedit_b4072_install.exe 2010-04-26 17:53 . 2009-04-19 15:33 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\VSO 2010-04-26 17:50 . 2010-04-26 17:50 -------- d-----w- c:\program files\Xvid 2010-04-26 17:49 . 2010-04-26 17:48 652794 ----a-w- c:\documents and settings\Ram\Xvid-1.2.2-07062009-[www.legalne.info].exe 2010-04-26 17:43 . 2010-04-26 17:42 892475 ----a-w- c:\documents and settings\Ram\xvidcore-1.2.2.zip 2010-04-26 17:01 . 2010-04-26 16:30 18172 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114652).NS.zip 2010-04-26 17:00 . 2010-04-25 18:51 18569 ----a-w- c:\documents and settings\Ram\How_to_Train_Your_Dragon_(NAPiSY-114704).NS.zip 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AVI ReComp 2010-04-26 16:50 . 2010-04-26 16:50 -------- d-----w- c:\program files\AviSynth 2.5 2010-04-25 21:04 . 2010-04-25 21:05 12615 ----a-w- c:\documents and settings\Ram\Clash_of_the_Titans_(NAPiSY-114794).NS.zip 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\documents and settings\Ram\Dane aplikacji\WinAVI 2010-04-25 15:43 . 2010-04-25 15:43 -------- d-----w- c:\program files\WinAVI Video Converter 2010-04-25 14:57 . 2010-04-25 14:54 -------- d-----w- c:\program files\VirtualDubMod 2010-04-25 13:36 . 2010-04-25 13:28 -------- d-----w- c:\program files\mkvtoavi 2010-04-17 16:30 . 2010-04-17 16:30 10 ----a-w- c:\windows\popcinfo.dat 2010-04-17 16:28 . 2010-04-17 16:28 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\MumboJumbo 2010-04-17 09:04 . 2009-11-01 16:33 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-04-17 09:04 . 2009-11-01 16:29 215128 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-04-12 15:51 . 2010-04-12 15:51 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard Entertainment 2010-04-11 12:49 . 2010-04-11 12:49 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Blizzard 2010-04-09 19:21 . 2010-04-26 18:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2010-04-04 21:07 . 2009-02-28 10:37 -------- d-----w- c:\program files\NAPI-PROJEKT 2009-08-28 07:07 . 2009-08-28 07:07 13439 ----a-w- c:\program files\Common Files\awabifal.db . ------- Sigcheck ------- [7] 2010-05-29 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\atapi.sys [-] 2010-05-29 16:24 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys [-] 2008-05-30 . C8BDAD4065118558B3DC360FC96D81DB . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AQQ"="f:\progra~1\WapSter\WAPSTE~1\AQQ.exe" [2010-05-11 6644736] "Steam"="f:\program files\Steam\Steam.exe" [2010-05-07 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-05 198160] "QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Ram\Menu Start\Programy\Autostart\ CurseClientStartup.ccip [2010-4-26 0] Skr˘t (2) do JDownloader.exe.lnk - f:\moje dokumenty\JDownloader 0.8.9\JDownloader.exe [2009-10-8 214528] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Gigaset WLAN Adapter Monitor.lnk - c:\program files\Siemens\Gigaset WLAN Adapter 54\WLANMonitor2003.exe [2003-12-15 516096] Kalendarz XP.lnk - f:\program files\Kalendarz XP\Kalendarz.exe [2009-12-11 882176] [HKLM\~\startupfolder\C:^Documents and Settings^Ram^Menu Start^Programy^Autostart^hamachi.lnk] path=c:\documents and settings\Ram\Menu Start\Programy\Autostart\hamachi.lnk backup=c:\windows\pss\hamachi.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2009-07-16 11:20 25604904 ----a-r- c:\program files\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\GIGABYTE\\EnergySaver\\run.exe"= "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"= "e:\\fear\\fpupdate.exe"= "e:\\fear\\FEAR.exe"= "e:\\fear\\FEARMP.exe"= "f:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"= "e:\\Soldat\\Soldat.exe"= "e:\\BOS I\\game.dat"= "c:\\Program Files\\DNA\\btdna.exe"= "e:\\Program Files\\BitTorrent\\bittorrent.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\lithtech.exe"= "e:\\Program Files\\FOX\\Aliens vs. Predator 2\\avp2.exe"= "c:\\Program Files\\Hamachi\\hamachi.exe"= "c:\\totalcmd\\TOTALCMD.EXE"= "c:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Home\\ftpte.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "e:\\Warcraft III na Adsko (Zzz-a61d285dbe5)\\Warcraft III.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "f:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "e:\\Program Files\\Electronic Arts\\Battlefield 2142 Deluxe Edition\\BF2142.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "e:\\NW2FR\\nwn2main.exe"= "e:\\NW2FR\\nwn2main_amdxp.exe"= "e:\\NW2FR\\nwupdate.exe"= "e:\\NW2FR\\nwn2server.exe"= "f:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "f:\\Program Files\\Kalendarz XP\\Kalendarz.exe"= "f:\\Program Files\\Steam\\Steam.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\condition zero\\hl.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\dreamkiller.exe"= "f:\\Program Files\\Steam\\steamapps\\common\\dreamkiller\\localized_readme.exe"= "f:\\Program Files\\Steam\\steamapps\\adsko1\\counter-strike\\hl.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "7171:UDP"= 7171:UDP:tibia "53:TCP"= 53:TCP:XBOX "3074:TCP"= 3074:TCP:XBOX "3074:UDP"= 3074:UDP:XBOX "3330:TCP"= 3330:TCP:XBOX "3330:UDP"= 3330:UDP:XBOX "88:TCP"= 88:TCP:XBOX "88:UDP"= 88:UDP:XBOX "53:UDP"= 53:UDP:XBOX R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2009-12-28 160640] R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2009-12-28 5248] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-18 108289] R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-09-25 80392] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2009-10-29 2368] R3 PONDIS5;PONDIS5 NDIS Protocol Driver;c:\windows\system32\PONDIS5.sys [2003-07-17 17097] S2 avupdate;ArcaBit Update Service;c:\progra~1\ArcaBit\ARCAUP~1\update.exe --> c:\progra~1\ArcaBit\ARCAUP~1\update.exe [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-11-21 682232] . Zawartość folderu 'Zaplanowane zadania' 2010-05-27 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2010-05-29 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2010-03-21 21:18] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: {{40525a66-db98-480d-bcf9-7af88c1af438} - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - c:\program files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll FF - ProfilePath - c:\documents and settings\Ram\Dane aplikacji\Mozilla\Firefox\Profiles\dkppvvuj.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin2.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin3.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin4.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin5.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin6.dll FF - plugin: e:\program files\QuickTime\Plugins\npqtplugin7.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX - SPOSÓB POSTĘPOWANIA ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-05-29 18:45 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A4A0008]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf74ebf28 \Driver\ACPI -> ACPI.sys @ 0xf7335cb8 \Driver\atapi -> 0x8a4a0008 IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 NDIS: Siemens Gigaset PCI Card 54 -> SendCompleteHandler -> NDIS.sys @ 0xf71bbbb0 PacketIndicateHandler -> NDIS.sys @ 0xf71c8a21 SendHandler -> NDIS.sys @ 0xf71a687b Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c9,6c,9b,07,f7,24,c0,fa,e5,e3,75,89,de,cb,e1,93,99,86,4d,ab,be,92,56, e0,8f,32,30,c1,5d,8a,3a,a5,43,65,ef,d5,5c,7b,00,db,3f,c6,ea,f4,2a,d8,5d,eb,\ "??"=hex:43,47,ee,52,ce,4e,24,0c,c9,24,8c,5a,8c,15,4f,92 [HKEY_USERS\S-1-5-21-2025429265-1450960922-1801674531-1004\Software\SecuROM\License information*] "datasecu"=hex:02,14,3c,00,79,1b,4e,b3,ab,7b,9e,01,f7,e3,7a,33,70,bf,51,2a,56, e3,90,0a,07,37,54,c5,af,3e,6c,d6,f1,16,e1,23,28,fe,fa,98,3a,1e,fb,40,4a,e9,\ "rkeysecu"=hex:17,0c,8b,a8,75,cb,05,56,56,b0,06,85,72,9c,ba,40 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > 'winlogon.exe'(1264) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3220) c:\windows\system32\WININET.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\documents and settings\All Users\Dane aplikacji\EPSON\EPW!3 SSRP\E_S40RP7.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE e:\xampp\mysql\bin\mysqld-nt.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe c:\program files\Java\jre6\bin\javaw.exe c:\documents and settings\Ram\Ustawienia lokalne\Apps\2.0\95Q7BBZX.Q3N\46EAKEHY.B0A\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe c:\program files\Skype\Toolbars\Shared\SkypeNames.exe c:\program files\Mozilla Firefox\firefox.exe . ************************************************************************** . Czas ukończenia: 2010-05-29 18:48:47 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2010-05-29 16:48 Przed: 13 980 434 432 bajtów wolnych Po: 13 942 005 760 bajtów wolnych - - End Of File - - 9CD8049E8283D63B60FD9A2A24674416[/log] Oto log i mam 1 zastrzeżenie ponieważ jak combofix uruchamia się to wyskakuje że musi zrestartować komputer ponieważ jest jakiś rootkit.
Tomek01 komentarz 29 maja 2010 komentarz 29 maja 2010 (edytowane) Powinien się zrestartować gdy usuwa infekcję. UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!! Następnym razem może się skończyć gorzej jak tego nie zrobisz. Wykonaj log Gmer. Zakładka rootkit/Malware - pokaż wszystko. Wykonaj pełny skan [url="http://www.instalki.pl/programy/download_c/14/155.html"][b]DrWebCureIt[/b][/url] i załącz raport.
Sohei komentarz 29 maja 2010 komentarz 29 maja 2010 (edytowane) Do autora wątku. Jak wykonasz polecenia powyzej to do systemlook wklej [code]:file C:\WINDOWS\system32\drivers\atapi.sys C:\WINDOWS\system32\dllcache\atapi.sys [/code] klikasz look i dajesz co wyskoczy MD5: 9F3A2F5AA6875C72BF062C712CFA2674 Tego nie bierz pod uwage jest to dla mnie
adsko komentarz 29 maja 2010 Autor komentarz 29 maja 2010 (edytowane) [log]SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 22:51 on 29/05/2010 by Ram (Administrator - Elevation successful) ========== file ========== C:\WINDOWS\system32\drivers\atapi.sys - Unable to find/read file. C:\WINDOWS\system32\dllcache\atapi.sys - File found and opened. MD5: 9F3A2F5AA6875C72BF062C712CFA2674 Created at 18:10 on 13/04/2008 Modified at 16:24 on 29/05/2010 Size: 96512 bytes Attributes: --a--c FileDescription: IDE/ATAPI Port Driver FileVersion: 5.1.2600.5512 (xpsp.080413-2108) ProductVersion: 5.1.2600.5512 OriginalFilename: atapi.sys InternalName: atapi.sys ProductName: Microsoft® Windows® Operating System CompanyName: Microsoft Corporation LegalCopyright: © Microsoft Corporation. All rights reserved. -=End Of File=-[/log] masz ten log i interesuje mnie [code]detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf74ebf28 \Driver\ACPI -> ACPI.sys @ 0xf7335cb8 \Driver\atapi -> 0x8a4a0008(...) Warning: possible MBR rootkit infection ![/code] komputer się zrestartował ale jak drugi raz robiłem skan to znów mi wywaliło że musi resnąć [quote="Tomek01"] Wykonaj log Gmer. Zakładka rootkit/Malware - pokaż wszystko. [/quote]Hmmm program wysiada podczas skanowania lub ładowania swoich plików i wywala "Nie wysyłaj" //P.S Ok wiec jak... jak chce użyć twój GMER to komputer łapie takiego zwiecha jakbym miał użycie procka 120% aż jak klikne myszką to wydaje pikanie. Nie wiem od czego to ale jakieś dziwne jest według mnie wcześniej tak nie miałem nawet na test procesor...
adsko komentarz 30 maja 2010 Autor komentarz 30 maja 2010 ale on się zawiesza kiedy się uruchamia więc nic zrobić nie mogę ponieważ: 1. Wyskakuje "Nie wysyłaj. 2. Zamula mi kompa
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.