Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   http://www2.flirtcafe.de/de/ , Google-Bildersuche funktioniert nicht mehr, Websites laden langsam (https://www.trojaner-board.de/108535-http-www2-flirtcafe-de-de-google-bildersuche-funktioniert-mehr-websites-laden-langsam.html)

interaktion 27.01.2012 14:23

Teil 2:

Code:

- 2009-07-14 05:30 . 2011-12-02 22:20        143360              c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2012-01-23 18:14        143360              c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-11-18 18:26        143360              c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2012-01-22 20:10        143360              c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:38 . 2012-01-20 07:41        262144              c:\windows\system32\config\systemprofile\ntuser.dat
- 2009-07-14 05:38 . 2011-04-06 03:11        262144              c:\windows\system32\config\systemprofile\ntuser.dat
- 2009-07-14 05:12 . 2011-12-28 23:58        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2012-01-27 12:10        262144              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-01-24 10:41 . 2012-01-24 10:41        114176              c:\windows\system32\admparse.dll
- 2011-05-30 02:17 . 2011-05-30 02:17        114176              c:\windows\system32\admparse.dll
- 2009-07-14 05:01 . 2011-12-29 16:18        460876              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-27 02:19        460876              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-12-26 04:18 . 2011-12-26 04:18        721680              c:\windows\Microsoft.NET\Framework64\v4.0.30319\webengine4.dll
+ 2011-12-26 04:47 . 2011-12-26 04:47        261912              c:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelReg.exe
+ 2011-12-29 18:38 . 2011-12-25 20:40        746256              c:\windows\Microsoft.NET\Framework64\v2.0.50727\webengine.dll
+ 2011-12-26 02:54 . 2011-12-26 02:54        496400              c:\windows\Microsoft.NET\Framework\v4.0.30319\webengine4.dll
+ 2011-12-26 03:39 . 2011-12-26 03:39        192792              c:\windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
+ 2011-12-29 18:38 . 2011-12-25 20:42        437520              c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        350592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        350592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        163168              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        163168              c:\windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        138592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        138592              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        699224              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        699224              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        431984              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        431984              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\System.WorkflowServices.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        511344              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        511344              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        857960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        857960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        826208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        826208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        321912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        321912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        137568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        137568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        132464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        132464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        237928              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        237928              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        675672              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        675672              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        113512              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        113512              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        326000              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        326000              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        129912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        129912              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Routing.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        390008              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        390008              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Discovery.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        505208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        505208              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activities.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        175992              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activation.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        175992              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Activation.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        261472              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        261472              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        122264              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        122264              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        291184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        291184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        349568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        349568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Runtime.DurableInstancing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        236880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        236880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        253280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        253280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        378720              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        378720              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        134528              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        134528              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        123736              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        123736              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        392552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        392552              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        125816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        125816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        120152              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        120152              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        607064              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        607064              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        395120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        395120              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        182144              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        182144              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        285072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        285072              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        829280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        829280              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        747360              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        747360              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        683368              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        683368              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        178040              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        178040              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Design.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        436600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        436600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Services.Client.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        683872              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        683872              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Linq.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        810352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        810352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        409448              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        409448              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        210816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        210816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        149848              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        149848              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\System.AddIn.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        122248              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        122248              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.DurableInstancing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        525704              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        525704              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Core.Presentation.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        112976              c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        112976              c:\windows\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        581464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        581464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        832856              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        832856              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        194424              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        194424              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        478576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        478576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        167288              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        167288              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        232304              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        232304              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        587624              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        587624              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        661352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        661352              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        349576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        349576              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        387960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        387960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        746336              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        746336              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        505184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        505184              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        220024              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v4.0.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        220024              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v4.0.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        107376              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        107376              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        714600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        714600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        498520              c:\windows\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        498520              c:\windows\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        288616              c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        288616              c:\windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        335712              c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        335712              c:\windows\Microsoft.NET\assembly\GAC_64\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        125440              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        125440              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        237424              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        237424              c:\windows\Microsoft.NET\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        512368              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        512368              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        187776              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        187776              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        269672              c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        269672              c:\windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        334688              c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        334688              c:\windows\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2011-12-29 18:41 . 2011-12-29 18:41        109568              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        109568              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2011-12-29 18:41 . 2011-12-29 18:41        246128              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        246128              c:\windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        495984              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        495984              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        170368              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        170368              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2011-02-19 22:08 . 2011-02-19 22:08        163840              c:\windows\Installer\8c1ff.msi
+ 2012-01-25 23:29 . 2012-01-25 23:29        207360              c:\windows\Installer\15f82e.msi
+ 2012-01-26 22:17 . 2012-01-26 22:17        909312              c:\windows\Installer\1111bf.msi
+ 2012-01-23 18:12 . 2012-01-23 18:12        897024              c:\windows\Installer\{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}\SafariIco.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        415584              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\pubs.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        415584              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\pubs.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        303456              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\outicon.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        303456              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\outicon.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        571232              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\misc.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        571232              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\misc.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        326496              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\joticon.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        326496              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\joticon.exe
+ 2012-01-23 18:15 . 2012-01-23 18:15        380928              c:\windows\Installer\{5E11C972-1E76-45FE-8F92-14E0D1140B1B}\iTunesIco.exe
+ 2011-09-14 03:54 . 2011-09-14 03:54        236904              c:\windows\Installer\$PatchCache$\Managed\638401577CACE4443AE9F3455191245F\4.0.0\OutlookChangeNotifierAddIn_x64.dll
+ 2011-09-14 03:54 . 2011-09-14 03:54        227176              c:\windows\Installer\$PatchCache$\Managed\638401577CACE4443AE9F3455191245F\4.0.0\OutlookChangeNotifierAddIn.dll
- 2011-05-19 19:52 . 2010-11-20 13:27        465920              c:\windows\ehome\mstvcapn.dll
+ 2012-01-11 12:13 . 2011-10-29 05:23        465920              c:\windows\ehome\mstvcapn.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        451072              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity\c47cd2fc542c0fc7e20689433fa5123c\System.Web.Entity.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        367104              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Entity.D#\efc6dead4b44c8e2e1963b7a3acd4988\System.Web.Entity.Design.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        973824              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DynamicD#\23d96e7cca727a45aca6f28b5bec7dc5\System.Web.DynamicData.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        331264              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\7257d37f6ed2f933793381870db07a81\System.Web.DataVisualization.Design.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        587776              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\92b694399f4f39b23a78ba679073f375\System.ServiceModel.Activation.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        995328              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Runtime.Remo#\fd8d112a2b0b4a65909d4174d503ae47\System.Runtime.Remoting.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        662528              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Service#\f36f39f48842409277d30dce974f6e7d\System.Data.Services.Design.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        661504              c:\windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\09cc3399142a93d77f317dda8c18a346\ComSvcConfig.ni.exe
+ 2011-12-29 22:13 . 2011-12-29 22:13        865280              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\c4688bf6b864e76fbd936a7fdd5f0748\System.Web.Extensions.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        335360              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity\8614eb36d94b640ab78ca4b7165f08f8\System.Web.Entity.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        297984              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Entity.D#\8e2860651899e90f4de23486fbd5be87\System.Web.Entity.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        712192              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DynamicD#\b1c10c1591154f94a93dad7bb306f3ed\System.Web.DynamicData.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        260608              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\17f371e10888ff6fdee8274a11f2605a\System.Web.DataVisualization.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        432640              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b998d241c567915a2069d0c790dd6c53\System.ServiceModel.Activation.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        771584              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\b209c76b6b03bee6deedfa3e1a8c4290\System.Runtime.Remoting.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        508928              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Service#\8feecdcd543403861ae71d1c7c37a67b\System.Data.Services.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        475136              c:\windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\c6a7103a6ee46deb73a7343bd7e71e61\ComSvcConfig.ni.exe
+ 2011-12-29 22:13 . 2011-12-29 22:13        851968              c:\windows\assembly\NativeImages_v4.0.30319_32\AspNetMMCExt\453bbfe8e7f07f9be9fe1c690687e15b\AspNetMMCExt.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        187392              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Routing\f715b47c2f0440ea23a71f1076b0af2b\System.Web.Routing.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        449024              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity\d258f45340e6e538a19a56d1165b750f\System.Web.Entity.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        398848              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Entity.D#\6f6d11e33e2f3f6bddd4c33809340a48\System.Web.Entity.Design.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        753664              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.DynamicD#\bca38e802e2b45f80f8fbde2b54ce0a2\System.Web.DynamicData.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        204800              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Abstract#\0e411c30fc2caebb55813b8fa0689d42\System.Web.Abstractions.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        634368              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\3ce94143060c3c8c9962f2160e908d8c\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2011-12-29 22:11 . 2011-12-29 22:11        156672              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dcc5d5ba905f05acef59b46aab72d78b\WindowsLive.Writer.HtmlParser.ni.dll
+ 2011-12-29 22:11 . 2011-12-29 22:11        871424              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\cdd1b8e0dbca86ad17055586dc2e5869\WindowsLive.Writer.BlogClient.ni.dll
+ 2011-12-29 22:11 . 2011-12-29 22:11        891392              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6cd04e54bc2f43a62c5968e7a1924eb4\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        129536              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\8e576ae7d946a5440bddfdbe06818a8b\System.Web.Routing.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        860160              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\5bd4f855a0b0386cb4baf093216ad2d3\System.Web.Extensions.Design.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        328192              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\8d56e2f2a05dbde707d87cb3bdf0dffc\System.Web.Entity.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        301568              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f560658d9ee6d2786cab976e775758d6\System.Web.Entity.Design.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        547328              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\e94f08faeb08a8ee9d51a3480083bd07\System.Web.DynamicData.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        141312              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\2dc7ec41005f6e6fe45e0cc0a20a12bc\System.Web.Abstractions.ni.dll
+ 2011-12-29 18:46 . 2011-12-29 18:46        771584              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b559a471eef00081f0b5c2719d1d9623\System.Runtime.Remoting.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        763392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\e6fa2be533d9e540ccafe51980ae0103\System.Data.Entity.Design.ni.dll
- 2011-04-06 03:54 . 2011-04-06 03:54        622592              c:\windows\assembly\GAC_MSIL\System.Web.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Web.Resources.dll
+ 2011-12-29 18:38 . 2010-11-12 23:26        622592              c:\windows\assembly\GAC_MSIL\System.Web.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Web.Resources.dll
- 2011-12-14 23:35 . 2011-11-03 22:39        1127424              c:\windows\SysWOW64\wininet.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        1127424              c:\windows\SysWOW64\wininet.dll
- 2011-12-14 23:35 . 2011-11-03 22:40        1103360              c:\windows\SysWOW64\urlmon.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        1103360              c:\windows\SysWOW64\urlmon.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58        4422992              c:\windows\SysWOW64\mfc100u.dll
+ 2011-06-11 00:58 . 2011-06-11 00:58        4397384              c:\windows\SysWOW64\mfc100.dll
- 2011-12-14 23:34 . 2011-11-03 22:47        1798144              c:\windows\SysWOW64\jscript9.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        1798144              c:\windows\SysWOW64\jscript9.dll
- 2011-12-14 23:35 . 2011-11-03 22:32        1792000              c:\windows\SysWOW64\iertutil.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        1792000              c:\windows\SysWOW64\iertutil.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        9705472              c:\windows\SysWOW64\ieframe.dll
- 2011-12-14 23:34 . 2011-11-03 22:46        9705472              c:\windows\SysWOW64\ieframe.dll
- 2011-05-30 02:17 . 2011-05-30 02:17        3695416              c:\windows\SysWOW64\ieapfltr.dat
+ 2012-01-24 10:41 . 2012-01-24 10:41        3695416              c:\windows\SysWOW64\ieapfltr.dat
+ 2012-01-24 10:41 . 2012-01-24 10:41        1390080              c:\windows\system32\wininet.dll
- 2011-12-14 23:35 . 2011-11-04 01:44        1390080              c:\windows\system32\wininet.dll
- 2011-12-14 23:35 . 2011-11-04 01:46        1345536              c:\windows\system32\urlmon.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        1345536              c:\windows\system32\urlmon.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        2309120              c:\windows\system32\jscript9.dll
- 2011-12-14 23:34 . 2011-11-04 01:53        2309120              c:\windows\system32\jscript9.dll
- 2011-12-14 23:35 . 2011-11-04 01:36        2144256              c:\windows\system32\iertutil.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        2144256              c:\windows\system32\iertutil.dll
- 2011-05-30 02:17 . 2011-05-30 02:17        3695416              c:\windows\system32\ieapfltr.dat
+ 2012-01-24 10:41 . 2012-01-24 10:41        3695416              c:\windows\system32\ieapfltr.dat
+ 2009-07-14 04:45 . 2012-01-24 10:47        7113171              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2011-12-28 20:00        7113171              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2011-04-21 14:56 . 2011-12-29 16:18        2207344              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-04-21 14:56 . 2012-01-24 11:30        2207344              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-12-26 02:54 . 2011-12-26 02:54        1863464              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Extensions.dll
+ 2011-12-26 04:18 . 2011-12-26 04:18        5200656              c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.dll
+ 2011-12-29 18:38 . 2011-12-25 20:40        5263360              c:\windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll
+ 2011-12-26 02:54 . 2011-12-26 02:54        1863464              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.Extensions.dll
+ 2011-12-26 02:54 . 2011-12-26 02:54        5230864              c:\windows\Microsoft.NET\Framework\v4.0.30319\System.Web.dll
+ 2011-12-29 18:38 . 2011-12-25 20:42        5255168              c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1368920              c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1368920              c:\windows\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        3510600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        3510600              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        2207568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        2207568              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1587064              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        1587064              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1070960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        1070960              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        5028200              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        5028200              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1711496              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1711496              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1863464              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1749880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        1749880              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.DataVisualization.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        6097256              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        6097256              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1026936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1026936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        5097816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        5097816              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        4464480              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        4464480              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1354584              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1354584              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1199968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1199968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        1462648              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        1462648              c:\windows\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\System.Activities.Presentation.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        6428520              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        6428520              c:\windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1327968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        1327968              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        1069936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
- 2011-09-17 12:14 . 2011-09-17 12:14        1069936              c:\windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v4.0.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        5200656              c:\windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        3116376              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        3116376              c:\windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        3824480              c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        3824480              c:\windows\Microsoft.NET\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        4967248              c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        4967248              c:\windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-29 18:43 . 2011-12-29 18:43        3563408              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        3563408              c:\windows\Microsoft.NET\assembly\GAC_64\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-12-29 18:45 . 2011-12-29 18:45        5230864              c:\windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        2975064              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        2975064              c:\windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        3788128              c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        3788128              c:\windows\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2011-12-29 18:41 . 2011-12-29 18:41        5197648              c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-10-12 18:02 . 2011-10-12 18:02        5197648              c:\windows\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-10-12 18:03 . 2011-10-12 18:03        2989456              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-12-29 18:42 . 2011-12-29 18:42        2989456              c:\windows\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Activities.Compiler.dll
+ 2011-12-26 05:24 . 2011-12-26 05:24        8835072              c:\windows\Installer\81a2ce.msp
+ 2011-06-28 20:27 . 2011-06-28 20:27        4028928              c:\windows\Installer\44f445.msp
+ 2011-12-12 15:15 . 2011-12-12 15:15        3446784              c:\windows\Installer\18fac5.msp
- 2011-12-27 00:43 . 2011-12-27 16:18        1479520              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\xlicons.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        1479520              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\xlicons.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        1858400              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\wordicon.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        1858400              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\wordicon.exe
- 2011-12-27 00:43 . 2011-12-27 16:18        3792736              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\pptico.exe
+ 2011-12-27 00:43 . 2012-01-11 12:34        3792736              c:\windows\Installer\{90140000-0012-0000-1000-0000000FF1CE}\pptico.exe
+ 2011-12-29 22:16 . 2011-12-29 22:16        1601024              c:\windows\assembly\NativeImages_v4.0.30319_64\System.WorkflowServ#\b581bfffc1808ae8b75717f2a8dd2135\System.WorkflowServices.ni.dll
+ 2011-12-29 22:16 . 2011-12-29 22:16        2887680              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Run#\e69d85c8210a988b4c104948f04cf5aa\System.Workflow.Runtime.ni.dll
+ 2011-12-29 22:16 . 2011-12-29 22:16        3743744              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Workflow.Act#\572967d338f59ea254e9c1affc52695d\System.Workflow.Activities.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        2287104              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Services\43728abc794e8a2f8b9178d83299f691\System.Web.Services.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        2964480              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Mobile\ae6e69ee7b8f89872246462ba8b6b186\System.Web.Mobile.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        3805184              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\6d04600d11baa5d8a09b594b591d0572\System.Web.Extensions.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        1100800              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.Extensio#\5a312292936c549b4a013fac180e2187\System.Web.Extensions.Design.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        5599232              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web.DataVisu#\4c3d1f744e5edf4b2ee6a6001c4e19c3\System.Web.DataVisualization.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        1506816              c:\windows\assembly\NativeImages_v4.0.30319_64\System.ServiceModel#\cfbec2879ae56c6bb8b1ba78a92694e9\System.ServiceModel.Web.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        2702848              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Services\0bd655a7f8793293240accf4c65758c8\System.Data.Services.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        1750528              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Data.Entity.#\18688c8627c24053b0b967d88210548b\System.Data.Entity.Design.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        1829888              c:\windows\assembly\NativeImages_v4.0.30319_64\Microsoft.VisualBas#\61b5e642d21b7e31457885975af7ce11\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        1007104              c:\windows\assembly\NativeImages_v4.0.30319_64\AspNetMMCExt\122733b12d421862dca6ce320ac6b733\AspNetMMCExt.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1223168              c:\windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\c62d9d8bb2b22f8eaf9d8cbbf6123e47\System.WorkflowServices.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1971712              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Run#\e8804a70f32e7804d259792e7d27b5b8\System.Workflow.Runtime.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        2871808              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Workflow.Act#\a0ba653e91dcb6fbbfb94e37e18ed736\System.Workflow.Activities.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1925632              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Services\53f1ed558eef032f8678a10b623db2c6\System.Web.Services.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        2334208              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Mobile\f2f7d93088dc2d346d680763d464c03f\System.Web.Mobile.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        3126784              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.Extensio#\3722b214046f3e48d9e78d9adf233263\System.Web.Extensions.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        4535808              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web.DataVisu#\a439f6190b9ad82d9345292736777c85\System.Web.DataVisualization.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1086464              c:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d40d01d24635877797a3c389510d9c3a\System.ServiceModel.Web.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        2026496              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Services\66ebacc95030b565991917af67cbd885\System.Data.Services.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1424384              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Data.Entity.#\3713bc9e571e75a2f26a3b082b3f2609\System.Data.Entity.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        1139200              c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\8c2ab599a8499bf042f4a256355ff223\Microsoft.VisualBasic.Compatibility.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        1818112              c:\windows\assembly\NativeImages_v2.0.50727_64\System.WorkflowServ#\455567dae39910d806447b77ee657a85\System.WorkflowServices.ni.dll
+ 2011-12-29 18:48 . 2011-12-29 18:48        2711040              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Run#\45339e741d73e8f1f9393df8163c8c00\System.Workflow.Runtime.ni.dll
+ 2011-12-29 18:48 . 2011-12-29 18:48        5957632              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Com#\48ef2f59740ad3d438d0514b335dd334\System.Workflow.ComponentModel.ni.dll
+ 2011-12-29 18:48 . 2011-12-29 18:48        3895296              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Workflow.Act#\7972e04df268430da009e63e90ff4ca9\System.Workflow.Activities.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        2292224              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Services\8d374a0a9c49f485a7ce6e89ec354b4c\System.Web.Services.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        3336704              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Mobile\91ecefc70d74ed44e5139ea2929adbb8\System.Web.Mobile.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        3044352              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\71da5a6d09e12eb94be32935e4a8d5a2\System.Web.Extensions.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        1155072              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web.Extensio#\2bb91a2edcc92d2bb79007e7d2ddc2ae\System.Web.Extensions.Design.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        2312704              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel#\3a6ac85c04453976c0f3a7c6a64ec43a\System.ServiceModel.Web.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        1022976              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\d12c2299179cb05591cf08c8712a6495\System.Runtime.Remoting.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        1444352              c:\windows\assembly\NativeImages_v2.0.50727_64\System.IdentityModel\1f90d38a42906a776be313d9720e350d\System.IdentityModel.ni.dll
+ 2011-12-29 22:14 . 2011-12-29 22:14        2805760              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Services\1d2c369d8e2d6f95c99ca90aca273418\System.Data.Services.ni.dll
+ 2011-12-29 19:22 . 2011-12-29 19:22        1080320              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Data.Entity.#\b7bd7d91dc9abd73f2506bb7a0292373\System.Data.Entity.Design.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        7970304              c:\windows\assembly\NativeImages_v2.0.50727_64\MIGUIControls\53fcf7f34708a9482d3e4059ce29608c\MIGUIControls.ni.dll
+ 2011-12-29 19:22 . 2011-12-29 19:22        2131968              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\486ff8cee09c8c63aa9c60ff4f5feafa\Microsoft.VisualBasic.ni.dll
+ 2011-12-29 19:22 . 2011-12-29 19:22        2176512              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.PowerShel#\b68f19bf3f3d545547d2b680eb54a660\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        8979456              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\7e81f50c34dec17b90bfebec5929853a\Microsoft.MediaCenter.UI.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        1516544              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\65a892a923b49b062bd8fc97254940d3\Microsoft.MediaCenter.ni.dll
+ 2011-12-29 19:22 . 2011-12-29 19:22        1508864              c:\windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\33fd1381f221898a53253303cb7e5380\Microsoft.MediaCenter.Bml.ni.dll
+ 2011-12-29 22:11 . 2011-12-29 22:11        7025152              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f41e64e045cd090194cb0d841be0c9b6\WindowsLive.Writer.PostEditor.ni.dll
+ 2011-12-29 22:11 . 2011-12-29 22:11        2193408              c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f07f84522a403885f7de2b26d57bc592\WindowsLive.Writer.CoreServices.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1358336              c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\a612958eaf641f0ba83b0daae44cb7b1\System.WorkflowServices.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        1917952              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\ad68aa9e6fa1ec8005e1f604579a76be\System.Workflow.Runtime.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        4515840              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\00b0a14ef5cb0154db7989da39a7f1e5\System.Workflow.ComponentModel.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        2995200              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\54873f241a4ad6d2a13e48d2da444538\System.Workflow.Activities.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        1840640              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\be4f1d78d06979df7fd08dedf0d8c804\System.Web.Services.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        2209792              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\d957ec1fb12ff02282a7f73d6318b66b\System.Web.Mobile.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        2404352              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\a90f033a5a062ff29f7df8f9edc1a80c\System.Web.Extensions.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1707008              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\828e31a37bfd9d432083be6307845630\System.ServiceModel.Web.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1083392              c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c0d9df88f2b37d14cf416281364c5b7f\System.IdentityModel.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        2029568              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\76e676a9b6387aad5544d61a4ac12a78\System.Data.Services.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        6438912              c:\windows\assembly\NativeImages_v2.0.50727_32\MIGUIControls\20d18697deb8413c01119531c6b987ad\MIGUIControls.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1670144              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dd759df05fad8dc6d3404e8e02b40819\Microsoft.VisualBasic.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1681920              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\695508ea67706e5f66208cabe5363099\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        1009664              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\5662462cfa995c71817791af93686db2\Microsoft.MediaCenter.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        6499840              c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\4676e3f99469bd1120f8aed9cf37e4d2\Microsoft.MediaCenter.UI.ni.dll
+ 2011-12-29 18:38 . 2011-12-25 20:42        1277952              c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2011-05-19 19:53 . 2010-11-05 01:53        1277952              c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2011-12-29 18:38 . 2011-12-25 20:40        5263360              c:\windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-12-29 18:38 . 2011-12-25 20:42        5255168              c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2011-12-14 23:34 . 2011-11-03 23:02        12279808              c:\windows\SysWOW64\mshtml.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        12279808              c:\windows\SysWOW64\mshtml.dll
- 2009-07-14 02:34 . 2011-12-14 23:44        10747904              c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-01-24 10:44        10747904              c:\windows\system32\SMI\Store\Machine\schema.dat
- 2011-12-14 23:34 . 2011-11-04 02:38        17786368              c:\windows\system32\mshtml.dll
+ 2012-01-24 10:41 . 2012-01-24 10:41        17786368              c:\windows\system32\mshtml.dll
+ 2011-04-23 01:33 . 2012-01-11 12:33        54008112              c:\windows\system32\MRT.exe
+ 2012-01-24 10:41 . 2012-01-24 10:41        10886656              c:\windows\system32\ieframe.dll
- 2011-12-14 23:34 . 2011-11-04 01:59        10886656              c:\windows\system32\ieframe.dll
+ 2011-04-21 15:42 . 2012-01-27 02:19        10663924              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3701193968-2768520944-2608497257-1000-8192.dat
+ 2011-05-30 02:23 . 2012-01-27 02:19        53875572              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3701193968-2768520944-2608497257-1000-4096.dat
+ 2011-07-09 03:43 . 2012-01-25 23:04        11335972              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3701193968-2768520944-2608497257-1000-12288.dat
+ 2012-01-03 17:58 . 2012-01-03 17:58        15929344              c:\windows\Installer\9a9f8.msp
+ 2012-01-25 23:28 . 2012-01-25 23:28        12905472              c:\windows\Installer\15f828.msi
+ 2012-01-23 18:13 . 2012-01-23 18:13        44700672              c:\windows\Installer\1264b27.msi
+ 2012-01-23 18:12 . 2012-01-23 18:12        11081728              c:\windows\Installer\1263f91.msi
+ 2012-01-23 18:12 . 2012-01-23 18:12        18706944              c:\windows\Installer\1263f6e.msi
+ 2012-01-23 18:11 . 2012-01-23 18:11        20304896              c:\windows\Installer\1263f2f.msi
+ 2011-12-29 22:15 . 2011-12-29 22:15        15761920              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Web\866ef200ca7a2ed4f26835709646125d\System.Web.ni.dll
+ 2011-12-29 22:15 . 2011-12-29 22:15        13300736              c:\windows\assembly\NativeImages_v4.0.30319_64\System.Design\6be8e8e57a83372e41481009ef6de482\System.Design.ni.dll
+ 2011-12-29 22:13 . 2011-12-29 22:13        12079104              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Web\c775972c9a15169ac27abb027154c1fd\System.Web.ni.dll
+ 2011-12-29 18:46 . 2011-12-29 18:46        10999296              c:\windows\assembly\NativeImages_v4.0.30319_32\System.Design\fa53ece586079c2eccc354b6feb31394\System.Design.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        15270912              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Web\ab920a032a9b63aa07f26c5592d7c72c\System.Web.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        23913984              c:\windows\assembly\NativeImages_v2.0.50727_64\System.ServiceModel\4bf05a9a1aebde89033c40b9e51af495\System.ServiceModel.ni.dll
+ 2011-12-29 18:48 . 2011-12-29 18:48        13609472              c:\windows\assembly\NativeImages_v2.0.50727_64\System.Design\665178c1ccfd538896eaa0fff283b6ef\System.Design.ni.dll
+ 2011-12-29 19:21 . 2011-12-29 19:21        25470976              c:\windows\assembly\NativeImages_v2.0.50727_64\ehshell\897b2e70eb1754bf8c557fadd93faf98\ehshell.ni.dll
+ 2011-12-29 18:46 . 2011-12-29 18:46        11833344              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\b41e38edbd6dfe20997f6ea7c080aceb\System.Web.ni.dll
+ 2011-12-29 22:12 . 2011-12-29 22:12        17478656              c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\7bc7e33d4568a214f226cdb6a161a37a\System.ServiceModel.ni.dll
+ 2011-12-29 18:47 . 2011-12-29 18:47        10580480              c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\70f9f6de6dc9611157ed563bdb4e79a4\System.Design.ni.dll
.
-- Snapshot auf jetziges Datum zurückgesetzt --
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2011-10-20 28651144]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snapfish PictureMover.lnk - c:\program files (x86)\PictureMover\Bin\PictureMover.exe [2010-9-28 1040952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer8"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirMailService;Avira Email Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [2012-01-23 342480]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-11 463824]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17        302592        ----a-w-        c:\windows\System32\cmd.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-05 c:\windows\Tasks\HPCeeScheduleForBLUBB-NEU$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2012-01-27 c:\windows\Tasks\HPCeeScheduleForBlubb.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-09-15 611896]
"Corel Photo Downloader"="c:\program files (x86)\Corel\Corel Snapfire\Corel Photo Downloader.exe" [2006-08-04 462336]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mStart Page =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} - hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-01-27  14:02:02
ComboFix-quarantined-files.txt  2012-01-27 13:02
ComboFix2.txt  2011-12-29 16:23
.
Vor Suchlauf: 19 Verzeichnis(se), 786.658.787.328 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 786.612.252.672 Bytes frei
.
- - End Of File - - 1C0CD0139A58F98DB7DAA010E645E3C2


cosinus 27.01.2012 14:34

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Registry::
[-HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]

Filelook::
c:\windows\System32\cmd.exe

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

interaktion 27.01.2012 15:02

Code:

ComboFix 12-01-27.01 - Blubb 27.01.2012  14:55:45.3.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.6007.4124 [GMT 1:00]
ausgeführt von:: c:\users\Blubb\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Blubb\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-27 bis 2012-01-27  ))))))))))))))))))))))))))))))
.
.
2012-01-27 13:59 . 2012-01-27 13:59        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-01-27 12:12 . 2012-01-27 12:12        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8D89D4E-355B-4FB0-BE4C-CA2E1849F3A9}\offreg.dll
2012-01-26 22:17 . 2012-01-26 22:17        525544        ----a-w-        c:\windows\system32\deployJava1.dll
2012-01-26 22:17 . 2012-01-26 22:17        --------        d-----w-        c:\program files\Java
2012-01-25 23:29 . 2012-01-25 23:29        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-01-25 12:40 . 2012-01-25 12:40        --------        d-----w-        c:\program files (x86)\ESET
2012-01-24 22:05 . 2012-01-06 05:15        8602168        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8D89D4E-355B-4FB0-BE4C-CA2E1849F3A9}\mpengine.dll
2012-01-24 11:28 . 2012-01-24 11:28        --------        d-----w-        c:\program files (x86)\7-Zip
2012-01-24 10:43 . 2012-01-24 10:43        --------        d-----w-        c:\windows\SysWow64\wbem\en-US
2012-01-24 10:43 . 2012-01-24 10:43        --------        d-----w-        c:\windows\system32\wbem\en-US
2012-01-23 18:15 . 2012-01-23 18:15        --------        d-----w-        c:\program files\iTunes
2012-01-23 18:15 . 2012-01-23 18:15        --------        d-----w-        c:\program files (x86)\iTunes
2012-01-23 18:15 . 2012-01-23 18:15        --------        d-----w-        c:\program files\iPod
2012-01-23 00:15 . 2012-01-23 00:15        --------        d-----w-        c:\users\Blubb\AppData\Roaming\SUPERAntiSpyware.com
2012-01-23 00:15 . 2012-01-23 00:15        --------        d-----w-        c:\program files\SUPERAntiSpyware
2012-01-23 00:15 . 2012-01-23 00:15        --------        d-----w-        c:\programdata\SUPERAntiSpyware.com
2012-01-22 20:11 . 2012-01-22 20:11        --------        d-----w-        c:\users\Blubb\AppData\Roaming\Avira
2012-01-22 20:10 . 2012-01-23 12:37        130760        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-01-22 20:10 . 2011-10-11 14:06        27760        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2012-01-22 20:10 . 2011-10-11 14:06        97312        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-01-22 20:10 . 2012-01-22 20:10        --------        d-----w-        c:\programdata\Avira
2012-01-22 20:10 . 2012-01-22 20:10        --------        d-----w-        c:\program files (x86)\Avira
2012-01-11 21:00 . 2012-01-11 21:00        --------        d-----w-        c:\windows\Sun
2012-01-11 12:13 . 2011-10-26 05:25        1572864        ----a-w-        c:\windows\system32\quartz.dll
2012-01-11 12:13 . 2011-10-26 05:25        366592        ----a-w-        c:\windows\system32\qdvd.dll
2012-01-11 12:13 . 2011-10-26 04:32        514560        ----a-w-        c:\windows\SysWow64\qdvd.dll
2012-01-11 12:13 . 2011-10-26 04:32        1328128        ----a-w-        c:\windows\SysWow64\quartz.dll
2012-01-11 12:13 . 2011-11-17 06:41        1731920        ----a-w-        c:\windows\system32\ntdll.dll
2012-01-11 12:13 . 2011-11-17 05:38        1292080        ----a-w-        c:\windows\SysWow64\ntdll.dll
2012-01-11 12:13 . 2011-11-19 14:58        77312        ----a-w-        c:\windows\system32\packager.dll
2012-01-11 12:13 . 2011-11-19 14:01        67072        ----a-w-        c:\windows\SysWow64\packager.dll
2012-01-06 21:07 . 2012-01-08 17:17        --------        d-----w-        c:\programdata\SecTaskMan
2012-01-05 15:08 . 2012-01-05 15:08        --------        d-----w-        c:\programdata\PDFC
2012-01-03 22:00 . 2012-01-03 22:00        --------        d-----w-        c:\users\Blubb\AppData\Local\FILSH_Media_GmbH
2012-01-03 13:10 . 2012-01-03 13:10        182672        ----a-w-        c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2011-12-29 00:33 . 2011-12-29 00:33        --------        d-----w-        C:\_OTL
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-25 23:28 . 2011-05-19 19:11        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2011-12-28 15:28 . 2011-05-29 02:41        55384        ----a-w-        c:\windows\system32\drivers\SBREDrv.sys
2011-12-26 22:06 . 2011-12-26 22:06        18328        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-12-10 14:24 . 2011-05-30 01:30        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2011-12-10 11:53 . 2011-05-20 18:13        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 04:52 . 2011-12-14 23:31        3145216        ----a-w-        c:\windows\system32\win32k.sys
2011-11-15 13:29 . 2011-04-21 15:15        270720        ------w-        c:\windows\system32\MpSigStub.exe
2011-11-05 05:32 . 2011-12-14 23:33        2048        ----a-w-        c:\windows\system32\tzres.dll
2011-11-05 04:26 . 2011-12-14 23:33        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--- c:\windows\System32\cmd.exe ---
Company: Microsoft Corporation
File Description: Windows-Befehlsprozessor
File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product Name: Betriebssystem Microsoft® Windows®
Copyright: © Microsoft Corporation. Alle Rechte vorbehalten.
Original Filename: Cmd.Exe.MUI
File size: 345088
Created time: 2011-05-19 19:53
Modified time: 2010-11-20 13:24
MD5: 5746BD7E255DD6A8AFA06F7C42C1BA41
SHA1: 0F3C4FF28F354AEDE202D54E9D1C5529A3BF87D8
.
.
(((((((((((((((((((((((((((((  SnapShot_2012-01-27_13.00.30  )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 02:36 . 2012-01-27 12:44        4254              c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-27 13:55        4254              c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-27 13:55        4062              c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-27 12:44        4062              c:\windows\system32\perfc009.dat
- 2011-04-06 03:55 . 2012-01-27 12:44        696620              c:\windows\system32\perfh007.dat
+ 2011-04-06 03:55 . 2012-01-27 13:55        696620              c:\windows\system32\perfh007.dat
+ 2011-04-06 03:55 . 2012-01-27 13:55        147916              c:\windows\system32\perfc007.dat
- 2011-04-06 03:55 . 2012-01-27 12:44        147916              c:\windows\system32\perfc007.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7.5\ICQ.exe" [2011-08-01 124480]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2011-10-20 28651144]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snapfish PictureMover.lnk - c:\program files (x86)\PictureMover\Bin\PictureMover.exe [2010-9-28 1040952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer8"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirMailService;Avira Email Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [2012-01-23 342480]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-11 463824]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-05 c:\windows\Tasks\HPCeeScheduleForBLUBB-NEU$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2012-01-27 c:\windows\Tasks\HPCeeScheduleForBlubb.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-09-15 611896]
"Corel Photo Downloader"="c:\program files (x86)\Corel\Corel Snapfire\Corel Photo Downloader.exe" [2006-08-04 462336]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mStart Page =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} - hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-01-27  15:00:35
ComboFix-quarantined-files.txt  2012-01-27 14:00
ComboFix2.txt  2012-01-27 13:02
ComboFix3.txt  2011-12-29 16:23
.
Vor Suchlauf: 19 Verzeichnis(se), 786.655.133.696 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 786.581.385.216 Bytes frei
.
- - End Of File - - 2EF19511C6E34C014A78BC7CAF03661E


cosinus 27.01.2012 15:45

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

interaktion 27.01.2012 21:32

Immer, wenn das Programm im scan bei so einer "Microsoft visual tool"-Datei angelangt ist, stürzt es ab. Er sagt dann: "aswMBR funktioniert nicht mehr, es wird nach einer Lösung für das Problem gesucht" - am Ende kommt dann immer, dass ich es beenden muss.

Was soll ich tun? :(

interaktion 28.01.2012 13:25

Habs nun mehrmals versucht, geht einfach nicht. Immer, wenn er im Scan zu: C:/Windows/assembly/Microsoft.VisualStudio.Applications-usw (welche es genau ist, lässt sich nicht ausmachen) kommt, stürzt das Programm ab.

Das Seltsamste ist ja, dass das Problem manchmal für kurze Zeit verschwindet. Alles geht dann wieder normal und mein Rechner ist symptomfrei, geschah die letzten Tage zweimal, vor allem nachts. Das letzte Mal, als ich das Problem hatte, war es ja auch urplötzlich einfach so verschwunden, ohne, dass ich irgendetwas geändert hätte.

Woran kann das liegen?

cosinus 29.01.2012 18:37

Probier aswMBR mal im abgesicherten Modus mit Netzwerk aus

interaktion 30.01.2012 04:20

Code:

aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-30 04:04:49
-----------------------------
04:04:49.308    OS Version: Windows x64 6.1.7601 Service Pack 1
04:04:49.308    Number of processors: 4 586 0x2505
04:04:49.308    ComputerName: BLUBB-NEU  UserName: Blubb
04:04:58.153    Initialze error C0000061 - driver not loaded
04:05:00.743    AVAST engine defs: 12012901
04:05:01.913    Service scanning
04:05:02.958    Modules scanning
04:05:02.958    Disk 0 trace - called modules:
04:05:02.958   
04:05:04.284    AVAST engine scan C:\Windows
04:05:10.274    AVAST engine scan C:\Windows\system32
04:07:26.057    AVAST engine scan C:\Windows\system32\drivers
04:07:41.064    AVAST engine scan C:\Users\Blubb
04:12:10.539    AVAST engine scan C:\ProgramData
04:13:03.220    Scan finished successfully
04:13:17.494    The log file has been saved successfully to "C:\Users\Blubb\Desktop\aswMBR.txt"

Ist es das, was du haben wolltest? :/ Einen anderen Log hab ich irgendwie nicht bekommen können...

cosinus 30.01.2012 10:33

Nee, das trifft den Nagel nicht so ganz auf den Kopf :(
Hast du aswMBR per Rechtsklick als Admin gestartet? SIeht so aus, als wenn nicht gemacht worden sei...

interaktion 30.01.2012 13:32

Doch! Aber es kam auch im abgesicherten Modus keine Frage danach, ob ich ihn denn per Admin starten möchte. Es startete einfach ganz normal, so als hätte ich doppelt geklickt.

Ich probiers nochmal.

interaktion 30.01.2012 14:14

Wieder nur so, obwohl als Administrator ausgeführt:

Code:

aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-30 13:40:44
-----------------------------
13:40:44.029    OS Version: Windows x64 6.1.7601 Service Pack 1
13:40:44.029    Number of processors: 4 586 0x2505
13:40:44.029    ComputerName: BLUBB-NEU  UserName: Blubb
13:40:51.018    Initialze error C0000061 - driver not loaded
13:40:53.451    AVAST engine defs: 12012901
13:40:56.431    Service scanning
13:40:57.336    Modules scanning
13:40:57.336    Disk 0 trace - called modules:
13:40:57.336   
13:41:03.232    AVAST engine scan C:\Windows
13:41:10.939    AVAST engine scan C:\Windows\system32
13:43:16.769    AVAST engine scan C:\Windows\system32\drivers
13:43:31.823    AVAST engine scan C:\Users\Blubb
13:48:13.559    AVAST engine scan C:\ProgramData
13:49:07.691    Scan finished successfully
13:49:16.833    The log file has been saved successfully to "C:\Users\Blubb\Desktop\aswMBR.txt"

Wollte es dann nochmal im "normalen Modus" versuchen; nach dem zweiten Versuch (weil Absturz) bekam ich wegen irgendeinem driver_irql_not_less_or_egual zweimal einen Blue-Screen. Musste den PC aus- und einschalten. Was ist das? :(

Was soll ich weiter tun? :(

cosinus 30.01.2012 14:16

Ich schlag mal vor:

Wir fixen den MBR jetzt manuell. Sichere vorher für den Fall der Fälle alle wichtigen Daten.

Hast Du noch andere Betriebssysteme außer Win7 (64-Bit) installiert?
Wenn nicht: Schau mal hier => RescueDisc-Win7-64-Bit

Lad das iso runter, brenn es zB mit ImgBurn per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten)

Falls Du eine normale Win7-Installations-DVD (64-Bit) hast, brauchst Du das o.g. Image nicht sondern kannst einfach von der dieser DVD booten.

Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Führe im normalen Windowsmodus MBRcheck bzw. aswmbr (je nachdem welches Tool ich dir vorhin aufgab) und poste das neue Log.

interaktion 30.01.2012 14:19

Meine Windows-Installations-CD liegt in Hamburg. :( Ich geh nämlich in Bayern zur Schule und wohne nicht immer zuhause. :(

Muss meine Mum anrufen, dass sie mir die schickt. 2 - 3 Tage, hier bitte nicht schließen. :(

Oder kann ich das trotzdem mit diesem Image machen? Das wär gut, ich will nämlich vermeiden, die anzurufen. :D

cosinus 30.01.2012 14:20

Bitte die Anleitung lesen :pfeiff:
Wenn du selbst keine hast, geht das auch mit dem Rescue-Teil was ich verlinkt habe
Und für den Fall der Fälle kann man sich auch legal DVD-Abbilder für Win7 runterladen! => UNAWAVE - Downloads von Windows 7 ISO-Image-Dateien

interaktion 30.01.2012 14:22

Jaaaa, hab grade meinen Beitrag editiert, weil ich deine Anleitung nochmal gelesen hatte. :D


Alle Zeitangaben in WEZ +1. Es ist jetzt 07:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131