Elkészült az OTl log:
OTL logfile created on: 2010.04.30. 11:38:54 - Run 2
OTL by OldTimer - Version 3.2.3.1 Folder = C:\Documents and Settings\xy\Asztal
Windows XP Professional Edition Szervizcsomag 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000040E | Country: Magyarország | Language: HUN | Date Format: yyyy.MM.dd.
126,00 Mb Total Physical Memory | 20,00 Mb Available Physical Memory | 16,00% Memory free
304,00 Mb Paging File | 169,00 Mb Available in Paging File | 55,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,53 Gb Total Space | 0,71 Gb Free Space | 7,41% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OTTHONI
Current User Name: xy
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.04.30 11:36:56 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
PRC - [2008.08.21 21:41:32 | 002,405,776 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.04.30 11:36:56 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
MOD - [2006.08.25 17:53:57 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (gupdate1ca9828fd274e70) Google frissítési szolgáltatás (gupdate1ca9828fd274e70)
SRV - File not found [Disabled | Stopped] -- -- (CarboniteService)
SRV - [2010.01.25 11:00:54 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2008.08.21 21:41:32 | 002,405,776 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
========== Driver Services (SafeList) ==========
DRV - [2008.08.21 21:41:40 | 000,353,680 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2008.04.21 08:19:58 | 000,051,648 | ---- | M] (Check Point Software Technologies LTD) [Kernel | Boot | Running] -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan)
DRV - [2004.08.03 23:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004.08.03 23:04:34 | 000,012,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2004.08.03 23:03:36 | 000,088,448 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2004.08.03 22:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wvchntxx.sys -- (iAimFP4)
DRV - [2004.08.03 22:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wsiintxx.sys -- (iAimFP3)
DRV - [2004.08.03 22:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv10nt.sys -- (iAimTV5)
DRV - [2004.08.03 22:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wch7xxnt.sys -- (iAimTV4)
DRV - [2004.08.03 22:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv06nt.sys -- (iAimTV6)
DRV - [2004.08.03 22:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv04nt.sys -- (iAimTV3)
DRV - [2004.08.03 22:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv02nt.sys -- (iAimTV1)
DRV - [2004.08.03 22:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv01nt.sys -- (iAimTV0)
DRV - [2004.08.03 22:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv09nt.sys -- (iAimFP7)
DRV - [2004.08.03 22:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv07nt.sys -- (iAimFP5)
DRV - [2004.08.03 22:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv08nt.sys -- (iAimFP6)
DRV - [2004.08.03 22:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004.08.03 22:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv01nt.sys -- (iAimFP0)
DRV - [2004.08.03 22:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv02nt.sys -- (iAimFP1)
DRV - [2004.08.03 22:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv05nt.sys -- (iAimFP2)
DRV - [2001.10.26 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2001.10.26 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2001.08.17 22:19:34 | 000,040,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
DRV - [2001.08.17 22:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.hu/
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010.04.29 21:19:36 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {DE2F0988-E455-48ED-A35D-4D73D333D561}
https://gate.gov.hu/sdx/SDXFormSigner.cab (FormSigner Class)
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65}
https://plugins.valueactive.eu/flashax/iefax.cab (Flash Casino Helper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 84.1.98.182 208.67.220.220
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Jelenlegi saját honlap) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\xy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\xy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007.10.24 14:34:14 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.at3 - C:\WINDOWS\System32\atrac3.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.hfyu - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\IR41_32.DLL (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\IYVU9_32.DLL ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 7 Days ==========
File not found -- C:\Documents and Settings\xy\Asztal\CAMN27A5.
[2010.04.30 11:36:45 | 000,562,176 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
[2010.04.29 21:58:45 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.04.29 15:14:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.04.29 14:49:21 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.29 14:49:08 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.28 21:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Application Data\Artweaver
[2010.04.28 20:57:38 | 000,000,000 | ---D | C] -- C:\Program Files\Artweaver 0.4
[2010.04.28 20:55:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Asztal\artweaver
[2010.04.28 17:30:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Asztal\Ovis képek
[2010.04.28 17:29:19 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010.04.24 20:24:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Asztal\keretek
[2010.04.24 20:05:21 | 000,000,000 | ---D | C] -- C:\Program Files\PhotoFiltre Studio
[2010.04.24 19:39:03 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\xy\Recent
[2010.04.24 08:29:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Asztal\Originals
[52 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
File not found -- C:\Documents and Settings\xy\Asztal\CAMN27A5.
[2010.04.30 11:36:56 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
[2010.04.30 11:04:06 | 000,348,371 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2010.04.30 11:03:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.30 11:03:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.30 11:03:09 | 132,427,776 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.30 10:53:17 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\Marina.exe
[2010.04.30 10:48:34 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.04.30 10:02:14 | 000,002,855 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.04.30 10:00:32 | 000,000,386 | -H-- | M] () -- C:\WINDOWS\tasks\{06C4A412-99DD-4FF5-AAF0-1A9F333550B5}_OTTHONI_xy.job
[2010.04.30 06:14:15 | 009,699,328 | ---- | M] () -- C:\Documents and Settings\xy\ntuser.dat
[2010.04.30 06:14:15 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\xy\ntuser.ini
[2010.04.29 23:38:36 | 003,229,904 | -H-- | M] () -- C:\Documents and Settings\xy\Local Settings\Application Data\IconCache.db
[2010.04.29 23:13:32 | 000,107,605 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\barátság.jpg
[2010.04.29 23:12:47 | 000,031,744 | -H-- | M] () -- C:\Documents and Settings\xy\Asztal\photothumb.db
[2010.04.29 21:30:40 | 000,000,846 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.29 21:19:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.04.29 19:45:17 | 000,490,232 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\HelpAsst_mebroot_fix.exe
[2010.04.29 15:11:54 | 003,923,816 | R--- | M] () -- C:\Documents and Settings\xy\Asztal\ComboFix.exe
[2010.04.29 14:43:06 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\RSIT.exe
[2010.04.28 20:59:24 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\Artweaver 0.4.lnk
[2010.04.28 17:25:35 | 041,116,464 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\setuphun.exe
[2010.04.26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010.04.24 20:06:36 | 000,000,045 | -H-- | M] () -- C:\WINDOWS\dsez0057.dat
[2010.04.24 20:05:56 | 000,000,685 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\PhotoFiltre Studio.lnk
[2010.04.24 08:29:13 | 000,075,332 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\anigif.gif
[52 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.04.30 10:53:16 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\Marina.exe
[2010.04.29 22:21:42 | 000,107,605 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\barátság.jpg
[2010.04.29 19:45:08 | 000,490,232 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\HelpAsst_mebroot_fix.exe
[2010.04.29 15:11:44 | 003,923,816 | R--- | C] () -- C:\Documents and Settings\xy\Asztal\ComboFix.exe
[2010.04.29 14:42:50 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\RSIT.exe
[2010.04.28 20:59:24 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\Artweaver 0.4.lnk
[2010.04.28 17:24:31 | 041,116,464 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\setuphun.exe
[2010.04.24 20:06:36 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez0057.dat
[2010.04.24 20:05:55 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\PhotoFiltre Studio.lnk
[2010.04.24 08:09:56 | 000,075,332 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\anigif.gif
[2010.03.18 08:21:37 | 000,312,968 | ---- | C] () -- C:\WINDOWS\System32\SDX.dll
[2010.02.10 10:36:13 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2009.09.25 19:15:48 | 000,000,026 | ---- | C] () -- C:\WINDOWS\ulead32.ini
[2009.06.17 21:33:57 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\IYVU9_32.DLL
[2009.03.20 19:31:36 | 004,425,326 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2009.03.19 23:36:48 | 000,557,469 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2009.03.02 21:10:48 | 000,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.03.02 21:10:22 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2009.03.02 18:19:36 | 000,183,296 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2009.03.02 18:19:30 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2009.03.02 18:19:14 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2009.03.02 18:18:46 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2009.03.02 18:18:32 | 000,257,024 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2009.03.02 18:18:28 | 000,142,848 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2009.03.02 18:18:18 | 000,486,400 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2009.03.02 16:54:20 | 000,328,334 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2009.03.02 16:45:14 | 000,146,098 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2009.03.02 16:42:54 | 000,425,040 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2009.03.02 16:35:56 | 000,898,465 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2009.02.01 19:31:43 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.01.11 00:17:32 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2009.01.11 00:16:56 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2009.01.11 00:16:50 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2009.01.11 00:16:14 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2009.01.11 00:15:54 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2009.01.11 00:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2009.01.11 00:15:32 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2009.01.11 00:15:28 | 000,246,784 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2009.01.11 00:15:12 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2009.01.11 00:14:08 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2009.01.11 00:14:06 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2008.12.04 00:11:50 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.11.29 18:40:33 | 000,000,206 | ---- | C] () -- C:\WINDOWS\MPLAYER.INI
[2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008.10.27 09:01:07 | 000,000,024 | ---- | C] () -- C:\WINDOWS\TB50.INI
[2008.04.15 18:54:28 | 000,000,048 | ---- | C] () -- C:\WINDOWS\mtb30.ini
[2008.04.15 18:54:26 | 000,000,037 | ---- | C] () -- C:\WINDOWS\progman.ini
[2008.02.29 09:43:20 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\ENoSignature.dll
[2008.02.12 16:47:41 | 000,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.01.28 18:08:09 | 000,000,063 | ---- | C] () -- C:\WINDOWS\System32\SKVersion.ini
[2008.01.28 18:06:17 | 000,002,368 | ---- | C] () -- C:\WINDOWS\System32\sk_bho.ini
[2008.01.09 16:01:48 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007.12.25 13:37:20 | 000,000,049 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2007.12.19 08:50:42 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007.12.02 18:05:13 | 000,000,248 | ---- | C] () -- C:\WINDOWS\phedit.ini
[2007.12.01 15:54:22 | 000,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2007.11.27 12:35:16 | 000,000,256 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.11.06 16:37:38 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2007.10.31 20:13:29 | 000,006,213 | ---- | C] () -- C:\WINDOWS\cncscore.ini
[2007.10.24 23:42:15 | 000,001,267 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.10.13 11:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2007.07.10 19:10:12 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2005.06.01 01:16:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SpyPryUN.dll
[2005.02.22 12:48:21 | 000,622,113 | ---- | C] () -- C:\WINDOWS\System32\List.dll
[2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000011.DLL
[2000.01.07 02:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[2000.01.07 02:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv
[1999.04.11 22:54:20 | 000,286,208 | ---- | C] () -- C:\WINDOWS\System32\cncs232.dll
========== LOP Check ==========
[2007.12.02 09:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2007.12.26 08:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarGameBox
[2010.04.14 19:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007.12.06 18:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008.01.08 11:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\namesuppressed
[2008.01.27 18:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Phenomedia
[2009.12.30 10:40:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SoftPerfect
[2008.07.20 15:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007.12.18 22:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2007.12.02 09:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\ACD Systems
[2007.12.26 08:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\alawar
[2010.04.28 21:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Artweaver
[2010.03.01 13:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit
[2007.10.31 14:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\funkitron
[2010.01.29 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\GetRightToGo
[2010.03.07 14:13:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\IObit
[2008.11.19 18:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\mbin.jp
[2010.03.21 08:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\OpenOffice.org
[2010.03.05 22:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Opera
[2010.01.02 15:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PVST Manager
[2009.10.31 10:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Uniblue
[2010.01.01 09:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Unity
[2010.01.25 14:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\VSTT Manager
[2010.04.30 10:00:32 | 000,000,386 | -H-- | M] () -- C:\WINDOWS\Tasks\{06C4A412-99DD-4FF5-AAF0-1A9F333550B5}_OTTHONI_xy.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2007.12.02 09:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2009.11.16 14:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2007.12.26 08:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarGameBox
[2010.04.14 19:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009.11.06 15:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2010.01.24 08:20:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.12.14 18:37:52 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2007.10.30 17:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2007.12.06 18:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008.01.08 11:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\namesuppressed
[2010.02.16 15:07:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2008.01.27 18:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Phenomedia
[2010.01.19 13:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2009.12.30 10:40:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SoftPerfect
[2008.07.20 15:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008.07.23 16:09:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2007.10.25 16:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007.12.18 22:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2007.12.02 09:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\ACD Systems
[2010.02.16 14:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Adobe
[2008.01.06 14:49:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\AdobeUM
[2007.12.26 08:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\alawar
[2010.02.23 18:03:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Apple Computer
[2010.04.28 21:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Artweaver
[2009.08.13 15:44:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DivX
[2010.03.01 13:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit
[2007.10.31 14:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\funkitron
[2010.01.29 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\GetRightToGo
[2007.11.01 11:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Google
[2010.04.23 10:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Help
[2007.10.24 19:29:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Identities
[2010.03.07 14:13:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\IObit
[2009.12.02 07:44:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Macromedia
[2010.01.24 08:21:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Malwarebytes
[2008.11.19 18:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\mbin.jp
[2009.10.20 10:10:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\xy\Application Data\Microsoft
[2010.03.01 15:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Mozilla
[2009.01.03 22:26:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\MSN6
[2010.03.21 08:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\OpenOffice.org
[2010.03.05 22:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Opera
[2010.01.02 15:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PVST Manager
[2010.01.19 12:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\skypePM
[2007.10.31 17:51:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Sun
[2008.01.22 12:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Talkback
[2009.10.31 10:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Uniblue
[2010.01.01 09:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Unity
[2010.01.25 14:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\VSTT Manager
[2008.03.02 21:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\WinRAR
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\dllcache\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2001.10.26 14:00:00 | 000,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CHANGER.SYS >
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:Changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\system32\dllcache\changer.sys
< MD5 for: CRYPTSVC.DLL >
[2001.10.26 14:00:00 | 000,051,200 | ---- | M] (Microsoft Corporation) MD5=05259C29C8093E6EE1AE7A8F4DE7B807 -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2001.10.26 14:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=2DA8D38CF8D86B5C02DFFAC2615FC1C4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2001.10.26 14:00:00 | 001,003,008 | ---- | M] (Microsoft Corporation) MD5=495D8BA14043F4402ECF51C2AB73D8DD -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004.08.17 16:47:58 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=5BF20DA8E16049C4BE8E15EEE1F427C1 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2004.08.17 16:47:58 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=5BF20DA8E16049C4BE8E15EEE1F427C1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 15:12:07 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=6CF1696892BE31A2EC25072A99E2E3FF -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2001.10.26 14:00:00 | 000,078,464 | ---- | M] (Microsoft Corporation) MD5=254916581AC499E53EE700E7E5B9E5B5 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[2004.08.03 22:59:08 | 000,081,280 | ---- | M] (Microsoft Corporation) MD5=4AF58CA3425F28FC5E3DB47DC122F722 -- C:\WINDOWS\system32\HAL.DLL
[2004.08.03 22:59:20 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=C321C95318495909A0066FB0EDC97287 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
< MD5 for: LSASS.EXE >
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\system32\lsass.exe
[2001.10.26 14:00:00 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=9AAD6A77CDBE6DAA9758A28B9145E580 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
< MD5 for: NDIS.SYS >
[2001.10.26 14:00:00 | 000,161,536 | ---- | M] (Microsoft Corporation) MD5=3EFD4F59BA0A340DE0A3AB984001DBF7 -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\system32\netlogon.dll
[2001.10.26 14:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=3D8811CB0A5AE38442BB0966282D7796 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\system32\scecli.dll
[2001.10.26 14:00:00 | 000,179,712 | ---- | M] (Microsoft Corporation) MD5=FA3E6E756841725EE113BADECBCB26D9 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\system32\smss.exe
[2001.08.17 23:37:00 | 000,469,504 | ---- | M] (Microsoft Corporation) MD5=C37F36D08F06A7B0CAF8C1EE9E4079A3 -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2001.10.26 14:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=ED12D92A7B26E99E3A5BF4B043F7314E -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
< MD5 for: SVCHOST.EXE >
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\system32\svchost.exe
[2001.10.26 14:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=9D08A7B580F0C829A40D7964E1D7CC68 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[2001.10.26 14:00:00 | 000,327,168 | ---- | M] (Microsoft Corporation) MD5=E7774698BB0D14B0710A9A31E209F9B6 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
< MD5 for: USERINIT.EXE >
[2001.10.26 14:00:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=969BA3BAC25FB9EB5D652F767B49717C -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\system32\winlogon.exe
[2001.10.26 14:00:00 | 000,432,128 | ---- | M] (Microsoft Corporation) MD5=E0F2312FB3DE3D83B915BB82CA42F3F0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\system32\ws2_32.dll
[2001.10.26 14:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=F57E0EA4977D1973D1A41B73352F56A2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007.10.24 16:17:28 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007.10.24 16:17:27 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007.10.24 16:17:27 | 000,380,928 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< End of report >