zbytek logu otl:
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.CDV5 - C:\Windows\System32\cdv5codc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CDVC - C:\Windows\System32\cdvccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CDVH - C:\Windows\System32\cdvhcodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CLLC - C:\Windows\System32\cllccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CMIC - C:\Windows\System32\cmiccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.CUVC - C:\Windows\System32\cuvccodc.dll (Canopus Co., Ltd.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (
www.helixcommunity.org)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ==========
[2010/11/28 22:46:34 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Robin\Desktop\OTL.exe
[2010/11/28 19:47:05 | 000,000,000 | ---D | C] -- C:\rsit
[2010/11/28 19:25:41 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/11/28 19:23:55 | 001,187,896 | ---- | C] (Piriform Ltd) -- C:\Users\Robin\Desktop\ccleaner.exe
[2010/11/27 01:16:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/11/27 01:16:50 | 000,000,000 | ---D | C] -- C:\Program Files\DNA
[2010/11/27 01:16:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\temp
[2010/11/27 01:07:32 | 002,613,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010/11/25 19:32:30 | 000,000,000 | ---D | C] -- C:\found.002
[2010/11/25 18:18:20 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\vlc
[2010/11/20 12:00:09 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\montana
[2010/11/19 23:46:18 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\STRUKTURA
[2010/11/11 10:53:11 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Western_Digital
[2010/11/09 11:57:51 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\robin
[2010/11/09 09:04:50 | 000,000,000 | ---D | C] -- C:\Program Files\Western Digital
[2010/11/08 21:51:38 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/11/08 21:51:16 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/11/08 18:11:10 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Malwarebytes
[2010/11/08 18:10:59 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/08 18:10:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/11/08 15:09:03 | 000,000,000 | ---D | C] -- C:\found.001
[2010/11/08 10:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010/11/01 19:53:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Western Digital
[2010/11/01 19:50:05 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\Western Digital
[2010/11/01 09:12:56 | 000,000,000 | ---D | C] -- C:\found.000
[2010/10/30 18:13:24 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\robin-loga
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/28 22:46:40 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Robin\Desktop\OTL.exe
[2010/11/28 19:48:41 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 19:48:41 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 19:48:20 | 000,339,991 | ---- | M] () -- C:\Users\Robin\Desktop\RSIT.exe
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 4).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 3).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 2).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Daily 1).job
[2010/11/28 19:43:25 | 000,067,584 | --S- | M] () -- C:\Windows\BootStat.dat
[2010/11/28 19:43:22 | 1610,014,720 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/28 19:41:54 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/11/28 19:41:54 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/11/28 19:25:42 | 000,000,965 | ---- | M] () -- C:\Users\Robin\Desktop\CCleaner.lnk
[2010/11/28 19:23:59 | 001,187,896 | ---- | M] (Piriform Ltd) -- C:\Users\Robin\Desktop\ccleaner.exe
[2010/11/25 18:17:48 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/11/17 16:04:02 | 000,008,808 | ---- | M] () -- C:\Users\Robin\Documents\Zaloba_Robin Kaleta.docx
[2010/11/10 08:50:12 | 000,216,138 | ---- | M] () -- C:\Windows\hpoins40.dat
[2010/11/10 04:18:43 | 000,013,679 | ---- | M] () -- C:\Users\Robin\Documents\Zaloba_Robin Kaletadoplneni.docx
[2010/11/09 09:05:35 | 000,001,318 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk
[2010/11/08 22:04:16 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/11/01 12:28:57 | 000,003,584 | ---- | M] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/31 19:25:20 | 001,628,856 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/28 19:48:18 | 000,339,991 | ---- | C] () -- C:\Users\Robin\Desktop\RSIT.exe
[2010/11/28 19:25:42 | 000,000,965 | ---- | C] () -- C:\Users\Robin\Desktop\CCleaner.lnk
[2010/11/27 00:52:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/11/27 00:52:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 4).job
[2010/11/27 00:52:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 3).job
[2010/11/27 00:52:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 2).job
[2010/11/27 00:52:56 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Daily 1).job
[2010/11/26 02:16:02 | 000,067,584 | --S- | C] () -- C:\Windows\BootStat.dat
[2010/11/18 11:16:47 | 173,975,152 | ---- | C] () -- C:\Users\Robin\Desktop\AVP-FINAL2.mov
[2010/11/10 08:50:12 | 000,000,992 | ---- | C] () -- C:\Windows\hpomdl40.dat.temp
[2010/11/10 04:18:43 | 000,013,679 | ---- | C] () -- C:\Users\Robin\Documents\Zaloba_Robin Kaletadoplneni.docx
[2010/11/10 03:21:56 | 000,008,808 | ---- | C] () -- C:\Users\Robin\Documents\Zaloba_Robin Kaleta.docx
[2010/11/09 09:05:35 | 000,001,318 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk
[2010/07/19 15:59:15 | 000,003,584 | ---- | C] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/03 19:15:23 | 000,001,024 | ---- | C] () -- C:\Windows\System32\pavplal.dll
[2010/02/03 18:56:40 | 000,030,720 | ---- | C] () -- C:\Windows\System32\pavedius.dll
[2010/02/03 18:11:24 | 000,065,536 | ---- | C] () -- C:\Windows\System32\pavedius5db.dll
[2010/01/27 11:42:01 | 000,003,038 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010/01/27 10:22:28 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/01/24 14:43:01 | 007,979,008 | ---- | C] () -- C:\Windows\System32\atioglxx.dll
[2010/01/24 14:43:01 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2010/01/24 14:33:40 | 000,178,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/01/24 14:33:39 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010/01/24 14:33:38 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/01/24 14:33:38 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/01/24 14:33:37 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/01/24 14:05:18 | 000,110,592 | R--- | C] () -- C:\Windows\System32\scardsyn.dll
[2010/01/24 14:05:18 | 000,069,632 | R--- | C] () -- C:\Windows\System32\ODMA32.dll
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2005/05/06 18:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
========== LOP Check ==========
[2010/02/02 19:59:35 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\AVG9
[2010/01/24 15:10:06 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\BSplayer
[2010/01/24 15:01:10 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\BSplayer Pro
[2010/02/03 19:20:32 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Canopus
[2010/11/28 22:44:00 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\DNA
[2010/01/27 10:53:47 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\GHISLER
[2010/07/25 18:10:25 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\IrfanView
[2010/01/24 21:47:17 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\OpenOffice.org
[2010/11/16 22:30:34 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\uTorrent
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 1).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 2).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 3).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Daily 4).job
[2010/11/28 19:44:39 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/11/12 16:16:01 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"BitTorrent DNA" = "C:\Users\Robin\Program Files\DNA\btdna.exe" -- [2010/01/24 13:43:25 | 000,323,392 | ---- | M] (BitTorrent, Inc.)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010/11/09 12:24:15 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Adobe
[2010/02/05 09:42:15 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Apple Computer
[2010/02/02 19:59:35 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\AVG9
[2010/01/24 15:10:06 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\BSplayer
[2010/01/24 15:01:10 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\BSplayer Pro
[2010/02/03 19:20:32 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Canopus
[2010/11/28 22:44:00 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\DNA
[2010/11/28 21:44:47 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\dvdcss
[2010/01/27 10:53:47 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\GHISLER
[2010/01/27 12:20:54 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\HP
[2010/01/24 21:51:50 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Identities
[2010/01/24 14:15:31 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\InstallShield
[2010/07/25 18:10:25 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\IrfanView
[2010/01/24 13:39:40 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Macromedia
[2010/11/08 18:11:10 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Malwarebytes
[2009/07/14 08:48:45 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Media Center Programs
[2010/11/28 19:27:28 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Media Player Classic
[2010/11/09 09:07:36 | 000,000,000 | --SD | M] -- C:\Users\Robin\AppData\Roaming\Microsoft
[2010/01/24 22:28:17 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Mozilla
[2010/04/26 13:26:54 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Nero
[2010/01/24 21:47:17 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\OpenOffice.org
[2010/11/27 00:36:56 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\Skype
[2010/11/27 00:00:06 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\skypePM
[2010/11/16 22:30:34 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\uTorrent
[2010/11/28 21:50:42 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\vlc
[2010/02/03 18:52:06 | 000,000,000 | ---D | M] -- C:\Users\Robin\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2007/08/18 18:54:02 | 000,020,480 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
[2007/08/18 18:53:50 | 000,016,384 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\AC3 Filter\dialog_patch.exe
[2008/04/14 02:26:54 | 000,036,396 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\AC3 Filter\uninstall.exe
[2008/04/01 20:51:06 | 000,691,717 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\FFDShow\unins000.exe
[2008/03/30 02:42:00 | 000,103,424 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
[2008/03/30 02:42:02 | 000,335,872 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
[2008/03/30 02:41:54 | 000,135,168 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
[2008/06/10 18:11:02 | 000,041,412 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
[2010/01/24 14:44:06 | 000,010,134 | R--- | M] () -- C:\Users\Robin\AppData\Roaming\Microsoft\Installer\{6E32B134-CA8D-49DD-B94C-0DB155CE70B5}\ARPPRODUCTICON.exe
[2010/01/24 14:44:06 | 000,009,158 | R--- | M] () -- C:\Users\Robin\AppData\Roaming\Microsoft\Installer\{6E32B134-CA8D-49DD-B94C-0DB155CE70B5}\NewShortcut1_45160C5661F6468DA5B09FAE2C3E68D6.exe
< MD5 for: AGP440.SYS >
[2004/08/17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\ERDNT\cache\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2004/08/17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\ERDNT\cache\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\Windows.old\Windows\system32\drivers\atapi.sys
< MD5 for: CDROM.SYS >
[2004/08/17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:cdrom.sys
[2004/08/03 21:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\Windows.old\Windows\system32\drivers\cdrom.sys
[2009/07/14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\drivers\cdrom.sys
[2009/07/14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_db87d184bc84f910\cdrom.sys
[2009/07/14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_5f7fb206051affbb\cdrom.sys
< MD5 for: CHANGER.SYS >
[2004/08/17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:Changer.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\ERDNT\cache\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2004/08/17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\Windows.old\Windows\system32\cryptsvc.dll
[2004/08/17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\Windows.old\Windows\system32\dllcache\cryptsvc.dll
[2009/07/14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\ERDNT\cache\cryptsvc.dll
[2009/07/14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\System32\cryptsvc.dll
[2009/07/14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2004/08/17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\Windows.old\Windows\system32\dllcache\eventlog.dll
[2004/08/17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\Windows.old\Windows\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\ERDNT\cache\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\explorer.exe
[2004/08/17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\Windows.old\Windows\explorer.exe
[2004/08/17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\Windows.old\Windows\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004/08/17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp2.cab:hal.dll
[2009/07/14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\System32\hal.dll
[2009/07/14 02:20:28 | 000,194,640 | ---- | M] (Microsoft Corporation) MD5=9A557EAE64ABAB3BA67A9BB035D24CB9 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_aaff48c7bafdccc6\hal.dll
[2004/08/03 21:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\Windows.old\Windows\system32\hal.dll
< MD5 for: IASTORV.SYS >
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\drivers\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2001/10/24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\Windows.old\Windows\system32\dllcache\isapnp.sys
[2001/10/24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\Windows.old\Windows\system32\drivers\isapnp.sys
[2001/10/25 15:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\Windows.old\Windows\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys
[2009/07/14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\drivers\isapnp.sys
[2009/07/14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\isapnp.sys
[2009/07/14 02:20:36 | 000,046,656 | ---- | M] (Microsoft Corporation) MD5=1F32BB6B38F62F7DF1A7AB7292638A35 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\isapnp.sys
< MD5 for: LSASS.EXE >
[2004/08/17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\Windows.old\Windows\system32\dllcache\lsass.exe
[2004/08/17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\Windows.old\Windows\system32\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\ERDNT\cache\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\System32\lsass.exe
[2009/07/14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=F42309C4191C506B71DB5D1126D26318 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_a620e0e5be1ecda7\lsass.exe
< MD5 for: NDIS.SYS >
[2009/07/14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\ERDNT\cache\ndis.sys
[2009/07/14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\System32\drivers\ndis.sys
[2009/07/14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_a79d81ea7d62a289\ndis.sys
[2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\Windows.old\Windows\system32\dllcache\ndis.sys
[2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\Windows.old\Windows\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004/08/17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\Windows.old\Windows\system32\dllcache\netlogon.dll
[2004/08/17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\Windows.old\Windows\system32\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\ERDNT\cache\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll
< MD5 for: NVRAID.SYS >
[2009/07/14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\System32\drivers\nvraid.sys
[2009/07/14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvraid.sys
[2009/07/14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) MD5=3F3D04B1D08D43C16EA7963954EC768D -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2004/08/17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\Windows.old\Windows\system32\dllcache\scecli.dll
[2004/08/17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\Windows.old\Windows\system32\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll
< MD5 for: SMSS.EXE >
[2004/08/17 14:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\Windows.old\Windows\system32\dllcache\smss.exe
[2004/08/17 14:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\Windows.old\Windows\system32\smss.exe
[2009/07/14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\System32\smss.exe
[2009/07/14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) MD5=16742790895960690237A5143CEDEC8B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_ac10fe207a85352b\smss.exe
< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2004/08/17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\Windows.old\Windows\system32\dllcache\svchost.exe
[2004/08/17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\Windows.old\Windows\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2009/07/14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\ERDNT\cache\tcpip.sys
[2009/07/14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\System32\drivers\tcpip.sys
[2009/07/14 02:19:10 | 001,285,712 | ---- | M] (Microsoft Corporation) MD5=2CC3D75488ABD3EC628BBB9A4FC84EFC -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_b2f46875c7b9d667\tcpip.sys
[2004/08/03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\Windows.old\Windows\system32\dllcache\tcpip.sys
[2004/08/03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\Windows.old\Windows\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\System32\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2004/08/17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\Windows.old\Windows\system32\dllcache\userinit.exe
[2004/08/17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\Windows.old\Windows\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\Windows.old\Windows\system32\dllcache\winlogon.exe
[2004/08/17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\Windows.old\Windows\system32\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\ERDNT\cache\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\System32\winlogon.exe
[2009/07/14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004/08/17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\Windows.old\Windows\system32\dllcache\ws2_32.dll
[2004/08/17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\Windows.old\Windows\system32\ws2_32.dll
[2009/07/14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\ERDNT\cache\ws2_32.dll
[2009/07/14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\System32\ws2_32.dll
[2009/07/14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
GINADLL REG_SZ C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\bin\ocgina.dll
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010/11/28 19:48:41 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 19:48:41 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 19:41:54 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/11/28 19:41:54 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/11/28 19:41:54 | 000,713,888 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
< End of report >