| Virtumonde nice, hab ich wieder was dazu gelernt :> Zitat:
ComboFix 08-05-21.3 - **** 2008-05-25 16:43:05.4 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1031.18.1366 [GMT 2:00]
ausgeführt von:: E:\Installationsdateien\Programme\AntiVirus und Firewall\ComboFix.exe
Command switches used :: C:\Users\****\Desktop\CFScript.txt
* Neuer Wiederherstellungspunkt wurde erstellt
FILE ::
C:\Users\****\AppData\Local\Temp\setup_526_1_.exe
C:\Users\****\AppData\Local\Temp\stdcons.exe
C:\Windows\system32\jegxonnb.dll
C:\Windows\system32\lnvscxgy.dll
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\jegxonnb.dll
C:\Windows\system32\lnvscxgy.dll
.
((((((((((((((((((((((( Dateien erstellt von 2008-04-25 bis 2008-05-25 ))))))))))))))))))))))))))))))
.
2008-05-25 15:29 . 2008-05-25 15:40 <DIR> d-------- C:\Users\****\AppData\Roaming\Winamp
2008-05-25 15:00 . 2008-05-25 15:00 <DIR> d-------- C:\Deckard
2008-05-25 12:09 . 2008-05-25 12:09 <DIR> d-------- C:\Users\****\AppData\Roaming\Malwarebytes
2008-05-25 12:09 . 2008-05-25 12:09 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-05-25 12:09 . 2008-05-25 12:09 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-25 12:09 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-25 12:09 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-25 02:45 . 2008-05-25 16:41 <DIR> d-------- C:\327882R2FWJFW
2008-05-25 01:40 . 2008-05-25 01:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-24 21:59 . 2008-05-24 21:59 <DIR> d-------- C:\Users\****\AppData\Roaming\SmartFTP
2008-05-21 22:32 . 2008-05-21 22:33 <DIR> d-------- C:\Program Files\CPU-Z
2008-05-21 22:32 . 2008-05-21 22:51 524,288 --ahs---- C:\ntuser.dat{e999d27f-2774-11dd-b51f-00508db7eb82}.TMContainer00000000000000000002.regtrans-ms
2008-05-21 22:32 . 2008-05-21 22:51 524,288 --ahs---- C:\ntuser.dat{e999d27f-2774-11dd-b51f-00508db7eb82}.TMContainer00000000000000000001.regtrans-ms
2008-05-21 22:32 . 2008-05-21 22:51 65,536 --ahs---- C:\ntuser.dat{e999d27f-2774-11dd-b51f-00508db7eb82}.TM.blf
2008-05-21 22:28 . 2008-05-25 14:41 262,144 --a------ C:\ntuser.dat
2008-05-21 22:28 . 2008-05-25 14:41 5,120 --ah----- C:\ntuser.dat.LOG1
2008-05-21 22:28 . 2008-05-21 22:32 0 --ah----- C:\ntuser.dat.LOG2
2008-05-21 21:52 . 2008-05-21 21:52 <DIR> d-------- C:\Program Files\Razer
2008-05-21 21:52 . 2005-11-10 09:15 69,632 --a------ C:\Windows\System32\copperhd.cpl
2008-05-21 20:37 . 2008-05-21 20:37 944,184 --a------ C:\Windows\System32\winload.exe
2008-05-21 20:37 . 2008-05-21 20:37 620,088 --a------ C:\Windows\System32\ci.dll
2008-05-21 20:37 . 2008-05-21 20:37 371,712 --a------ C:\Windows\System32\srcore.dll
2008-05-21 20:37 . 2008-05-21 20:37 313,856 --a------ C:\Windows\System32\rstrui.exe
2008-05-21 20:37 . 2008-05-21 20:37 40,960 --a------ C:\Windows\System32\srclient.dll
2008-05-21 20:37 . 2008-05-21 20:37 19,000 --a------ C:\Windows\System32\kd1394.dll
2008-05-21 20:37 . 2008-05-21 20:37 16,384 --a------ C:\Windows\System32\srdelayed.exe
2008-05-21 20:37 . 2008-05-21 20:37 7,168 --a------ C:\Windows\System32\f3ahvoas.dll
2008-05-21 20:37 . 2008-05-21 20:37 6,656 --a------ C:\Windows\System32\kbd106n.dll
2008-05-21 20:36 . 2008-05-21 20:36 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-05-21 20:35 . 2008-05-21 20:35 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-05-21 20:34 . 2008-05-21 20:34 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-05-21 20:34 . 2008-05-21 20:34 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-05-21 20:33 . 2008-05-21 20:33 99,840 --a------ C:\Windows\System32\poqexec.exe
2008-05-21 19:39 . 2008-05-24 22:41 54,832 --a------ C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-21 19:39 . 2008-05-24 22:41 54,832 --a------ C:\Windows\System32\BMXState-{00000004-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-21 19:39 . 2008-05-24 22:41 788 --a------ C:\Windows\System32\DVCState-{00000004-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-21 18:52 . 2008-05-21 18:53 524,288 --ahs---- C:\ntuser.dat{3fab4d87-2756-11dd-b970-00508db7eb82}.TMContainer00000000000000000002.regtrans-ms
2008-05-21 18:52 . 2008-05-21 18:53 524,288 --ahs---- C:\ntuser.dat{3fab4d87-2756-11dd-b970-00508db7eb82}.TMContainer00000000000000000001.regtrans-ms
2008-05-21 18:52 . 2008-05-21 18:53 65,536 --ahs---- C:\ntuser.dat{3fab4d87-2756-11dd-b970-00508db7eb82}.TM.blf
2008-05-20 23:26 . 2008-05-24 04:04 2,064 --a------ C:\Windows\System32\settingsbkup.sfm
2008-05-20 23:26 . 2008-05-24 04:04 2,064 --a------ C:\Windows\System32\settings.sfm
2008-05-20 22:36 . 2008-05-25 15:25 54,928 --a------ C:\Windows\System32\BMXStateBkp-{00000005-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-20 22:36 . 2008-05-25 15:25 54,928 --a------ C:\Windows\System32\BMXState-{00000005-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-20 22:36 . 2008-05-25 15:25 788 --a------ C:\Windows\System32\DVCState-{00000005-00000000-00000003-00001102-00000005-002C1102}.rfx
2008-05-18 22:04 . 2008-05-25 02:43 969 --a------ C:\Windows\wininit.ini
2008-05-18 21:49 . 2008-05-18 22:04 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-05-18 21:49 . 2008-05-18 21:49 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-18 21:27 . 2008-05-18 21:27 <DIR> d-------- C:\Users\****\AppData\Roaming\Scooter Software
2008-05-18 21:27 . 2008-05-18 21:51 <DIR> d-------- C:\Program Files\Beyond Compare 2
2008-05-11 16:36 . 2008-05-11 17:17 1,905 --a------ C:\Windows\diagwrn.xml
2008-05-11 16:36 . 2008-05-11 17:17 1,905 --a------ C:\Windows\diagerr.xml
2008-05-11 08:17 . 2008-05-11 08:17 <DIR> d-------- C:\Users\****\AppData\Roaming\InstallShield
2008-05-10 16:26 . 2008-05-10 16:26 <DIR> d-------- C:\Program Files\Microsoft Web Designer Tools
2008-05-10 16:26 . 2008-05-10 16:26 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-10 16:26 . 2008-05-10 16:26 <DIR> dr-h----- C:\MSOCache
2008-05-10 16:00 . 2008-05-10 16:10 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-05-10 15:55 . 2008-05-10 15:55 <DIR> d-------- C:\Program Files\Microsoft Synchronization Services
2008-05-10 15:55 . 2008-05-10 15:55 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-10 15:52 . 2008-05-10 16:28 <DIR> d-------- C:\ProgramData\Microsoft Help
2008-05-10 15:52 . 2008-05-10 16:27 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-10 15:52 . 2008-05-10 15:52 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-05-10 15:46 . 2008-05-10 15:46 779,800 --a------ C:\Windows\System32\PresentationNative_v0300.dll
2008-05-10 15:46 . 2008-05-10 15:46 579,584 --a------ C:\Windows\System32\icardagt.exe
2008-05-10 15:46 . 2008-05-10 15:46 350,744 --a------ C:\Windows\System32\PresentationHost.exe
2008-05-10 15:46 . 2008-05-10 15:46 106,520 --a------ C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2008-05-10 15:46 . 2008-05-10 15:46 88,576 --a------ C:\Windows\System32\infocardapi.dll
2008-05-10 15:46 . 2008-05-10 15:46 33,304 --a------ C:\Windows\System32\PresentationHostProxy.dll
2008-05-10 15:46 . 2008-05-10 15:46 28,160 --a------ C:\Windows\System32\infocardcpl.cpl
2008-05-10 15:46 . 2008-05-10 15:46 11,776 --a------ C:\Windows\System32\icardres.dll
2008-05-10 15:41 . 2008-05-10 15:41 282,112 --a------ C:\Windows\System32\mscoree.dll
2008-05-10 15:41 . 2008-05-10 15:41 158,720 --a------ C:\Windows\System32\mscorier.dll
2008-05-10 15:41 . 2008-05-10 15:41 96,760 --a------ C:\Windows\System32\dfshim.dll
2008-05-10 15:41 . 2008-05-10 15:41 84,480 --a------ C:\Windows\System32\mscories.dll
2008-05-10 15:41 . 2008-05-10 15:41 41,984 --a------ C:\Windows\System32\netfxperf.dll
2008-05-10 14:18 . 2008-05-12 10:59 <DIR> d-------- C:\Program Files\sft-loader_2008_rc1
2008-05-10 05:49 . 2008-05-11 12:39 <DIR> d-------- C:\Program Files\DC++
2008-05-10 04:13 . 2008-05-10 18:59 <DIR> d-------- C:\Program Files\Teamspeak2_RC2Server
2008-05-06 19:22 . 2008-05-06 19:22 <DIR> d-------- C:\Users\****\AppData\Roaming\IDMComp
2008-05-06 19:22 . 2008-05-06 19:22 <DIR> d-------- C:\Program Files\IDM Computer Solutions
2008-05-03 15:04 . 2008-05-03 15:04 1,720,086 --a------ C:\Windows\System32\TmpA19755795
2008-04-28 21:53 . 2008-04-28 22:00 <DIR> d-------- C:\Users\****\AppData\Roaming\XnView
2008-04-28 21:53 . 2008-04-28 21:53 <DIR> d-------- C:\Program Files\XnView
2008-04-28 19:23 . 2008-04-28 19:23 <DIR> d-------- C:\Windows\Sun
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-25 13:49 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-25 13:48 107,832 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-05-25 13:29 --------- d-----w C:\Program Files\Winamp
2008-05-24 23:41 --------- d-----w C:\Program Files\Gamers.IRC
2008-05-21 19:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-21 19:22 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-05-21 19:22 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-05-21 19:22 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-05-21 19:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-05-20 20:37 --------- d-----w C:\ProgramData\NVIDIA
2008-05-20 20:33 413,696 ----a-w C:\Windows\System32\wrap_oal.dll
2008-05-20 20:33 110,592 ----a-w C:\Windows\System32\OpenAL32.dll
2008-05-18 11:03 --------- d-----w C:\ProgramData\Xfire
2008-05-18 11:03 --------- d-----w C:\Program Files\Xfire
2008-05-17 15:12 --------- d-----w C:\Users\****\AppData\Roaming\Xfire
2008-05-15 20:25 --------- d-----w C:\Program Files\HLSW
2008-05-14 19:53 --------- d-----w C:\Users\****\AppData\Roaming\teamspeak2
2008-05-11 06:54 --------- d-----w C:\ProgramData\Media Center Programs
2008-05-10 14:06 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-22 22:29 41,296 ----a-w C:\Windows\System32\xfcodec.dll
2008-04-21 17:38 --------- d-----w C:\ProgramData\FLEXnet
2008-04-18 15:20 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-18 11:35 --------- d-----w C:\Users\****\AppData\Roaming\Nero
2008-04-18 11:34 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-18 11:33 --------- d-----w C:\ProgramData\Nero
2008-04-18 11:33 --------- d-----w C:\Program Files\Nero
2008-04-14 16:48 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-12 13:47 --------- d-----w C:\Program Files\Fraps
2008-04-11 21:10 --------- d-----w C:\Users\****\AppData\Roaming\Ubisoft
2008-04-11 20:20 --------- d-----w C:\ProgramData\Ubisoft
2008-04-11 15:31 --------- d-----w C:\Users\****\AppData\Roaming\InstallShield Installation Information
2008-04-11 15:23 38,400 ----a-w C:\Windows\System32\SoundSchemes.exe
2008-04-11 15:07 --------- d-----w C:\Program Files\Unreal Tournament 3 (LG)
2008-04-11 15:06 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-11 15:06 --------- d-----w C:\Program Files\AGEIA Technologies
2008-04-10 20:23 --------- d-----w C:\Program Files\Ventrilo23
2008-04-09 16:01 --------- d-----w C:\ProgramData\Adobe Systems
2008-04-09 16:01 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-04-09 15:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-08 21:05 --------- d-----w C:\Users\****\AppData\Roaming\U3
2008-04-08 20:35 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-07 14:32 --------- d-----w C:\Program Files\Samsung
2008-04-04 13:01 --------- d-----w C:\Program Files\Java
2008-04-04 13:00 --------- d-----w C:\Program Files\Common Files\Java
2008-04-01 14:31 --------- d-----w C:\Program Files\PokerStars
2008-03-31 12:23 --------- d-----w C:\Program Files\Alcohol Soft
2008-03-31 03:02 174 --sha-w C:\Program Files\desktop.ini
2008-03-31 02:58 --------- d-----w C:\Program Files\Windows Defender
2008-03-31 02:58 --------- d-----w C:\Program Files\Windows Calendar
2008-03-31 02:52 905,400 ----a-w C:\Windows\System32\winresume.exe
2008-03-31 02:51 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-03-31 02:51 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-03-31 02:49 88,576 ----a-w C:\Windows\System32\avifil32.dll
2008-03-31 02:48 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-03-31 02:48 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
2008-03-31 02:48 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-31 02:48 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-31 02:48 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-03-31 02:48 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-03-31 02:48 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-31 02:48 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-31 02:48 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-03-29 11:12 233,888 ----a-w C:\Windows\System32\DreamScene.dll
2008-03-29 11:12 1,152,000 ----a-w C:\Windows\System32\themecpl.dll
2008-03-28 15:16 --------- d-----r C:\Users\****\AppData\Roaming\Brother
2008-03-27 14:47 --------- d-----w C:\Program Files\audiograbber
2008-03-26 23:57 --------- d-----w C:\Program Files\Empire Interactive
2008-03-26 22:07 --------- d-----w C:\Program Files\Core Temp
2008-03-24 12:50 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-03-24 05:11 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-03-24 05:11 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-03-24 05:11 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-03-24 05:10 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-24 05:10 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-03-24 05:10 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-03-24 05:09 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-24 05:09 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-24 05:09 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-03-24 05:09 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-24 05:09 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-24 05:09 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-24 05:09 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-24 05:09 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-24 05:08 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-24 05:08 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-24 05:08 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-24 05:07 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-03-24 05:07 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-03-24 05:07 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-03-24 05:07 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-03-24 05:06 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-24 05:06 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-03-24 05:06 2,048 ----a-w C:\Windows\System32\msxml6r.dll
2008-03-24 05:06 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-03-24 05:06 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-03-24 05:05 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-03-24 05:05 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-03-24 05:05 669,184 ----a-w C:\Windows\System32\pbsvc.exe
2008-03-24 05:05 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-03-24 05:05 22,328 ----a-w C:\Users\****\AppData\Roaming\PnkBstrK.sys
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot_2008-05-25_ 2.47.23,87 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-25 00:26:32 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-25 13:26:50 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-25 00:26:33 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-05-25 13:26:50 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-05-25 00:26:33 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-05-25 13:26:50 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-05-25 00:28:07 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-25 13:28:25 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-25 13:28:25 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-05-25 00:28:01 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-25 13:28:20 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-25 13:28:20 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-05-25 00:26:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-25 08:26:47 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-25 00:26:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-25 08:26:47 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-25 00:26:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-25 08:26:47 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-25 00:32:31 145,766 ----a-w C:\Windows\System32\perfc007.dat
+ 2008-05-25 13:32:04 145,766 ----a-w C:\Windows\System32\perfc007.dat
- 2008-05-25 00:32:31 125,902 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-05-25 13:32:04 125,902 ----a-w C:\Windows\System32\perfc009.dat
- 2008-05-25 00:32:31 711,582 ----a-w C:\Windows\System32\perfh007.dat
+ 2008-05-25 13:32:04 711,582 ----a-w C:\Windows\System32\perfh007.dat
- 2008-05-25 00:32:31 667,884 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-05-25 13:32:04 667,884 ----a-w C:\Windows\System32\perfh009.dat
- 2008-05-25 00:28:29 8,124 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1067182651-4116881732-1640251941-1000_UserData.bin
+ 2008-05-25 13:28:42 8,124 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1067182651-4116881732-1640251941-1000_UserData.bin
- 2008-05-25 00:28:29 78,814 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-25 13:28:42 80,102 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-05-25 00:28:26 32,742 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-05-25 13:28:41 32,806 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
[...]
| |