Stránka 1 z 2

o5 revelantknowledge

Napsal: 13 říj 2011 19:39
od [ACze]miky
Dobrý den, už po druhé mám problém s tímto svinctvem. Prosim o navod na odstranění. Log z RSIT:


Logfile of random's system information tool 1.09 (written by random/random)
Run by matmik at 2011-10-13 20:38:55
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 1 GB (7%) free of 20 GB
Total RAM: 3070 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:38:59, on 13.10.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
D:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\WINDOWS\system32\qttask.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\vsnp325.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\WgaTray.exe
D:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\program files\relevantknowledge\rlvknlg.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\audio svms\OTM.exe
C:\Documents and Settings\matmik\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\audio svms\RSIT.exe
C:\Program Files\trend micro\matmik.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [snp325] C:\WINDOWS\vsnp325.exe
O4 - HKLM\..\Run: [RelevantKnowledge] C:\program files\relevantknowledge\rlvknlg.exe -boot
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Global Startup: avast! Free Antivirus.lnk = C:\Program Files\Alwil Software\Avast5\AvastUI.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: (no name) - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files\Common Files\Desura\desura_service.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hyperdesk Theme Enabler (HdThemeEnabler) - The Skins Factory, Inc. - C:\Program Files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - D:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9874 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\UpdateCheck.job
C:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "google.cz"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:6.0.1289, ffxtlbr@babylon.com:1.1.3, engine@conduit.com:3.3.3.2, plugin@gameplaylabs.com:1.0, {75656794-AB59-4712-BFBC-5D816D56F3BC}:1.1.6, jqs@sun.com:1.0, {AA994882-F391-4d2e-806F-8908DA4814ED}:2.11.19, {37b1d48c-6e0a-dfe8-8a74-05116b74c806}:4.6.6.3, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.3.3.2, {C8431CD2-C25A-45F3-BEA9-A9103C31409A}:1.0, {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}:1.0.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.16"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... id=afex&q="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=D:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@bittorrent.com/BitTorrentDNA]
"Description"=Delivery Network Acceleration by BitTorrent™
"Path"=C:\Program Files\DNA\plugins\npbtdna.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=D:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=D:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027]
"Description"=RealMedia Plugin
"Path"=D:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040]
"Description"=6.0.12.1040
"Path"=D:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll

D:\Program Files\Mozilla Firefox\extensions\
{37b1d48c-6e0a-dfe8-8a74-05116b74c806}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{C8431CD2-C25A-45F3-BEA9-A9103C31409A}

D:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

D:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeploytk.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

D:\Program Files\Mozilla Firefox\searchplugins\
avg_igeared.xml
google.xml
jookz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default\extensions\
engine@conduit.com
ffxtlbr@babylon.com
plugin@gameplaylabs.com
{20a82645-c095-46ed-80e3-08825760534b}
{75656794-AB59-4712-BFBC-5D816D56F3BC}
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{AA994882-F391-4d2e-806F-8908DA4814ED}

C:\Documents and Settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default\searchplugins\
askcom.xml
conduit.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.xml
Search.xml
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-09-23 1088296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-17 305328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-06-28 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-11 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files\HyperCam Toolbar\tbcore3.dll [2010-02-16 2495488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-17 305328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"QuickTime Task"=C:\WINDOWS\system32\qttask.exe [2008-06-29 98304]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-28 98304]
"snp325"=C:\WINDOWS\vsnp325.exe [2006-10-10 827392]
"RelevantKnowledge"=C:\program files\relevantknowledge\rlvknlg.exe [2011-08-16 2927744]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-16 68856]
"uTorrent"=D:\Program Files\uTorrent\uTorrent.exe [2011-04-08 399736]
"DAEMON Tools Lite"=D:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2010-05-04 311296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
D:\Documents and Settings\matmik\Plocha\bittorrent.exe [2007-09-08 43008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desura]
D:\Program Files\Desura\desura.exe [2011-06-11 2482496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.exe [2007-02-12 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Game Fire]
C:\Program Files\Smart PC Utilities\Game Fire\GFTray.exe [2011-03-08 46592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2010-12-30 19972712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp325]
C:\WINDOWS\vsnp325.exe [2006-10-10 827392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-16 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp325]
C:\WINDOWS\tsnp325.exe [2006-10-10 270336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
D:\Program Files\uTorrent\uTorrent.exe [2011-04-08 399736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ImageMixer 3 SE Camera Monitor for SD.lnk]
D:\PROGRA~1\PIXELA\IMAGEM~1\CAMERA~1.EXE [2010-03-30 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^BluetoothPCDialer.lnk]
D:\PROGRA~1\BLUETO~1\BLUETO~1.EXE [2005-11-29 266240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.3.lnk]
C:\PROGRA~1\OPENOF~1.3\program\QUICKS~1.EXE [2007-09-11 393216]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
D:\PROGRA~1\Xfire\xfire.exe [2011-02-26 3502992]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
avast! Free Antivirus.lnk - C:\Program Files\Alwil Software\Avast5\AvastUI.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2011-07-28 188416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll [2005-01-31 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
D:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 312112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\PROGRA~1\COMMON~1\Stardock\MCPCore.dll [2005-05-10 86016]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\Documents and Settings\matmik\Plocha\bittorrent.exe"="D:\Documents and Settings\matmik\Plocha\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"D:\Program Files\Steam\Steam.exe"="D:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\Team JPN\SpiderMan Web of Shadows\image\pc\Spider-Man Web of Shadows.exe"="D:\Program Files\Team JPN\SpiderMan Web of Shadows\image\pc\Spider-Man Web of Shadows.exe:*:Enabled:Spider-Man(R) - Web of Shadows(TM) "
"D:\Program Files\ICQ7.2\ICQ.exe"="D:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"D:\Program Files\ICQ7.2\aolload.exe"="D:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"D:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe"="D:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe:*:Enabled:ZeroGearServer"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"D:\Program Files\Valve\csstrike\hl.exe"="D:\Program Files\Valve\csstrike\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="D:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"D:\Program Files\Xfire\xfire.exe"="D:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire"
"D:\Program Files\Steam\steamapps\common\aliens vs predator dedicated server\AvP_CLI.exe"="D:\Program Files\Steam\steamapps\common\aliens vs predator dedicated server\AvP_CLI.exe:*:Enabled:Aliens vs Predator Dedicated Server"
"D:\Program Files\Electronic Arts\Crytek\Crysis 2\bin32\Crysis2.exe"="D:\Program Files\Electronic Arts\Crytek\Crysis 2\bin32\Crysis2.exe:*:Enabled:Crysis2"
"D:\Program Files\LucasArts\KotF Jedi Academy Expansion Pack\GameData\jamp.exe"="D:\Program Files\LucasArts\KotF Jedi Academy Expansion Pack\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer"
"D:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe"="D:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer"
"D:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\EoC-S-EDed.exe"="D:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\EoC-S-EDed.exe:*:Enabled:Jedi Academy MP Dedicated Server"
"D:\Documents and Settings\matmik\Dokumenty\Downloads\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\ACBSP.exe"="D:\Documents and Settings\matmik\Dokumenty\Downloads\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\ACBSP.exe:*:Enabled:ACBSP"
"C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:*:Enabled:Crysis_32_sp_demo"
"D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"D:\Documents and Settings\matmik\Dokumenty\Downloads\Medal.Of.Honor.2010.Limited Edition.RiP.JoeKkerr\Binaries\moh.exe"="D:\Documents and Settings\matmik\Dokumenty\Downloads\Medal.Of.Honor.2010.Limited Edition.RiP.JoeKkerr\Binaries\moh.exe:*:Enabled:Medal of Honor™"
"D:\Program Files\Electronic Arts\Medal of Honor\Binaries\moh.exe"="D:\Program Files\Electronic Arts\Medal of Honor\Binaries\moh.exe:*:Enabled:Medal of Honor™"
"D:\Program Files\EA GAMES\BFP4f.exe"="D:\Program Files\EA GAMES\BFP4f.exe:*:Enabled:BFP4f"
"D:\Program Files\Steam\steamapps\common\zero gear\ZeroGear.bat"="D:\Program Files\Steam\steamapps\common\zero gear\ZeroGear.bat:*:Enabled:Zero Gear Demo"
"D:\Program Files\Steam\steamapps\common\call of juarez - bound in blood sp demo\CoJBiBDemo_x86.exe"="D:\Program Files\Steam\steamapps\common\call of juarez - bound in blood sp demo\CoJBiBDemo_x86.exe:*:Enabled:Call of Juarez: Bound in Blood Demo"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Program Files\Activision\Call of Duty - Black Ops\BlackOps.exe"="D:\Program Files\Activision\Call of Duty - Black Ops\BlackOps.exe:*:Enabled:BlackOps"
"D:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe"="D:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2"
"D:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe"="D:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer"
"D:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="D:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe"="D:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe:*:Enabled:Client"
"D:\Program Files\Rar$EX10.625\Connector.exe"="D:\Program Files\Rar$EX10.625\Connector.exe:*:Enabled:[ExF-F] Server Connector"
"D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP_Launcher.exe"="D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP_Launcher.exe:*:Enabled:Aliens vs. Predator"
"D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP_DX11.exe"="D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP_DX11.exe:*:Enabled:Aliens vs. Predator"
"D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP.exe"="D:\Program Files\Steam\steamapps\common\aliens vs predator\AvP.exe:*:Enabled:Aliens vs. Predator"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.2\ICQ.exe"="D:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"D:\Program Files\ICQ7.2\aolload.exe"="D:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"msacm.lameacm"=D:\PROGRA~1\ACEMEG~1\SystemS\lameacm.acm
"vidc.div3"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div5"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.mpg3"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div4"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.div6"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.ap41"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"msacm.divxa32"=D:\PROGRA~1\ACEMEG~1\SystemS\DivX\divxa32.acm
"vidc.dv25"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.msmc"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mmjp"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx1"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx2"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx3"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx4"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx5"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx6"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx7"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx8"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx9"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mmes"=D:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.xvid"=D:\PROGRA~1\ACEMEG~1\SystemS\XviD\xvidvfw.dll
"VIDC.XFR1"=xfcodec.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"VIDC.FPS1"=frapsvid.dll
"msacm.lhacm"=lhacm.acm
"msacm.vorbis"=vorbis.acm
"VIDC.CFHD"=CFHD.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-10-13 20:31:29 ----A---- C:\desktop.ini
2011-10-13 20:30:47 ----D---- C:\Documents and Settings\matmik\Data aplikací\Skinux
2011-10-13 20:25:37 ----D---- C:\Program Files\The Skins Factory
2011-10-13 20:25:24 ----D---- C:\Program Files\RelevantKnowledge
2011-10-13 20:21:19 ----D---- C:\Program Files\belchfire.net
2011-10-13 06:48:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-10-13 06:33:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-10-13 06:32:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-10-13 06:32:55 ----A---- C:\WINDOWS\imsins.BAK
2011-10-13 06:32:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2586448$
2011-10-12 18:32:25 ----N---- C:\WINDOWS\system32\SET951.tmp
2011-10-04 15:52:33 ----ASH---- C:\pagefile.sys
2011-09-30 14:51:55 ----D---- C:\Documents and Settings\matmik\Data aplikací\AVI ReComp
2011-09-26 18:32:09 ----D---- C:\Program Files\Common Files\ODBC
2011-09-25 17:53:03 ----A---- C:\WINDOWS\lolihackz.ini
2011-09-20 12:48:09 ----D---- C:\Documents and Settings\matmik\Data aplikací\VDownloader
2011-09-20 12:48:01 ----D---- C:\Program Files\WinPcap
2011-09-20 12:47:59 ----D---- C:\ProgramData
2011-09-20 12:47:59 ----A---- C:\Program Files\Common Files\WinPcapNmap.exe
2011-09-16 06:25:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-16 06:20:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$

======List of files/folders modified in the last 1 month======

2011-10-13 20:38:57 ----D---- C:\Program Files\trend micro
2011-10-13 20:36:29 ----D---- C:\WINDOWS\Temp
2011-10-13 20:29:40 ----D---- C:\Documents and Settings\matmik\Data aplikací\uTorrent
2011-10-13 20:26:14 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-10-13 20:25:50 ----SHD---- C:\WINDOWS\Installer
2011-10-13 20:25:37 ----D---- C:\Program Files
2011-10-13 20:12:31 ----D---- C:\Documents and Settings\matmik\Data aplikací\Adobe
2011-10-13 20:12:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-10-13 18:14:22 ----AC---- C:\WINDOWS\system32\PnkBstrB.exe
2011-10-13 16:47:44 ----D---- C:\WINDOWS\Microsoft.NET
2011-10-13 16:47:05 ----RSD---- C:\WINDOWS\assembly
2011-10-13 16:33:02 ----D---- C:\WINDOWS\system32\config
2011-10-13 13:24:27 ----AD---- C:\WINDOWS
2011-10-13 13:20:45 ----DC---- C:\WINDOWS\system32\dllcache
2011-10-13 13:20:45 ----D---- C:\WINDOWS\system32
2011-10-13 13:19:42 ----D---- C:\WINDOWS\security
2011-10-13 13:19:34 ----D---- C:\WINDOWS\system32\CatRoot2
2011-10-13 06:48:22 ----D---- C:\WINDOWS\inf
2011-10-13 06:47:39 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-13 06:47:15 ----D---- C:\WINDOWS\WinSxS
2011-10-13 06:33:21 ----AC---- C:\WINDOWS\system32\MRT.exe
2011-10-13 06:33:01 ----D---- C:\WINDOWS\system32\drivers
2011-10-13 06:32:59 ----HD---- C:\WINDOWS\$hf_mig$
2011-10-12 18:48:09 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2011-10-12 18:37:05 ----A---- C:\WINDOWS\win.ini
2011-10-11 18:32:12 ----ACT---- C:\WINDOWS\system32\SIntfNT.dll
2011-10-11 18:32:12 ----ACT---- C:\WINDOWS\system32\SIntf32.dll
2011-10-11 18:32:12 ----ACT---- C:\WINDOWS\system32\SIntf16.dll
2011-10-09 09:03:18 ----D---- C:\Documents and Settings\matmik\Data aplikací\Vso
2011-10-08 20:45:40 ----AC---- C:\WINDOWS\NeroDigital.ini
2011-10-08 09:37:43 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-07 16:23:54 ----D---- C:\Documents and Settings\matmik\Data aplikací\ICQ
2011-10-07 13:41:44 ----D---- C:\WINDOWS\Prefetch
2011-09-30 15:29:46 ----D---- C:\Documents and Settings\matmik\Data aplikací\vlc
2011-09-29 06:17:05 ----D---- C:\WINDOWS\Debug
2011-09-28 12:30:20 ----D---- C:\WINDOWS\Minidump
2011-09-26 18:33:16 ----AC---- C:\WINDOWS\ODBC.INI
2011-09-26 18:32:09 ----D---- C:\Program Files\Common Files
2011-09-26 18:32:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-09-26 11:41:42 ----A---- C:\WINDOWS\system32\uiautomationcore.dll
2011-09-26 11:41:42 ----A---- C:\WINDOWS\system32\oleaccrc.dll
2011-09-26 11:41:20 ----A---- C:\WINDOWS\system32\oleacc.dll
2011-09-20 12:43:18 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2011-09-18 10:07:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 d347bus;d347bus; C:\WINDOWS\system32\DRIVERS\d347bus.sys [2004-08-22 155136]
R0 d347prt;d347prt; C:\WINDOWS\System32\Drivers\d347prt.sys [2004-08-22 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2007-03-08 43528]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-09-06 30808]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-09-05 232512]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 HWiNFO32;HWiNFO32 Kernel Driver; \??\D:\Program Files\HWiNFO32\HWiNFO32.SYS []
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2002-07-17 16877]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-09-06 110552]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-01-27 50704]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2011-07-29 7084544]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2009-11-18 95232]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-12-30 6290024]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 NTProcDrv;Process creation detector for NT.; \??\C:\WINDOWS\TEMP\drv1.tmp []
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-03-13 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-15 83200]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 catchme;catchme; \??\C:\DOCUME~1\matmik\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 CFcatchme;CFcatchme; \??\C:\DOCUME~1\matmik\LOCALS~1\Temp\CFcatchme.sys []
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\matmik\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\Program Files\MediaCoder\SysInfo.sys []
S3 GMSIPCI;GMSIPCI; C:\WINDOWS\system32\drivers\GMSIPCI.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-02-07 17480]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-11-01 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-11-01 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-21 21568]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP325;USB PC Camera (SNPSTD325); C:\WINDOWS\system32\DRIVERS\snp325.sys [2007-04-03 10251904]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2011-07-28 643072]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 HdThemeEnabler;Hyperdesk Theme Enabler; C:\Program Files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe [2008-07-21 106496]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-11 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 NMSAccessU;NMSAccessU; D:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-10-12 75136]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2008-05-02 126976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-25 135664]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-12-15 72704]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Desura Install Service;Desura Install Service; C:\Program Files\Common Files\Desura\desura_service.exe [2011-06-11 130368]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-04-19 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-25 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-25 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-05-03 74656]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\wmpnetwk.exe []
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: o5 revelantknowledge

Napsal: 13 říj 2011 19:41
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: o5 revelantknowledge

Napsal: 14 říj 2011 12:46
od [ACze]miky
ComboFix 1. část logu:

ComboFix 11-10-14.01 - matmik 14.10.2011 13:20:58.11.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.2312 [GMT 2:00]
Spuštěný z: d:\audio svms\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\desktop.ini
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\rlls.dll
c:\program files\RelevantKnowledge\rlls64.dll
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlservice.exe
c:\program files\RelevantKnowledge\rlvknlg.exe
c:\program files\RelevantKnowledge\rlvknlg64.exe
c:\windows\ehome\medctrro.exe
c:\windows\iun6002.exe
c:\windows\msmqinst.log
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-14 do 2011-10-14 )))))))))))))))))))))))))))))))
.
.
2011-10-13 18:30 . 2011-10-13 18:30 -------- d-----w- c:\documents and settings\matmik\Data aplikací\Skinux
2011-10-13 18:25 . 2011-10-13 18:25 -------- d-----w- c:\program files\The Skins Factory
2011-10-13 18:21 . 2011-10-13 18:21 -------- d-----w- c:\program files\belchfire.net
2011-10-12 16:32 . 2008-04-14 06:51 4096 ------w- c:\windows\system32\SET951.tmp
2011-09-30 12:51 . 2011-09-30 13:00 -------- d-----w- c:\documents and settings\matmik\Data aplikací\AVI ReComp
2011-09-22 16:19 . 2011-09-22 16:19 -------- d-----w- c:\documents and settings\matmik\Local Settings\Data aplikací\MW2_Hack_Project
2011-09-20 10:48 . 2011-09-20 10:49 -------- d-----w- c:\documents and settings\matmik\Data aplikací\VDownloader
2011-09-20 10:48 . 2011-09-20 10:48 -------- d-----w- c:\program files\WinPcap
2011-09-20 10:47 . 2011-09-20 10:47 -------- d-----w- C:\ProgramData
2011-09-20 10:47 . 2010-01-26 21:11 444283 ----a-w- c:\program files\Common Files\WinPcapNmap.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 16:14 . 2009-03-15 16:08 138264 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-10-13 16:14 . 2010-05-04 14:56 234768 -c--a-w- c:\windows\system32\PnkBstrB.xtr
2011-10-13 16:14 . 2009-03-15 16:08 234768 -c--a-w- c:\windows\system32\PnkBstrB.exe
2011-10-12 16:48 . 2009-03-15 16:08 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-10-11 16:32 . 2008-10-19 15:06 21840 -c--atw- c:\windows\system32\SIntfNT.dll
2011-10-11 16:32 . 2008-10-19 15:06 17212 -c--atw- c:\windows\system32\SIntf32.dll
2011-10-11 16:32 . 2008-10-19 15:06 12067 -c--atw- c:\windows\system32\SIntf16.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 14:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 14:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-12 13:16 . 2010-05-03 13:47 22328 -c--a-w- c:\documents and settings\matmik\Data aplikací\PnkBstrK.sys
2011-09-09 09:12 . 2004-08-17 13:49 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 20:45 . 2011-07-01 15:40 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2011-07-01 15:40 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-07-01 15:40 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2011-07-01 15:40 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2011-07-01 15:40 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2011-07-01 15:40 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2011-07-01 15:40 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2011-07-01 15:40 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2011-07-01 15:40 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2011-07-01 15:40 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-09-06 14:10 . 2004-08-17 13:44 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 14:15 . 2011-09-05 14:15 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-09-05 13:56 . 2004-08-17 13:49 668160 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2004-08-17 13:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 13:56 . 2004-08-03 20:59 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:55 . 2004-08-17 13:44 370176 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-03 21:14 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-12 11:51 . 2008-01-26 14:48 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-07-30 15:26 . 2011-07-30 15:26 87552 --sh--w- c:\windows\system32\h4x0r.dll
2011-07-29 18:34 . 2010-05-13 13:17 669184 -c--a-w- c:\windows\system32\pbsvc.exe
2011-07-28 22:20 . 2007-03-15 01:57 7084544 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-07-28 22:17 . 2008-02-06 17:06 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2011-07-28 22:01 . 2010-02-11 04:23 57344 ----a-w- c:\windows\system32\aticalrt.dll
2011-07-28 22:01 . 2010-02-11 04:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2011-07-28 21:57 . 2010-02-11 04:21 5697536 ----a-w- c:\windows\system32\aticaldd.dll
2011-07-28 21:40 . 2007-03-15 01:19 18440192 ----a-w- c:\windows\system32\atioglxx.dll
2011-07-28 21:34 . 2007-03-15 01:40 3973696 ----a-w- c:\windows\system32\ati3duag.dll
2011-07-28 21:32 . 2008-02-06 17:06 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-28 21:31 . 2007-03-15 01:57 303104 ----a-w- c:\windows\system32\ati2dvag.dll
2011-07-28 21:27 . 2011-02-16 10:58 956160 ----a-w- c:\windows\system32\ativvamv.dll
2011-07-28 21:15 . 2007-03-15 01:29 3166208 ----a-w- c:\windows\system32\ativvaxx.dll
2011-07-28 21:14 . 2007-03-15 01:50 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2011-07-28 21:13 . 2007-03-15 01:50 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-07-28 21:13 . 2007-03-15 01:50 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-07-28 21:13 . 2007-03-15 01:50 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-07-28 21:13 . 2007-03-15 01:49 188416 ----a-w- c:\windows\system32\ati2evxx.dll
2011-07-28 21:12 . 2007-03-15 01:48 643072 ----a-w- c:\windows\system32\ati2evxx.exe
2011-07-28 21:10 . 2007-03-15 01:47 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-07-28 21:09 . 2010-12-24 18:39 151552 ----a-w- c:\windows\system32\atiapfxx.exe
2011-07-28 21:05 . 2007-03-15 01:16 704512 ----a-w- c:\windows\system32\atikvmag.dll
2011-07-28 21:01 . 2010-02-11 03:54 208896 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-28 21:00 . 2007-03-15 01:14 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-07-28 20:59 . 2010-02-11 04:37 507904 ----a-w- c:\windows\system32\atiok3x2.dll
2011-07-28 20:55 . 2007-03-15 01:10 876544 ----a-w- c:\windows\system32\ati2cqag.dll
2011-07-28 20:53 . 2010-02-11 03:59 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2011-07-28 20:53 . 2009-11-24 13:26 64512 ----a-w- c:\windows\system32\atimpc32.dll
2011-07-28 20:53 . 2007-03-15 01:14 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-28 15:49 . 2011-07-28 15:49 53760 ----a-w- c:\windows\system32\OVDecode.dll
2011-07-28 15:48 . 2011-07-28 15:48 13555712 ----a-w- c:\windows\system32\amdocl.dll
2011-07-18 13:42 . 2011-06-05 09:33 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-20_07.29.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-13 18:30 . 2011-10-13 18:30 16384 c:\windows\Temp\Perflib_Perfdata_958.dat
+ 2011-10-13 18:27 . 2011-10-13 18:27 16384 c:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2011-01-20 17:30 . 2008-04-14 06:52 54272 c:\windows\system32\vfwwdm32.dll
- 2011-01-20 17:30 . 2008-04-14 07:52 54272 c:\windows\system32\vfwwdm32.dll
+ 1999-11-25 00:40 . 1999-11-25 00:40 40960 c:\windows\system32\VBAME.DLL
- 1999-11-25 01:40 . 1999-11-25 01:40 40960 c:\windows\system32\VBAME.DLL
+ 2004-08-17 13:49 . 2011-09-05 13:56 37888 c:\windows\system32\url.dll
- 2004-08-17 13:49 . 2008-04-14 06:52 37888 c:\windows\system32\url.dll
+ 2007-11-13 11:31 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2007-11-13 11:31 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
- 2008-01-27 12:04 . 2003-06-19 00:31 18944 c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2008-01-27 12:04 . 2003-06-18 23:31 18944 c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
- 2010-10-26 14:48 . 2003-06-19 00:31 35328 c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2011-08-28 11:25 . 2003-06-18 23:31 35328 c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2011-08-28 11:25 . 2003-06-18 23:31 35328 c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
- 2010-10-26 14:48 . 2003-06-19 00:31 35328 c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
- 2010-09-23 04:17 . 2010-02-22 14:20 18296 c:\windows\system32\spmsg.dll
+ 2010-09-23 04:17 . 2011-08-12 11:51 18296 c:\windows\system32\spmsg.dll
+ 2011-06-16 01:34 . 2011-06-16 01:34 79872 c:\windows\system32\SlotMaximizerAg.dll
+ 1998-03-25 03:54 . 1998-03-25 03:54 15872 c:\windows\system32\SCP32.DLL
- 1998-03-25 04:54 . 1998-03-25 04:54 15872 c:\windows\system32\SCP32.DLL
+ 2011-09-09 17:06 . 2001-11-09 15:01 24064 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ativcoxx.dll
+ 2011-09-09 17:06 . 2011-07-28 21:00 17408 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atitvo32.dll
+ 2011-09-09 17:06 . 2009-06-22 15:34 45056 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ATIODCLI.exe
+ 2011-09-09 17:06 . 2011-07-28 20:53 64512 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atimpc32.dll
+ 2011-09-09 17:06 . 2011-07-28 21:10 53248 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ATIDDC.DLL
+ 2011-09-09 17:06 . 2011-07-28 22:01 57344 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\aticalrt.dll
+ 2011-09-09 17:06 . 2011-07-28 22:01 53248 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\aticalcl.dll
+ 2011-09-09 17:06 . 2011-07-28 21:13 26112 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\Ati2mdxx.exe
+ 2011-09-09 17:06 . 2011-07-28 20:53 53248 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2erec.dll
+ 2011-09-09 17:06 . 2011-05-25 02:39 43520 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2edxx.dll
+ 2010-01-27 02:09 . 2010-01-27 02:09 53299 c:\windows\system32\pthreadVC.dll
+ 2001-10-25 14:00 . 2011-10-13 04:47 73632 c:\windows\system32\perfc009.dat
+ 2001-10-25 14:00 . 2011-10-13 04:47 85482 c:\windows\system32\perfc005.dat
+ 1998-08-09 17:07 . 1998-08-09 17:07 94208 c:\windows\system32\MSSTKPRP.DLL
- 1998-08-09 18:07 . 1998-08-09 18:07 94208 c:\windows\system32\MSSTKPRP.DLL
+ 1999-03-26 14:59 . 1999-03-26 14:59 53248 c:\windows\system32\MFC42CSY.DLL
- 1999-03-26 15:59 . 1999-03-26 15:59 53248 c:\windows\system32\MFC42CSY.DLL
- 2008-01-27 12:04 . 2003-06-19 00:31 17920 c:\windows\system32\mdimon.dll
+ 2008-01-27 12:04 . 2003-06-18 23:31 17920 c:\windows\system32\mdimon.dll
+ 2011-09-10 18:22 . 2008-04-14 06:51 21504 c:\windows\system32\hidserv.dll
+ 2003-07-15 04:57 . 2003-07-15 04:57 32584 c:\windows\system32\FM20ENU.DLL
- 2003-07-15 05:57 . 2003-07-15 05:57 32584 c:\windows\system32\FM20ENU.DLL
+ 2011-09-05 11:43 . 2011-07-28 21:13 81692 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\oemdspif.dll
+ 2011-09-05 11:43 . 2001-11-09 15:01 12614 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ativcoxx.dll
+ 2011-09-05 11:43 . 2010-08-27 18:32 81222 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiode.exe
+ 2011-09-05 11:43 . 2009-06-22 15:34 25130 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiodcli.exe
+ 2011-09-05 11:43 . 2011-07-28 20:53 41419 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atimpc32.dll
+ 2011-09-05 11:43 . 2011-07-28 21:10 28700 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiddc.dll
+ 2011-09-05 11:43 . 2011-07-28 22:01 29988 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\aticalrt.dll
+ 2011-09-05 11:43 . 2011-07-28 22:01 29027 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\aticalcl.dll
+ 2011-09-05 11:43 . 2009-05-11 21:35 71662 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atibtmon.exe
+ 2011-09-05 11:43 . 2011-07-28 21:09 57514 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiapfxx.exe
+ 2011-09-05 11:43 . 2011-07-28 21:13 16309 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2mdxx.exe
+ 2011-09-05 11:43 . 2011-07-28 20:53 13652 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2erec.dll
+ 2011-09-05 11:43 . 2011-07-28 21:13 28841 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2edxx.dll
+ 2010-01-27 02:09 . 2010-01-27 02:09 50704 c:\windows\system32\drivers\npf.sys
+ 2001-10-25 14:00 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
- 2011-01-20 17:30 . 2008-04-14 07:52 54272 c:\windows\system32\dllcache\vfwwdm32.dll
+ 2011-01-20 17:30 . 2008-04-14 06:52 54272 c:\windows\system32\dllcache\vfwwdm32.dll
+ 2011-06-21 18:18 . 2011-09-05 13:56 37888 c:\windows\system32\dllcache\url.dll
+ 2001-10-25 14:00 . 2011-09-26 09:41 22528 c:\windows\system32\dllcache\oleaccrc.dll
+ 2011-08-11 16:42 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
- 2004-08-17 13:49 . 2011-04-25 14:47 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2011-09-10 18:22 . 2008-04-14 06:51 21504 c:\windows\system32\dllcache\hidserv.dll
- 2010-09-23 13:55 . 2010-09-23 13:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 12:00 . 2011-07-08 12:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 10:04 . 2011-07-07 10:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 00:26 . 2010-09-23 00:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 10:04 . 2011-07-07 10:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 00:26 . 2010-09-23 00:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 00:26 . 2010-09-23 00:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 10:03 . 2011-07-07 10:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 01:17 . 2010-09-23 01:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 11:09 . 2011-07-07 11:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-09-23 01:17 . 2010-09-23 01:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-07-07 11:09 . 2011-07-07 11:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-09-25 15:44 . 2011-09-25 15:44 22016 c:\windows\Installer\1adf9b66.msi
+ 2011-09-05 11:44 . 2011-09-05 11:44 10134 c:\windows\Installer\{F7F2F97C-D65C-550D-FEBE-6B71ED9D241F}\ARPPRODUCTICON.exe
+ 2011-09-05 11:45 . 2011-09-05 11:45 10134 c:\windows\Installer\{C5D11688-7A08-C8E6-BD36-67B88E3A245F}\ARPPRODUCTICON.exe
+ 2011-09-05 11:43 . 2011-09-09 17:06 88102 c:\windows\Installer\{AC5F0006-B59B-EEB5-BAE2-02F53E6A484D}\NewShortcut5_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-09-05 11:43 . 2011-09-09 17:06 88102 c:\windows\Installer\{AC5F0006-B59B-EEB5-BAE2-02F53E6A484D}\NewShortcut4_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-09-05 11:43 . 2011-09-09 17:06 88102 c:\windows\Installer\{AC5F0006-B59B-EEB5-BAE2-02F53E6A484D}\NewShortcut3_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-09-05 11:43 . 2011-09-09 17:06 88102 c:\windows\Installer\{AC5F0006-B59B-EEB5-BAE2-02F53E6A484D}\NewShortcut2_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2011-09-09 17:06 . 2011-09-09 17:06 88102 c:\windows\Installer\{AC5F0006-B59B-EEB5-BAE2-02F53E6A484D}\ARPPRODUCTICON.exe
+ 2011-09-05 11:45 . 2011-09-05 11:45 10134 c:\windows\Installer\{A25FF1C0-80B6-4B8B-A551-DC525697A408}\ARPPRODUCTICON.exe
- 2011-06-26 07:54 . 2011-06-26 07:54 10134 c:\windows\Installer\{A25FF1C0-80B6-4B8B-A551-DC525697A408}\ARPPRODUCTICON.exe
+ 2011-09-12 13:36 . 2011-09-12 13:36 10134 c:\windows\Installer\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\ARPPRODUCTICON.exe
+ 2011-07-20 15:11 . 2011-07-20 15:11 10134 c:\windows\Installer\{92AF2F5A-4407-4A03-A80A-5A2582264746}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 23040 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 23040 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 61440 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 61440 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 27136 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 27136 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 11264 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 11264 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 86016 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 86016 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 12288 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 12288 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2011-09-12 13:34 . 2011-09-12 13:34 10134 c:\windows\Installer\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\ARPPRODUCTICON.exe
+ 2011-09-09 17:06 . 2011-09-09 17:06 10134 c:\windows\Installer\{80612765-75C0-274D-A7E7-D24F3C928A9B}\ARPPRODUCTICON.exe
+ 2011-09-05 11:44 . 2011-09-05 11:44 10134 c:\windows\Installer\{284B8284-A557-F842-5A71-78B49BB56B6B}\ARPPRODUCTICON.exe
- 2011-06-26 07:54 . 2011-06-26 07:54 10134 c:\windows\Installer\{19A492A0-888F-44A0-9B21-D91700763F62}\ARPPRODUCTICON.exe
+ 2011-09-05 11:44 . 2011-09-05 11:44 10134 c:\windows\Installer\{19A492A0-888F-44A0-9B21-D91700763F62}\ARPPRODUCTICON.exe
+ 2011-09-05 11:44 . 2011-09-05 11:44 10134 c:\windows\Installer\{141EB687-5AFE-B981-0A01-A62F6B862712}\ARPPRODUCTICON.exe
+ 2011-07-29 18:34 . 2011-07-29 20:04 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2011-07-29 18:34 . 2011-07-29 20:04 10134 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2007-10-24 19:13 . 2007-10-24 19:13 13024 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\shallocator.dll
+ 2007-10-24 22:11 . 2007-10-24 22:11 17120 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysisdedicatedserver.exe
+ 2011-10-13 04:32 . 2011-10-13 04:32 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_fa500368\System.Drawing.Design.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_273cf4c0\CustomMarshalers.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 75776 c:\windows\assembly\NativeImages_v2.0.50727_32\UpdateCheck\de56c0e8d1f10594041a5a149e4aecc5\UpdateCheck.ni.exe
+ 2011-08-28 07:53 . 2011-08-28 07:53 75776 c:\windows\assembly\NativeImages_v2.0.50727_32\UpdateCheck\3e064a52216827ee236bb09578555e24\UpdateCheck.ni.exe
+ 2011-10-13 04:49 . 2011-10-13 04:49 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\888b745ca99d39692c2e9af222e5eae8\UIAutomationProvider.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\6c334564da041df8fb75415f2d503224\System.Windows.Presentation.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\343c52b741531ce9ae874ea7508831a7\System.Windows.Presentation.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a54a122f1070ab71931dd9679ddd8e90\System.Web.DynamicData.Design.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\246110974e3c48733458819b07464b23\System.Web.DynamicData.Design.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ace861fe8dbf146c3e449abaa7691e9f\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-13 14:47 . 2011-10-13 14:47 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\ac92806d5bd508eb25f1b4b73a36b101\System.ComponentModel.DataAnnotations.ni.dll
+ 2011-10-13 14:47 . 2011-10-13 14:47 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\e6a9cd66d11a21776dbf425e8e28099c\System.AddIn.Contract.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\66873b557d5c7013e4c630361473b0c2\PresentationFontCache.ni.exe
+ 2011-08-12 11:54 . 2011-08-12 11:54 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\40ee65aacd9d7472cd6f8dddbfca604b\PresentationFontCache.ni.exe
+ 2011-10-13 04:49 . 2011-10-13 04:49 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\5b30652a7b802199984f93b5e414260f\PresentationCFFRasterizer.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\12c424eed7ee0e9c017bf72ff09eb78c\PresentationCFFRasterizer.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 96768 c:\windows\assembly\NativeImages_v2.0.50727_32\NeroBar\c8887a070ae61dbc37f5fc9fa0584009\NeroBar.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 96768 c:\windows\assembly\NativeImages_v2.0.50727_32\NeroBar\2a19646fd908ade85bb84bff8034639f\NeroBar.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\f9c514544c8e23220493cd42a0e20678\Microsoft.Vsa.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\eaa8d72317e5b8047e413939cc71ffba\Microsoft.Vsa.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\a140509b1342934fc5e58ae22ac9696c\Microsoft.VisualC.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\aefe683674c97a998f4e908c1a7ee7c6\Microsoft.Build.Framework.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\845eef4d09f28da6ee05d99f93c90f6e\Microsoft.Build.Framework.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 44544 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop\cc9da65719197dc00c2a27658e180d6a\Interop.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 44544 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop\9d1b56973da4b593f90aac72024fa4c0\Interop.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\GFTray\cf41a294f7ca94e019e62a332ba547b7\GFTray.ni.exe
+ 2011-08-28 07:53 . 2011-08-28 07:53 86528 c:\windows\assembly\NativeImages_v2.0.50727_32\GFTray\a3e1aa256ecbb2133ea9e45e3f9e6927\GFTray.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\ab7ce2d94ca725c3889a4e3c1ee88ece\dfsvc.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\ControlLibrary\9e1ba852af824d40c4136533f003459a\ControlLibrary.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\ControlLibrary\75d1200a42589df19641ba59079e5443\ControlLibrary.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 53248 c:\windows\assembly\NativeImages_v2.0.50727_32\AjaVideoProperties\b3ce2bfc2605ce4bc81c33b9f57c0f5c\AjaVideoProperties.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 53248 c:\windows\assembly\NativeImages_v2.0.50727_32\AjaVideoProperties\13a09fb48e89e292789c04769bb8e800\AjaVideoProperties.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-10-03 05:39 . 2010-10-03 05:39 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-08-28 11:24 . 2011-08-28 11:24 16384 c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
- 2010-10-26 14:47 . 2010-10-26 14:47 16384 c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2011-08-28 11:24 . 2011-08-28 11:24 64088 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2010-10-26 14:47 . 2010-10-26 14:47 64088 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2011-08-26 16:24 . 2010-11-03 13:12 46080 c:\windows\$NtUninstallKB2570791$\tzchange.exe
+ 2011-08-26 16:24 . 2011-07-09 00:32 16896 c:\windows\$NtUninstallKB2570791$\spuninst\tzchange.dll
+ 2011-08-11 16:46 . 2008-04-13 22:27 10112 c:\windows\$NtUninstallKB2566454$\ndistapi.sys
+ 2011-08-11 16:46 . 2008-04-14 06:52 37888 c:\windows\$NtUninstallKB2559049$\url.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 81920 c:\windows\$NtUninstallKB2559049$\ieencode.dll
+ 2011-09-08 11:23 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2607712\update\spcustom.dll
+ 2011-09-08 11:23 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2607712\spmsg.dll
+ 2011-08-11 16:50 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2570222\update\spcustom.dll
+ 2011-08-11 16:50 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2570222\spmsg.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 26488 c:\windows\$hf_mig$\KB2567680\update\spcustom.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 18296 c:\windows\$hf_mig$\KB2567680\spmsg.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 26488 c:\windows\$hf_mig$\KB2566454\update\spcustom.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 18296 c:\windows\$hf_mig$\KB2566454\spmsg.dll
+ 2011-08-11 16:42 . 2011-07-08 13:51 10496 c:\windows\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys
+ 2011-08-11 16:46 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2562937\update\spcustom.dll
+ 2011-08-11 16:46 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2562937\spmsg.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 26488 c:\windows\$hf_mig$\KB2559049\update\spcustom.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 18296 c:\windows\$hf_mig$\KB2559049\spmsg.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 37888 c:\windows\$hf_mig$\KB2559049\SP3QFE\url.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 81920 c:\windows\$hf_mig$\KB2559049\SP3QFE\ieencode.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 26488 c:\windows\$hf_mig$\KB2536276-v2\update\spcustom.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 18296 c:\windows\$hf_mig$\KB2536276-v2\spmsg.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 1999-05-19 13:58 . 1999-05-19 13:58 7680 c:\windows\system32\MSPRPCS.DLL
- 1999-05-19 14:58 . 1999-05-19 14:58 7680 c:\windows\system32\MSPRPCS.DLL
+ 2011-09-05 11:43 . 2011-07-28 21:00 8347 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atitvo32.dll
+ 2011-09-05 11:45 . 2011-09-05 11:45 9662 c:\windows\Installer\{C5D11688-7A08-C8E6-BD36-67B88E3A245F}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2011-07-20 15:11 . 2011-07-20 15:11 9662 c:\windows\Installer\{92AF2F5A-4407-4A03-A80A-5A2582264746}\ARPPRODUCTICON.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 4096 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 4096 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2011-07-29 18:34 . 2011-07-29 20:04 9662 c:\windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
- 2011-06-22 19:10 . 2011-06-22 19:10 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-08-28 11:24 . 2011-08-28 11:24 4096 c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
- 2010-10-26 14:47 . 2010-10-26 14:47 4096 c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2009-06-07 14:16 . 2009-06-07 14:16 819200 c:\windows\system32\xvidcore.dll
+ 2010-01-27 02:09 . 2010-01-27 02:09 281104 c:\windows\system32\wpcap.dll
+ 2002-08-21 03:13 . 2002-08-21 03:13 189952 c:\windows\system32\WISPTIS.EXE
- 2002-08-21 04:13 . 2002-08-21 04:13 189952 c:\windows\system32\WISPTIS.EXE
+ 2004-08-17 13:49 . 2011-06-20 17:44 293376 c:\windows\system32\winsrv.dll
- 2004-08-17 13:49 . 2011-04-26 11:07 293376 c:\windows\system32\winsrv.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 627712 c:\windows\system32\urlmon.dll
- 2010-10-26 14:48 . 2003-06-19 00:31 758784 c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2011-08-28 11:25 . 2003-06-18 23:31 758784 c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2011-08-28 11:25 . 2003-06-18 23:31 758784 c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2010-10-26 14:48 . 2003-06-19 00:31 758784 c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2011-09-09 17:06 . 2011-07-28 21:13 155648 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\Oemdspif.dll
+ 2011-09-09 17:06 . 2011-07-28 21:27 956160 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ativvamv.dll
+ 2011-09-09 17:06 . 2011-07-28 21:10 887724 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ativva6x.dat
+ 2011-09-09 17:06 . 2011-05-25 02:39 212992 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atipdlxx.dll
+ 2011-09-09 17:06 . 2011-05-25 03:05 503808 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atiok3x2.dll
+ 2011-09-09 17:06 . 2010-08-27 18:32 294912 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ATIODE.exe
+ 2011-09-09 17:06 . 2011-05-25 02:31 651264 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atikvmag.dll
+ 2011-09-09 17:06 . 2011-07-28 22:17 311296 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atiiiexx.dll
+ 2011-09-09 17:06 . 2011-06-27 18:53 234855 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atiicdxx.dat
+ 2011-09-09 17:06 . 2011-07-28 21:32 462848 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ATIDEMGX.dll
+ 2011-09-09 17:06 . 2009-05-11 21:35 118784 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atibtmon.exe
+ 2011-09-09 17:06 . 2011-07-28 21:09 151552 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atiapfxx.exe
+ 2011-09-09 17:06 . 2011-05-25 02:27 200704 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atiadlxx.dll
+ 2011-09-09 17:06 . 2011-05-25 02:37 643072 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2evxx.exe
+ 2011-09-09 17:06 . 2011-05-25 02:38 188416 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2evxx.dll
+ 2011-09-09 17:06 . 2011-05-25 02:55 302592 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2dvag.dll
+ 2011-09-09 17:06 . 2011-05-25 02:22 856064 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2cqag.dll
+ 2000-04-03 15:52 . 2000-04-03 15:52 151552 c:\windows\system32\RDOCURS.DLL
- 2000-04-03 16:52 . 2000-04-03 16:52 151552 c:\windows\system32\RDOCURS.DLL
+ 2001-10-25 14:00 . 2011-10-13 04:47 446776 c:\windows\system32\perfh009.dat
+ 2001-10-25 14:00 . 2011-10-13 04:47 443642 c:\windows\system32\perfh005.dat
+ 2010-01-27 02:09 . 2010-01-27 02:09 100880 c:\windows\system32\Packet.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 532480 c:\windows\system32\mstime.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 532480 c:\windows\system32\mstime.dll
- 2000-05-24 05:45 . 2000-05-24 05:45 118784 c:\windows\system32\MSSTDFMT.DLL
+ 2000-05-24 04:45 . 2000-05-24 04:45 118784 c:\windows\system32\MSSTDFMT.DLL
+ 2000-05-11 11:06 . 2000-05-11 11:06 397312 c:\windows\system32\MSRDO20.DLL
- 2000-05-11 12:06 . 2000-05-11 12:06 397312 c:\windows\system32\MSRDO20.DLL
- 2004-08-17 13:49 . 2011-04-25 14:47 449536 c:\windows\system32\mshtmled.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 449536 c:\windows\system32\mshtmled.dll
+ 2004-08-17 15:49 . 2008-04-14 06:53 294912 c:\windows\system32\msh263.drv
- 2004-08-17 15:49 . 2008-04-14 07:53 294912 c:\windows\system32\msh263.drv
+ 2002-08-21 03:10 . 2002-08-21 03:10 204800 c:\windows\system32\INKED.DLL
- 2002-08-21 04:10 . 2002-08-21 04:10 204800 c:\windows\system32\INKED.DLL
+ 2004-08-17 13:49 . 2011-09-05 13:56 251904 c:\windows\system32\iepeers.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 251904 c:\windows\system32\iepeers.dll
+ 2011-09-05 14:15 . 2011-09-05 14:15 232512 c:\windows\system32\DRVSTORE\dtsoftbus0_96CD4CCD694797A5F664292054A030F47D8B3AEA\dtsoftbus01.sys
+ 2011-09-05 11:43 . 2011-07-28 21:27 501642 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ativvamv.dll
+ 2011-09-05 11:43 . 2011-07-28 21:10 887724 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ativva6x.dat
+ 2011-09-05 11:43 . 2011-07-28 21:14 110216 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atipdlxx.dll
+ 2011-09-05 11:43 . 2011-07-28 20:59 237390 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiok3x2.dll
+ 2011-09-05 11:43 . 2011-07-28 21:05 361886 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atikvmag.dll
+ 2011-09-05 11:43 . 2011-07-28 22:17 311296 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiiiexx.dll
+ 2011-09-05 11:43 . 2011-06-27 18:53 234855 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiicdxx.dat
+ 2011-09-05 11:43 . 2011-07-28 21:32 462848 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atidemgx.dll
+ 2011-09-05 11:43 . 2011-07-28 21:01 114203 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atiadlxx.dll
+ 2011-09-05 11:43 . 2011-07-28 21:12 345540 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2evxx.exe
+ 2011-09-05 11:43 . 2011-07-28 21:13 102784 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2evxx.dll
+ 2011-09-05 11:43 . 2011-07-28 21:31 190532 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2dvag.dll
+ 2011-09-05 11:43 . 2011-07-28 20:55 441130 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2cqag.dll
- 2008-01-26 14:17 . 2008-04-14 06:53 139656 c:\windows\system32\drivers\rdpwd.sys
+ 2008-01-26 14:17 . 2011-06-24 14:10 139656 c:\windows\system32\drivers\rdpwd.sys
- 2004-08-03 21:15 . 2011-04-29 16:19 456320 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-03 21:15 . 2011-07-15 13:29 456320 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-03 23:15 . 2008-04-13 22:46 141056 c:\windows\system32\drivers\ks.sys
- 2004-08-03 23:15 . 2008-04-13 23:46 141056 c:\windows\system32\drivers\ks.sys
+ 2010-06-18 17:47 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
- 2010-06-18 17:47 . 2011-04-26 11:07 293376 c:\windows\system32\dllcache\winsrv.dll
- 2008-04-21 06:45 . 2011-04-25 14:47 668160 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-21 06:45 . 2011-09-05 13:56 668160 c:\windows\system32\dllcache\wininet.dll
+ 2008-06-26 08:14 . 2011-09-05 13:56 627712 c:\windows\system32\dllcache\urlmon.dll
+ 2011-08-11 16:42 . 2011-06-24 14:10 139656 c:\windows\system32\dllcache\rdpwd.sys
+ 2001-10-25 14:00 . 2011-09-26 09:41 220160 c:\windows\system32\dllcache\oleacc.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 532480 c:\windows\system32\dllcache\mstime.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 532480 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 449536 c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 449536 c:\windows\system32\dllcache\mshtmled.dll
- 2008-11-12 19:25 . 2011-04-29 16:19 456320 c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-11-12 19:25 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
- 2004-08-03 23:15 . 2008-04-13 23:46 141056 c:\windows\system32\dllcache\ks.sys
+ 2004-08-03 23:15 . 2008-04-13 22:46 141056 c:\windows\system32\dllcache\ks.sys
+ 2004-08-17 13:49 . 2011-09-05 13:56 251904 c:\windows\system32\dllcache\iepeers.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2011-09-03 10:17 . 2011-09-09 09:12 602112 c:\windows\system32\dllcache\crypt32.dll
+ 2008-06-20 11:40 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
- 2004-02-22 08:11 . 2004-02-22 08:11 719872 c:\windows\system32\devil.dll
+ 2004-02-22 08:11 . 2004-02-22 08:11 719872 c:\windows\system32\devil.dll
+ 2008-12-21 21:46 . 2008-12-21 21:46 351744 c:\windows\system32\avisynth.dll
- 2010-02-11 04:12 . 2011-05-25 02:51 887724 c:\windows\system32\ativva6x.dat
+ 2010-02-11 04:12 . 2011-07-28 21:10 887724 c:\windows\system32\ativva6x.dat
+ 2008-02-06 17:06 . 2011-06-27 18:53 234855 c:\windows\system32\atiicdxx.dat
- 2011-03-25 04:15 . 2011-03-25 04:15 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2011-07-07 03:18 . 2011-07-07 03:18 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
- 2011-03-25 04:15 . 2011-03-25 04:15 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2011-07-07 03:18 . 2011-07-07 03:18 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
- 2010-09-23 00:26 . 2010-09-23 00:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 10:04 . 2011-07-07 10:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 00:25 . 2010-09-23 00:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 10:01 . 2011-07-07 10:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 01:17 . 2010-09-23 01:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 11:09 . 2011-07-07 11:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-09-09 17:06 . 2011-09-09 17:06 440320 c:\windows\Installer\fe84ac.msi
+ 2011-09-05 11:45 . 2011-09-05 11:45 843264 c:\windows\Installer\4d3858e.msi
+ 2011-09-05 11:44 . 2011-09-05 11:44 231936 c:\windows\Installer\4d38578.msi
+ 2011-09-05 11:44 . 2011-09-05 11:44 251392 c:\windows\Installer\4d38572.msi
+ 2011-09-05 11:44 . 2011-09-05 11:44 264192 c:\windows\Installer\4d3856c.msi
+ 2011-09-05 11:44 . 2011-09-05 11:44 323584 c:\windows\Installer\4d38562.msi
+ 2011-09-12 13:15 . 2011-09-12 13:15 216358 c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe
+ 2011-10-13 18:25 . 2011-10-13 18:25 839242 c:\windows\Installer\{97F868BE-3FCD-42BB-863B-36EE10E60127}\NewShortcut7_AA71C5EB7F9F41EA9AB9B57E240142F5.exe
+ 2011-10-13 18:25 . 2011-10-13 18:25 630784 c:\windows\Installer\{97F868BE-3FCD-42BB-863B-36EE10E60127}\NewShortcut11_5505D87059B349C9863A6517D79862AA.exe
+ 2011-10-13 18:25 . 2011-10-13 18:25 630784 c:\windows\Installer\{97F868BE-3FCD-42BB-863B-36EE10E60127}\NewShortcut1_F7F8582E40BB44E68609E536A446BA80.exe
+ 2011-10-13 18:25 . 2011-10-13 18:25 839242 c:\windows\Installer\{97F868BE-3FCD-42BB-863B-36EE10E60127}\ARPPRODUCTICON.exe
- 2008-01-27 12:04 . 2011-06-25 16:51 409600 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 409600 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 286720 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 286720 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 249856 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 249856 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 794624 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 794624 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 135168 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 135168 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2011-08-28 11:25 . 2011-09-26 16:32 593920 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2010-10-26 14:47 . 2011-06-25 16:51 593920 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2011-07-19 17:49 . 2011-07-19 17:49 478432 c:\windows\Installer\{6033673D-2530-4587-8AD0-EB059FC263F9}\Crysis2Launcher.exe
+ 2011-08-28 14:14 . 2011-08-28 14:14 478432 c:\windows\Installer\{6033673D-2530-4587-8AD0-EB059FC263F9}\Crysis2Launcher.exe
+ 2007-09-19 14:29 . 2007-09-19 14:29 294912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\pbsv.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 644320 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysoundsystem.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 660704 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryscriptsystem.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 885984 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrendernull.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 943328 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crynetwork.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 386272 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crymovie.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 197856 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryinput.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 394464 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryfont.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 840928 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryentitysystem.dll
+ 2008-11-12 19:25 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
- 2008-11-12 19:25 . 2011-04-29 16:19 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-10-13 04:32 . 2011-10-13 04:32 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_912b3699\System.Drawing.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_20f882a2\System.Drawing.Design.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_69eb9090\CustomMarshalers.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\cc14c69205b984edba1db26fd5e421ac\WsatConfig.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\c8627df7adb416722d8e0f05c57fef6b\WsatConfig.ni.exe
+ 2011-10-13 04:52 . 2011-10-13 04:52 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a2c1bb3c5b1447b398e72c56091ca571\WindowsFormsIntegration.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\39ce0c9c9cc294c0ee26c4ff01522961\WindowsFormsIntegration.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f102afdffdbe2565bcedb7fa0626b865\UIAutomationTypes.ni.dll
+ 2011-10-13 04:52 . 2011-10-13 04:52 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\ba55240b7753047f8d1b03ef473bf74e\UIAutomationClient.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\431e918aee8da919f5b9e3a5195ccf93\UIAutomationClient.ni.dll
+ 2011-08-28 14:20 . 2011-08-28 14:20 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\946eefb99bc116ee68e0e7c69a5a8a5c\System.Xml.Linq.ni.dll
+ 2011-10-14 11:26 . 2011-10-14 11:26 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\566b2e11e7f3f6d973b17b86cf42f9bc\System.Xml.Linq.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\a82eef3128b9527dc05b3c8667e713bc\System.Web.Routing.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\3533d614ebecd4344efbee619dd11a74\System.Web.Routing.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\203c148c913357bfc2ae9d209101f2b3\System.Web.RegularExpressions.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\018b6e48c32d5b5d78086998e3505f1c\System.Web.RegularExpressions.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f89fe39468ea6faf71c4257c89cf3c54\System.Web.Extensions.Design.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\d93514a764a83b18f6f3547b59cc8ae9\System.Web.Extensions.Design.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\93b5d1b77a74b76ac73cbf51ec871c01\System.Web.Entity.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\2314ff800782dc85224e69e802a073f7\System.Web.Entity.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f690a8f5d784a5bb20f2cbaa7277eb6c\System.Web.Entity.Design.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d06a7d5872bbe85795f947f6c75d38c6\System.Web.Entity.Design.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\c5c96400424b85536443623f96f64581\System.Web.DynamicData.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\ad0851438a18bf730d974c9b2f5f776a\System.Web.DynamicData.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\734ab0ea87d7dfd5c583eea535c05878\System.Web.Abstractions.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5f8e87b47465a038403e73012c6d102a\System.Web.Abstractions.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\846dd505f97805f00999ee26aec9bf75\System.Transactions.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\de9cd25ccb24bcf8a0316756e766721f\System.Security.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\21248037960cf6dfa2ce401d355bd6c9\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b7e0214a811f81e09041864081139641\System.Runtime.Remoting.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\36bf3d5f05a40c9e3cadca5789c8a469\System.Runtime.Remoting.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\b2a84980f206431821d85d5155d5916f\System.Net.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\480ea914e13fe41cdd8fb542bb1f7e81\System.Net.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\8acd508fd65801747e89bb5ab7e981e4\System.Messaging.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\18a7efd299665b8bfa0d0dc6701343c6\System.Messaging.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e563a58e6fc0117070d5b8fd59e4e1b\System.Management.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\f36eded354122da9555a6c7cdbdb5431\System.Management.Instrumentation.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\dc72c7581f1b3794c0ea595ba02ff7ad\System.Management.Instrumentation.ni.dll
+ 2011-08-28 07:51 . 2011-08-28 07:51 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\fcf8612a210d1f76e0b37dc8467b4696\System.IO.Log.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\20a77c41ee12362d303fb2574fcd5a24\System.IO.Log.ni.dll
+ 2011-08-28 07:51 . 2011-08-28 07:51 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\ec017b5a95d02fccaefd835490ef1e14\System.IdentityModel.Selectors.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\41c3a2fcffc58b20023c7d54e57ea956\System.IdentityModel.Selectors.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.Wrapper.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\75f452279422a7898e840ee5768c9d2e\System.EnterpriseServices.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.Wrapper.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\f7cd3d07c15366b76fe4c38d24455d6b\System.Drawing.Design.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\896eca06e2d9377b2dc4fad56ce49b07\System.Drawing.Design.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\822c996e6ad4901219b7de399a6f78bf\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\33e9b0c368c31ef37a2ec7b5a181044b\System.DirectoryServices.Protocols.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1ffe911e62f482e42be2c4428bd08c10\System.DirectoryServices.Protocols.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\11cdd1c0d65428cd3505d3813d36638c\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e5ada332a9bc3c982e6aede6ba354196\System.Data.Services.Client.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e1c009b2c9becdb732a2ea45f32a46b8\System.Data.Services.Design.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3f179f373f31817a914b639a56cc0497\System.Data.Services.Design.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1defd94e1662a4478ccf2cd0b1b4e6a6\System.Data.Services.Client.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\fee1a48b769a8c4beb335ee5ce006091\System.Data.Entity.Design.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\04267c1dbdcdd8ec37e1518126767ead\System.Data.Entity.Design.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\f2a6d41b3f6e26eea6dcac9298aa637b\System.Data.DataSetExtensions.ni.dll
+ 2011-10-13 14:47 . 2011-10-13 14:47 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\b9d9ff5d03e90ede1116794f2c7dd6da\System.Data.DataSetExtensions.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\585e68739b2a8aff61ee6b2786513245\System.Configuration.Install.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\29d7091f6eab0ec61c4eb625ed221b73\System.Configuration.Install.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\fbf6ef12d1456058acde29f2640092fb\System.AddIn.ni.dll
+ 2011-10-13 14:47 . 2011-10-13 14:47 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\3048737e9e3bf5173121a084337256bc\System.AddIn.ni.dll
+ 2011-10-13 04:52 . 2011-10-13 04:52 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\90e4975b3dffcc5ba853ec0fe1d912cb\sysglobl.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 869888 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Vegas\b782078389047c7ee2f48716105d25a6\Sony.Vegas.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 869888 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Vegas\7c9f6cd6a33cae9fd29eb080136e1993\Sony.Vegas.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 222208 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Vegas.NetRender\ad4cd8559a40365790946d149de50129\Sony.Vegas.NetRender.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 222208 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Vegas.NetRender\4057b7c4e4f5bbea407d2d1bf319eb19\Sony.Vegas.NetRender.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 278016 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.MediaSoftware.#\dda1b2ea9c40765e660e0868cf4c0765\Sony.MediaSoftware.ExternalVideoDevice.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 278016 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.MediaSoftware.#\d926d7c7f67c0045a82d1bd39a72720e\Sony.MediaSoftware.ExternalVideoDevice.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 644096 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Capture\ee92e3c73b94a9f9ff66212603fbc771\Sony.Capture.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 644096 c:\windows\assembly\NativeImages_v2.0.50727_32\Sony.Capture\72e0b106e2c32455acd84001f9586c71\Sony.Capture.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\896e42071939e038008b0bbbfed1213c\SMSvcHost.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\6e45cf503f025c5fe814ea7e52f62a78\SMSvcHost.ni.exe
+ 2011-08-28 07:53 . 2011-08-28 07:53 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\ca07e9cf488af1290d2340d682574a24\SMDiagnostics.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\474a341340f687bcbd7777f2820a8c7a\SMDiagnostics.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\f2df1ca28301bfe7e1d52b86c8394217\ServiceModelReg.ni.exe
+ 2011-08-28 07:53 . 2011-08-28 07:53 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\a5aa977dd575a6beb3a416bd480b98a7\ServiceModelReg.ni.exe
+ 2011-08-12 11:55 . 2011-08-12 11:55 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f52e48f55258d0a04fbab3a1f93752e9\PresentationFramework.Classic.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\cf812b99f587ab514afb36fa9d4c1567\PresentationFramework.Aero.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c2ebcc8d60422f224b4088f3d7a2ac1f\PresentationFramework.Luna.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b7795999cc67f3a6cec40f5b24005e00\PresentationFramework.Luna.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94cfc00ad448575bfb0e67c53b514cd5\PresentationFramework.Aero.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\478d57d96f3d8d5fc15c7ac635a4a6a1\PresentationFramework.Classic.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\23c5852ff8ed973ff9b63ce9ba7f91f0\PresentationFramework.Royale.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09f5af61ea2af04eb32c04b3091ffc86\PresentationFramework.Royale.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\2d89c7b72bc8e527b26d5b6f3b931012\MSBuild.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\04595f414c49cf2a65b349648ba23e62\MSBuild.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\4cbd7ed9fbf9f1b3cbdf23906cc0f5a3\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\39e9d172f0cf5eec30b1b67212cc032b\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\ff6d4892775fd1f9b137f7c92ea453f2\Microsoft.Build.Utilities.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\f1b0ec3ccde9142e67ac681fb521ac66\Microsoft.Build.Utilities.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\9250f038410f0d6432e3ccb0b046862b\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-10-13 14:47 . 2011-10-13 14:47 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\47ff0720cb80a0fc0bbd15ddc3d12adc\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\da112c5757e3c68d6369b6aa46cc9682\Microsoft.Build.Engine.ni.dll
+ 2011-08-28 09:51 . 2011-08-28 09:51 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\a4672179aba638cd78bdfe268391b47b\Microsoft.Build.Engine.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\dc278e1123086ae32fec8f7e9751db14\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-08-28 09:51 . 2011-08-28 09:51 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\37db660a84ee52b61a7ca55812581bbd\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 634880 c:\windows\assembly\NativeImages_v2.0.50727_32\GameFire\cb3d27a55dc50dd55660bf30cf3379f8\GameFire.ni.exe
+ 2011-10-13 14:45 . 2011-10-13 14:45 634880 c:\windows\assembly\NativeImages_v2.0.50727_32\GameFire\b9c7170094b7f427dae2e844c774484e\GameFire.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 325632 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreUI\84aaf71600e2e7333f1d8b396a4ec4f5\CoreUI.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 325632 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreUI\0d8293187c8b7258e876429c4872fc9d\CoreUI.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 809984 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreUI.XmlSerialize#\d85a033387dbfdef9c45c717b5b78f28\CoreUI.XmlSerializers.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 809984 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreUI.XmlSerialize#\903a171bfa4cc53312c779d9a173250a\CoreUI.XmlSerializers.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 119808 c:\windows\assembly\NativeImages_v2.0.50727_32\CorePrimitives\ad3b4e0a73613976bb52d67a8d9e5677\CorePrimitives.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 119808 c:\windows\assembly\NativeImages_v2.0.50727_32\CorePrimitives\5f75813ab6792275384a4b9261aa73c5\CorePrimitives.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\fe9a21b94803f74697bb42b9d1fdea5b\ComSvcConfig.ni.exe
+ 2011-10-13 14:46 . 2011-10-13 14:46 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\4e68d5df30b197ff72c75f1c3c24b949\ComSvcConfig.ni.exe
+ 2011-08-28 07:51 . 2011-08-28 07:51 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\f160c8e40b60edd47ae74b0b911fece1\AspNetMMCExt.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\e1bcee92f5af50d560d577c0a99ea3bd\AspNetMMCExt.ni.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

Re: o5 revelantknowledge

Napsal: 14 říj 2011 12:50
od [ACze]miky
ComboFix 2. část logu:

- 2011-06-22 19:10 . 2011-06-22 19:10 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2010-10-26 14:47 . 2010-10-26 14:47 223800 c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2011-08-28 11:24 . 2011-08-28 11:24 223800 c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
- 2010-10-26 14:47 . 2010-10-26 14:47 229376 c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2011-08-28 11:24 . 2011-08-28 11:24 229376 c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
- 2011-07-18 08:57 . 2011-07-18 08:57 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2011-09-12 13:17 . 2011-09-12 13:17 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2010-10-26 14:47 . 2010-10-26 14:47 110592 c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2011-08-28 11:24 . 2011-08-28 11:24 110592 c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2011-09-08 11:23 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2607712$\spuninst\updspapi.dll
+ 2011-09-08 11:23 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2607712$\spuninst\spuninst.exe
+ 2011-09-08 11:23 . 2008-04-14 06:51 602112 c:\windows\$NtUninstallKB2607712$\crypt32.dll
+ 2011-08-26 16:24 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2570791$\spuninst\updspapi.dll
+ 2011-08-26 16:24 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2570791$\spuninst\spuninst.exe
+ 2011-08-11 16:50 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2570222$\spuninst\updspapi.dll
+ 2011-08-11 16:50 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2570222$\spuninst\spuninst.exe
+ 2011-08-11 16:50 . 2008-04-14 06:53 139656 c:\windows\$NtUninstallKB2570222$\rdpwd.sys
+ 2011-08-11 16:50 . 2011-04-26 11:07 293376 c:\windows\$NtUninstallKB2567680$\winsrv.dll
+ 2011-08-11 16:50 . 2010-02-22 14:21 391032 c:\windows\$NtUninstallKB2567680$\spuninst\updspapi.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 233848 c:\windows\$NtUninstallKB2567680$\spuninst\spuninst.exe
+ 2011-08-11 16:46 . 2010-02-22 14:21 391032 c:\windows\$NtUninstallKB2566454$\spuninst\updspapi.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 233848 c:\windows\$NtUninstallKB2566454$\spuninst\spuninst.exe
+ 2011-08-11 16:46 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2562937$\spuninst\updspapi.dll
+ 2011-08-11 16:46 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2562937$\spuninst\spuninst.exe
+ 2011-08-11 16:46 . 2011-04-25 14:47 668160 c:\windows\$NtUninstallKB2559049$\wininet.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 627200 c:\windows\$NtUninstallKB2559049$\urlmon.dll
+ 2011-08-11 16:46 . 2010-02-22 14:21 391032 c:\windows\$NtUninstallKB2559049$\spuninst\updspapi.dll
+ 2011-08-11 16:46 . 2010-02-22 14:20 233848 c:\windows\$NtUninstallKB2559049$\spuninst\spuninst.exe
+ 2011-08-11 16:46 . 2011-04-25 14:47 532480 c:\windows\$NtUninstallKB2559049$\mstime.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 449536 c:\windows\$NtUninstallKB2559049$\mshtmled.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 251904 c:\windows\$NtUninstallKB2559049$\iepeers.dll
+ 2011-08-11 16:50 . 2010-02-22 14:21 391032 c:\windows\$NtUninstallKB2536276-v2$\spuninst\updspapi.dll
+ 2011-08-11 16:50 . 2010-02-22 14:20 233848 c:\windows\$NtUninstallKB2536276-v2$\spuninst\spuninst.exe
+ 2011-08-11 16:50 . 2011-04-29 16:19 456320 c:\windows\$NtUninstallKB2536276-v2$\mrxsmb.sys
+ 2011-09-08 11:23 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2607712\update\updspapi.dll
+ 2011-09-08 11:23 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2607712\update\update.exe
+ 2011-09-08 11:23 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2607712\spuninst.exe
+ 2011-09-03 10:16 . 2011-09-03 10:16 602624 c:\windows\$hf_mig$\KB2607712\SP3QFE\crypt32.dll
+ 2011-08-11 16:50 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2570222\update\updspapi.dll
+ 2011-08-11 16:50 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2570222\update\update.exe
+ 2011-08-11 16:50 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2570222\spuninst.exe
+ 2011-08-11 16:42 . 2011-06-24 14:09 139656 c:\windows\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys
+ 2011-08-11 16:50 . 2010-02-22 14:21 391032 c:\windows\$hf_mig$\KB2567680\update\updspapi.dll
+ 2011-08-11 16:50 . 2010-02-22 14:21 759160 c:\windows\$hf_mig$\KB2567680\update\update.exe
+ 2011-08-11 16:50 . 2010-02-22 14:20 233848 c:\windows\$hf_mig$\KB2567680\spuninst.exe
+ 2011-06-20 17:43 . 2011-06-20 17:43 293376 c:\windows\$hf_mig$\KB2567680\SP3QFE\winsrv.dll
+ 2011-08-11 16:46 . 2010-02-22 14:21 391032 c:\windows\$hf_mig$\KB2566454\update\updspapi.dll
+ 2011-08-11 16:46 . 2010-02-22 14:21 759160 c:\windows\$hf_mig$\KB2566454\update\update.exe
+ 2011-08-11 16:46 . 2010-02-22 14:20 233848 c:\windows\$hf_mig$\KB2566454\spuninst.exe
+ 2011-08-11 16:46 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2562937\update\updspapi.dll
+ 2011-08-11 16:46 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2562937\update\update.exe
+ 2011-08-11 16:46 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2562937\spuninst.exe
+ 2011-08-11 16:46 . 2010-02-22 14:21 391032 c:\windows\$hf_mig$\KB2559049\update\updspapi.dll
+ 2011-08-11 16:46 . 2010-02-22 14:21 759160 c:\windows\$hf_mig$\KB2559049\update\update.exe
+ 2011-08-11 16:46 . 2010-02-22 14:20 233848 c:\windows\$hf_mig$\KB2559049\spuninst.exe
+ 2011-06-21 18:16 . 2011-06-21 18:16 669696 c:\windows\$hf_mig$\KB2559049\SP3QFE\wininet.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 628224 c:\windows\$hf_mig$\KB2559049\SP3QFE\urlmon.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 532480 c:\windows\$hf_mig$\KB2559049\SP3QFE\mstime.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 449536 c:\windows\$hf_mig$\KB2559049\SP3QFE\mshtmled.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 251904 c:\windows\$hf_mig$\KB2559049\SP3QFE\iepeers.dll
+ 2011-08-11 16:50 . 2010-02-22 14:21 391032 c:\windows\$hf_mig$\KB2536276-v2\update\updspapi.dll
+ 2011-08-11 16:50 . 2010-02-22 14:21 759160 c:\windows\$hf_mig$\KB2536276-v2\update\update.exe
+ 2011-08-11 16:50 . 2010-02-22 14:20 233848 c:\windows\$hf_mig$\KB2536276-v2\spuninst.exe
+ 2011-08-11 16:42 . 2011-07-15 13:29 457856 c:\windows\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys
+ 2011-06-16 01:34 . 2011-06-16 01:34 2117632 c:\windows\system32\SlotMaximizerBe.dll
- 2004-08-17 13:49 . 2011-04-25 14:47 1510912 c:\windows\system32\shdocvw.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 1510912 c:\windows\system32\shdocvw.dll
+ 2011-09-09 17:06 . 2011-05-25 02:54 3152384 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ativvaxx.dll
+ 2011-09-09 17:06 . 2011-07-28 21:57 5697536 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\aticaldd.dll
+ 2011-09-09 17:06 . 2011-05-25 03:14 4059328 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati3duag.dll
+ 2011-09-09 17:06 . 2011-07-28 22:20 7084544 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\ati2mtag.sys
+ 2004-08-17 13:49 . 2011-09-05 13:56 3107328 c:\windows\system32\mshtml.dll
+ 2008-01-26 15:10 . 2011-10-13 11:22 2337936 c:\windows\system32\FNTCACHE.DAT
- 2003-08-03 17:56 . 2003-08-03 17:56 1146184 c:\windows\system32\FM20.DLL
+ 2003-08-03 16:56 . 2003-08-03 16:56 1146184 c:\windows\system32\FM20.DLL
+ 2011-09-05 11:43 . 2011-07-28 21:15 1564556 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ativvaxx.dll
+ 2011-09-05 11:43 . 2011-07-28 21:40 7942658 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\atioglxx.dll
+ 2011-09-05 11:43 . 2011-07-28 21:57 2489654 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\aticaldd.dll
+ 2011-09-05 11:43 . 2011-07-28 21:34 2083419 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati3duag.dll
+ 2011-09-05 11:43 . 2011-07-28 22:20 4770029 c:\windows\system32\DRVSTORE\CX124441_DCE444CAEC0CD68FEF52A8A74E336DC43AFD5F2E\B123158\ati2mtag.sys
- 2008-10-15 04:36 . 2011-06-06 11:35 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2008-10-15 04:36 . 2011-09-06 14:10 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2008-06-26 08:14 . 2011-09-05 13:56 1510912 c:\windows\system32\dllcache\shdocvw.dll
- 2008-06-26 08:14 . 2011-04-25 14:47 1510912 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-21 06:45 . 2011-09-05 13:56 3107328 c:\windows\system32\dllcache\mshtml.dll
+ 2010-06-24 12:12 . 2011-09-05 13:56 1025024 c:\windows\system32\dllcache\browseui.dll
- 2010-06-24 12:12 . 2011-04-25 14:47 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2007-03-15 01:57 . 2011-07-28 22:20 7084544 c:\windows\system32\dllcache\ati2mtag.sys
- 2004-08-17 13:49 . 2011-04-25 14:47 1025024 c:\windows\system32\browseui.dll
+ 2004-08-17 13:49 . 2011-09-05 13:56 1025024 c:\windows\system32\browseui.dll
+ 2008-09-26 10:02 . 2008-09-26 10:02 1644544 c:\windows\Resources\Themes\Crysis Warhead\Shell\rubber\Shellstyle.dll
+ 2008-09-26 10:02 . 2008-09-26 10:02 1644544 c:\windows\Resources\Themes\Crysis Warhead\Shell\NormalColor\Shellstyle.dll
+ 2008-09-26 10:02 . 2008-09-26 10:02 1644544 c:\windows\Resources\Themes\Crysis Warhead\Shell\glass\Shellstyle.dll
+ 2011-04-28 19:50 . 2011-04-28 19:50 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
- 2011-01-18 02:39 . 2011-01-18 02:39 3182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2011-07-07 03:18 . 2011-07-07 03:18 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- 2011-03-25 04:15 . 2011-03-25 04:15 5912400 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2011-07-07 03:18 . 2011-07-07 03:18 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2011-03-25 04:15 . 2011-03-25 04:15 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
- 2010-09-23 13:55 . 2010-09-23 13:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 11:59 . 2011-07-08 11:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 11:59 . 2011-07-08 11:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 13:55 . 2010-09-23 13:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-07 10:02 . 2011-07-07 10:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-09-23 00:26 . 2010-09-23 00:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 10:02 . 2011-07-07 10:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2011-07-08 11:59 . 2011-07-08 11:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-09-23 13:55 . 2010-09-23 13:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-09-09 17:06 . 2011-09-09 17:06 1650176 c:\windows\Installer\fe84b3.msi
+ 2011-05-01 22:06 . 2011-05-01 22:06 2705920 c:\windows\Installer\af012.msp
+ 2011-08-28 14:14 . 2011-08-28 14:14 4032512 c:\windows\Installer\a11706.msi
+ 2011-08-28 11:24 . 2011-08-28 11:24 5788160 c:\windows\Installer\67175.msi
+ 2011-09-05 11:45 . 2011-09-05 11:45 1134080 c:\windows\Installer\4d3857f.msi
+ 2011-07-29 18:34 . 2011-07-29 18:34 5521920 c:\windows\Installer\25d7aa3.msi
+ 2011-09-12 13:36 . 2011-09-12 13:36 1154048 c:\windows\Installer\19cb761.msi
+ 2011-10-13 18:25 . 2011-10-13 18:25 6866432 c:\windows\Installer\1855a25.msi
+ 2011-09-12 13:15 . 2011-09-12 13:15 8742912 c:\windows\Installer\176bec6.msi
+ 2011-07-20 15:11 . 2011-07-20 15:11 4037632 c:\windows\Installer\13160d4.msi
+ 2007-10-24 19:13 . 2007-10-24 19:13 2098400 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysystem.dll
+ 2007-10-24 22:11 . 2007-10-24 22:11 4674784 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crysis.exe
+ 2007-10-24 19:13 . 2007-10-24 19:13 3024096 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d9.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 3036384 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryrenderd3d10.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 1991904 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryphysics.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 2823392 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\crygame.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 1574112 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryanimation.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 1942752 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaisystem.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 2942176 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cryaction.dll
+ 2007-10-24 19:13 . 2007-10-24 19:13 1778912 c:\windows\Installer\$PatchCache$\Managed\7B97E000527E10F478A01C92247B8F4E\1.0.0\cry3dengine.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_e8fbd156\System.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_5d197bff\System.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_2ac6d94c\System.Xml.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_11599c54\System.Xml.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6b14895c\System.Windows.Forms.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_370d816b\System.Windows.Forms.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_18279927\System.Drawing.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_ce955239\System.Design.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_6780a3dd\System.Design.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0ad9d51d\mscorlib.dll
+ 2011-10-13 04:33 . 2011-10-13 04:33 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_0116417d\mscorlib.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd6e0cd6f124a6d041ef1b4c9a5f080b\WindowsBase.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1368064 c:\windows\assembly\NativeImages_v2.0.50727_32\WidgetLibrary\d875abb26cd28b38e8373fa5320855f3\WidgetLibrary.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 1368064 c:\windows\assembly\NativeImages_v2.0.50727_32\WidgetLibrary\9f0caa16e2252b2e9945c1df345fd07a\WidgetLibrary.ni.dll
+ 2011-10-13 04:52 . 2011-10-13 04:52 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\55d4813580b1e5d268ff0564942cee9c\UIAutomationClientsideProviders.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\162600dde59fbaa0c048a949158ecba3\UIAutomationClientsideProviders.ni.dll
+ 2011-08-12 11:52 . 2011-08-12 11:52 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 7950848 c:\windows\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll
+ 2011-08-28 14:20 . 2011-08-28 14:20 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\22229a30650a9afbac984e1093898b13\System.WorkflowServices.ni.dll
+ 2011-10-14 11:26 . 2011-10-14 11:26 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\17902fdb0e0d3bc8b49bce693415fe7e\System.WorkflowServices.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\f72c5f649951b0403e62bfab6c453e6f\System.Workflow.Runtime.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\4d6b3cc1fc7a4788612241af7966715a\System.Workflow.Runtime.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\e4c9853af945c9cfede19f3faf18af6e\System.Workflow.ComponentModel.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\0aa4f4174204c93cc5181df4a6b2fb09\System.Workflow.ComponentModel.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\ab4b50c7c789e46a485903365765fde8\System.Workflow.Activities.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\921629dc69a5a895101097c88ae67897\System.Workflow.Activities.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\a2392c995b1bb6b63079091259222357\System.Web.Services.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f5dac0448a1dbe2687a5df92904d6274\System.Web.Mobile.ni.dll
+ 2011-08-28 10:03 . 2011-08-28 10:03 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\3da92a0b9b8ac97e11ca8bf4df671a78\System.Web.Mobile.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\ccaf6bdd256a9b5079fedadcc8993327\System.Web.Extensions.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\01f4d6aa3299a41b8578b7e96afdcfb1\System.Web.Extensions.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\e1208f0d981c420fc59f806bfbaa713b\System.Speech.ni.dll
+ 2011-10-13 04:52 . 2011-10-13 04:52 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\10d7daa3d1e62a0e40587cdc707be93f\System.Speech.ni.dll
+ 2011-10-14 11:25 . 2011-10-14 11:25 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9ec7da53380a754b4ad97709df0dd7e7\System.ServiceModel.Web.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\27e1b8dfd5e1ccf2c5b9efc51f674c69\System.ServiceModel.Web.ni.dll
+ 2011-08-28 07:51 . 2011-08-28 07:51 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\dece01bd9e9c32e47630fdfc78d3bd32\System.Runtime.Serialization.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\90b444d02047ef27921153d46967ef0e\System.Printing.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\0f8e14bfdb27645fb1a92ce26f9bf521\System.Printing.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d14065ede44df8e9b5d6b60c5ddccc69\System.IdentityModel.ni.dll
+ 2011-08-28 07:51 . 2011-08-28 07:51 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\a50e2fc92db32751857fb8d297f9d7bc\System.IdentityModel.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\91cd88a803768151c6262853d3454ba7\System.DirectoryServices.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\259ecf480769f4e60514b7ae2abaa6f1\System.DirectoryServices.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\71cf3eb40fc38e6ac8fba09e872d2878\System.Deployment.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\db2d84e279807592a680ef4135e9fe9a\System.Data.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ef748704f543a8791e23387652d34dfb\System.Data.SqlXml.ni.dll
+ 2011-08-12 11:53 . 2011-08-12 11:53 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0b16305773369cf740c6a2b1f1d785b2\System.Data.SqlXml.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\c1b9b8ce390548dcca661a5e6a908408\System.Data.Services.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\541142d8742e6e88f1e729fafee04e71\System.Data.Services.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\c729750d54f6e7427230622bcccd4709\System.Data.OracleClient.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\5d5aa4b926ae422607ea833d934665c2\System.Data.OracleClient.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\d96a94076acb8e0c5a96a1b2de4b3a7a\System.Data.Linq.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\571af34939797a7c1cd05b0b925a45bf\System.Data.Linq.ni.dll
+ 2011-10-14 11:24 . 2011-10-14 11:24 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\a3ce22c2a84fdcb008d72d230ee0b2c0\System.Data.Entity.ni.dll
+ 2011-08-28 10:02 . 2011-08-28 10:02 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\2b58cc071d6bf0c741e91f86c09de5d7\System.Data.Entity.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e54e013315849f5e34d8f2a8e7fdb450\System.Core.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\d507b9e0e50e453793ee5e01c07a5485\System.Core.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\714e9504255565bd9076fe13628e104a\ReachFramework.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\24ab0cacc77e8696ceff3157942a2de4\ReachFramework.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\fac1ca86f4fea17de40d7fdaba38563e\PresentationUI.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\7dc6ee14234b0686182ced75f7dae990\PresentationUI.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b42ad515bb20ec1f1250c040371c6730\PresentationBuildTasks.ni.dll
+ 2011-08-12 11:52 . 2011-08-12 11:52 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b187becbc388c4ce7f33ede4da76e7b1\PresentationBuildTasks.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c6b19db2534042d435ede580f92bc75c\Microsoft.VisualBasic.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\24331b719aa25ac2b21099e32232840c\Microsoft.VisualBasic.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\ce1ecd602ca089eb13a9b428dc7f0449\Microsoft.Transactions.Bridge.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\08594c4ba9ea0253a836fe1d8d341984\Microsoft.Transactions.Bridge.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\8ad32b72258899177c07dc5912b5b748\Microsoft.JScript.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\345abd035c9378667b1cac54c1f21c97\Microsoft.JScript.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\906cd5555b79e4e0486dc8ef2a748b13\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-08-28 10:00 . 2011-08-28 10:00 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\7baff7d694394aaba490082c88d48fd2\Microsoft.Build.Tasks.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\50e7c5eb58c982dba7b21cd10a69b095\Microsoft.Build.Tasks.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\415cef6abab5bb959f200f6c537bc289\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\eea7bcc8d356e3f2dcb4f36dfc1c6bc0\Microsoft.Build.Engine.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\235a22e1ae9742bb724d411629dd99d5\Microsoft.Build.Engine.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1527808 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreGraphics\d74e1bdb080153ec8555cb13d4ffa407\CoreGraphics.ni.dll
+ 2011-08-28 07:53 . 2011-08-28 07:53 1527808 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreGraphics\ba4ef97b4977b913a729361f3ef04f1f\CoreGraphics.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 1165824 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreGraphics.XmlSer#\f8b32759691f15ae135f76bbb893d4fa\CoreGraphics.XmlSerializers.ni.dll
+ 2011-08-28 07:54 . 2011-08-28 07:54 1165824 c:\windows\assembly\NativeImages_v2.0.50727_32\CoreGraphics.XmlSer#\d33d5d0607fab7b28dc6a4b65f6a2097\CoreGraphics.XmlSerializers.ni.dll
+ 2011-10-13 14:46 . 2011-10-13 14:46 8727552 c:\windows\assembly\NativeImages_v2.0.50727_32\ComponentFactory.Kr#\d1eb111aa164c5aa60d915315eeed425\ComponentFactory.Krypton.Toolkit.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 8727552 c:\windows\assembly\NativeImages_v2.0.50727_32\ComponentFactory.Kr#\8e62e7701ec0a0ef2670b69f172c0012\ComponentFactory.Krypton.Toolkit.ni.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-10-13 04:47 . 2011-10-13 04:47 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-08-11 16:52 . 2011-10-13 04:47 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-06-22 19:10 . 2011-06-22 19:10 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-10-03 05:39 . 2010-10-03 05:39 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-10-13 04:32 . 2011-10-13 04:32 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-03 05:39 . 2010-10-03 05:39 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2011-07-18 08:57 . 2011-07-18 08:57 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-09-12 13:16 . 2011-09-12 13:16 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 1510912 c:\windows\$NtUninstallKB2559049$\shdocvw.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 3100672 c:\windows\$NtUninstallKB2559049$\mshtml.dll
+ 2011-08-11 16:46 . 2011-04-25 14:47 1025024 c:\windows\$NtUninstallKB2559049$\browseui.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 1510912 c:\windows\$hf_mig$\KB2559049\SP3QFE\shdocvw.dll
+ 2011-06-27 09:41 . 2011-06-27 09:41 3106304 c:\windows\$hf_mig$\KB2559049\SP3QFE\mshtml.dll
+ 2011-06-21 18:16 . 2011-06-21 18:16 1025024 c:\windows\$hf_mig$\KB2559049\SP3QFE\browseui.dll
+ 2011-09-09 17:06 . 2011-07-28 21:40 18440192 c:\windows\system32\ReinstallBackups\0003\DriverFiles\B123158\atioglxx.dll
+ 2008-02-13 17:08 . 2011-10-13 04:33 48324552 c:\windows\system32\MRT.exe
+ 2011-07-12 20:49 . 2011-07-12 20:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-07-29 19:57 . 2011-07-29 19:57 38363136 c:\windows\Installer\2ba225c.msp
+ 2011-07-11 18:43 . 2011-07-11 18:43 11641344 c:\windows\Installer\145a2c6a.msp
+ 2011-07-12 13:50 . 2011-07-12 13:50 17555968 c:\windows\Installer\144d3f54.msp
+ 2011-08-12 11:54 . 2011-08-12 11:54 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:51 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\60df958ca96c9b8945f836759b6abd34\System.Web.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\40893760431f8f0dcce3e18630e45b23\System.Web.ni.dll
+ 2011-08-28 07:52 . 2011-08-28 07:52 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\e3a0205acab2215fbad7927d9d483aeb\System.ServiceModel.ni.dll
+ 2011-10-13 14:45 . 2011-10-13 14:45 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll
+ 2011-10-13 04:51 . 2011-10-13 04:51 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c6374d32e4af7b7e3e46b32176f76558\System.Design.ni.dll
+ 2011-08-12 11:55 . 2011-08-12 11:55 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\63ad0cd9b5e038c8e2e41415657db8fc\System.Design.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\704556e34128441ea9f1a81cc89f8a79\PresentationFramework.ni.dll
+ 2011-10-13 04:50 . 2011-10-13 04:50 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll
+ 2011-10-13 04:49 . 2011-10-13 04:49 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll
+ 2011-08-12 11:54 . 2011-08-12 11:54 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\5f332c48d03eca57419c4f0e884092ee\PresentationCore.ni.dll
+ 2011-10-13 04:48 . 2011-10-13 04:48 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
+ 2011-07-29 19:21 . 2011-07-29 19:21 378156544 c:\windows\Installer\295330a.msp
+ 2011-09-12 13:34 . 2011-09-12 13:34 241051648 c:\windows\Installer\19cb75a.msi
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- d:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-16 68856]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2011-04-08 399736]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2008-06-29 98304]
"avast"="d:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-28 98304]
"snp325"="c:\windows\vsnp325.exe" [2006-10-10 827392]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
avast! Free Antivirus.lnk - c:\program files\Alwil Software\Avast5\AvastUI.exe [N/A]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonuiX.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 13:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- d:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ImageMixer 3 SE Camera Monitor for SD.lnk]
backup=c:\windows\pss\ImageMixer 3 SE Camera Monitor for SD.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^BluetoothPCDialer.lnk]
backup=c:\windows\pss\BluetoothPCDialer.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\matmik\Nabídka Start\Programy\Po spuštění\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-05-04 15:05 311296 ----a-r- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2007-09-07 23:01 43008 ----a-w- d:\documents and settings\matmik\Plocha\bittorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desura]
2011-06-11 12:10 2482496 ----a-w- d:\program files\Desura\desura.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-02-12 13:50 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Game Fire]
2011-03-08 11:26 46592 ----a-w- c:\program files\Smart PC Utilities\Game Fire\GFTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2010-12-30 13:17 19972712 ----a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp325]
2006-10-10 13:11 827392 ----a-w- c:\windows\vsnp325.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-04-16 05:00 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp325]
2006-10-10 14:49 270336 ----a-w- c:\windows\tsnp325.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-04-08 12:46 399736 ----a-w- d:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Documents and Settings\\matmik\\Plocha\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Team JPN\\SpiderMan Web of Shadows\\image\\pc\\Spider-Man Web of Shadows.exe"=
"d:\\Program Files\\ICQ7.2\\ICQ.exe"=
"d:\\Program Files\\ICQ7.2\\aolload.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\zero gear\\Server\\ZeroGearServer.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Program Files\\Valve\\csstrike\\hl.exe"=
"d:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"d:\\Program Files\\Xfire\\xfire.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator dedicated server\\AvP_CLI.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis 2\\bin32\\Crysis2.exe"=
"d:\\Program Files\\LucasArts\\KotF Jedi Academy Expansion Pack\\GameData\\jamp.exe"=
"d:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"d:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\EoC-S-EDed.exe"=
"d:\\Documents and Settings\\matmik\\Dokumenty\\Downloads\\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\\ACBSP.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"d:\\Program Files\\Electronic Arts\\Medal of Honor\\Binaries\\moh.exe"=
"d:\\Program Files\\EA GAMES\\BFP4f.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\zero gear\\ZeroGear.bat"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of juarez - bound in blood sp demo\\CoJBiBDemo_x86.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Activision\\Call of Duty - Black Ops\\BlackOps.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"d:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_Launcher.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_DX11.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP.exe"=
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [28.5.2008 10:13 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [28.5.2008 10:13 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [1.7.2011 17:40 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1.7.2011 17:40 320856]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [5.9.2011 16:15 232512]
R1 HWiNFO32;HWiNFO32 Kernel Driver;d:\program files\HWiNFO32\HWiNFO32.SYS [2.5.2010 10:12 19064]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1.7.2011 17:40 20568]
R2 HdThemeEnabler;Hyperdesk Theme Enabler;c:\program files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe [21.7.2008 12:50 106496]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27.1.2010 4:09 50704]
R3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\TEMP\drv1.tmp --> c:\windows\TEMP\drv1.tmp [?]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [13.3.2009 11:51 47360]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25.3.2010 17:27 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2.5.2010 10:27 1691480]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\matmik\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\matmik\LOCALS~1\Temp\CFcatchme.sys [?]
S3 Desura Install Service;Desura Install Service;c:\program files\Common Files\Desura\desura_service.exe [11.6.2011 14:10 130368]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [25.3.2010 17:27 135664]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [20.1.2011 19:27 10251904]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - NTPROCDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-25 15:27]
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-25 15:27]
.
2011-10-07 c:\windows\Tasks\UpdateCheck.job
- c:\program files\Smart PC Utilities\Game Fire\UpdateCheck.exe [2011-03-08 13:40]
.
2011-10-13 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-09-14 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page =
uSearch Page = hxxp://www.google.com
uLocal Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
mStart Page =
mLocal Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} -
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default\
FF - prefs.js: browser.startup.homepage - google.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - Ext: LoudMo Contextual Ad Assistant: {37b1d48c-6e0a-dfe8-8a74-05116b74c806} - d:\program files\Mozilla Firefox\extensions\{37b1d48c-6e0a-dfe8-8a74-05116b74c806}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ResultUrl: {C8431CD2-C25A-45F3-BEA9-A9103C31409A} - d:\program files\Mozilla Firefox\extensions\{C8431CD2-C25A-45F3-BEA9-A9103C31409A}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: HyperCamToolbar: {75656794-AB59-4712-BFBC-5D816D56F3BC} - %profile%\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
FF - Ext: MyAshampoo Community Toolbar: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - %profile%\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
FF - Ext: kikin plugin: {AA994882-F391-4d2e-806F-8908DA4814ED} - %profile%\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: avast! WebRep: wrc@avast.com - d:\program files\AVAST Software\Avast\WebRep\FF
FF - Ext: SpeedBit Toolbar: {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - c:\program files\SpeedBit Toolbar\SPFireFox
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files\relevantknowledge\rlvknlg.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-14 13:30
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
hpqSRMon = c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTProcDrv]
"ImagePath"="\??\c:\windows\TEMP\drv1.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-73586283-115176313-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:c9,0f,8c,a9,08,b0,de,8d,38,f3,ff,29,76,d6,7f,58,27,8e,71,e0,ac,72,81,
d1,9b,16,1b,79,d8,aa,7a,33,a8,21,ff,8f,89,2b,c6,85,bf,d6,80,ae,26,18,b4,56,\
"??"=hex:92,b0,92,2a,dc,c2,cb,71,6f,15,f8,be,4d,6c,5a,9d
.
[HKEY_USERS\S-1-5-21-73586283-115176313-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:91,0f,e4,33,13,2c,c9,78,50,7e,38,82,2b,59,a2,ae,d1,d1,2c,9d,b1,
89,51,7a,41,d3,e9,f7,aa,b4,6c,a9,2b,45,d2,87,1c,ac,26,11,73,5d,3e,2c,91,ef,\
"rkeysecu"=hex:fa,cc,90,47,0b,38,b2,f6,05,78,af,05,fe,55,ff,a3
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
Celkový čas: 2011-10-14 13:33:28
ComboFix-quarantined-files.txt 2011-10-14 11:33
ComboFix2.txt 2011-07-20 11:20
ComboFix3.txt 2011-07-20 07:32
ComboFix4.txt 2011-06-24 14:51
.
Před spuštěním: 1 511 735 296
Po spuštění: 4 459 937 792
.
- - End Of File - - AFE2049945985979C81C97D52821FBD5

Re: o5 revelantknowledge

Napsal: 14 říj 2011 13:11
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    c:\windows\system32\SET951.tmp
    c:\windows\TEMP\drv1.tmp
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "uTorrent"=-
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
    
    Driver::
    gupdate
    gupdatem
    NTProcDrv
    
    DDS::
    uStart Page = 
    mStart Page = 
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default\
    FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... id=afex&q=
    FF - Ext: MyAshampoo Community Toolbar: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - %profile%\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
    FF - Ext: SpeedBit Toolbar: {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - c:\program files\SpeedBit Toolbar\SPFireFox
    
    RegNull::
    [HKEY_USERS\S-1-5-21-73586283-115176313-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-73586283-115176313-725345543-1003\Software\SecuROM\License information*]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: o5 revelantknowledge

Napsal: 14 říj 2011 14:30
od [ACze]miky
ComboFix 11-10-14.01 - matmik 14.10.2011 15:15:44.12.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.2444 [GMT 2:00]
Spuštěný z: d:\audio svms\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\matmik\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
FILE ::
"c:\windows\system32\SET951.tmp"
"c:\windows\TEMP\drv1.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\SpeedBit Toolbar\SPFireFox
c:\program files\SpeedBit Toolbar\SPFireFox\chrome.manifest
c:\program files\SpeedBit Toolbar\SPFireFox\chrome\speedbit.jar
c:\program files\SpeedBit Toolbar\SPFireFox\install.rdf
c:\windows\system32\SET951.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Legacy_NTPROCDRV
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_NTProcDrv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-14 do 2011-10-14 )))))))))))))))))))))))))))))))
.
.
2011-10-13 18:30 . 2011-10-13 18:30 -------- d-----w- c:\documents and settings\matmik\Data aplikací\Skinux
2011-10-13 18:25 . 2011-10-13 18:25 -------- d-----w- c:\program files\The Skins Factory
2011-10-13 18:21 . 2011-10-13 18:21 -------- d-----w- c:\program files\belchfire.net
2011-09-30 12:51 . 2011-09-30 13:00 -------- d-----w- c:\documents and settings\matmik\Data aplikací\AVI ReComp
2011-09-22 16:19 . 2011-09-22 16:19 -------- d-----w- c:\documents and settings\matmik\Local Settings\Data aplikací\MW2_Hack_Project
2011-09-20 10:48 . 2011-09-20 10:49 -------- d-----w- c:\documents and settings\matmik\Data aplikací\VDownloader
2011-09-20 10:48 . 2011-09-20 10:48 -------- d-----w- c:\program files\WinPcap
2011-09-20 10:47 . 2011-09-20 10:47 -------- d-----w- C:\ProgramData
2011-09-20 10:47 . 2010-01-26 21:11 444283 ----a-w- c:\program files\Common Files\WinPcapNmap.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 16:14 . 2009-03-15 16:08 138264 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-10-13 16:14 . 2010-05-04 14:56 234768 -c--a-w- c:\windows\system32\PnkBstrB.xtr
2011-10-13 16:14 . 2009-03-15 16:08 234768 -c--a-w- c:\windows\system32\PnkBstrB.exe
2011-10-12 16:48 . 2009-03-15 16:08 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-10-11 16:32 . 2008-10-19 15:06 21840 -c--atw- c:\windows\system32\SIntfNT.dll
2011-10-11 16:32 . 2008-10-19 15:06 17212 -c--atw- c:\windows\system32\SIntf32.dll
2011-10-11 16:32 . 2008-10-19 15:06 12067 -c--atw- c:\windows\system32\SIntf16.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 14:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 14:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-12 13:16 . 2010-05-03 13:47 22328 -c--a-w- c:\documents and settings\matmik\Data aplikací\PnkBstrK.sys
2011-09-09 09:12 . 2004-08-17 13:49 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 20:45 . 2011-07-01 15:40 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2011-07-01 15:40 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-07-01 15:40 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2011-07-01 15:40 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2011-07-01 15:40 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2011-07-01 15:40 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2011-07-01 15:40 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2011-07-01 15:40 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2011-07-01 15:40 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2011-07-01 15:40 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-09-06 14:10 . 2004-08-17 13:44 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 14:15 . 2011-09-05 14:15 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-09-05 13:56 . 2004-08-17 13:49 668160 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2004-08-17 13:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 13:56 . 2004-08-03 20:59 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:55 . 2004-08-17 13:44 370176 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-03 21:14 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-12 11:51 . 2008-01-26 14:48 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-07-30 15:26 . 2011-07-30 15:26 87552 --sh--w- c:\windows\system32\h4x0r.dll
2011-07-29 18:34 . 2010-05-13 13:17 669184 -c--a-w- c:\windows\system32\pbsvc.exe
2011-07-28 22:20 . 2007-03-15 01:57 7084544 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-07-28 22:17 . 2008-02-06 17:06 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2011-07-28 22:01 . 2010-02-11 04:23 57344 ----a-w- c:\windows\system32\aticalrt.dll
2011-07-28 22:01 . 2010-02-11 04:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2011-07-28 21:57 . 2010-02-11 04:21 5697536 ----a-w- c:\windows\system32\aticaldd.dll
2011-07-28 21:40 . 2007-03-15 01:19 18440192 ----a-w- c:\windows\system32\atioglxx.dll
2011-07-28 21:34 . 2007-03-15 01:40 3973696 ----a-w- c:\windows\system32\ati3duag.dll
2011-07-28 21:32 . 2008-02-06 17:06 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-28 21:31 . 2007-03-15 01:57 303104 ----a-w- c:\windows\system32\ati2dvag.dll
2011-07-28 21:27 . 2011-02-16 10:58 956160 ----a-w- c:\windows\system32\ativvamv.dll
2011-07-28 21:15 . 2007-03-15 01:29 3166208 ----a-w- c:\windows\system32\ativvaxx.dll
2011-07-28 21:14 . 2007-03-15 01:50 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2011-07-28 21:13 . 2007-03-15 01:50 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-07-28 21:13 . 2007-03-15 01:50 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-07-28 21:13 . 2007-03-15 01:50 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-07-28 21:13 . 2007-03-15 01:49 188416 ----a-w- c:\windows\system32\ati2evxx.dll
2011-07-28 21:12 . 2007-03-15 01:48 643072 ----a-w- c:\windows\system32\ati2evxx.exe
2011-07-28 21:10 . 2007-03-15 01:47 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-07-28 21:09 . 2010-12-24 18:39 151552 ----a-w- c:\windows\system32\atiapfxx.exe
2011-07-28 21:05 . 2007-03-15 01:16 704512 ----a-w- c:\windows\system32\atikvmag.dll
2011-07-28 21:01 . 2010-02-11 03:54 208896 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-28 21:00 . 2007-03-15 01:14 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-07-28 20:59 . 2010-02-11 04:37 507904 ----a-w- c:\windows\system32\atiok3x2.dll
2011-07-28 20:55 . 2007-03-15 01:10 876544 ----a-w- c:\windows\system32\ati2cqag.dll
2011-07-28 20:53 . 2010-02-11 03:59 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2011-07-28 20:53 . 2009-11-24 13:26 64512 ----a-w- c:\windows\system32\atimpc32.dll
2011-07-28 20:53 . 2007-03-15 01:14 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-28 15:49 . 2011-07-28 15:49 53760 ----a-w- c:\windows\system32\OVDecode.dll
2011-07-28 15:48 . 2011-07-28 15:48 13555712 ----a-w- c:\windows\system32\amdocl.dll
2011-07-18 13:42 . 2011-06-05 09:33 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-14_11.30.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-14 13:24 . 2011-10-14 13:24 16384 c:\windows\Temp\Perflib_Perfdata_610.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- d:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"avast"="d:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-28 98304]
"snp325"="c:\windows\vsnp325.exe" [2006-10-10 827392]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
avast! Free Antivirus.lnk - c:\program files\Alwil Software\Avast5\AvastUI.exe [N/A]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 13:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- d:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ImageMixer 3 SE Camera Monitor for SD.lnk]
backup=c:\windows\pss\ImageMixer 3 SE Camera Monitor for SD.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^BluetoothPCDialer.lnk]
backup=c:\windows\pss\BluetoothPCDialer.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\matmik\Nabídka Start\Programy\Po spuštění\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^matmik^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-05-04 15:05 311296 ----a-r- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desura]
2011-06-11 12:10 2482496 ----a-w- d:\program files\Desura\desura.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-02-12 13:50 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Game Fire]
2011-03-08 11:26 46592 ----a-w- c:\program files\Smart PC Utilities\Game Fire\GFTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2010-12-30 13:17 19972712 ----a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp325]
2006-10-10 13:11 827392 ----a-w- c:\windows\vsnp325.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-04-16 05:00 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp325]
2006-10-10 14:49 270336 ----a-w- c:\windows\tsnp325.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Documents and Settings\\matmik\\Plocha\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Team JPN\\SpiderMan Web of Shadows\\image\\pc\\Spider-Man Web of Shadows.exe"=
"d:\\Program Files\\ICQ7.2\\ICQ.exe"=
"d:\\Program Files\\ICQ7.2\\aolload.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\zero gear\\Server\\ZeroGearServer.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Program Files\\Valve\\csstrike\\hl.exe"=
"d:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"d:\\Program Files\\Xfire\\xfire.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator dedicated server\\AvP_CLI.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis 2\\bin32\\Crysis2.exe"=
"d:\\Program Files\\LucasArts\\KotF Jedi Academy Expansion Pack\\GameData\\jamp.exe"=
"d:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"d:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\EoC-S-EDed.exe"=
"d:\\Documents and Settings\\matmik\\Dokumenty\\Downloads\\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\\Assassins.Creed.Brotherhood.[ENG].RiP.JoeKkerr\\ACBSP.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"d:\\Program Files\\Electronic Arts\\Medal of Honor\\Binaries\\moh.exe"=
"d:\\Program Files\\EA GAMES\\BFP4f.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\zero gear\\ZeroGear.bat"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of juarez - bound in blood sp demo\\CoJBiBDemo_x86.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Activision\\Call of Duty - Black Ops\\BlackOps.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"d:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_Launcher.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_DX11.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP.exe"=
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [28.5.2008 10:13 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [28.5.2008 10:13 5248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [1.7.2011 17:40 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1.7.2011 17:40 320856]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [5.9.2011 16:15 232512]
R1 HWiNFO32;HWiNFO32 Kernel Driver;d:\program files\HWiNFO32\HWiNFO32.SYS [2.5.2010 10:12 19064]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1.7.2011 17:40 20568]
R2 HdThemeEnabler;Hyperdesk Theme Enabler;c:\program files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe [21.7.2008 12:50 106496]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [27.1.2010 4:09 50704]
R3 NTProcDrv;Process creation detector for NT.;c:\windows\Temp\drv1.tmp [14.10.2011 15:24 3584]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [13.3.2009 11:51 47360]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2.5.2010 10:27 1691480]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\matmik\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\matmik\LOCALS~1\Temp\CFcatchme.sys [?]
S3 Desura Install Service;Desura Install Service;c:\program files\Common Files\Desura\desura_service.exe [11.6.2011 14:10 130368]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [20.1.2011 19:27 10251904]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - NTPROCDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-25 15:27]
.
2011-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-25 15:27]
.
2011-10-07 c:\windows\Tasks\UpdateCheck.job
- c:\program files\Smart PC Utilities\Game Fire\UpdateCheck.exe [2011-03-08 13:40]
.
2011-10-14 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-09-14 20:18]
.
.
------- Doplňkový sken -------
.
uLocal Page = hxxp://www.google.com/
mLocal Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} -
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\matmik\Data aplikací\Mozilla\Firefox\Profiles\iciim6xk.default\
FF - prefs.js: browser.startup.homepage - google.cz
FF - Ext: LoudMo Contextual Ad Assistant: {37b1d48c-6e0a-dfe8-8a74-05116b74c806} - d:\program files\Mozilla Firefox\extensions\{37b1d48c-6e0a-dfe8-8a74-05116b74c806}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ResultUrl: {C8431CD2-C25A-45F3-BEA9-A9103C31409A} - d:\program files\Mozilla Firefox\extensions\{C8431CD2-C25A-45F3-BEA9-A9103C31409A}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: HyperCamToolbar: {75656794-AB59-4712-BFBC-5D816D56F3BC} - %profile%\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
FF - Ext: MyAshampoo Community Toolbar: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - %profile%\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
FF - Ext: kikin plugin: {AA994882-F391-4d2e-806F-8908DA4814ED} - %profile%\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: avast! WebRep: wrc@avast.com - d:\program files\AVAST Software\Avast\WebRep\FF
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-14 15:26
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
hpqSRMon = c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTProcDrv]
"ImagePath"="\??\c:\windows\TEMP\drv1.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(840)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
d:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
- - - - - - - > 'explorer.exe'(1472)
c:\progra~1\COMMON~1\Stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
d:\program files\AVAST Software\Avast\AvastSvc.exe
c:\progra~1\COMMON~1\Stardock\SDMCP.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\UAService7.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Celkový čas: 2011-10-14 15:29:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-14 13:29
ComboFix2.txt 2011-10-14 11:33
ComboFix3.txt 2011-07-20 11:20
ComboFix4.txt 2011-07-20 07:32
ComboFix5.txt 2011-10-14 13:14
.
Před spuštěním: 4 458 217 472
Po spuštění: 4 329 336 832
.
- - End Of File - - 3F634BA0276972CCDCC71C5776B81A71

Re: o5 revelantknowledge

Napsal: 14 říj 2011 14:48
od [ACze]miky
Jinak další problém. Už minule když jsem tu zakládal téma ohledně RK tak sem psal, že mám při přihlašování tuto tabulku http://helpict.org/Dept%20Web%20Site/Ye ... _logon.jpg a chtěl bych aby byla takováhle http://www.guidebookgallery.org/pics/gu ... nxppro.png

Re: o5 revelantknowledge

Napsal: 14 říj 2011 15:01
od vyosek
Mam ted pred sebou W7, bohuzel k XPeckam se dostanu az pozdeji vecer, ale zkuste toto:
Start –> Ovládací panely –> Uživatelské účty –> Změnit způsob přihlašování a odhlašování uživatelů - zaškrtněte Používat úvodní obrazovku

Pak napiste ci pomohlo

Re: o5 revelantknowledge

Napsal: 14 říj 2011 15:09
od [ACze]miky
Právě to už jsem zkoušel. Jakoby s tim něco ten rk udělal protože když otevřu ty účty, tak nevidím text jen políčka k zaškrtnutí. To přihlašovací okno se mi změnilo i minule, když jsem měl v pc toho trojana. Už si ale nevzpomínám jak jsem to změnil. :D Teď od té doby co to tam mám znovu, mám to přihlašovací okno zase tak.

Re: o5 revelantknowledge

Napsal: 14 říj 2011 15:23
od vyosek
:arrow: Otevrete si poznamkovy blok
  • Start->spustit->notepad
  • Vlozte text nize
  • Kód: Vybrat vše

    REGEDIT4
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="c:\windows\system32\logonuiX.exe"
  • Soubor ulozte jako oprava.reg
  • Pri ukladani dejte ulozit jako typ Vsechny soubory (nastevni je uvedeno na obrazku nize)
  • Obrázek
  • Zavrit notepad a spustit dvojklikem oprava.reg
  • Pripadny dotaz na zmenu registru potvrdte
  • Okno jen problikne a opravi regsitry - soubor muzete smazat
:arrow: Restart PC a napiste ci pomohlo :)

Re: o5 revelantknowledge

Napsal: 14 říj 2011 16:11
od [ACze]miky
No zatim to nic neudělalo. Ještě jsem zapoměl detail. Že když kliknu na změnit způsob přihlašování, tak mi to napíše: Funkci Rychlé přepínání uživatelů nelze povolit, pokud je povolena funkce Soubory Offline. Pokud chcete změnit nastavení souborů offline, klepněte na tlačítko online. Pak se mi něco otevře ale s tim vůbec nevím co mám dělat.

Re: o5 revelantknowledge

Napsal: 14 říj 2011 16:21
od vyosek
Huh, tak to se tez nechytam :?: Uklidime po utilitach a budem badat dale :wink:

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Zkuste na opravu pouzit WinXP Manager http://www.viry.cz/forum/viewtopic.php?f=46&t=17549 - cast Security - karta LogIn

Re: o5 revelantknowledge

Napsal: 14 říj 2011 16:23
od [ACze]miky
Další problém. Teď jsem si všimnul, že se mi přeházeli ikony na ploše... U např. exe souboru mam ikonu adobe flashplayeru apod.

Re: o5 revelantknowledge

Napsal: 14 říj 2011 16:27
od vyosek
:arrow: Aplikujte exeHelper by Raktor :arrow: Provedte uklid

:arrow: Zkuste opravu XP Managerem

:arrow: Dejte novy log z RSIT a popiste pripadne problemy

Re: o5 revelantknowledge

Napsal: 14 říj 2011 16:52
od [ACze]miky
Dobře, takže ikony jsou v pořádku. Teď už jen to přihlašování.