+ 2010-08-12 19:40 . 2010-08-12 19:40 156813 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\1033\StructuredQuerySchema.bin
- 2007-11-19 11:44 . 2010-07-14 10:05 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-08-12 12:09 . 2010-05-06 10:41 916480 c:\windows\ie8updates\KB2183461-IE8\wininet.dll
+ 2010-08-12 12:09 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB2183461-IE8\spuninst\updspapi.dll
+ 2010-08-12 12:09 . 2009-05-26 09:01 231288 c:\windows\ie8updates\KB2183461-IE8\spuninst\spuninst.exe
+ 2010-08-12 12:09 . 2010-05-06 10:41 206848 c:\windows\ie8updates\KB2183461-IE8\occache.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 611840 c:\windows\ie8updates\KB2183461-IE8\mstime.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 599040 c:\windows\ie8updates\KB2183461-IE8\msfeeds.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 247808 c:\windows\ie8updates\KB2183461-IE8\ieproxy.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 184320 c:\windows\ie8updates\KB2183461-IE8\iepeers.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 743424 c:\windows\ie8updates\KB2183461-IE8\iedvtool.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 387584 c:\windows\ie8updates\KB2183461-IE8\iedkcs32.dll
+ 2010-08-12 12:09 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2183461-IE8\ie4uinit.exe
+ 2009-07-11 17:46 . 2009-07-11 17:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 17:46 . 2009-07-11 17:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2006-02-28 12:00 . 2010-06-24 12:22 1210368 c:\windows\system32\urlmon.dll
- 2006-02-28 12:00 . 2010-02-16 14:08 2146304 c:\windows\system32\ntoskrnl.exe
+ 2006-02-28 12:00 . 2010-04-27 13:59 2146304 c:\windows\system32\ntoskrnl.exe
+ 2004-08-03 22:59 . 2010-04-27 13:05 2024448 c:\windows\system32\ntkrnlpa.exe
- 2004-08-03 22:59 . 2010-02-16 13:25 2024448 c:\windows\system32\ntkrnlpa.exe
+ 2006-02-28 12:00 . 2010-06-24 12:22 5951488 c:\windows\system32\mshtml.dll
+ 2007-08-13 16:34 . 2010-06-24 12:21 1986560 c:\windows\system32\iertutil.dll
- 2007-11-14 21:57 . 2010-07-26 04:24 2275512 c:\windows\system32\FNTCACHE.DAT
+ 2007-11-14 21:57 . 2010-08-12 13:02 2275512 c:\windows\system32\FNTCACHE.DAT
+ 2008-10-15 03:14 . 2010-06-23 13:44 1851904 c:\windows\system32\dllcache\win32k.sys
+ 2006-02-28 12:00 . 2010-06-24 12:22 1210368 c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-15 03:13 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-15 03:13 . 2010-02-17 06:10 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-15 03:13 . 2010-02-16 13:25 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 03:13 . 2010-04-27 13:05 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
- 2008-10-15 03:13 . 2010-02-16 13:25 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-15 03:13 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-15 03:13 . 2010-02-16 14:08 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-10-15 03:13 . 2010-04-27 13:59 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-11-12 19:14 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-11-12 19:14 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2006-02-28 12:00 . 2010-06-24 12:22 5951488 c:\windows\system32\dllcache\mshtml.dll
+ 2010-03-10 18:10 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2010-03-10 18:10 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2007-08-20 10:04 . 2010-06-24 12:21 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2010-07-26 13:00 . 2010-07-26 13:00 5010944 c:\windows\Installer\cdf8f.msp
+ 2010-08-12 07:01 . 2010-08-12 07:01 4151296 c:\windows\Installer\a3ccc.msi
+ 2007-11-19 11:44 . 2010-08-12 12:11 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2007-11-19 11:44 . 2010-08-12 12:11 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2007-11-19 11:44 . 2010-07-14 10:05 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-08-12 12:09 . 2010-05-06 10:41 1209344 c:\windows\ie8updates\KB2183461-IE8\urlmon.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 5950976 c:\windows\ie8updates\KB2183461-IE8\mshtml.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 1985536 c:\windows\ie8updates\KB2183461-IE8\iertutil.dll
- 2008-10-15 03:13 . 2010-02-17 06:10 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-15 03:13 . 2010-04-28 02:25 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-10-15 03:13 . 2010-02-16 13:25 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-15 03:13 . 2010-04-27 13:05 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-15 03:13 . 2010-02-16 13:25 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 03:13 . 2010-04-27 13:05 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 03:13 . 2010-04-27 13:59 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-15 03:13 . 2010-02-16 14:08 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2007-11-19 11:26 . 2010-08-03 18:09 35962312 c:\windows\system32\MRT.exe
+ 2007-08-13 16:54 . 2010-06-24 14:51 11077120 c:\windows\system32\ieframe.dll
+ 2007-08-20 10:04 . 2010-06-24 14:51 11077120 c:\windows\system32\dllcache\ieframe.dll
+ 2010-08-12 12:09 . 2010-05-06 10:41 11076096 c:\windows\ie8updates\KB2183461-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2007-05-11 2512392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2010-06-19 38840]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-06-19 640440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations MP4\avp.exe" [2010-03-12 311680]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\prinect\Start Menu\Programs\Startup\
map.bat [2008-11-26 116]
mapI.bat [2009-10-8 61]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2008-1-23 708608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Signa Station 3\\PrinectSignaStation3.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Signa Station 4\\PrinectSignaStation4.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\PTSupport\\PrinectService\\HDPrinectService.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\CEPSConverter\\HDCEPSConverter.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\ColorCarver\\HDColorCarver.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\ContentHotfolder\\HDContentHotfolder.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\CopydotConverter\\HDCopydotConverter.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\DocumentHandler\\HDPDFDocumentHandler.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\ImageHandler\\HDPDFImageHandler.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Imposer\\HDPDFImposer.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\JobImExporter\\HDJobImportExport.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Messenger\\HDMessenger.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Normalizer\\HDNormalizer.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\AutoPage\\HDAutoPage.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Preflighter\\HDPreflighter.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Recombiner\\HDRecombiner.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\ResponseHandler\\HDResponseHandler.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\AutoSheet\\HDAutoSheet.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Trapper\\HDTrapper.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\Cockpit\\PTClient.exe"=
"c:\\Program Files\\Heidelberg\\Prinect Workflow\\PTSupport\\JRE\\bin\\java.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\Heidelberg\\Licensing\\License Server\\HDLicenseServer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24654:UDP"= 24654:UDP:Enfocus Port
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"123:UDP"= 123:UDP:System Time (NTP) Port
"427:UDP"= 427:UDP:AppleShare IP TCP Port 427
"548:UDP"= 548:UDP:AppleShare IP TCP Port 548
"520:UDP"= 520:UDP:Routing Information Protocol (RIP) Port
"65001:TCP"= 65001:TCP:Heidelberg Local Information Service Monitor (65001)
"65001:UDP"= 65001:UDP:Heidelberg Local Information Service Monitor (65001)
"65002:TCP"= 65002:TCP:Heidelberg Local Information Service Monitor (65002)
"65002:UDP"= 65002:UDP:Heidelberg Local Information Service Monitor (65002)
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R2 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_0\bin\fb_inet_server.exe -s --> c:\program files\Firebird\Firebird_2_0\bin\fb_inet_server.exe -s [?]
R2 HDLicenseServer;Heidelberg License Server Service;c:\program files\Heidelberg\Licensing\License Server\HDLicenseServer.exe [13.9.2004 г. 15:23 221184]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [23.1.2008 г. 16:41 14416]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [03.9.2009 г. 15:24 24848]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14.9.2009 г. 13:42 32272]
S2 Color Proof Pro Server;Color Proof Pro Server;c:\program files\Heidelberg\Color Proof Pro\Server\ColorProofPro_Server.exe -service "Color Proof Pro Server" --> c:\program files\Heidelberg\Color Proof Pro\Server\ColorProofPro_Server.exe -service Color Proof Pro Server [?]
S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29.7.2009 г. 15:59 133104]
S2 HDLISMonitor;Heidelberg Local Information Service Monitor;c:\program files\Heidelberg\Service Tools\bin\HDLISMonitor.exe [14.4.2008 г. 15:11 382256]
S2 HDPrinectSignaStationServer4;Heidelberg Prinect Signa Station 4 Server;c:\program files\Heidelberg\Prinect Signa Station 4\HDPrinectSignaStationServer4.exe [08.9.2004 г. 14:00 303104]
S2 Printready;Heidelberg Prinect;c:\program files\Heidelberg\Prinect Workflow\PTSupport\PrinectService\HDPrinectService.exe [24.4.2008 г. 09:09 1537328]
S3 eyeonedp;eye-one display;c:\windows\system32\drivers\eyeonedp.sys [23.1.2008 г. 16:38 44344]
S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe --> c:\program files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [06.5.2008 г. 16:06 11520]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.11.2007 г. 20:18 685816]
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
2010-08-18 c:\windows\Tasks\User_Feed_Synchronization-{11F60A2F-4588-43E6-A463-EB640A8120EA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:31]