+ 2001-10-25 12:00 . 2010-05-06 10:35 1209344 c:\windows\system32\urlmon.dll
- 2001-10-25 12:00 . 2008-04-14 03:21 1437696 c:\windows\system32\query.dll
+ 2001-10-25 12:00 . 2009-07-17 16:17 1437696 c:\windows\system32\query.dll
+ 2001-10-25 12:00 . 2010-02-05 18:27 1294336 c:\windows\system32\quartz.dll
+ 2001-10-25 12:00 . 2010-02-17 12:09 2192128 c:\windows\system32\ntoskrnl.exe
+ 2001-10-24 11:46 . 2010-02-16 19:09 2068992 c:\windows\system32\ntkrnlpa.exe
+ 2009-08-13 04:28 . 2009-07-31 09:05 1372672 c:\windows\system32\msxml6.dll
+ 2009-07-20 23:05 . 2009-07-20 23:05 1348432 c:\windows\system32\msxml4.dll
+ 2001-10-25 12:00 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2001-10-25 12:00 . 2010-05-06 10:35 5950976 c:\windows\system32\mshtml.dll
+ 2010-01-27 01:07 . 2010-06-26 14:21 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-03-08 02:32 . 2010-05-06 10:35 1985536 c:\windows\system32\iertutil.dll
- 2009-03-08 02:32 . 2009-07-03 16:59 1985536 c:\windows\system32\iertutil.dll
+ 2009-03-25 16:21 . 2009-03-25 16:21 1724416 c:\windows\system32\GDIPLUS.DLL
+ 2009-08-08 18:48 . 2010-07-24 21:02 2408032 c:\windows\system32\FNTCACHE.DAT
+ 2009-08-17 22:33 . 2009-08-17 22:33 1193832 c:\windows\system32\FM20.DLL
+ 2009-08-08 19:00 . 2009-08-06 18:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2008-06-18 03:03 . 2010-04-06 02:52 2462720 c:\windows\system32\dllcache\WMVCore.dll
+ 2009-04-19 19:52 . 2010-05-02 08:09 1851264 c:\windows\system32\dllcache\win32k.sys
+ 2009-06-26 16:51 . 2010-05-06 10:35 1209344 c:\windows\system32\dllcache\urlmon.dll
+ 2009-07-17 16:17 . 2009-07-17 16:17 1437696 c:\windows\system32\dllcache\query.dll
+ 2009-06-03 19:11 . 2010-02-05 18:27 1294336 c:\windows\system32\dllcache\quartz.dll
+ 2009-08-12 12:00 . 2010-02-17 12:09 2192128 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-08-12 12:00 . 2010-02-16 19:08 2026496 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-10 17:09 . 2010-02-16 19:09 2068992 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-08-12 12:00 . 2010-02-16 19:08 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-08-13 04:28 . 2009-07-31 09:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2009-08-12 11:59 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2009-08-12 11:59 . 2010-01-29 15:01 1315328 c:\windows\system32\dllcache\msoe.dll
- 2009-08-12 11:59 . 2009-07-10 13:28 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2009-07-18 16:05 . 2010-05-06 10:35 5950976 c:\windows\system32\dllcache\mshtml.dll
+ 2010-03-10 16:03 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2009-08-13 18:38 . 2010-05-06 10:35 1985536 c:\windows\system32\dllcache\iertutil.dll
- 2009-08-13 18:38 . 2009-07-03 16:59 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2009-11-06 23:06 . 2009-11-06 23:06 1130824 c:\windows\system32\dfshim.dll
+ 2009-08-29 10:42 . 2006-03-31 11:40 2388176 c:\windows\system32\d3dx9_30.dll
- 2009-08-29 10:42 . 2006-03-31 10:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2010-04-07 21:48 . 2010-04-07 21:48 5967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2010-03-23 03:32 . 2010-03-23 03:32 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
- 2008-11-25 02:59 . 2008-11-25 02:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2010-03-23 03:32 . 2010-03-23 03:32 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2009-08-07 22:51 . 2009-08-07 22:51 5812560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2008-11-25 02:59 . 2008-11-25 02:59 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2009-08-07 22:51 . 2009-08-07 22:51 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2010-04-01 09:42 . 2010-04-01 09:42 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2010-06-26 07:26 . 2010-06-26 07:26 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll
+ 2010-06-11 21:38 . 2010-06-11 21:38 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\ead93b6a4f0101cb99d09f3e3fc6491c\PresentationUI.ni.dll
+ 2010-06-26 07:26 . 2010-06-26 07:26 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll
+ 2010-06-11 21:36 . 2010-06-11 21:36 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\20ef773b20f6ce721ae60e5c2c2e8f80\PresentationBuildTasks.ni.dll
+ 2010-07-24 11:09 . 2010-07-24 11:09 1206784 c:\windows\assembly\NativeImages_v2.0.50727_32\P1CaptureCoreNet\d3df6d8fd94514de0bbbf2c98ddbfd9f\P1CaptureCoreNet.ni.dll
+ 2010-07-24 11:09 . 2010-07-24 11:09 1548288 c:\windows\assembly\NativeImages_v2.0.50727_32\P1.C1.Common\b36997cfa3c045b86e73c34eabc4ec7d\P1.C1.Common.ni.dll
+ 2010-06-13 07:28 . 2010-06-13 07:28 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\935b855860088a86bb65d37a19f059cc\Microsoft.VisualBasic.ni.dll
+ 2010-06-13 07:27 . 2010-06-13 07:27 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7a266de493d30eed21cb60ebe300be53\Microsoft.Transactions.Bridge.ni.dll
+ 2010-06-13 07:29 . 2010-06-13 07:29 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\9db8f9f7fe63ca4451bb5316a3ebb009\Microsoft.JScript.ni.dll
+ 2010-06-13 07:28 . 2010-06-13 07:28 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c96be82d6cb00367db4e3553272165ef\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-06-13 07:27 . 2010-06-13 07:27 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3815de5b052187b5d9375681a6784255\Microsoft.Build.Tasks.ni.dll
+ 2010-06-13 07:27 . 2010-06-13 07:27 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\43fc6723d08e9ce88701c29653efd224\Microsoft.Build.Engine.ni.dll
+ 2010-07-24 11:09 . 2010-07-24 11:09 8471040 c:\windows\assembly\NativeImages_v2.0.50727_32\ComponentFactory.Kr#\ec3849a546f915b14013fc0803554fc5\ComponentFactory.Krypton.Toolkit.ni.dll
+ 2010-06-26 00:55 . 2010-06-26 00:55 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-06-11 21:36 . 2010-06-11 21:36 5967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-26 00:55 . 2010-06-26 00:55 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-06-26 00:55 . 2010-06-26 00:55 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2009-08-30 05:41 . 2009-08-30 05:41 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-06-26 00:54 . 2010-06-26 00:54 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2009-08-30 05:44 . 2009-08-30 05:44 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-06-11 21:43 . 2010-06-11 21:43 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-08-18 17:19 . 2009-08-18 17:19 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2010-06-11 21:43 . 2010-06-11 21:43 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-08-18 17:19 . 2009-08-18 17:19 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-04-16 19:46 . 2009-12-09 10:11 2191360 c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
+ 2010-04-16 19:46 . 2009-12-09 10:11 2025984 c:\windows\$NtUninstallKB979683$\ntkrpamp.exe
+ 2010-04-16 19:46 . 2009-12-09 10:11 2068224 c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
+ 2010-04-16 19:46 . 2009-12-09 10:11 2147328 c:\windows\$NtUninstallKB979683$\ntkrnlmp.exe
+ 2010-06-11 21:41 . 2009-08-14 15:15 1850624 c:\windows\$NtUninstallKB979559$\win32k.sys
+ 2010-06-11 21:38 . 2009-05-20 02:56 2458112 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
+ 2010-05-15 05:44 . 2009-07-10 13:28 1315328 c:\windows\$NtUninstallKB978542$\msoe.dll
+ 2010-03-10 19:19 . 2009-08-04 21:59 2191360 c:\windows\$NtUninstallKB977165-v2$\ntoskrnl.exe
+ 2010-03-10 19:19 . 2009-08-04 17:29 2025984 c:\windows\$NtUninstallKB977165-v2$\ntkrpamp.exe
+ 2010-03-10 19:19 . 2009-08-04 17:29 2068224 c:\windows\$NtUninstallKB977165-v2$\ntkrnlpa.exe
+ 2010-03-10 19:19 . 2009-08-04 17:29 2147328 c:\windows\$NtUninstallKB977165-v2$\ntkrnlmp.exe
+ 2010-06-11 21:37 . 2009-11-27 17:14 1294336 c:\windows\$NtUninstallKB975562$\quartz.dll
+ 2010-03-10 19:19 . 2008-04-14 03:22 3558912 c:\windows\$NtUninstallKB975561$\moviemk.exe
+ 2010-02-15 20:57 . 2009-06-03 19:11 1293824 c:\windows\$NtUninstallKB975560$\quartz.dll
+ 2009-12-10 11:59 . 2008-09-10 01:16 1307648 c:\windows\$NtUninstallKB973687$\msxml6.dll
+ 2009-12-10 11:59 . 2008-09-04 17:17 1106944 c:\windows\$NtUninstallKB973687$\msxml3.dll
+ 2009-12-10 11:55 . 2009-02-09 11:26 2191232 c:\windows\$NtUninstallKB971486$\ntoskrnl.exe
+ 2009-12-10 11:55 . 2009-02-09 11:26 2025984 c:\windows\$NtUninstallKB971486$\ntkrpamp.exe
+ 2009-12-10 11:55 . 2009-02-10 17:09 2068224 c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe
+ 2009-12-10 11:55 . 2009-02-09 11:26 2147328 c:\windows\$NtUninstallKB971486$\ntkrnlmp.exe
+ 2009-12-10 11:59 . 2009-04-19 19:52 1847168 c:\windows\$NtUninstallKB969947$\win32k.sys
+ 2009-12-10 11:55 . 2008-04-14 03:21 1437696 c:\windows\$NtUninstallKB969059$\query.dll
+ 2010-06-11 21:18 . 2010-05-06 10:28 1209856 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\urlmon.dll
+ 2010-06-11 21:18 . 2010-05-06 10:28 5953024 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
+ 2010-06-11 21:18 . 2010-05-06 10:28 1986048 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\iertutil.dll
+ 2010-03-31 06:05 . 2010-02-25 06:12 1209856 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\urlmon.dll
+ 2010-03-31 06:05 . 2010-02-25 06:12 5946880 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
+ 2010-03-31 06:05 . 2010-02-25 06:12 1986048 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\iertutil.dll
+ 2010-04-16 19:40 . 2010-02-16 19:02 2192256 c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
+ 2010-04-16 19:40 . 2010-02-16 19:02 2026496 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrpamp.exe
+ 2010-04-16 19:40 . 2010-02-16 19:02 2069120 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
+ 2010-04-16 19:40 . 2010-02-16 19:02 2148352 c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlmp.exe
+ 2010-05-02 08:03 . 2010-05-02 08:03 1860352 c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys
+ 2010-01-29 14:54 . 2010-01-29 14:54 1315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
+ 2010-01-21 23:49 . 2009-12-21 19:02 1209344 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\urlmon.dll
+ 2010-01-21 23:49 . 2009-12-21 19:02 5945856 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
+ 2010-01-21 23:49 . 2009-12-21 19:02 1986048 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\iertutil.dll
+ 2009-12-10 04:03 . 2009-12-10 04:03 2191488 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntoskrnl.exe
+ 2010-03-10 16:03 . 2009-12-09 10:03 2025984 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrpamp.exe
+ 2009-12-10 04:03 . 2009-12-10 04:03 2068352 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlpa.exe
+ 2010-03-10 16:03 . 2009-12-09 10:03 2147328 c:\windows\$hf_mig$\KB977165-v2\SP3QFE\ntkrnlmp.exe
+ 2009-12-10 11:00 . 2009-10-29 07:38 1209344 c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\urlmon.dll
+ 2009-12-10 11:00 . 2009-10-29 07:38 5944320 c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
+ 2009-12-10 11:00 . 2009-10-29 07:38 1986048 c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\iertutil.dll
+ 2010-02-05 18:29 . 2010-02-05 18:29 1294336 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
+ 2010-03-10 16:03 . 2009-10-23 14:53 3558912 c:\windows\$hf_mig$\KB975561\SP3QFE\moviemk.exe
+ 2009-11-27 17:25 . 2009-11-27 17:25 1294336 c:\windows\$hf_mig$\KB975560\SP3QFE\quartz.dll
+ 2009-12-10 11:00 . 2009-07-31 04:30 1447424 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml6.dll
+ 2009-12-10 11:00 . 2009-07-31 04:30 1172480 c:\windows\$hf_mig$\KB973687\SP3QFE\msxml3.dll
+ 2009-12-10 10:59 . 2009-08-04 17:23 2191488 c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
+ 2009-12-10 10:59 . 2009-08-04 17:23 2025984 c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrpamp.exe
+ 2009-08-04 21:53 . 2009-08-04 21:53 2068352 c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
+ 2009-12-10 10:59 . 2009-08-04 17:23 2147328 c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlmp.exe
+ 2009-08-14 16:00 . 2009-08-14 16:00 1859712 c:\windows\$hf_mig$\KB969947\SP3QFE\win32k.sys
+ 2009-07-17 16:02 . 2009-07-17 16:02 1437696 c:\windows\$hf_mig$\KB969059\SP3QFE\query.dll
+ 2009-08-12 11:32 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
+ 2009-03-08 02:39 . 2010-05-06 10:35 11076096 c:\windows\system32\ieframe.dll
+ 2009-07-19 16:46 . 2010-05-06 10:35 11076096 c:\windows\system32\dllcache\ieframe.dll
+ 2010-04-02 17:29 . 2010-04-02 17:29 11413504 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp
+ 2010-01-19 23:41 . 2010-01-19 23:41 15710720 c:\windows\Installer\e56137.msp
+ 2009-11-20 22:46 . 2009-11-20 22:46 11524608 c:\windows\Installer\cd7900.msp
+ 2010-01-28 05:17 . 2010-01-28 05:17 17510400 c:\windows\Installer\cd78d4.msp
+ 2010-05-20 17:58 . 2010-05-20 17:58 12114432 c:\windows\Installer\92d1a2.msp
+ 2010-04-04 06:54 . 2010-04-04 06:54 11850240 c:\windows\Installer\8e4d1.msp
+ 2010-03-22 14:03 . 2010-03-22 14:03 11732992 c:\windows\Installer\8e3d5.msp
+ 2009-10-08 17:04 . 2009-10-08 17:04 17510400 c:\windows\Installer\3733ee.msp
+ 2009-08-18 11:50 . 2009-08-18 11:50 12022272 c:\windows\Installer\373382.msp
+ 2009-08-14 19:32 . 2009-08-14 19:32 11110912 c:\windows\Installer\3732f9.msp
+ 2009-08-10 13:09 . 2009-08-10 13:09 17254912 c:\windows\Installer\3732f1.msp
+ 2010-06-04 20:25 . 2010-06-04 20:25 20242432 c:\windows\Installer\2a4c4e4.msp
+ 2010-03-30 23:23 . 2010-03-30 23:23 15638528 c:\windows\Installer\23f5eb1.msp
+ 2010-04-02 10:30 . 2010-04-02 10:30 17456640 c:\windows\Installer\15555f.msp
+ 2010-04-24 15:09 . 2010-04-24 15:09 11750912 c:\windows\Installer\155542.msp
+ 2010-04-11 20:17 . 2010-04-11 20:17 14599680 c:\windows\Installer\1554b7.msp
+ 2010-04-24 15:07 . 2010-04-24 15:07 10118144 c:\windows\Installer\15549d.msp
+ 2010-04-15 19:34 . 2010-04-15 19:34 17510912 c:\windows\Installer\155465.msp
+ 2009-12-21 21:21 . 2009-12-21 21:21 20436408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0300000010\9.3.0\AcroRd32.dll
+ 2009-04-03 16:46 . 2009-04-03 16:46 17314688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSO.DLL
+ 2009-03-06 00:37 . 2009-03-06 00:37 10222432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\MSACCESS.EXE
+ 2010-06-11 21:40 . 2010-02-25 09:48 11070976 c:\windows\ie8updates\KB982381-IE8\ieframe.dll
+ 2010-03-31 06:09 . 2009-03-08 02:39 11063808 c:\windows\ie8updates\KB980182-IE8\ieframe.dll
+ 2010-06-11 21:40 . 2010-06-11 21:40 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
+ 2010-06-13 07:29 . 2010-06-13 07:29 11797504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
+ 2010-06-13 07:27 . 2010-06-13 07:27 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8b74f2fe3f3632f95ff4ddb8c4839a1e\System.ServiceModel.ni.dll
+ 2010-06-11 21:40 . 2010-06-11 21:40 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll
+ 2010-06-11 21:38 . 2010-06-11 21:38 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ca898d942e4d85af4c3d5f14a77c359a\PresentationFramework.ni.dll
+ 2010-06-26 07:25 . 2010-06-26 07:25 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll
+ 2010-06-11 21:37 . 2010-06-11 21:37 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ba8f917fd89d7afa8885c2a326379f03\PresentationCore.ni.dll
+ 2010-06-26 07:25 . 2010-06-26 07:25 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll
+ 2009-12-10 11:54 . 2009-12-10 11:54 11486720 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
+ 2010-07-24 11:08 . 2010-07-24 11:08 16838144 c:\windows\assembly\NativeImages_v2.0.50727_32\CaptureOne\fc24fb81f39fcebf91a0dc26ea3f83dd\CaptureOne.ni.exe
+ 2010-05-06 13:58 . 2010-05-06 13:58 11078144 c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\ieframe.dll
+ 2010-03-31 06:05 . 2010-02-25 06:12 11073024 c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\ieframe.dll
+ 2009-12-22 13:02 . 2009-12-22 13:02 11070976 c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\ieframe.dll
+ 2009-10-29 12:08 . 2009-10-29 12:08 11070464 c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Download Manager"="c:\program files3\Free Download Manager\fdm.exe" [2009-01-31 3399727]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13684736]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-17 202256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" silent loginmode=4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe_ID0EZEHM"=c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"MFPrintServer_Pro_LL"="c:\program files\Companion Suite Pro LL\MFPrintServer.exe"
"MFServices_Pro_LL"="c:\program files\Companion Suite Pro LL\MFServices.exe" -n
"Alcmtr"=ALCMTR.EXE
"IndexSearch"=c:\program files\ScanSoft\PaperPort\IndexSearch.exe
"PaperPort PTD"=c:\program files\ScanSoft\PaperPort\pptd40nt.exe
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE c:\windows\System32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE c:\windows\System32\NvCpl.dll,NvStartup
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\photoshop\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files2\\uTorrent\\utorrent.exe"=
"c:\\Program Files2\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files3\\Free Download Manager\\fdm.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Photoshop\\Adobe Photoshop CS4\\Photoshop.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 16:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 16:49 94360]
R1 lfxnt;lfxnt;c:\windows\system32\drivers\lfxnt.sys [8.8.2009 21:16 61740]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 16:47 731840]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [8.8.2009 22:19 246520]
S3 AsAudioDevice_351;AsAudioDevice_351;c:\windows\system32\drivers\AsAudioDevice_351.sys [15.7.2010 21:52 16640]
S3 DsAudioDevice_310;DsAudioDevice_310;c:\windows\system32\drivers\DsAudioDevice_310.sys [15.7.2010 21:44 16640]
S3 LFXACT;Companion Suite Pro LL F@X activities;c:\windows\system32\drivers\LFXACT.sys [8.8.2009 21:16 20672]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [21.6.2007 17:21 30720]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [16.7.2010 6:13 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [16.7.2010 6:13 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [16.7.2010 6:13 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [16.7.2010 6:13 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [16.7.2010 6:13 25704]
S3 XMLDIUSB;XML USB Device Interface;c:\windows\system32\drivers\XMLDIUSB.sys [8.8.2009 21:16 31879]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880d85-aad9-4558-abdc-2ab1552d831f}]
2009-04-13 13:08 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-07-02 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files3\TuneUp Utilities 2008\OneClick.exe [2008-01-08 11:31]
2010-08-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1454471165-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-08-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1454471165-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-08-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1454471165-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-07-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1454471165-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]
2010-08-11 c:\windows\Tasks\User_Feed_Synchronization-{A0CF5E4E-E4A1-41E2-8A32-820B591ECACD}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout Free Download Managerem - file://c:\program files3\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files3\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files3\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files3\Free Download Manager\dlall.htm
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Vlastník\Data aplikací\Mozilla\Firefox\Profiles\nnt0qxql.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/index.php?toolbar=centrum-1.0.0&q=
FF - component: c:\documents and settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils2.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils3.dll
FF - component: c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared\components\IGeared_cetrumczp_xputils35.dll
FF - component: c:\program files3\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - plugin: c:\photoshop\Reader\browser\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-AKVIS Retrialer from Unsofter.com - c:\documents and settings\Vlastník\Dokumenty\Obrázky\VYPÁLIT\VAPALENO -programy\AKVIS - programy\AKVIS ArtSuite 6.5 Rus for Adobe Photoshop\Lekarstvo\Retrialer.exe
AddRemove-Artistic Effects by Lokas Software - c:\windows\AWuninstall.exe Software\Lokas Ltd\Artistic Effects
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-11 13:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8840AEC5]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb80ecf28
\Driver\ACPI -> ACPI.sys @ 0xb7f7fcb8
\Driver\atapi -> atapi.sys @ 0xb7f37852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
NDIS: NVIDIA nForce 10/100 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb7df3bb0
PacketIndicateHandler -> NDIS.sys @ 0xb7e00a21
SendHandler -> NDIS.sys @ 0xb7dde87b
user & kernel MBR OK
**************************************************************************
.
Celkový čas: 2010-08-11 13:24:33
ComboFix-quarantined-files.txt 2010-08-11 11:24
ComboFix2.txt 2009-12-10 10:57
Před spuštěním: Volných bajtů: 60 151 873 536
Po spuštění: Volných bajtů: 63 899 799 552
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 9B5B3300840199DA7CF62847AB7CC17E