OTL logfile created on: 26. 2. 2011 12:45:28 - Run 1
OTL by OldTimer - Version 3.2.22.0 Folder = C:\Users\Krucifix\Downloads
Microsoft Hyper-V Server (Version = 6.1.7600) - Type = NTServer
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 163,15 Gb Free Space | 70,06% Space Free | Partition Type: NTFS
Drive E: | 19,28 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: KRUCIFIX-PC | User Name: Krucifix | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/02/26 12:45:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Krucifix\Downloads\OTL(2).exe
PRC - [2011/02/06 20:28:38 | 000,536,576 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe
PRC - [2011/01/20 10:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010/12/03 20:39:33 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
========== Modules (SafeList) ========== MOD - [2011/02/26 12:45:05 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Krucifix\Downloads\OTL(2).exe
MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2011/01/24 18:36:34 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/05/08 12:48:36 | 000,229,376 | ---- | M] () [Auto | Stopped] -- C:\ProgramData\DataCardService\DCService.exe -- (DCService.exe)
SRV - [2009/07/14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ========== DRV - [2011/02/05 19:46:23 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010/05/22 14:48:20 | 000,070,656 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010/04/30 16:52:06 | 000,206,336 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010/03/25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010/03/20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/01/13 16:36:40 | 006,755,840 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5s32.sys -- (NETw5s32) Intel(R)
DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 23:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009/07/13 23:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2007/11/09 05:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\S-1-5-21-3328446074-2473342617-3046448505-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 03 6F 87 15 BB CB 01 [binary data]
IE - HKU\S-1-5-21-3328446074-2473342617-3046448505-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/06 15:53:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/30 09:04:59 | 000,000,000 | ---D | M]
[2011/01/23 17:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krucifix\AppData\Roaming\mozilla\Extensions
[2011/01/23 17:43:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krucifix\AppData\Roaming\mozilla\Firefox\Profiles\a36nt6wl.default\extensions
[2011/02/05 19:46:16 | 000,002,059 | ---- | M] () -- C:\Users\Krucifix\AppData\Roaming\Mozilla\Firefox\Profiles\a36nt6wl.default\searchplugins\daemon-search.xml
[2011/01/23 17:43:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/12/03 19:08:29 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010/12/03 19:08:29 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010/12/03 19:08:29 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010/12/03 19:08:29 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010/12/03 19:08:29 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011/01/26 13:46:02 | 000,000,864 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-3328446074-2473342617-3046448505-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3328446074-2473342617-3046448505-1000..\Run: [Mobile Partner] C:\Program Files\Mobile Partner\Mobile Partner.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\programy\Microsoft office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\programy\Microsoft office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/05/10 20:48:36 | 000,126,976 | R--- | M] () - E:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008/09/19 10:12:34 | 000,000,045 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{032aa990-2708-11e0-ab66-00238babee7c}\Shell - "" = AutoRun
O33 - MountPoints2\{032aa990-2708-11e0-ab66-00238babee7c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{1eb0c5c7-3157-11e0-954a-001e101f21c1}\Shell - "" = AutoRun
O33 - MountPoints2\{1eb0c5c7-3157-11e0-954a-001e101f21c1}\Shell\AutoRun\command - "" = G:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{1eb0c5c7-3157-11e0-954a-001e101f21c1}\Shell\dinstall\command - "" = G:\Directx\dxsetup.exe
O33 - MountPoints2\{3feca4df-294e-11e0-9488-001e101f4da1}\Shell - "" = AutoRun
O33 - MountPoints2\{3feca4df-294e-11e0-9488-001e101f4da1}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{5e914c57-3228-11e0-95f8-00238babee7c}\Shell - "" = AutoRun
O33 - MountPoints2\{5e914c57-3228-11e0-95f8-00238babee7c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{6e323087-3309-11e0-a629-00238babee7c}\Shell - "" = AutoRun
O33 - MountPoints2\{6e323087-3309-11e0-a629-00238babee7c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{75800df3-3225-11e0-beed-00238babee7c}\Shell - "" = AutoRun
O33 - MountPoints2\{75800df3-3225-11e0-beed-00238babee7c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{8e5171b2-2955-11e0-948a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8e5171b2-2955-11e0-948a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{cd02f84a-3282-11e0-a962-00238babee7c}\Shell - "" = AutoRun
O33 - MountPoints2\{cd02f84a-3282-11e0-a962-00238babee7c}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2010/05/10 20:48:36 | 000,126,976 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (
www.helixcommunity.org)
========== Files/Folders - Created Within 30 Days ========== [2011/02/26 11:42:08 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011/02/26 11:31:12 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/02/25 17:57:40 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Malwarebytes
[2011/02/25 17:57:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/02/25 17:57:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/25 17:57:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/02/25 17:57:27 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/02/25 17:57:27 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/25 17:52:03 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/02/24 18:43:33 | 000,895,503 | ---- | C] (free-windows-registry-cleaner.com ) -- C:\Users\Krucifix\Desktop\free-wrc.exe
[2011/02/24 18:08:45 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\VS Revo Group
[2011/02/24 18:08:40 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/02/24 17:44:58 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\ElevatedDiagnostics
[2011/02/24 17:00:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/02/24 17:00:43 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/16 12:00:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Keronsoft
[2011/02/16 12:00:31 | 000,000,000 | ---D | C] -- C:\Program Files\Keronsoft
[2011/02/15 11:51:53 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Media Player Classic
[2011/02/15 11:51:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/02/15 11:51:03 | 000,237,568 | ---- | C] (
www.helixcommunity.org) -- C:\Windows\System32\yv12vfw.dll
[2011/02/15 11:51:03 | 000,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\mp3fhg.acm
[2011/02/15 11:51:03 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm
[2011/02/15 11:51:00 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2011/02/15 11:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\LightTPD
[2011/02/15 11:43:32 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\WMTools Downloaded Files
[2011/02/11 18:10:22 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\Filmy
[2011/02/09 21:17:29 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\Video
[2011/02/09 21:13:04 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\Parazit
[2011/02/09 19:46:53 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\Musica
[2011/02/09 19:38:09 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Juce VST Host
[2011/02/09 19:38:06 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Hardcore
[2011/02/09 15:50:15 | 000,225,280 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\rewire.dll
[2011/02/09 15:50:13 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Documents\Image-Line
[2011/02/09 15:50:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
[2011/02/09 15:50:03 | 001,554,944 | ---- | C] (HMS
http://hp.vector.co.jp/authors/VA012897/) -- C:\Windows\System32\vorbis.acm
[2011/02/09 15:49:52 | 000,000,000 | ---D | C] -- C:\Program Files\VstPlugins
[2011/02/09 15:49:52 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2011/02/09 15:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\Outsim
[2011/02/09 15:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Image-Line
[2011/02/09 14:53:58 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\FL Studio XXL v9.0.0 +UN-LOCKER +UN-LOCKED VSTi [ P.r.t.CreW!] 100% Clean
[2011/02/06 20:38:58 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\Diagnostics
[2011/02/06 20:29:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner
[2011/02/06 20:28:58 | 000,167,936 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_juwwanecm.sys
[2011/02/06 20:28:58 | 000,070,656 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jubusenum.sys
[2011/02/06 20:28:58 | 000,069,632 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcacm.sys
[2011/02/06 20:28:58 | 000,051,584 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_jucdcecm.sys
[2011/02/06 20:28:58 | 000,026,880 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_juextctrl.sys
[2011/02/06 20:28:50 | 000,206,336 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys
[2011/02/06 20:28:50 | 000,105,984 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys
[2011/02/06 20:28:50 | 000,027,136 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys
[2011/02/06 20:28:50 | 000,011,136 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_usbenumfilter.sys
[2011/02/06 20:28:41 | 000,101,504 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ew_hwusbdev.sys
[2011/02/06 20:28:08 | 000,000,000 | ---D | C] -- C:\Program Files\Mobile Partner
[2011/02/05 20:01:34 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2011/02/05 20:01:34 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2011/02/05 20:01:34 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2011/02/05 20:01:34 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2011/02/05 20:01:34 | 000,018,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_2.dll
[2011/02/05 20:01:33 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2011/02/05 20:01:32 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2011/02/05 20:01:32 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2011/02/05 20:01:31 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2011/02/05 20:01:31 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2011/02/05 20:01:31 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2011/02/05 20:01:30 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2011/02/05 20:01:30 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2011/02/05 20:01:30 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2011/02/05 20:01:30 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2011/02/05 20:01:30 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2011/02/05 20:01:20 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2011/02/05 20:01:20 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2011/02/05 20:01:19 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2011/02/05 20:01:19 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2011/02/05 20:01:19 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2011/02/05 20:01:18 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2011/02/05 20:01:18 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2011/02/05 20:01:18 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2011/02/05 20:01:18 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2011/02/05 20:00:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/02/05 19:56:01 | 000,000,000 | ---D | C] -- C:\Program Files\Activision
[2011/02/05 19:46:23 | 000,218,688 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2011/02/05 19:46:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011/02/05 19:46:09 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2011/02/05 19:41:01 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\DAEMON Tools Lite
[2011/02/05 19:41:01 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2011/01/31 20:09:57 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Documents\The KMPlayer
[2011/01/31 10:05:10 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\World in Conflict
[2011/01/31 10:04:54 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Documents\World in Conflict
[2011/01/31 10:04:36 | 000,000,000 | RH-D | C] -- C:\Users\Krucifix\AppData\Roaming\SecuROM
[2011/01/31 10:02:41 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2011/01/31 10:02:41 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2011/01/31 10:02:41 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2011/01/31 10:02:41 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2011/01/31 10:02:40 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2011/01/31 10:02:40 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2011/01/31 10:02:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
[2011/01/31 09:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\Sierra Entertainment
[2011/01/31 09:46:18 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\InstallShield
[2011/01/30 09:05:40 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Local\Adobe
[2011/01/30 09:04:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/01/30 09:04:49 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/01/30 09:03:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2011/01/29 22:37:35 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\WinRAR
[2011/01/29 22:29:15 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\Desktop\CoD
[2011/01/29 16:54:47 | 000,000,000 | ---D | C] -- C:\Program Files\Valve
[2011/01/29 16:54:46 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/01/29 16:54:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2011/01/29 16:23:07 | 000,000,000 | ---D | C] -- C:\Users\Krucifix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2011/01/29 16:22:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6
[2011/01/29 16:21:07 | 000,000,000 | ---D | C] -- C:\Program Files\Counter-Strike 1.6
========== Files - Modified Within 30 Days ========== [2011/02/26 11:41:48 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/02/26 11:41:48 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/02/26 11:36:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/02/26 11:36:51 | 1504,337,920 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/26 11:31:23 | 000,018,128 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/26 11:31:23 | 000,018,128 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/25 17:57:30 | 000,001,031 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/25 17:50:31 | 000,015,264 | ---- | M] () -- C:\Users\Krucifix\Documents\cc_20110225_175002.reg
[2011/02/24 18:43:46 | 000,001,037 | ---- | M] () -- C:\Users\Public\Desktop\Error Repair Professional.lnk
[2011/02/24 17:00:45 | 000,000,929 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/02/16 12:00:34 | 000,001,060 | ---- | M] () -- C:\Users\Krucifix\Desktop\iMPEG Converter.lnk
[2011/02/15 11:52:33 | 000,037,363 | ---- | M] () -- C:\Users\Krucifix\Desktop\malickosť.wlmp
[2011/02/15 11:36:21 | 000,002,495 | ---- | M] () -- C:\Users\Krucifix\Desktop\Windows Movie Maker 2.6.lnk
[2011/02/09 15:50:14 | 000,001,061 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 9.lnk
[2011/02/06 20:29:15 | 000,001,001 | ---- | M] () -- C:\Users\Public\Desktop\Mobile Partner.lnk
[2011/02/06 15:53:23 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2011/02/05 20:01:10 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2011/02/05 20:01:10 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2011/02/05 20:00:36 | 000,000,319 | ---- | M] () -- C:\Windows\game.ini
[2011/02/05 19:46:23 | 000,218,688 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2011/02/05 19:46:10 | 000,001,900 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/02/02 17:11:20 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2011/01/30 09:05:00 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/01/29 16:54:47 | 000,001,622 | ---- | M] () -- C:\Users\Public\Desktop\Counter-Strike 1.6.lnk
[2011/01/29 16:22:50 | 000,001,005 | ---- | M] () -- C:\Users\Public\Desktop\Half-Life.lnk
[2011/01/28 09:00:00 | 000,080,896 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll
[2011/01/28 09:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini
========== Files Created - No Company Name ========== [2011/02/25 17:57:30 | 000,001,031 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/25 17:50:05 | 000,015,264 | ---- | C] () -- C:\Users\Krucifix\Documents\cc_20110225_175002.reg
[2011/02/24 18:43:46 | 000,001,037 | ---- | C] () -- C:\Users\Public\Desktop\Error Repair Professional.lnk
[2011/02/24 17:00:45 | 000,000,929 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/02/16 12:00:34 | 000,001,060 | ---- | C] () -- C:\Users\Krucifix\Desktop\iMPEG Converter.lnk
[2011/02/15 11:52:49 | 000,037,363 | ---- | C] () -- C:\Users\Krucifix\Desktop\malickosť.wlmp
[2011/02/15 11:51:05 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/02/15 11:51:04 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/02/15 11:51:03 | 000,810,496 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/02/15 11:51:03 | 000,183,808 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/02/15 11:51:03 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/02/15 11:38:22 | 000,002,495 | ---- | C] () -- C:\Users\Krucifix\Desktop\Windows Movie Maker 2.6.lnk
[2011/02/09 21:58:38 | 001,125,123 | ---- | C] () -- C:\Users\Krucifix\Desktop\sirava.JPG
[2011/02/09 21:05:07 | 004,183,030 | ---- | C] () -- C:\Users\Krucifix\Desktop\02 Balls Out.wma
[2011/02/09 20:08:13 | 143,708,872 | ---- | C] () -- C:\Users\Krucifix\Desktop\Carl Cox - Essential Mix - 27 May 07.mp3
[2011/02/09 15:50:14 | 000,001,061 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 9.lnk
[2011/02/06 20:29:15 | 000,001,001 | ---- | C] () -- C:\Users\Public\Desktop\Mobile Partner.lnk
[2011/02/06 15:53:23 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/05 20:01:10 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk
[2011/02/05 20:01:10 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk
[2011/02/05 20:00:35 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2011/02/05 19:46:10 | 000,001,900 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/01/30 09:05:00 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/01/30 09:05:00 | 000,001,989 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/01/29 16:22:50 | 000,001,622 | ---- | C] () -- C:\Users\Public\Desktop\Counter-Strike 1.6.lnk
[2011/01/29 16:22:50 | 000,001,005 | ---- | C] () -- C:\Users\Public\Desktop\Half-Life.lnk
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,343,112 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,607,190 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,103,568 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/13 23:09:19 | 000,982,196 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2009/07/13 23:09:19 | 000,417,344 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2009/07/13 23:09:19 | 000,139,824 | ---- | C] () -- C:\Windows\System32\igfcg500.bin
[2009/07/13 23:09:19 | 000,097,448 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== Custom Scans ========== < HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2011/01/20 10:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd)
"Mobile Partner" = "C:\Program Files\Mobile Partner\Mobile Partner.exe" -- [2011/02/06 20:28:38 | 000,536,576 | ---- | M] ()
< c:\windows\*.* /U > < MD5 for: AGP440.SYS >[2008/04/14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
< MD5 for: ATAPI.SYS >[2008/04/14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: EXPLORER.EXE >[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: HAL.DLL >[2008/04/14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\sp3.cab:hal.dll
[2009/07/14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\System32\hal.dll
[2009/07/14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_aaff48c7bafdccc6\hal.dll
< MD5 for: IASTORV.SYS >[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\drivers\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
< MD5 for: LSASS.EXE >[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\System32\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_a620e0e5be1ecda7\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_a61fe281be1fb177\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_a69eaf60d7456d32\lsass.exe
< MD5 for: NDIS.SYS >[2009/07/14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\System32\drivers\ndis.sys
[2009/07/14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_a79d81ea7d62a289\ndis.sys
< MD5 for: NETLOGON.DLL >[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVSTOR.SYS >[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL >[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< MD5 for: SMSS.EXE >[2009/07/14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\System32\smss.exe
[2009/07/14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
[2008/04/14 13:00:00 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=F209B5C79A87A9521DC0BD88B039EEE3 -- C:\I386\SYSTEM32\SMSS.EXE
< MD5 for: SVCHOST.EXE >[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
< MD5 for: USERINIT.EXE >[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
< MD5 for: WINLOGON.EXE >[2009/10/28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009/10/28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2_32.DLL >[2009/07/14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\System32\ws2_32.dll
[2009/07/14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >< End of report >