Itt a log:OTL logfile created on: 2010.06.27. 20:00:36 - Run 3
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\xy\Asztal
Windows XP Professional Edition Szervizcsomag 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000040E | Country: Magyarország | Language: HUN | Date Format: yyyy.MM.dd.
126,00 Mb Total Physical Memory | 21,00 Mb Available Physical Memory | 17,00% Memory free
316,00 Mb Paging File | 61,00 Mb Available in Paging File | 19,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,53 Gb Total Space | 0,76 Gb Free Space | 8,00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OTTHONI
Current User Name: xy
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010.06.27 19:58:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
PRC - [2010.04.01 13:33:19 | 000,267,432 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010.03.02 11:28:31 | 000,282,792 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.02.24 10:28:09 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.01.14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008.08.21 21:41:32 | 002,405,776 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2008.08.21 21:41:32 | 000,981,904 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2010.06.27 19:58:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
MOD - [2006.08.25 17:53:57 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004.08.03 23:01:18 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- -- (gusvc)
SRV - File not found [Auto | Stopped] -- -- (gupdate1ca9828fd274e70) Google frissítési szolgáltatás (gupdate1ca9828fd274e70)
SRV - File not found [Disabled | Stopped] -- -- (CarboniteService)
SRV - File not found [On_Demand | Stopped] -- -- (aspnet_state)
SRV - [2010.04.01 13:33:19 | 000,267,432 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.03.29 08:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2010.02.24 10:28:09 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008.08.21 21:41:32 | 002,405,776 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2010.05.22 08:29:52 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.03.01 10:05:24 | 000,124,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.02.16 14:24:01 | 000,060,936 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.05.11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009.05.11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008.08.21 21:41:40 | 000,353,680 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2008.04.21 08:19:58 | 000,051,648 | ---- | M] (Check Point Software Technologies LTD) [Kernel | Boot | Running] -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan)
DRV - [2004.08.03 23:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004.08.03 23:04:34 | 000,012,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2004.08.03 23:03:36 | 000,088,448 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2004.08.03 22:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wvchntxx.sys -- (iAimFP4)
DRV - [2004.08.03 22:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wsiintxx.sys -- (iAimFP3)
DRV - [2004.08.03 22:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv10nt.sys -- (iAimTV5)
DRV - [2004.08.03 22:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wch7xxnt.sys -- (iAimTV4)
DRV - [2004.08.03 22:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv06nt.sys -- (iAimTV6)
DRV - [2004.08.03 22:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv04nt.sys -- (iAimTV3)
DRV - [2004.08.03 22:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv02nt.sys -- (iAimTV1)
DRV - [2004.08.03 22:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv01nt.sys -- (iAimTV0)
DRV - [2004.08.03 22:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv09nt.sys -- (iAimFP7)
DRV - [2004.08.03 22:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv07nt.sys -- (iAimFP5)
DRV - [2004.08.03 22:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv08nt.sys -- (iAimFP6)
DRV - [2004.08.03 22:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004.08.03 22:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv01nt.sys -- (iAimFP0)
DRV - [2004.08.03 22:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv02nt.sys -- (iAimFP1)
DRV - [2004.08.03 22:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv05nt.sys -- (iAimFP2)
DRV - [2001.10.26 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2001.10.26 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2001.08.17 22:19:34 | 000,040,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
DRV - [2001.08.17 22:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=
IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.hu/IE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010.06.27 18:16:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\ShellBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No CLSID value found.
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..\Toolbar\WebBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKU\S-1-5-21-725345543-1078145449-1202660629-1003\..Trusted Domains: 999jatekok.hu ([www] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/Messenger ... E_UNO1.cab (UnoCtrl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/f ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7}
http://www.gamehouse.com/games/SproutLauncher.cab (SproutLauncherCtrl Class)
O16 - DPF: {DE2F0988-E455-48ED-A35D-4D73D333D561}
https://gate.gov.hu/sdx/SDXFormSigner.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/Mi ... b56986.cab (Minesweeper Flags Class)
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65}
https://plugins.valueactive.eu/flashax/iefax.cab (Flash Casino Helper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 84.1.98.182 208.67.220.220
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Jelenlegi saját honlap) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\xy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\xy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007.10.24 14:34:14 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.at3 - C:\WINDOWS\System32\atrac3.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.hfyu - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\IR41_32.DLL (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\IYVU9_32.DLL ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ========== File not found -- C:\Documents and Settings\xy\Asztal\CAMN27A5.
[2010.06.27 19:57:31 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
[2010.06.27 19:16:26 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.06.27 18:29:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.06.27 14:25:54 | 000,000,000 | ---D | C] -- C:\_OTM
[2010.06.27 14:24:13 | 000,518,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTM.exe
[2010.06.26 07:30:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Asztal\Balazs Feco - Erints meg meg egyszer (Best Of) 2009
[2010.06.26 05:05:24 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.06.26 05:05:05 | 000,000,000 | ---D | C] -- C:\rsit
[2010.06.25 14:23:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\xy\Recent
[2010.06.25 06:50:42 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.06.25 06:50:19 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.06.25 06:50:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.06.21 15:51:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2010.06.21 06:39:20 | 007,010,816 | ---- | C] (Foxit Software Company) -- C:\Documents and Settings\xy\Asztal\FoxitReader331_enu_Setup.exe
[2010.06.10 06:21:36 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2010.06.08 17:22:58 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\xy\IECompatCache
[2010.06.07 19:37:50 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\plugin.ocx
[2010.06.07 19:14:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\xy\Application Data\PhotoScape
[2010.06.07 19:04:36 | 000,000,000 | ---D | C] -- C:\Program Files\PhotoScape
========== Files - Modified Within 30 Days ========== File not found -- C:\Documents and Settings\xy\Asztal\CAMN27A5.
[2010.06.27 19:58:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTL.exe
[2010.06.27 19:44:00 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2010.06.27 18:43:50 | 000,348,371 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2010.06.27 18:18:16 | 000,000,846 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.06.27 18:16:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.06.27 17:33:53 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.06.27 17:33:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.06.27 17:33:29 | 132,427,776 | -HS- | M] () -- C:\hiberfil.sys
[2010.06.27 17:31:49 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\xy\ntuser.ini
[2010.06.27 17:31:48 | 009,961,472 | ---- | M] () -- C:\Documents and Settings\xy\ntuser.dat
[2010.06.27 16:13:08 | 003,228,354 | -H-- | M] () -- C:\Documents and Settings\xy\Local Settings\Application Data\IconCache.db
[2010.06.27 16:11:46 | 003,721,479 | R--- | M] () -- C:\Documents and Settings\xy\Asztal\ComboFix.exe
[2010.06.27 14:24:36 | 000,518,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xy\Asztal\OTM.exe
[2010.06.27 14:16:08 | 000,000,181 | ---- | M] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\eBay.url
[2010.06.27 14:15:45 | 000,000,901 | ---- | M] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010.06.27 14:15:44 | 000,000,883 | ---- | M] () -- C:\Documents and Settings\All Users\Asztal\Foxit Reader.lnk
[2010.06.26 05:12:56 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\xy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.26 05:04:49 | 000,824,681 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\RSIT.exe
[2010.06.25 06:51:04 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Asztal\Malwarebytes' Anti-Malware.lnk
[2010.06.24 10:00:31 | 000,000,386 | -H-- | M] () -- C:\WINDOWS\tasks\{06C4A412-99DD-4FF5-AAF0-1A9F333550B5}_OTTHONI_xy.job
[2010.06.21 07:05:29 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\HVI_lista_2010_03.xls
[2010.06.21 06:39:23 | 007,010,816 | ---- | M] (Foxit Software Company) -- C:\Documents and Settings\xy\Asztal\FoxitReader331_enu_Setup.exe
[2010.06.19 18:54:11 | 000,626,694 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\névtelen.bmp
[2010.06.18 20:23:23 | 000,028,309 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\babe.gif
[2010.06.10 06:22:50 | 000,001,512 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\Recuva.lnk
[2010.06.10 06:11:28 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\Az Internet Explorer böngésző indítása.lnk
[2010.06.09 21:55:39 | 000,000,144 | ---- | M] () -- C:\WINDOWS\Eudcedit.ini
[2010.06.07 19:13:20 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2010.06.07 19:13:20 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\xy\Asztal\PhotoScape.lnk
[2010.06.02 10:35:01 | 000,000,885 | ---- | M] () -- C:\WINDOWS\TB50.INI
========== Files Created - No Company Name ========== [2010.06.27 15:27:53 | 003,721,479 | R--- | C] () -- C:\Documents and Settings\xy\Asztal\ComboFix.exe
[2010.06.27 14:16:08 | 000,000,181 | ---- | C] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\eBay.url
[2010.06.27 14:15:45 | 000,000,901 | ---- | C] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010.06.27 14:15:44 | 000,000,883 | ---- | C] () -- C:\Documents and Settings\All Users\Asztal\Foxit Reader.lnk
[2010.06.26 05:04:26 | 000,824,681 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\RSIT.exe
[2010.06.25 06:51:02 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Asztal\Malwarebytes' Anti-Malware.lnk
[2010.06.21 07:05:27 | 000,065,024 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\HVI_lista_2010_03.xls
[2010.06.19 18:54:10 | 000,626,694 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\névtelen.bmp
[2010.06.18 20:31:01 | 000,028,309 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\babe.gif
[2010.06.10 06:22:50 | 000,001,512 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\Recuva.lnk
[2010.06.09 21:55:38 | 000,000,144 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2010.06.07 19:37:50 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2010.06.07 19:37:50 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ieencode.dll
[2010.06.07 19:13:20 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\xy\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2010.06.07 19:13:20 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\xy\Asztal\PhotoScape.lnk
[2009.09.25 19:15:48 | 000,000,026 | ---- | C] () -- C:\WINDOWS\ulead32.ini
[2009.06.17 21:33:57 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\IYVU9_32.DLL
[2009.03.20 19:31:36 | 004,425,326 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2009.03.19 23:36:48 | 000,557,469 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2009.03.02 21:10:48 | 000,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.03.02 21:10:22 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2009.03.02 18:19:36 | 000,183,296 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2009.03.02 18:19:30 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2009.03.02 18:19:14 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2009.03.02 18:18:46 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2009.03.02 18:18:32 | 000,257,024 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2009.03.02 18:18:28 | 000,142,848 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2009.03.02 18:18:18 | 000,486,400 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2009.03.02 16:54:20 | 000,328,334 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2009.03.02 16:45:14 | 000,146,098 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2009.03.02 16:42:54 | 000,425,040 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2009.03.02 16:35:56 | 000,898,465 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2009.02.01 19:31:43 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.01.11 00:17:32 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2009.01.11 00:16:56 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2009.01.11 00:16:50 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2009.01.11 00:16:14 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2009.01.11 00:15:54 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2009.01.11 00:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2009.01.11 00:15:32 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2009.01.11 00:15:28 | 000,246,784 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2009.01.11 00:15:12 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2009.01.11 00:14:08 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2009.01.11 00:14:06 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2008.12.04 00:11:50 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.11.29 18:40:33 | 000,000,206 | ---- | C] () -- C:\WINDOWS\MPLAYER.INI
[2008.11.06 18:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008.11.06 18:34:00 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008.10.27 09:01:07 | 000,000,885 | ---- | C] () -- C:\WINDOWS\TB50.INI
[2008.04.15 18:54:28 | 000,000,048 | ---- | C] () -- C:\WINDOWS\mtb30.ini
[2008.04.15 18:54:26 | 000,000,037 | ---- | C] () -- C:\WINDOWS\progman.ini
[2008.02.29 09:43:20 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\ENoSignature.dll
[2008.02.12 16:47:41 | 000,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.01.28 18:08:09 | 000,000,063 | ---- | C] () -- C:\WINDOWS\System32\SKVersion.ini
[2008.01.28 18:06:17 | 000,002,368 | ---- | C] () -- C:\WINDOWS\System32\sk_bho.ini
[2008.01.09 16:01:48 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007.12.25 13:37:20 | 000,000,049 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2007.12.19 08:50:42 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007.12.02 18:05:13 | 000,000,248 | ---- | C] () -- C:\WINDOWS\phedit.ini
[2007.12.01 15:54:22 | 000,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2007.11.27 12:35:16 | 000,000,256 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.11.06 16:37:38 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2007.10.31 20:13:29 | 000,006,213 | ---- | C] () -- C:\WINDOWS\cncscore.ini
[2007.10.24 23:42:15 | 000,001,267 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.10.13 11:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2007.07.10 19:10:12 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2005.06.01 01:16:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SpyPryUN.dll
[2005.02.22 12:48:21 | 000,622,113 | ---- | C] () -- C:\WINDOWS\System32\List.dll
[2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000011.DLL
[2000.01.07 02:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[2000.01.07 02:00:00 | 000,024,448 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv
[1999.04.11 22:54:20 | 000,286,208 | ---- | C] () -- C:\WINDOWS\System32\cncs232.dll
========== LOP Check ========== [2007.12.02 09:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2007.12.26 08:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarGameBox
[2010.04.14 19:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010.05.22 09:26:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010.06.21 15:51:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2007.12.06 18:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008.01.08 11:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\namesuppressed
[2008.01.27 18:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Phenomedia
[2009.12.30 10:40:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SoftPerfect
[2010.05.21 22:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007.12.18 22:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2007.12.02 09:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\ACD Systems
[2007.12.26 08:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\alawar
[2010.04.28 21:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Artweaver
[2010.05.22 09:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools
[2010.05.22 12:22:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools Lite
[2010.05.22 12:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools Pro
[2010.03.01 13:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit
[2010.05.21 09:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit Software
[2007.10.31 14:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\funkitron
[2010.01.29 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\GetRightToGo
[2010.03.07 14:13:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\IObit
[2008.11.19 18:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\mbin.jp
[2010.03.21 08:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\OpenOffice.org
[2010.03.05 22:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Opera
[2010.06.07 19:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PhotoScape
[2010.01.02 15:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PVST Manager
[2009.10.31 10:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Uniblue
[2010.01.01 09:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Unity
[2010.01.25 14:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\VSTT Manager
[2010.06.24 10:00:31 | 000,000,386 | -H-- | M] () -- C:\WINDOWS\Tasks\{06C4A412-99DD-4FF5-AAF0-1A9F333550B5}_OTTHONI_xy.job
========== Purity Check ========== ========== Custom Scans ========== < HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s > < c:\windows\*.* /U > < %SYSTEMDRIVE%\*.exe > < %ALLUSERSPROFILE%\Application Data\*. >[2007.12.02 09:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2009.11.16 14:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2007.12.26 08:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarGameBox
[2010.04.14 19:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010.04.30 19:21:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2010.05.22 09:26:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010.06.21 15:51:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2010.06.07 19:12:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2010.01.24 08:20:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.12.14 18:37:52 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2007.10.30 17:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2007.12.06 18:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008.01.08 11:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\namesuppressed
[2010.05.23 11:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2008.01.27 18:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Phenomedia
[2010.01.19 13:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2009.12.30 10:40:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SoftPerfect
[2010.05.16 07:39:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010.05.21 22:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008.07.23 16:09:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2007.10.25 16:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007.12.18 22:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
< %ALLUSERSPROFILE%\Application Data\*.exe /s > < %APPDATA%\*. >[2007.12.02 09:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\ACD Systems
[2010.06.21 16:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Adobe
[2008.01.06 14:49:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\AdobeUM
[2007.12.26 08:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\alawar
[2010.02.23 18:03:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Apple Computer
[2010.04.28 21:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Artweaver
[2010.04.30 19:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Avira
[2010.05.22 09:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools
[2010.05.22 12:22:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools Lite
[2010.05.22 12:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DAEMON Tools Pro
[2009.08.13 15:44:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\DivX
[2010.03.01 13:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit
[2010.05.21 09:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Foxit Software
[2007.10.31 14:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\funkitron
[2010.01.29 11:52:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\GetRightToGo
[2007.11.01 11:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Google
[2010.04.23 10:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Help
[2007.10.24 19:29:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Identities
[2010.03.07 14:13:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\IObit
[2010.06.21 16:18:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Macromedia
[2010.01.24 08:21:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Malwarebytes
[2008.11.19 18:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\mbin.jp
[2009.10.20 10:10:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\xy\Application Data\Microsoft
[2010.03.01 15:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Mozilla
[2009.01.03 22:26:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\MSN6
[2010.03.21 08:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\OpenOffice.org
[2010.03.05 22:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Opera
[2010.06.07 19:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PhotoScape
[2010.01.02 15:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\PVST Manager
[2010.01.19 12:55:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\skypePM
[2007.10.31 17:51:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Sun
[2008.01.22 12:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Talkback
[2009.10.31 10:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Uniblue
[2010.01.01 09:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\Unity
[2010.01.25 14:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\VSTT Manager
[2008.03.02 21:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\xy\Application Data\WinRAR
< %APPDATA%\*.exe /s > < MD5 for: AGP440.SYS >[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\dllcache\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2001.10.26 14:00:00 | 000,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CDROM.SYS >[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys
[2001.10.26 14:00:00 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=CB762E814F602229A574F4D78D3D6A30 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CHANGER.SYS >[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:Changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\system32\dllcache\changer.sys
< MD5 for: CRYPTSVC.DLL >[2001.10.26 14:00:00 | 000,051,200 | ---- | M] (Microsoft Corporation) MD5=05259C29C8093E6EE1AE7A8F4DE7B807 -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 16:46:40 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=98EA924C4C1B0EA53393289D64218822 -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >[2001.10.26 14:00:00 | 000,047,616 | ---- | M] (Microsoft Corporation) MD5=2DA8D38CF8D86B5C02DFFAC2615FC1C4 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 16:46:56 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=9BF16BF2A92E9946C034947E45C6FB4E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >[2001.10.26 14:00:00 | 001,003,008 | ---- | M] (Microsoft Corporation) MD5=495D8BA14043F4402ECF51C2AB73D8DD -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004.08.17 16:47:58 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=5BF20DA8E16049C4BE8E15EEE1F427C1 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2004.08.17 16:47:58 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=5BF20DA8E16049C4BE8E15EEE1F427C1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 15:12:07 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=6CF1696892BE31A2EC25072A99E2E3FF -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\explorer.exe
[2007.06.13 15:23:54 | 001,035,264 | ---- | M] (Microsoft Corporation) MD5=F8ECCBA428D0B2B53E4F2F824A13FA10 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.17 17:02:36 | 018,786,561 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2001.10.26 14:00:00 | 000,078,464 | ---- | M] (Microsoft Corporation) MD5=254916581AC499E53EE700E7E5B9E5B5 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[2004.08.03 22:59:08 | 000,081,280 | ---- | M] (Microsoft Corporation) MD5=4AF58CA3425F28FC5E3DB47DC122F722 -- C:\WINDOWS\system32\HAL.DLL
[2004.08.03 22:59:20 | 000,105,472 | ---- | M] (Microsoft Corporation) MD5=C321C95318495909A0066FB0EDC97287 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
< MD5 for: ISAPNP.SYS >[2001.10.26 14:00:00 | 000,036,096 | ---- | M] (Microsoft Corporation) MD5=AE9857353A6D45F101C4496789585C25 -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2001.10.26 14:00:00 | 000,036,096 | ---- | M] (Microsoft Corporation) MD5=AE9857353A6D45F101C4496789585C25 -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 16:48:06 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=13C29FBA0388BEF38F06600994FAA2BA -- C:\WINDOWS\system32\lsass.exe
[2001.10.26 14:00:00 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=9AAD6A77CDBE6DAA9758A28B9145E580 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
< MD5 for: NDIS.SYS >[2001.10.26 14:00:00 | 000,161,536 | ---- | M] (Microsoft Corporation) MD5=3EFD4F59BA0A340DE0A3AB984001DBF7 -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 16:47:20 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=38A4E873DEBBA38F1E7E8D9D6AF593D8 -- C:\WINDOWS\system32\netlogon.dll
[2001.10.26 14:00:00 | 000,397,824 | ---- | M] (Microsoft Corporation) MD5=3D8811CB0A5AE38442BB0966282D7796 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 16:47:26 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=DE117DA3508ECAAECEA21901DBA31DAB -- C:\WINDOWS\system32\scecli.dll
[2001.10.26 14:00:00 | 000,179,712 | ---- | M] (Microsoft Corporation) MD5=FA3E6E756841725EE113BADECBCB26D9 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: SMSS.EXE >[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 16:48:30 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=6B0B3C8487EA447BDD155FB52222A156 -- C:\WINDOWS\system32\smss.exe
[2001.08.17 23:37:00 | 000,469,504 | ---- | M] (Microsoft Corporation) MD5=C37F36D08F06A7B0CAF8C1EE9E4079A3 -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2001.10.26 14:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=ED12D92A7B26E99E3A5BF4B043F7314E -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
< MD5 for: SVCHOST.EXE >[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 16:48:32 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=22D8D9F0F5EBE312A1747D6172205F1B -- C:\WINDOWS\system32\svchost.exe
[2001.10.26 14:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=9D08A7B580F0C829A40D7964E1D7CC68 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[2001.10.26 14:00:00 | 000,327,168 | ---- | M] (Microsoft Corporation) MD5=E7774698BB0D14B0710A9A31E209F9B6 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
< MD5 for: USERINIT.EXE >[2001.10.26 14:00:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=969BA3BAC25FB9EB5D652F767B49717C -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 16:48:34 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=B722651FB16A7777E885711DB94571DA -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 16:48:36 | 000,504,320 | ---- | M] (Microsoft Corporation) MD5=63E65D180BB0607B7240E700D2F73EAD -- C:\WINDOWS\system32\winlogon.exe
[2001.10.26 14:00:00 | 000,432,128 | ---- | M] (Microsoft Corporation) MD5=E0F2312FB3DE3D83B915BB82CA42F3F0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
< MD5 for: WS2_32.DLL >[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 16:47:38 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=AF3CC3CB92FB06A47CE979FB9D2CA127 -- C:\WINDOWS\system32\ws2_32.dll
[2001.10.26 14:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=F57E0EA4977D1973D1A41B73352F56A2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2007.10.24 16:17:28 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007.10.24 16:17:27 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007.10.24 16:17:27 | 000,380,928 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles > < reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< %systemroot%\system32\drivers\*.sys /3 > < %systemroot%\system32\*.* /3 >[2010.06.27 18:43:50 | 000,348,371 | ---- | M] () -- C:\WINDOWS\system32\vsconfig.xml
[2010.06.27 19:44:00 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\system32\zllictbl.dat
========== Alternate Data Streams ========== @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33D7490A
< End of report >