- OTL logfile created on: 21.3.2010 16:59:19 - Run 1
- OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Chaos Wizard\Desktop
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.6001.18702)
- Locale: 0000041A | Country: Croatia | Language: HRV | Date Format: d.M.yyyy
- 246,00 Mb Total Physical Memory | 59,00 Mb Available Physical Memory | 24,00% Memory free
- 603,00 Mb Paging File | 250,00 Mb Available in Paging File | 41,00% Paging File free
- Paging file location(s): C:\pagefile.sys 372 744 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 19,53 Gb Total Space | 9,12 Gb Free Space | 46,67% Space Free | Partition Type: NTFS
- D: Drive not present or media not loaded
- Drive E: | 17,76 Gb Total Space | 17,25 Gb Free Space | 97,10% Space Free | Partition Type: NTFS
- F: Drive not present or media not loaded
- G: Drive not present or media not loaded
- H: Drive not present or media not loaded
- I: Drive not present or media not loaded
- Computer Name: KILLKENNY
- Current User Name: Chaos Wizard
- Logged in as Administrator.
- Current Boot Mode: Normal
- Scan Mode: Current user
- Company Name Whitelist: On
- Skip Microsoft Files: On
- File Age = 14 Days
- Output = Standard
- Quick Scan
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
- PRC - [2009.05.06 17:57:47 | 000,949,376 | ---- | M] (Eset ) -- C:\Program Files\ESET\nod32kui.exe
- PRC - [2009.05.06 17:57:47 | 000,552,064 | ---- | M] (Eset ) -- C:\Program Files\ESET\nod32krn.exe
- PRC - [2009.04.13 17:24:06 | 000,602,220 | ---- | M] (Executive Software International, Inc.) -- C:\Program Files\Executive Software\Diskeeper\DkService.exe
- PRC - [2008.04.14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
- PRC - [2005.06.01 13:17:08 | 000,192,512 | ---- | M] (Acer Inc) -- C:\Acer\ePM\epm-dm.exe
- PRC - [2005.04.15 10:01:46 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
- PRC - [2005.01.31 08:05:50 | 000,253,952 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
- PRC - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
- PRC - [2004.08.16 14:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) -- C:\Acer\eManager\anbmServ.exe
- [color=#E56717]========== Modules (SafeList) ==========[/color]
- MOD - [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV - File not found [Auto | Stopped] -- -- (ioloSystemService)
- SRV - File not found [Auto | Stopped] -- -- (ioloFileInfoList)
- SRV - [2009.05.06 17:57:47 | 000,552,064 | ---- | M] (Eset ) [Auto | Running] -- C:\Program Files\ESET\nod32krn.exe -- (NOD32krn)
- SRV - [2009.04.13 17:24:06 | 000,602,220 | ---- | M] (Executive Software International, Inc.) [Auto | Running] -- C:\Program Files\Executive Software\Diskeeper\DkService.exe -- (Diskeeper)
- SRV - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
- SRV - [2004.08.16 14:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) [Auto | Running] -- C:\Acer\eManager\anbmServ.exe -- (anbmService)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.hr/
- IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultenginename: "Yahoo"
- FF - prefs.js..browser.search.order.1: "Yahoo"
- FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
- FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
- FF - prefs.js..browser.search.selectedEngine: "Google"
- FF - prefs.js..browser.search.update: false
- FF - prefs.js..browser.startup.homepage: "http://google.hr"
- FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:1.6.4
- FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
- FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
- FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr=megaup&p="
- FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.03.31 20:11:56 | 000,000,000 | ---D | M]
- FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.03.10 16:47:51 | 000,000,000 | ---D | M]
- [2008.07.15 21:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Extensions
- [2009.03.05 16:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions
- [2008.06.26 15:17:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
- [2008.06.26 15:17:35 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
- [2008.07.27 21:46:10 | 000,000,000 | ---D | M] (Firefox Companion for eBay) -- C:\Documents and Settings\Chaos Wizard\Application Data\Mozilla\Firefox\Profiles\sft7nasm.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
- [2010.03.10 16:47:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
- [2008.06.26 15:15:49 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla(2).org
- [2007.03.10 00:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
- [2007.07.26 12:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
- O1 HOSTS File: ([2010.03.21 15:13:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
- O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
- O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
- O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
- O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
- O4 - HKLM..\Run: [epm-dm] c:\Acer\ePM\epm-dm.exe (Acer Inc)
- O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
- O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
- O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
- O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
- O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - File not found
- O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
- O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
- O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1267121494387 (WUWebControl Class)
- O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1267121473168 (MUWebControl Class)
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
- O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
- O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
- O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
- O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
- O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
- O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
- O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
- O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
- O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
- O24 - Desktop WallPaper: C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2006.06.20 16:28:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *) - File not found
- O34 - HKLM BootExecute: (smrgdf C:\Program Files\iolo\System Mechanic 5) - File not found
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = ComFile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- NetSvcs: Ias - C:\WINDOWS\system32\ias [2006.06.20 16:27:34 | 000,000,000 | ---D | M]
- NetSvcs: Iprip - File not found
- NetSvcs: Irmon - File not found
- NetSvcs: NWCWorkstation - File not found
- NetSvcs: Nwsapagent - File not found
- NetSvcs: WmdmPmSp - File not found
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point (55735438412873728)
- [color=#E56717]========== Files/Folders - Created Within 14 Days ==========[/color]
- [2010.03.21 16:48:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller
- [2010.03.21 16:45:02 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
- [2010.03.21 15:23:01 | 000,000,000 | -HSD | C] -- C:\RECYCLER
- [2010.03.21 15:12:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
- [2010.03.20 18:44:32 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Chaos Wizard\Recent
- [2010.03.20 12:53:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Desktop\Stranice
- [2010.03.19 14:36:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
- [2010.03.19 14:35:43 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
- [2010.03.19 14:35:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Application Data\SUPERAntiSpyware.com
- [2010.03.19 11:33:27 | 000,050,504 | ---- | C] (Prevx) -- C:\WINDOWS\System32\drivers\pxrts.sys
- [2010.03.19 11:33:25 | 000,024,368 | ---- | C] (Prevx) -- C:\WINDOWS\System32\drivers\pxkbf.sys
- [2010.03.18 16:58:18 | 000,000,000 | RHSD | C] -- C:\cmdcons
- [2010.03.18 16:56:05 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
- [2010.03.18 16:56:01 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
- [2010.03.18 16:55:59 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
- [2010.03.18 16:55:58 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
- [2010.03.18 16:55:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
- [2010.03.14 19:23:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Application Data\PC Tools
- [2010.03.14 15:06:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\Threat Expert
- [2010.03.14 14:57:57 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll.old
- [2010.03.14 14:52:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
- [2010.03.14 14:52:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
- [2010.03.13 21:11:01 | 000,000,000 | ---D | C] -- C:\Qoobox
- [2010.03.06 15:02:37 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Chaos Wizard\My Documents\HJTInstall.exe
- [2010.03.04 21:51:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
- [2010.03.02 20:33:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer
- [2010.02.28 20:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
- [2010.02.28 19:38:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
- [2010.02.28 19:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
- [2010.02.25 20:21:09 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\IECompatCache
- [2010.02.25 20:19:24 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\PrivacIE
- [2010.02.25 20:17:11 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Chaos Wizard\IETldCache
- [2010.02.25 20:13:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
- [2010.02.25 20:11:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
- [2010.02.25 20:09:42 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
- [2010.02.25 19:49:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
- [2010.02.25 19:12:27 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
- [2009.05.06 19:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
- [2008.03.06 19:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\iolo
- [2006.06.22 15:52:12 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
- [2006.06.22 15:52:12 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
- [2006.06.20 16:33:36 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
- [2006.06.20 16:33:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
- [57 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 14 Days ==========[/color]
- [2010.03.21 16:49:08 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
- [2010.03.21 16:49:03 | 000,000,932 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
- [2010.03.21 16:47:30 | 000,155,752 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller.zip
- [2010.03.21 16:45:10 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chaos Wizard\Desktop\OTL.exe
- [2010.03.21 15:14:44 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
- [2010.03.21 15:14:17 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
- [2010.03.21 15:13:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
- [2010.03.21 15:13:35 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
- [2010.03.21 15:13:33 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
- [2010.03.21 15:13:27 | 258,461,696 | -HS- | M] () -- C:\hiberfil.sys
- [2010.03.21 15:12:39 | 008,126,464 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\ntuser.dat
- [2010.03.21 15:12:39 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Chaos Wizard\ntuser.ini
- [2010.03.19 16:44:13 | 000,000,051 | ---- | M] () -- C:\WINDOWS\System32\imon1.dat
- [2010.03.19 11:33:27 | 000,050,504 | ---- | M] (Prevx) -- C:\WINDOWS\System32\drivers\pxrts.sys
- [2010.03.19 11:33:25 | 000,024,368 | ---- | M] (Prevx) -- C:\WINDOWS\System32\drivers\pxkbf.sys
- [2010.03.19 11:33:10 | 000,000,051 | ---- | M] () -- C:\WINDOWS\wininit.ini
- [2010.03.18 16:58:34 | 000,000,281 | RHS- | M] () -- C:\boot.ini
- [2010.03.16 19:08:57 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
- [2010.03.12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
- [2010.03.10 16:46:47 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
- [2010.03.10 16:46:46 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
- [2010.03.10 16:46:46 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
- [2010.03.10 16:46:45 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
- [2010.03.10 16:46:43 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
- [2010.03.08 11:12:23 | 000,001,735 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
- [2010.03.06 15:02:42 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Chaos Wizard\My Documents\HJTInstall.exe
- [2010.03.04 21:41:36 | 000,404,302 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
- [2010.03.04 21:41:36 | 000,063,522 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
- [2010.03.04 21:41:33 | 000,475,330 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
- [2010.03.02 20:32:18 | 001,615,732 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer.zip
- [2010.02.28 20:53:42 | 000,001,921 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
- [2010.02.25 20:27:57 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\Chaos Wizard\Desktop\CCleaner.lnk
- [2010.02.25 20:15:13 | 004,840,692 | -H-- | M] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\IconCache.db
- [57 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2010.03.21 16:47:27 | 000,155,752 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Desktop\tdsskiller.zip
- [2010.03.19 16:44:13 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\imon1.dat
- [2010.03.19 11:33:10 | 000,000,051 | ---- | C] () -- C:\WINDOWS\wininit.ini
- [2010.03.18 16:58:34 | 000,000,211 | ---- | C] () -- C:\Boot.bak
- [2010.03.18 16:58:25 | 000,260,272 | ---- | C] () -- C:\cmldr
- [2010.03.18 16:56:06 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
- [2010.03.18 16:56:02 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
- [2010.03.18 16:56:00 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
- [2010.03.18 16:56:00 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
- [2010.03.18 16:56:00 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
- [2010.03.14 14:57:58 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
- [2010.03.08 11:12:23 | 000,001,735 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
- [2010.03.02 20:32:04 | 001,615,732 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\My Documents\ProcessExplorer.zip
- [2010.02.28 20:53:42 | 000,001,921 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
- [2010.02.28 19:33:28 | 000,000,936 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
- [2010.02.28 19:33:25 | 000,000,932 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
- [2010.02.25 20:27:57 | 000,001,554 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Desktop\CCleaner.lnk
- [2009.05.06 17:57:50 | 000,015,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\nod32drv.sys
- [2009.05.06 17:46:36 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\nms32.dll
- [2009.01.11 10:38:03 | 000,000,544 | ---- | C] () -- C:\WINDOWS\_delis32.ini
- [2008.08.12 08:02:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
- [2008.07.01 00:04:30 | 000,000,845 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Installer.log
- [2008.05.19 07:53:41 | 000,000,608 | ---- | C] () -- C:\WINDOWS\tenkey.ini
- [2008.05.14 22:19:13 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\fusioncache.dat
- [2008.04.11 06:38:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
- [2008.04.09 12:12:27 | 000,000,734 | ---- | C] () -- C:\WINDOWS\disney.ini
- [2008.04.05 10:38:16 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
- [2008.03.20 05:55:33 | 000,000,238 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
- [2008.03.12 20:33:50 | 000,612,864 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
- [2008.03.12 06:46:06 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
- [2008.03.12 06:46:02 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
- [2008.03.12 06:46:02 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
- [2008.03.12 06:46:02 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
- [2008.03.12 06:46:00 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
- [2008.03.12 06:46:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
- [2008.03.06 19:40:14 | 000,936,288 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
- [2008.02.10 20:59:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
- [2007.12.24 14:33:28 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
- [2006.12.27 22:10:17 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\iolo.ini
- [2006.12.27 21:28:55 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\iavlsp.dll
- [2006.09.01 18:27:43 | 000,039,933 | ---- | C] () -- C:\WINDOWS\php.ini
- [2006.08.13 22:40:28 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
- [2006.08.04 21:39:30 | 000,003,082 | ---- | C] () -- C:\WINDOWS\System32\affv6628p3now.sys
- [2006.08.04 21:39:08 | 000,000,059 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
- [2006.07.29 00:45:35 | 000,064,000 | ---- | C] () -- C:\Documents and Settings\Chaos Wizard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- [2006.07.20 18:28:34 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
- [2006.07.09 11:41:52 | 000,000,618 | ---- | C] () -- C:\WINDOWS\WT.INI
- [2006.06.21 01:04:01 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
- [2006.06.20 21:09:21 | 000,000,147 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
- [2006.06.20 17:48:18 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
- [2006.06.20 17:37:43 | 000,421,888 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
- [2006.06.20 17:37:41 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
- [2006.06.20 17:10:17 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini
- [2005.05.26 02:17:16 | 000,110,657 | ---- | C] () -- C:\Program Files\Common Files\UninstallDrv.exe
- [2004.08.03 21:59:44 | 000,095,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys
- [2003.08.07 20:01:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
- [2001.05.01 01:01:24 | 001,015,808 | ---- | C] () -- C:\WINDOWS\System32\php4ts.dll
- [2001.04.30 23:19:14 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
- [2001.04.30 23:18:38 | 000,696,320 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
- [2001.04.30 18:30:18 | 000,368,640 | ---- | C] () -- C:\WINDOWS\System32\libxml2.dll
- [2001.04.13 19:16:02 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\sablot.dll
- [2000.11.30 02:18:46 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\yaz.dll
- [2000.10.22 17:26:44 | 000,438,334 | ---- | C] () -- C:\WINDOWS\System32\expat.dll
- [2000.10.22 03:41:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\libsasl.dll
- [2000.09.27 00:28:20 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\libpq.dll
- [2000.08.24 17:44:10 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
- [2000.08.24 17:44:08 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
- [2000.06.02 19:11:38 | 000,282,679 | ---- | C] () -- C:\WINDOWS\System32\jvm.dll
- [1999.07.05 11:00:00 | 000,074,512 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
- [1999.05.24 10:26:42 | 000,317,440 | ---- | C] () -- C:\WINDOWS\System32\FdfTk.dll
- [1999.01.27 12:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
- [1997.09.07 23:13:48 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\mSQL.dll
- [1997.06.13 06:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
- [color=#E56717]========== LOP Check ==========[/color]
- [2008.03.04 19:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
- [2008.03.26 18:48:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ConeXware
- [2007.11.11 19:59:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
- [2009.01.11 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
- [2008.05.14 22:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Equis
- [2008.08.12 11:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
- [2009.04.28 11:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
- [2007.09.06 15:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
- [2008.08.12 12:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Slapdash Games
- [2010.03.14 18:40:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
- [2008.09.02 22:51:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania
- [2010.03.04 21:53:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
- [2007.03.23 15:29:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Atari
- [2008.03.27 16:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Azureus
- [2009.01.11 09:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\eBay
- [2009.05.06 16:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\iolo
- [2006.06.21 12:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Leadertech
- [2008.04.01 19:06:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\LimeWire
- [2009.04.20 16:25:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Opera
- [2007.09.30 14:11:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\PlayFirst
- [2008.06.25 10:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Sahmon Games
- [2006.10.23 19:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Seven Zip
- [2007.10.25 20:49:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Super-Cow
- [2006.08.16 23:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\Teleca
- [2009.01.11 09:31:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\uTorrent
- [2008.09.05 11:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chaos Wizard\Application Data\WholeSecurity
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
- [color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
- [2004.08.04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
- [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
- [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
- [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
- [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
- [2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
- [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
- [2004.08.04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
- [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
- [2008.04.14 04:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
- [2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
- [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
- [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
- [2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
- [2004.08.03 21:59:44 | 000,095,360 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\drivers\atapi.sys
- [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
- [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
- [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
- [2008.04.14 04:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
- [2004.08.03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
- [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
- [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
- [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
- [2008.04.14 04:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
- [2004.08.03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
- [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
- [2004.08.03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
- [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
- [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
- [2008.04.14 04:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
- [2009.03.08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dxtmsft.dll
- [2009.03.08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\dxtrans.dll
- [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 88 bytes -> C:\Program Files\Executive Software\Diskeeper\DkService.exe:SummaryInformation
- @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
- @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
- < End of report >
