Share Pastebin
Guest
Public paste!

Untitled

By: a guest | Mar 21st, 2010 | Syntax: None | Size: 35.55 KB | Hits: 55 | Expires: Never
Copy text to clipboard
  1. OTL logfile created on: 21.3.2010 16:59:19 - Run 1
  2. OTL by OldTimer - Version 3.1.37.3     Folder = C:\Documents and Settings\Chaos Wizard\Desktop
  3. Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
  4. Internet Explorer (Version = 8.0.6001.18702)
  5. Locale: 0000041A | Country: Croatia | Language: HRV | Date Format: d.M.yyyy
  6.  
  7. 246,00 Mb Total Physical Memory | 59,00 Mb Available Physical Memory | 24,00% Memory free
  8. 603,00 Mb Paging File | 250,00 Mb Available in Paging File | 41,00% Paging File free
  9. Paging file location(s): C:\pagefile.sys 372 744 [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
  12. Drive C: | 19,53 Gb Total Space | 9,12 Gb Free Space | 46,67% Space Free | Partition Type: NTFS
  13. D: Drive not present or media not loaded
  14. Drive E: | 17,76 Gb Total Space | 17,25 Gb Free Space | 97,10% Space Free | Partition Type: NTFS
  15. F: Drive not present or media not loaded
  16. G: Drive not present or media not loaded
  17. H: Drive not present or media not loaded
  18. I: Drive not present or media not loaded
  19.  
  20. Computer Name: KILLKENNY
  21. Current User Name: Chaos Wizard
  22. Logged in as Administrator.
  23.  
  24. Current Boot Mode: Normal
  25. Scan Mode: Current user
  26. Company Name Whitelist: On
  27. Skip Microsoft Files: On
  28. File Age = 14 Days
  29. Output = Standard
  30. Quick Scan
  31.  
  32. [color=#E56717]========== Processes (SafeList) ==========[/color]
  33.  
  34. PRC - [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
  35. PRC - [2009.05.06 17:57:47 | 000,949,376 | ---- | M] (Eset ) -- C:\Program Files\ESET\nod32kui.exe
  36. PRC - [2009.05.06 17:57:47 | 000,552,064 | ---- | M] (Eset ) -- C:\Program Files\ESET\nod32krn.exe
  37. PRC - [2009.04.13 17:24:06 | 000,602,220 | ---- | M] (Executive Software International, Inc.) -- C:\Program Files\Executive Software\Diskeeper\DkService.exe
  38. PRC - [2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
  39. PRC - [2005.06.01 13:17:08 | 000,192,512 | ---- | M] (Acer Inc) -- C:\Acer\ePM\epm-dm.exe
  40. PRC - [2005.04.15 10:01:46 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
  41. PRC - [2005.01.31 08:05:50 | 000,253,952 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
  42. PRC - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
  43. PRC - [2004.08.16 14:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) -- C:\Acer\eManager\anbmServ.exe
  44.  
  45.  
  46. [color=#E56717]========== Modules (SafeList) ==========[/color]
  47.  
  48. MOD - [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
  49.  
  50.  
  51. [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
  52.  
  53. SRV - File not found [Auto | Stopped] --  -- (ioloSystemService)
  54. SRV - File not found [Auto | Stopped] --  -- (ioloFileInfoList)
  55. SRV - [2009.05.06 17:57:47 | 000,552,064 | ---- | M] (Eset ) [Auto | Running] -- C:\Program Files\ESET\nod32krn.exe -- (NOD32krn)
  56. SRV - [2009.04.13 17:24:06 | 000,602,220 | ---- | M] (Executive Software International, Inc.) [Auto | Running] -- C:\Program Files\Executive Software\Diskeeper\DkService.exe -- (Diskeeper)
  57. SRV - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
  58. SRV - [2004.08.16 14:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) [Auto | Running] -- C:\Acer\eManager\anbmServ.exe -- (anbmService)
  59.  
  60.  
  61. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  62.  
  63.  
  64. [color=#E56717]========== Internet Explorer ==========[/color]
  65.  
  66.  
  67. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.hr/
  68. IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
  69. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  70.  
  71. [color=#E56717]========== FireFox ==========[/color]
  72.  
  73. FF - prefs.js..browser.search.defaultenginename: "Yahoo"
  74. FF - prefs.js..browser.search.order.1: "Yahoo"
  75. FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
  76. FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
  77. FF - prefs.js..browser.search.selectedEngine: "Google"
  78. FF - prefs.js..browser.search.update: false
  79. FF - prefs.js..browser.startup.homepage: "http://google.hr"
  80. FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:1.6.4
  81. FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
  82. FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
  83. FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr=megaup&p="
  84.  
  85. FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.03.31 20:11:56 | 000,000,000 | ---D | M]
  86. FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.03.10 16:47:51 | 000,000,000 | ---D | M]
  87.  
  88. [2008.07.15 21:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Extensions
  89. [2009.03.05 16:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions
  90. [2008.06.26 15:17:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
  91. [2008.06.26 15:17:35 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
  92. [2008.07.27 21:46:10 | 000,000,000 | ---D | M] (Firefox Companion for eBay) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
  93. [2010.03.10 16:47:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
  94. [2008.06.26 15:15:49 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla(2).org
  95. [2007.03.10 00:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
  96. [2007.07.26 12:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
  97.  
  98. O1 HOSTS File: ([2010.03.21 15:13:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
  99. O1 - Hosts: 127.0.0.1       localhost
  100. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
  101. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
  102. O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
  103. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
  104. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
  105. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
  106. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
  107. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
  108. O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
  109. O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
  110. O4 - HKLM..\Run: [epm-dm] c:\Acer\ePM\epm-dm.exe (Acer Inc)
  111. O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
  112. O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
  113. O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
  114. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
  115. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
  116. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
  117. O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
  118. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
  119. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
  120. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
  121. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
  122. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  123. O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
  124. O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
  125. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
  126. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
  127. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
  128. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
  129. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
  130. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
  131. O10 - Protocol_Catalog9\Catalog_Entries\000000000043 -  File not found
  132. O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
  133. O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
  134. O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1267121494387 (WUWebControl Class)
  135. O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1267121473168 (MUWebControl Class)
  136. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
  137. O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
  138. O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
  139. O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
  140. O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
  141. O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
  142. O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
  143. O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
  144. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
  145. O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
  146. O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
  147. O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
  148. O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
  149. O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
  150. O24 - Desktop WallPaper: C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
  151. O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
  152. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
  153. O32 - HKLM CDRom: AutoRun - 1
  154. O32 - AutoRun File - [2006.06.20 16:28:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
  155. O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
  156. O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic 5) -  File not found
  157. O35 - HKLM\..comfile [open] -- "%1" %*
  158. O35 - HKLM\..exefile [open] -- "%1" %*
  159. O37 - HKLM\...com [@ = ComFile] -- "%1" %*
  160. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  161.  
  162. NetSvcs: Ias - C:\WINDOWS\system32\ias [2006.06.20 16:27:34 | 000,000,000 | ---D | M]
  163. NetSvcs: Iprip -  File not found
  164. NetSvcs: Irmon -  File not found
  165. NetSvcs: NWCWorkstation -  File not found
  166. NetSvcs: Nwsapagent -  File not found
  167. NetSvcs: WmdmPmSp -  File not found
  168.  
  169. CREATERESTOREPOINT
  170. Restore point Set: OTL Restore Point (55735438412873728)
  171.  
  172. [color=#E56717]========== Files/Folders - Created Within 14 Days ==========[/color]
  173.  
  174. [2010.03.21 16:48:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller
  175. [2010.03.21 16:45:02 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
  176. [2010.03.21 15:23:01 | 000,000,000 | -HSD | C] -- C:\RECYCLER
  177. [2010.03.21 15:12:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
  178. [2010.03.20 18:44:32 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Chaos Wizard\Recent
  179. [2010.03.20 12:53:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Desktop\Stranice
  180. [2010.03.19 14:36:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
  181. [2010.03.19 14:35:43 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
  182. [2010.03.19 14:35:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Application Data\SUPERAntiSpyware.com
  183. [2010.03.19 11:33:27 | 000,050,504 | ---- | C] (Prevx) -- C:\WINDOWS\System32\drivers\pxrts.sys
  184. [2010.03.19 11:33:25 | 000,024,368 | ---- | C] (Prevx) -- C:\WINDOWS\System32\drivers\pxkbf.sys
  185. [2010.03.18 16:58:18 | 000,000,000 | RHSD | C] -- C:\cmdcons
  186. [2010.03.18 16:56:05 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
  187. [2010.03.18 16:56:01 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
  188. [2010.03.18 16:55:59 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
  189. [2010.03.18 16:55:58 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
  190. [2010.03.18 16:55:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
  191. [2010.03.14 19:23:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Application Data\PC Tools
  192. [2010.03.14 15:06:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Threat Expert
  193. [2010.03.14 14:57:57 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll.old
  194. [2010.03.14 14:52:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
  195. [2010.03.14 14:52:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
  196. [2010.03.13 21:11:01 | 000,000,000 | ---D | C] -- C:\Qoobox
  197. [2010.03.06 15:02:37 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Chaos Wizard\My Documents\HJTInstall.exe
  198. [2010.03.04 21:51:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
  199. [2010.03.02 20:33:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer
  200. [2010.02.28 20:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
  201. [2010.02.28 19:38:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
  202. [2010.02.28 19:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
  203. [2010.02.25 20:21:09 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\IECompatCache
  204. [2010.02.25 20:19:24 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\PrivacIE
  205. [2010.02.25 20:17:11 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\IETldCache
  206. [2010.02.25 20:13:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
  207. [2010.02.25 20:11:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
  208. [2010.02.25 20:09:42 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
  209. [2010.02.25 19:49:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
  210. [2010.02.25 19:12:27 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
  211. [2009.05.06 19:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
  212. [2008.03.06 19:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\iolo
  213. [2006.06.22 15:52:12 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
  214. [2006.06.22 15:52:12 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
  215. [2006.06.20 16:33:36 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
  216. [2006.06.20 16:33:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
  217. [57 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
  218. [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
  219.  
  220. [color=#E56717]========== Files - Modified Within 14 Days ==========[/color]
  221.  
  222. [2010.03.21 16:49:08 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  223. [2010.03.21 16:49:03 | 000,000,932 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  224. [2010.03.21 16:47:30 | 000,155,752 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller.zip
  225. [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
  226. [2010.03.21 15:14:44 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
  227. [2010.03.21 15:14:17 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
  228. [2010.03.21 15:13:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
  229. [2010.03.21 15:13:35 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
  230. [2010.03.21 15:13:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
  231. [2010.03.21 15:13:27 | 258,461,696 | -HS- | M] () -- C:\hiberfil.sys
  232. [2010.03.21 15:12:39 | 008,126,464 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\ntuser.dat
  233. [2010.03.21 15:12:39 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Chaos Wizard\ntuser.ini
  234. [2010.03.19 16:44:13 | 000,000,051 | ---- | M] () -- C:\WINDOWS\System32\imon1.dat
  235. [2010.03.19 11:33:27 | 000,050,504 | ---- | M] (Prevx) -- C:\WINDOWS\System32\drivers\pxrts.sys
  236. [2010.03.19 11:33:25 | 000,024,368 | ---- | M] (Prevx) -- C:\WINDOWS\System32\drivers\pxkbf.sys
  237. [2010.03.19 11:33:10 | 000,000,051 | ---- | M] () -- C:\WINDOWS\wininit.ini
  238. [2010.03.18 16:58:34 | 000,000,281 | RHS- | M] () -- C:\boot.ini
  239. [2010.03.16 19:08:57 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
  240. [2010.03.12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
  241. [2010.03.10 16:46:47 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
  242. [2010.03.10 16:46:46 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
  243. [2010.03.10 16:46:46 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
  244. [2010.03.10 16:46:45 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
  245. [2010.03.10 16:46:43 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
  246. [2010.03.08 11:12:23 | 000,001,735 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
  247. [2010.03.06 15:02:42 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Chaos Wizard\My Documents\HJTInstall.exe
  248. [2010.03.04 21:41:36 | 000,404,302 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
  249. [2010.03.04 21:41:36 | 000,063,522 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
  250. [2010.03.04 21:41:33 | 000,475,330 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
  251. [2010.03.02 20:32:18 | 001,615,732 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer.zip
  252. [2010.02.28 20:53:42 | 000,001,921 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
  253. [2010.02.25 20:27:57 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\Desktop\CCleaner.lnk
  254. [2010.02.25 20:15:13 | 004,840,692 | -H-- | M] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\IconCache.db
  255. [57 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
  256. [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
  257.  
  258. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  259.  
  260. [2010.03.21 16:47:27 | 000,155,752 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller.zip
  261. [2010.03.19 16:44:13 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\imon1.dat
  262. [2010.03.19 11:33:10 | 000,000,051 | ---- | C] () -- C:\WINDOWS\wininit.ini
  263. [2010.03.18 16:58:34 | 000,000,211 | ---- | C] () -- C:\Boot.bak
  264. [2010.03.18 16:58:25 | 000,260,272 | ---- | C] () -- C:\cmldr
  265. [2010.03.18 16:56:06 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
  266. [2010.03.18 16:56:02 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
  267. [2010.03.18 16:56:00 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
  268. [2010.03.18 16:56:00 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
  269. [2010.03.18 16:56:00 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
  270. [2010.03.14 14:57:58 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
  271. [2010.03.08 11:12:23 | 000,001,735 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
  272. [2010.03.02 20:32:04 | 001,615,732 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer.zip
  273. [2010.02.28 20:53:42 | 000,001,921 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
  274. [2010.02.28 19:33:28 | 000,000,936 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
  275. [2010.02.28 19:33:25 | 000,000,932 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
  276. [2010.02.25 20:27:57 | 000,001,554 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Desktop\CCleaner.lnk
  277. [2009.05.06 17:57:50 | 000,015,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\nod32drv.sys
  278. [2009.05.06 17:46:36 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\nms32.dll
  279. [2009.01.11 10:38:03 | 000,000,544 | ---- | C] () -- C:\WINDOWS\_delis32.ini
  280. [2008.08.12 08:02:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
  281. [2008.07.01 00:04:30 | 000,000,845 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Installer.log
  282. [2008.05.19 07:53:41 | 000,000,608 | ---- | C] () -- C:\WINDOWS\tenkey.ini
  283. [2008.05.14 22:19:13 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\fusioncache.dat
  284. [2008.04.11 06:38:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
  285. [2008.04.09 12:12:27 | 000,000,734 | ---- | C] () -- C:\WINDOWS\disney.ini
  286. [2008.04.05 10:38:16 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
  287. [2008.03.20 05:55:33 | 000,000,238 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
  288. [2008.03.12 20:33:50 | 000,612,864 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
  289. [2008.03.12 06:46:06 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
  290. [2008.03.12 06:46:02 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
  291. [2008.03.12 06:46:02 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
  292. [2008.03.12 06:46:02 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
  293. [2008.03.12 06:46:00 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
  294. [2008.03.12 06:46:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
  295. [2008.03.06 19:40:14 | 000,936,288 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
  296. [2008.02.10 20:59:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
  297. [2007.12.24 14:33:28 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
  298. [2006.12.27 22:10:17 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\iolo.ini
  299. [2006.12.27 21:28:55 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\iavlsp.dll
  300. [2006.09.01 18:27:43 | 000,039,933 | ---- | C] () -- C:\WINDOWS\php.ini
  301. [2006.08.13 22:40:28 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
  302. [2006.08.04 21:39:30 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv6628p3now.sys
  303. [2006.08.04 21:39:08 | 000,000,059 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
  304. [2006.07.29 00:45:35 | 000,064,000 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  305. [2006.07.20 18:28:34 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
  306. [2006.07.09 11:41:52 | 000,000,618 | ---- | C] () -- C:\WINDOWS\WT.INI
  307. [2006.06.21 01:04:01 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
  308. [2006.06.20 21:09:21 | 000,000,147 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
  309. [2006.06.20 17:48:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
  310. [2006.06.20 17:37:43 | 000,421,888 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
  311. [2006.06.20 17:37:41 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
  312. [2006.06.20 17:10:17 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini
  313. [2005.05.26 02:17:16 | 000,110,657 | ---- | C] () -- C:\Program Files\Common Files\UninstallDrv.exe
  314. [2004.08.03 21:59:44 | 000,095,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys
  315. [2003.08.07 20:01:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
  316. [2001.05.01 01:01:24 | 001,015,808 | ---- | C] () -- C:\WINDOWS\System32\php4ts.dll
  317. [2001.04.30 23:19:14 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
  318. [2001.04.30 23:18:38 | 000,696,320 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
  319. [2001.04.30 18:30:18 | 000,368,640 | ---- | C] () -- C:\WINDOWS\System32\libxml2.dll
  320. [2001.04.13 19:16:02 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\sablot.dll
  321. [2000.11.30 02:18:46 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\yaz.dll
  322. [2000.10.22 17:26:44 | 000,438,334 | ---- | C] () -- C:\WINDOWS\System32\expat.dll
  323. [2000.10.22 03:41:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\libsasl.dll
  324. [2000.09.27 00:28:20 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\libpq.dll
  325. [2000.08.24 17:44:10 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
  326. [2000.08.24 17:44:08 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
  327. [2000.06.02 19:11:38 | 000,282,679 | ---- | C] () -- C:\WINDOWS\System32\jvm.dll
  328. [1999.07.05 11:00:00 | 000,074,512 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
  329. [1999.05.24 10:26:42 | 000,317,440 | ---- | C] () -- C:\WINDOWS\System32\FdfTk.dll
  330. [1999.01.27 12:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
  331. [1997.09.07 23:13:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\mSQL.dll
  332. [1997.06.13 06:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
  333.  
  334. [color=#E56717]========== LOP Check ==========[/color]
  335.  
  336. [2008.03.04 19:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
  337. [2008.03.26 18:48:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ConeXware
  338. [2007.11.11 19:59:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
  339. [2009.01.11 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
  340. [2008.05.14 22:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Equis
  341. [2008.08.12 11:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
  342. [2009.04.28 11:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
  343. [2007.09.06 15:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
  344. [2008.08.12 12:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Slapdash Games
  345. [2010.03.14 18:40:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
  346. [2008.09.02 22:51:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania
  347. [2010.03.04 21:53:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
  348. [2007.03.23 15:29:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Atari
  349. [2008.03.27 16:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Azureus
  350. [2009.01.11 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\eBay
  351. [2009.05.06 16:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\iolo
  352. [2006.06.21 12:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Leadertech
  353. [2008.04.01 19:06:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\LimeWire
  354. [2009.04.20 16:25:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Opera
  355. [2007.09.30 14:11:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\PlayFirst
  356. [2008.06.25 10:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Sahmon Games
  357. [2006.10.23 19:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Seven Zip
  358. [2007.10.25 20:49:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Super-Cow
  359. [2006.08.16 23:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Teleca
  360. [2009.01.11 09:31:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\uTorrent
  361. [2008.09.05 11:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\WholeSecurity
  362.  
  363. [color=#E56717]========== Purity Check ==========[/color]
  364.  
  365.  
  366.  
  367. [color=#E56717]========== Custom Scans ==========[/color]
  368.  
  369.  
  370. [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
  371.  
  372.  
  373. [color=#A23BEC]< MD5 for: AGP440.SYS  >[/color]
  374. [2004.08.04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
  375. [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
  376. [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
  377. [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
  378. [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
  379. [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
  380.  
  381. [color=#A23BEC]< MD5 for: ATAPI.SYS  >[/color]
  382. [2004.08.04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
  383. [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
  384. [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
  385. [2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
  386. [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
  387. [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
  388. [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
  389. [2004.08.03 21:59:44 | 000,095,360 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drivers\atapi.sys
  390.  
  391. [color=#A23BEC]< MD5 for: EVENTLOG.DLL  >[/color]
  392. [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
  393. [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
  394. [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
  395. [2004.08.03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
  396.  
  397. [color=#A23BEC]< MD5 for: NETLOGON.DLL  >[/color]
  398. [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
  399. [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
  400. [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
  401. [2004.08.03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
  402.  
  403. [color=#A23BEC]< MD5 for: SCECLI.DLL  >[/color]
  404. [2004.08.03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
  405. [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
  406. [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
  407. [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
  408.  
  409. [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
  410.  
  411. [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
  412. [2009.03.08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dxtmsft.dll
  413. [2009.03.08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dxtrans.dll
  414. [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
  415.  
  416. [color=#E56717]========== Alternate Data Streams ==========[/color]
  417.  
  418. @Alternate Data Stream - 88 bytes -> C:\Program Files\Executive Software\Diskeeper\DkService.exe:SummaryInformation
  419. @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
  420. @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
  421. < End of report >